Logo Questions Linux Laravel Mysql Ubuntu Git Menu
 

What is the purpose behind the personalized security image often used on banking websites?

Tags:

security

Many banking websites have you select your own security image when creating your account. For subsequent log ins the image is displayed along with a caption, if you do not see the image and caption you chose, you are instructed not to log in.

What is the purpose of this added step, which type of attacks does it protect against?

Thanks!

like image 671
StapleGun Avatar asked May 10 '12 13:05

StapleGun


People also ask

What is the purpose of a security image?

About a decade ago, banks began introducing security images — photos of beaches, teapots, coffee and foods, among other options users can select from — as a way to show customers that the web page they were logging into was legitimate and not a phony website designed by a fraudster.

What is security picture?

Security Picture means an image that is being displayed to you as an anti-phishing security measure to ensure that you have logged in to the genuine Connect portal.


1 Answers

Short answer:

Phishing.

Long story:

If you receive a fake email instructing you to log in to your bank account following this link: http://i.am.an.cyber.pirate.com/give/me/your/money/paypal/official/site/ultra/secured/website/

And because you don't know about that kind of people, you click on it, but since you don't see your custom image, you know that you are not on the official site, because you, and only you should know about this image.

Let's say you choosed a picture of your dog and see your neighboor cat, well, don't log in then.

like image 62
Boris Guéry Avatar answered Nov 12 '22 20:11

Boris Guéry