Mark Bowytz

Besides contributing at @TheDailyWTF, I write DevDisasters for Visual Studio Magazine, and involved in various side projects including child rearing and marriage.

Sep 2011

WTF Factor Authentication

by in Feature Articles on

Recently, when Jeff T’s credit union enhanced its online banking, it forced him to re-register his account under the new system. He thought that this was strange because, well, the "old" system was fairly reasonable. Beside the usual username and password, they had your typical Wish-It-Was Two Factor authentication and an even anti-phishing image presented during the logon process to make you feel that much more secure. It wasn't great, but it wasn't Harland Financial bad.

However, this new system didn’t inspire a ton of confidence. First, were the security questions. The previous security questions allowed for any old free-typed answer, but instead, they were replaced with different set of really dumb questions, each one limited to a dropdown of possible answers.