# The futility of site key images

**URL:** <https://boards.straightdope.com/t/the-futility-of-site-key-images/591480>\
**Category:** Factual Questions\
**Created:** [August 4, 2011, 5:25pm UTC](https://boards.straightdope.com/t/the-futility-of-site-key-images/591480 "2011-08-04T17:25:49Z")\
**Posts on this page:** 3\
**Page:** 2

<div class="post-metadata">

**Author:** ![Mr.Slant](https://avatars.discourse-cdn.com/v4/letter/m/c57346/32.png) [@Mr.Slant](https://boards.straightdope.com/u/Mr.Slant)\
**Post date:** [August 5, 2011, 4:36am UTC](https://boards.straightdope.com/t/the-futility-of-site-key-images/591480/21 "2011-08-05T04:36:00Z")

</div>

Note that if you’re a large bank, and these tools result in even a 5% decrease in fraud losses that the bank is unable to recover, they are still worth millions to you.

---

<div class="post-metadata">

**Author:** ![rbroome](https://avatars.discourse-cdn.com/v4/letter/r/838e76/32.png) [@rbroome](https://boards.straightdope.com/u/rbroome)\
**Post date:** [August 5, 2011, 11:47am UTC](https://boards.straightdope.com/t/the-futility-of-site-key-images/591480/22 "2011-08-05T11:47:48Z")

</div>

> [@CookingWithGas](#):
>
> I manage a group that implemented two-factor authentication for Department of Education employees this year. Site keys ain’t it. A site key isn’t user authentication at all. It’s \*site \*authentication. (We implemented TFA by using VeriSign tokens that generate sequences of numbers.)
> 
> BTW can a MITM site spoof the user’s computer to the genuine site? I am not a web developer and I don’t know what info a browser gets in the HTTP request that identifies a computer–I know that it can get an IP address, but that wouldn’t work well for dynamic IP assignment. MAC address?.

you are correct. site authentication is not two factor id. I mixed the ideas up. But my point that the site key idea was in response to a Gov’t (I believe Federal Reserve) regulation that also envisioned two factor authentication. Since site id is cheaper that is what got implemented even though it doesn’t help much with security.

---

<div class="post-metadata">

**Author:** ![CookingWithGas](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/cookingwithgas/32/485_2.png) [@CookingWithGas](https://boards.straightdope.com/u/CookingWithGas)\
**Post date:** [August 9, 2011, 3:05pm UTC](https://boards.straightdope.com/t/the-futility-of-site-key-images/591480/23 "2011-08-09T15:05:09Z")

</div>

> [@Alley\_Dweller](#):
>
> I don’t know if I should post the exact mechanism in public, but it would be be trivially easy for a MITM to spoof the user’s computer. No, it doesn’t use IP or MAC addresses. It’s so trivially simple, I discovered it in just using the web site and doing normal things I do everyday on my computer and noticing that after I did a certain thing, it would ask me the security questions and if I did not do this certain thing, it would not ask me the questions until I did the thing again.

I wouldn’t want you to post a “how to hack” tutorial, although I note that what you did was entirely on your own computer. The bank’s web site does seem to detect if I am on a computer it does not recognize, and it re-authenticates me with challenge questions. So I have two theories about how this could work, but like I said I’m not a web developer so this might be naive:

1. HTTP includes data in the request header that uniquely identifies your computer. The bank keeps a record of that. In that case a MITM can simply read your header and spoof it when it forwards the request to the bank.

2. The bank’s site stores a unique identifier in a cookie, and checks the cookie when you log in. In that case a MITM could read the same cookie and simulate it on the attacking computer for when it forwards the login to the bank. However, I don’t know the underlying mechanism for how cookies work and if there is any security on them. That is, can any web site I connect to read any cookie they want?

[Previous page](https://boards.straightdope.com/t/the-futility-of-site-key-images/591480.md?page=1)
