SYS-CON MEDIA Authors: Greg Ness, Sean Houghton, Glenn Rossman, Ignacio M. Llorente, Xenia von Wedel

News Feed Item

Banking Websites Pose Easy Target for Malicious WIFI Hotspots

AACHEN, GERMANY and BOSTON, MA -- (Marketwired) -- 05/29/14 -- Recent studies in the Netherlands showed that consumers who are sending Internet banking transactions through a malicious WIFI hotspot could be easily manipulated if the SSL security is switched off during communication. For only $100 cyber criminals can buy a malicious WIFI router, which will give them access to any data sent through the hotspot in order to intercept passwords and to manipulate payment transactions.

Today every large city has hundreds of WIFI hotspots available, free to access and easy to use but it's very difficult or even impossible to identify whether a WIFI hotspot is malicious or not. To solve the problem of disabling the SSL security, most Dutch banks and web browsers are now supporting the new HTTP Strict Transport Security (HSTS) protocol to ensure that the communication security between the consumer and the bank is guaranteed. The problem however is that not all browsers, like the current Microsoft Internet Explorer version, are supporting the new web security standard.

The security leak is very serious according to SecureLabs, a Dutch security company that has tested the security of Dutch banking websites using a malicious WIFI hotspot. The risk heightens especially when using Microsoft IE or any other outdated Internet browser. As long as all online banking websites and browser vendors are not embracing the new security standard, the SSL web security can be easily bypassed with a cheap and easily assessable WIFI hotspot.

Several Dutch banks have now implemented fraud detection technology from INFORM GmbH to avoid this problem. With RiskShield, INFORM GmbH offers a real-time fraud detection solution that monitors transaction details and web anomalies to identify unusual behavior when payments are processed through hotspots.

"Most of the larger banks in the Netherlands are using RiskShield to protect them from fraudulent payments. With RiskShield we provide them the tools to respond quickly to the new modus operandi of cyber criminals. The new cyber threat is a good example of how critical it is for banks to be able to quickly react to new types of threats. It allows them to easily adapt the detection rules in a short timeframe and without any IT involvement. Banking websites are not the only targets. Any other online merchants like airlines or web shops are vulnerable to these cyber hacks," says Stanley Harmsen van der Vliet, Product Marketing Manager of INFORM GmbH.

For more information about RiskShield, please visit our website at www.riskshield.com or call us at +49 2408 9456 5000.

About INFORM GmbH

INFORM develops and markets software systems to optimize business processes on the basis of operations research and fuzzy logic. Using these two technologies, INFORM is able to develop software systems that "think" and can make intelligent decisions. The benefits for users are better on-time delivery performance, lower costs and a significant competitive advantage.

More than 1000 companies worldwide benefit from advanced optimization software systems by INFORM in industries such as transport logistics, airport resource management, production planning, financial crime risk management and insurance claims handling optimization. INFORM employs over 500 staff from more than 30 countries.

Contact RiskShield
INFORM GmbH
Caroline Lenkitsch
Risk & Fraud Division
Pascalstrasse 23, 52076 Aachen, Germany
Phone: +49 2408-9456-5000
E-Mail: Email Contact

Contact INFORM Communications
INFORM GmbH
Sabine Walter
Pascalstrasse 23, 52076 Aachen, Germany
Phone: +49 2408 9456-1233
E-Mail: Email Contact

US Media Relations Contact
Valerie Harding
Ripple Effect Communications
Phone: 617-429-8628
E-Mail: Email Contact

More Stories By Marketwired .

Copyright © 2009 Marketwired. All rights reserved. All the news releases provided by Marketwired are copyrighted. Any forms of copying other than an individual user's personal reference without express written permission is prohibited. Further distribution of these materials is strictly forbidden, including but not limited to, posting, emailing, faxing, archiving in a public database, redistributing via a computer network or in a printed form.

Latest Stories
15th Cloud Expo, which took place Nov. 4-6, 2014, at the Santa Clara Convention Center in Santa Clara, CA, expanded the conference content of @ThingsExpo, Big Data Expo, and DevOps Summit to include two developer events. IBM held a Bluemix Developer Playground on November 5 and ElasticBox held a Hackathon on November 6. Both events took place on the expo floor. The Bluemix Developer Playground, for developers of all levels, highlighted the ease of use of Bluemix, its services and functionalit...
SYS-CON Media announced today that Skytap blog on "DevOps Journal" exceeded 84,000 story reads. DevOps Journal is focused on this critical enterprise IT topic in the world of cloud computing. DevOps Journal brings valuable information to DevOps professionals who are transforming the way enterprise IT is done. Noel Wurst is the managing content editor at Skytap. Skytap provides SaaS-based dev/test environments to the enterprise. Skytap solution removes the inefficiencies and constraints that comp...
SYS-CON Events announced today that Gridstore™, the leader in hyper-converged infrastructure purpose-built to optimize Microsoft workloads, will exhibit at SYS-CON's 16th International Cloud Expo®, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY. Gridstore™ is the leader in hyper-converged infrastructure purpose-built for Microsoft workloads and designed to accelerate applications in virtualized environments. Gridstore’s hyper-converged infrastructure is the ...
In her General Session at 15th Cloud Expo, Anne Plese, Senior Consultant, Cloud Product Marketing, at Verizon Enterprise, focused on finding the right mix of renting vs. buying Oracle capacity to scale to meet business demands, and offer validated Oracle database TCO models for Oracle development and testing environments. Anne Plese is a marketing and technology enthusiast/realist with over 19+ years in high tech. At Verizon Enterprise, she focuses on driving growth for the Verizon Cloud platfo...
The 3rd International @ThingsExpo, co-located with the 16th International Cloud Expo - to be held June 9-11, 2015, at the Javits Center in New York City, NY - announces that it is now accepting Keynote Proposals. The Internet of Things (IoT) is the most profound change in personal and enterprise IT since the creation of the Worldwide Web more than 20 years ago. All major researchers estimate there will be tens of billions devices - computers, smartphones, tablets, and sensors - connected to th...
"There is a natural synchronization between the business models, the IoT is there to support ,” explained Brendan O'Brien, Co-founder and Chief Architect of Aria Systems, in this SYS-CON.tv interview at the 15th International Cloud Expo®, held Nov 4–6, 2014, at the Santa Clara Convention Center in Santa Clara, CA.
The Internet of Things promises to transform businesses (and lives), but navigating the business and technical path to success can be difficult to understand. In his session at @ThingsExpo, Sean Lorenz, Technical Product Manager for Xively at LogMeIn, demonstrated how to approach creating broadly successful connected customer solutions using real world business transformation studies including New England BioLabs and more.
The Internet of Things will greatly expand the opportunities for data collection and new business models driven off of that data. In her session at @ThingsExpo, Esmeralda Swartz, CMO of MetraTech, discussed how for this to be effective you not only need to have infrastructure and operational models capable of utilizing this new phenomenon, but increasingly service providers will need to convince a skeptical public to participate. Get ready to show them the money!
How do APIs and IoT relate? The answer is not as simple as merely adding an API on top of a dumb device, but rather about understanding the architectural patterns for implementing an IoT fabric. There are typically two or three trends: Exposing the device to a management framework Exposing that management framework to a business centric logic Exposing that business layer and data to end users. This last trend is the IoT stack, which involves a new shift in the separation of what stuff happe...
WebRTC defines no default signaling protocol, causing fragmentation between WebRTC silos. SIP and XMPP provide possibilities, but come with considerable complexity and are not designed for use in a web environment. In his session at @ThingsExpo, Matthew Hodgson, technical co-founder of the Matrix.org, discussed how Matrix is a new non-profit Open Source Project that defines both a new HTTP-based standard for VoIP & IM signaling and provides reference implementations.
"ElasticBox is an enterprise company that makes it very easy for developers and IT ops to collaborate to develop, build and deploy applications on any cloud - private, public or hybrid," stated Monish Sharma, VP of Customer Success at ElasticBox, in this SYS-CON.tv interview at DevOps Summit, held Nov 4–6, 2014, at the Santa Clara Convention Center in Santa Clara, CA.
The definition of IoT is not new, in fact it’s been around for over a decade. What has changed is the public's awareness that the technology we use on a daily basis has caught up on the vision of an always on, always connected world. If you look into the details of what comprises the IoT, you’ll see that it includes everything from cloud computing, Big Data analytics, “Things,” Web communication, applications, network, storage, etc. It is essentially including everything connected online from ha...
The Internet of Things is tied together with a thin strand that is known as time. Coincidentally, at the core of nearly all data analytics is a timestamp. When working with time series data there are a few core principles that everyone should consider, especially across datasets where time is the common boundary. In his session at Internet of @ThingsExpo, Jim Scott, Director of Enterprise Strategy & Architecture at MapR Technologies, discussed single-value, geo-spatial, and log time series dat...
An entirely new security model is needed for the Internet of Things, or is it? Can we save some old and tested controls for this new and different environment? In his session at @ThingsExpo, New York's at the Javits Center, Davi Ottenheimer, EMC Senior Director of Trust, reviewed hands-on lessons with IoT devices and reveal a new risk balance you might not expect. Davi Ottenheimer, EMC Senior Director of Trust, has more than nineteen years' experience managing global security operations and asse...
SYS-CON Events announced today Isomorphic Software, the global leader in high-end, web-based business applications, will exhibit at SYS-CON's DevOps Summit 2015 New York, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY. Isomorphic Software is the global leader in high-end, web-based business applications. We develop, market, and support the SmartClient & Smart GWT HTML5/Ajax platform, combining the productivity and performance of traditional desktop software ...