It would be very interesting to hear the thoughts of some of the security expert HN-readers on this matter.
It would be very interesting to hear the thoughts of some of the security expert HN-readers on this matter.
If the users system is compromised there is nothing you can do. Sacrificing general security for that case is silly.
The best defence to a keylogger attack is to have a secondary number vaidation alongside the password that requires you to enter a random subset of that number each time (eg 1st, 2nd, 8th).
The only better defence I can think is to have a user enter 3 genuine numbers from their password and 3 randomly generated numbers given to you, but it the 6 numbers are requested randomly. Requesting only random genuine numbers gives you encryption by hiding the sequence of the numbers, if you are also hiding the genuine numbers it's two levels of deceit.
I love my bank, their authentication is cheap, platform-independent and reasonably secure. It's definitely safe from keyloggers, because it requires access to items that are in my possession. And best of all, it's not annoying for me as a user.