I've heard about new devices that connect to USB ports and create a secure communication channel to online banking servers. Can this type of technology prevent man-in-the middle attacks, and will they become mainstream in the future?
I think this is a great idea. However, the devil is in the details. There can be outstanding implementations of this technology as well as bad ones. For example, if the session with the bank does not employ proper SSL certificate verification, it may still be possible to hijack the session via a man-in-the-middle attack.
I have also seen implementations of this technology where the only authentication is with the key. This is not an optimal approach; if someone has the key, an attacker can log in to your bank without a user ID or a password. The better implementations utilize the key along with an ID and password.
Dig Deeper on VPN security
Related Q&A from John Strand
Expert John Strand explains how to shore up security as you plan a large-scale advertising campaign. Continue Reading
Expert John Strand reveals two exciting trends in antivirus software. Continue Reading
In this expert response, John Strand explains what to do when your personal identity is impersonated online. Continue Reading