skip to content
rss Subscribe print Printer Friendly Share this Page

ING Direct Fights Keystroke Loggers

ING Direct USA is doing its best to thwart keystroke logging software by using a web-based numeric keypad.

Since a secure connection won’t protect you if a keystroke logger has been installed on your computer, ING Direct is using the keypad to keep you from having to enter your numbers from your keyboard. This will keep you typing in your account number and password and hopefully, keeping it from being tracked by thieves.

If your bank isn’t using a strategy like this you should request it - it’s a great idea!

Here's what it looks like:

ING Direct PIN Input

See it in action on the live ING Direct web site

December 11, 2005
Categories
Add a comment

1 Comment

Matt

Posted 4/22/2006

The system is useless. For the letter images, the letter is THE NAME OF THE IMAGE; No OCR is even necessary. I've already created an exploit to disable the keypad and allow direct entry of the PIN (which I intend to post to http://userscripts.org). It wouldn't be much extra effort to integrate the parsing code into a keylogger. The only real effect is an inconvenience.