I agree with a comment in the story - we need a better framework that actually supports non-replayable (ie, one-time) codes being transferred.
If Blizzard can give keyfobs to gamers for auth, why cant banks include that in tech for ATMs?
More and more I think corruption and fraud are the likely reasons - those are features the establishment wants to support, not prevent... they can profit from all of it.
If Blizzard can give keyfobs to gamers for auth, why cant banks include that in tech for ATMs?
Well, banks here in Portugal do offer one-time authorization codes, either by SMS (default) or keyfob, but only for online operations, not in ATMs.
That said, a Chip and PIN solution prevents (in theory) this problem, since it can actually authenticate the transaction by providing a cryptographic signature, without ever exposing the private key to either the ATM or any skimmer.
If Blizzard can give keyfobs to gamers for auth, why cant banks include that in tech for ATMs?
More and more I think corruption and fraud are the likely reasons - those are features the establishment wants to support, not prevent... they can profit from all of it.