Cronto. I saw a demo of this the other day—it’s a neat anti-phishing scheme that also protects against man in the middle attacks. It works using challenge/response: an image is shown which embeds a signed transaction code; the user then uses an application on their laptop or mobile phone to decode the image and enters the resulting code back in to the online application.
They did a demo for us at work as well. Seems quite cool, although it's not all that cheap considering what it does -- I knocked up a quick demo version of a similar concept in a couple of hours to prove that it's perhaps not worth the money. Nice idea, though.
Many thanks for such positive comments. We did put lots of effort into trying to "hide" all complications of the security protocol behind deceivingly simple front end so that it looks extremely straightforward and intuitive for the end user - after all, the majority of the security solutions failed not because they were bad but because they were perceived as "too complicated" by users :-)
Elena Punskaya, Cronto Ltd - 3rd October 2007 23:41 - #