More Weaknesses in SiteKey

The fake boarding pass guy is at it again, according to Slashdot this week. He posted videos on his blog about how he bypassed SiteKey, an authentication scheme for logging onto Bank of America's web sites.

Two weeks ago, another commentary on SiteKey weaknesses came out, and there was some press in February. More information is in my original post.


