3.2 Hardware Trojans in Computers
223
(1) The user connects to the Internet and opens a dialog window for entering
personal data.
(2) After that, the user presses the key button to generate a one-time password, and
the password is displayed on the LED screen of the pendant for 15 s.
(3) The user enters the login, personal PIN code, and the generated value of a onetime password in the dialog window (usually, PIN code and key are entered one
after another in the single field called passcode).
(4) The entered values are checked on the server side; after that, a decision is made
on whether their owner has a right to work with locked data.
When using such device as a calculator for password generation, the user enters the
PIN code on the keyboard and presses the button.
In order to obtain one-time passwords, it is also possible to use system based
on SMS messaging from a mobile phone; however, this solution has been long
considered not the most reasonable and safe, and it is recommended to avoid it
with all else being equal.
However, generally speaking, the most reliable option today is using two-factor
authorization based on generation of temporary codes.
Essentially, they are hardware-based, since the generation is performed using a
separate device (phone, tablet, etc.) with installed software like Google Authenticator.
A few words shall be said about proactive protection. The most popular solution
is using proactive protection systems that can warn the user about installation or
activation of software keyloggers.
The main downside of this method is the necessity of active participation of the
user to determine further actions with suspicious code.
If the user is not sufficiently prepared in technical terms, the keylogger can be
missed due to the user’s uninformed decision.
If the user’s participation in decision-making of the proactive protection system
is minimized, the keylogger can be missed due to insufficiently strict security policy
of the system.
This is indeed a double-edge sword. Let us note something else.
The last of the considered ways of protection from both software and hardware
keyloggers is using a virtual keyboard.
Virtual keyboard is a program displaying a screen keyboard, the keys of which
can be pressed with the help of a computer mouse.
It should be noted that screen keyboard is not especially applicable for cheating
keyloggers, since it was created not as a means of protection but to help people with
disabilities, and transfer of data input with the help of such keyboard can be easily
intercepted by any malware.
Of course, screen keyboard can be used to bypass a keylogger, but its design has
to prevent interception of the input data during any stage of its input and transmission
(as a rule, the algorithm of changing the position of buttons and digits is used along
with encryption of the final result).
Now, let us take a very brief look at the programs for search and deletion of
keyloggers.
223
(1) The user connects to the Internet and opens a dialog window for entering
personal data.
(2) After that, the user presses the key button to generate a one-time password, and
the password is displayed on the LED screen of the pendant for 15 s.
(3) The user enters the login, personal PIN code, and the generated value of a onetime password in the dialog window (usually, PIN code and key are entered one
after another in the single field called passcode).
(4) The entered values are checked on the server side; after that, a decision is made
on whether their owner has a right to work with locked data.
When using such device as a calculator for password generation, the user enters the
PIN code on the keyboard and presses the button.
In order to obtain one-time passwords, it is also possible to use system based
on SMS messaging from a mobile phone; however, this solution has been long
considered not the most reasonable and safe, and it is recommended to avoid it
with all else being equal.
However, generally speaking, the most reliable option today is using two-factor
authorization based on generation of temporary codes.
Essentially, they are hardware-based, since the generation is performed using a
separate device (phone, tablet, etc.) with installed software like Google Authenticator.
A few words shall be said about proactive protection. The most popular solution
is using proactive protection systems that can warn the user about installation or
activation of software keyloggers.
The main downside of this method is the necessity of active participation of the
user to determine further actions with suspicious code.
If the user is not sufficiently prepared in technical terms, the keylogger can be
missed due to the user’s uninformed decision.
If the user’s participation in decision-making of the proactive protection system
is minimized, the keylogger can be missed due to insufficiently strict security policy
of the system.
This is indeed a double-edge sword. Let us note something else.
The last of the considered ways of protection from both software and hardware
keyloggers is using a virtual keyboard.
Virtual keyboard is a program displaying a screen keyboard, the keys of which
can be pressed with the help of a computer mouse.
It should be noted that screen keyboard is not especially applicable for cheating
keyloggers, since it was created not as a means of protection but to help people with
disabilities, and transfer of data input with the help of such keyboard can be easily
intercepted by any malware.
Of course, screen keyboard can be used to bypass a keylogger, but its design has
to prevent interception of the input data during any stage of its input and transmission
(as a rule, the algorithm of changing the position of buttons and digits is used along
with encryption of the final result).
Now, let us take a very brief look at the programs for search and deletion of
keyloggers.
