Safari Books Online is a digital library providing on-demand subscription access to thousands of learning resources.
Appealing to everyday human activity gives some useful countermeasures for attacks against identification and authentication.
Banks and credit card companies struggle to find new ways to make sure the holder of a credit card number is authentic. The first secret was mother’s maiden name, which is something a bank might have asked when someone opened an account. However, when all financial institutions started to use this same secret, it was no longer as secret. Next, credit card companies moved to a secret verification number imprinted on a credit card to prove the person giving the card number also possessed the card. Again, overuse is reducing the usefulness of this authenticator. Now, financial institutions are asking new customers to file the answers to questions presumably only the right person will know. As long as different places use different questions and the answers are not easily derived, these measures can confirm authentication.