Wito
The new strong authentication mechanism developed by Iamboo. Patent Pending.
How it works
Wito is an authentication mechanism based on phone call.
Nowdays there are several other products based on the caller ID identification, every one of them requires that the user calls to a phone number (commonly a toll-free number) to login towards a service like home-banking website.
Unfortunately this kind of authentication has a serious security issue: it's subjected to mobile impersonation attacks (based on spoofing of the caller ID), which lets an attacker make the service think that he's actually another person.
Wito is different. By changing the paradigm, it's totally immune from this vulnerability.
The mechanism works as follows:
The user fills the form with his username and password.

At this moment the system immediatly calls the user, it's not necessary to answer because the calling number will be always the same apart from the last digits (e.g. the last four ones).
Nowdays there are several other products based on the caller ID identification, every one of them requires that the user calls to a phone number (commonly a toll-free number) to login towards a service like home-banking website.
Unfortunately this kind of authentication has a serious security issue: it's subjected to mobile impersonation attacks (based on spoofing of the caller ID), which lets an attacker make the service think that he's actually another person.
Wito is different. By changing the paradigm, it's totally immune from this vulnerability.
The mechanism works as follows:
The user fills the form with his username and password.

At this moment the system immediatly calls the user, it's not necessary to answer because the calling number will be always the same apart from the last digits (e.g. the last four ones).

Th user has to simply type the last digits of the calling number, and he will by immediatly authenticated.

Advantages
- It's not subjected to mobile impoersonation attacks
- The final user isn't charged.
- There are no connection costs for the services
- The call is in real time. All the procedure is managed in a few seconds
- Differently from the SMS, che call has no costs
For more information please fille the apposite form



