PhoneFactor launched an app for smart phones and tablets that allow users to physically verify a transaction. The app pushes a notification to the user’s smart phone alerting the user a transaction is in process.
The user has to tap “Authenticate” or enter a PIN to verify account logins and transactions. The app is now available for iPhones and iPads, and will be available soon for Android devices.
PhoneFactor says its app offers several benefits, particularly when compared to one-time passcode apps, including:
Out-of-band authentication – By leveraging a separate device, in this case the mobile phone, PhoneFactor protects against malware running on the user’s computer. Passcodes from mobile apps, which are entered into the user’s computer, are not out-of-band and are vulnerable to attack.
Real time fraud alerts – If an attacker tries to log in with stolen credentials or transfer funds from an account, the legitimate user receives a notification and can report fraud instantly from the PhoneFactor App.
Transaction verification – The app can be used to verify transaction details by displaying them in the app.
Ease of Use – With no one-time pass codes to enter, authenticating with the app is easier. It works with any enterprise or web application, including those running on the user’s phone.
The app works anywhere the user’s mobile device is connected to a cellular or Wi-Fi network.