Anti-Phishing

Start a Free Trial
Watch the Video
Read the Data Sheet
Read the White Paper
Try the Demo

Dynamic, Mutual Authentication Technology for Anti-Phishing

Some websites attempt to combat phishing by placing a static picture on the login page. The picture is supposed to assure the user that they are on the real website and not a spoofed website (also called a phishing site). However because the picture never changes, users begin to ignore the picture and enter their passwords on the webpage without ever really looking at it – defeating the purpose entirely.

Confident ImageShield™ can be used as a dynamic, mutual authentication solution to fight phishing. It requires the user to actively verify that they are on the legitimate website, while at the same time allowing the website to authenticate the user. The user is only able to enter their password after they have actively authenticated using Confident ImageShield.

Anti-Phishing Authentication

How it works:

1. The first time a user registers on the website they choose a username and password. They also select a few categories of images they can easily remember.

2. To login, the user enters their username on the web page.

3. Next, the user is presented with a randomly-generated grid of images – the Confident ImageShield.  The user authenticates by identifying the images that fit their pre-chosen categories. Confident ImageShield creates a one-time password or PIN that is unique for each login session.  

4. Only after successfully authenticating using Confident ImageShield, the password field becomes enabled and the user is allowed to enter their text password to complete the secure login.

The specific pictures on the Confident ImageShield, their location on the grid and their corresponding characters are different each time. In this way, the user must actively engage with Confident ImageShield in order to identify the images that fit their secret categories. This ensures that the user is an active participant in strong security practices and also prevents the user from ever entering their password on a spoofed website where the Confident ImageShield does not appear.

To learn more about how image-based authentication can be used for dynamic, mutual authentication and anti-phishing, contact us or start a free trial today.