« Citibank's iPod Offer -- Too Much of a Good Thing? | Main | Branchless Banks now Hold 2% of U.S. Retail Deposits »

FDIC Recommends Two-Factor Bank Authentication

By Jim Bruene on January 11, 2005 4:38 PM | Comments (0)

Now that the FDIC has officially come out in favor of two-factor authentication, it's only a matter of time before every major bank has upgraded their login procedures.

According to a Dec. 24 New York Times article, E*Trade Bank will be the first US bank offering two-factor authentication for retail customers. They are expected to use a token system similar to that used by AOL and several international banks including ABN Amro, Credit Suisse, Rabobank, and First National Bank (South Africa), winner of Online Banking Report's Best of the Web in November.

E*Trade's system is expected in Q1 2005 and will be optional for the customer. It's already in testing with 200 customers.

US Bank is also said to be testing a token system from Verisign.

Analysis: A simpler solution needed for the mass market
We commend these banks for doing something to reassure frightened users. According to Forrester, 26% of online users have not applied online for a financial product due to phishing fears and 14% have stopped paying bills or banking online. Finally 20% have stopped opening emails from their financial providers.

However, a hardware token is overkill for most retail users. It requires ongoing maintenance expenses, tech support, and is a logistical headache for the end user. It's kind of like a car alarm. They make sense if you live in a high-crime area, but mostly they are just a nuisance.

Luckily, there are simpler choices on the way. Just yesterday, an interesting company was profiled in The Seattle Times, BioPassword. Its software records the unique typing patter of the end-user and will keep out anyone else attempting to type the user's password. At a recent conference, the company offered up to $100,000 to anyone who could successfully login to its account, even after they'd been told what the password was. Not one of 1200 attempts was successful.

Entrust_identity_guardAnother interesting alternative to tokens is Entrust's IdentityGuard which Forrester analyst Jonathon Penn raved about in a November 19, 2004 research note. The EntrusEntrust_identity_guard_2_2t solution is a low-tech version of the token, using a paper-based "bingo card" users are asked to enter digits from certain rows/columns of the card (see card right).

Another solution receiving a lot of attention, partly because ex-Intuit CEO Bill Harris is founder, is PassMark. The company touts its "2x2 factor" program that authenticates users to the bank and the bank to the user. The latter is done via visual aid, hence the company name. They also have an excellent easy-to-digest demo.

-- JB

Comments (0)
Categories: Security & Privacy

Most Recent Posts:

Leave a comment

Sponsors

BackBase IntelliResponse Yodlee FinovateEurope 2012

Events

  • FinovateEurope 2012 -- On February 7th, 2012, the second annual FinovateEurope will feature dozens of Europe's newest fintech innovations via a fast-paced demo-only format in the financial capital of London. 7 minutes each on stage. No slides allowed. Come watch the future of fintech in Europe unfold live! Get your ticket today and lock in your spot before it is too late!
  • FinovateSpring 2012 -- On May 8th & 9th, 2012, Finovate will return to San Francisco for our 5th annual west coast showcase of the newest fintech innovations from Silicon Valley and beyond. Each company gets 7 minutes to demo live. No slides allowed. Come watch the future of fintech debut! Get your ticket today and save big!

Research

  • NEW! Online & Mobile Banking Forecast: Current, future and historical usage: 1994 to 2021 - Find out more
  • NEW! Selling Insurance Online (Banking Edition): Can insurance help fill the fee-income gap? - Find out more
  • NEW! True Virtual Banking Has Arrived: BankSimple, Personal Capital, Betterment and others go branchless, paperless and “bank-less” - Find out more
  • 2012 Guide to Online & Mobile Banking Products, Pricing & Strategy: Preparing for a mobile-first world - Find out more
  • Family Banking: Tweens, Teens & their Parents: In a remote banking world, your most-promising prospects aren’t even driving yet! - Find out more

 

   

RSS Subscribe via RSS
RSS Subscribe to Comments



Email:


@NetBanker Twitter Feed



See all @NetBanker tweets