« Monetize Your Online Customers with Insurance | Main | New Upost Webinar Date »

Put an End to "3 Strikes and You're Out" Password Management

By Jim Bruene on May 19, 2005 12:01 AM | Comments (0)

3_strikesPassword management is a pain and only promises to get worse as banks and other ecommerce providers tighten up access controls due to sophisticated fraud attacks.

However there is one area where some banks are still "penny-wise and pound foolish." Specifically, the old-fashioned notion of locking an account after three unsuccessful password attempts.

It's just too easy for to miss three times. Here's what just happened to me at Bank One's credit card site:

1. Correct username, incorrect password
2. Correct username, retype same (incorrect) password in case I made an inadvertent typo the first time (since the password is masked and I can't see what I typed the first time)
3. Correct username, another shot at the password which turned out to be incorrect (probably because I changed it last time I was locked out)

RESULT: Locked out and in need of an account reset, which luckily you can do online if you have the card number, expiration date, 3-digit code, and primary social security number.

Analysis
The last time we took an in-depth survey, in our April 2003 report on Security & Privacy (OBR 93/94), 4 of the 14 major financial institutions we tested locked users out after just three attempts, while 6 of 14 fell within the recommended range of 5 to 10 attempts.

We recommend that you allow at least five unsuccessful logins, and preferably closer to 10, prior to freezing the account. The amount of fraud deterred between locking out at three attempts vs. locking out at six is so small as to be virtually unmeasurable. However, there is a real cost in customer service and consumer dissatisfaction for constantly requiring password resets.

OK, I feel better now. Thanks for listening.

-- JB

Comments (0)
Categories: Security & Privacy , Service

Most Recent Posts:

Leave a comment

Sponsors

BackBase IntelliResponse Yodlee FinovateEurope 2012

Events

  • FinovateEurope 2012 -- On February 7th, 2012, the second annual FinovateEurope will feature dozens of Europe's newest fintech innovations via a fast-paced demo-only format in the financial capital of London. 7 minutes each on stage. No slides allowed. Come watch the future of fintech in Europe unfold live! Get your ticket today and lock in your spot before it is too late!
  • FinovateSpring 2012 -- On May 8th & 9th, 2012, Finovate will return to San Francisco for our 5th annual west coast showcase of the newest fintech innovations from Silicon Valley and beyond. Each company gets 7 minutes to demo live. No slides allowed. Come watch the future of fintech debut! Get your ticket today and save big!

Research

  • NEW! Online & Mobile Banking Forecast: Current, future and historical usage: 1994 to 2021 - Find out more
  • NEW! Selling Insurance Online (Banking Edition): Can insurance help fill the fee-income gap? - Find out more
  • NEW! True Virtual Banking Has Arrived: BankSimple, Personal Capital, Betterment and others go branchless, paperless and “bank-less” - Find out more
  • 2012 Guide to Online & Mobile Banking Products, Pricing & Strategy: Preparing for a mobile-first world - Find out more
  • Family Banking: Tweens, Teens & their Parents: In a remote banking world, your most-promising prospects aren’t even driving yet! - Find out more

 

   

RSS Subscribe via RSS
RSS Subscribe to Comments



Email:


@NetBanker Twitter Feed



See all @NetBanker tweets