« E-Loan Extends "Employee Pricing" to Loans | Main | Banking and Coffee? »

Mandatory Online Banking Password Changes

By Jim Bruene on September 9, 2005 3:19 PM | Comments (0)

Katie Kuehner-Hebert looks at the issue of mandating consumer password changes in today's American Banker. She cited only a single bank doing it, West Georgia National Bank <www.wgnb.com>, which recently began requiring new passwords every 45 days. None of the financial institutions we are familiar with force password changes, although NextCard did when it first launched in 1997, but later it did away with the annoying requirement.

Analysis
This is one of the least effective ways to improve security. In fact, it may have exactly the opposite effect for two reasons:

  1. Customers cannot memorize a new password every 45 days, so they will have to write it down somewhere near their PC where it can be seen by others.
  2. Once users begin to realize what a hassle it is logging in to your website, they will forgo online access altogether or use it much less frequently, therefore reducing the frequency of account monitoring which can reduce the impact of identity theft and other fraud.

And even the method did reduce fraud, it's unlikely to be cost effective due to the increased burden on customer service and decreased customer satisfaction.

Offer choice
Mandt_password_resetSome customers do like the idea of periodic password changes, but forget about mandatory changes. We like the M&T Bank <www.mandtbank.com>. The Buffalo-based banks allows customers to choose whether to have mandatory password changes at either 30, 60, 90, 180 or 365 days. They can also choose NOT to have a mandatory password change (click on inset for a closeup).

An even simpler way to give customers the choice is to allow customers to program an alert reminding themselves to change their password. The alert should NOT have a link back to the bank, otherwise it will look like a phishing message.

--JB

Comments (0)
Categories: Security & Privacy

Most Recent Posts:

Leave a comment

Sponsors

BackBase IntelliResponse Yodlee FinovateEurope 2012

Events

  • FinovateEurope 2012 -- On February 7th, 2012, the second annual FinovateEurope will feature dozens of Europe's newest fintech innovations via a fast-paced demo-only format in the financial capital of London. 7 minutes each on stage. No slides allowed. Come watch the future of fintech in Europe unfold live! Get your ticket today and lock in your spot before it is too late!
  • FinovateSpring 2012 -- On May 8th & 9th, 2012, Finovate will return to San Francisco for our 5th annual west coast showcase of the newest fintech innovations from Silicon Valley and beyond. Each company gets 7 minutes to demo live. No slides allowed. Come watch the future of fintech debut! Get your ticket today and save big!

Research

  • NEW! Online & Mobile Banking Forecast: Current, future and historical usage: 1994 to 2021 - Find out more
  • NEW! Selling Insurance Online (Banking Edition): Can insurance help fill the fee-income gap? - Find out more
  • NEW! True Virtual Banking Has Arrived: BankSimple, Personal Capital, Betterment and others go branchless, paperless and “bank-less” - Find out more
  • 2012 Guide to Online & Mobile Banking Products, Pricing & Strategy: Preparing for a mobile-first world - Find out more
  • Family Banking: Tweens, Teens & their Parents: In a remote banking world, your most-promising prospects aren’t even driving yet! - Find out more

 

   

RSS Subscribe via RSS
RSS Subscribe to Comments



Email:


@NetBanker Twitter Feed



See all @NetBanker tweets