« Citibank, Microsoft Join Forces with Bundle, a Personal Finance Site with a Data Bent | Main | Thanks to Yodlee, a long-term NetBanker.com sponsor »

Trusteer Quantifies the Biggest Online Banking Security Weakness: The End User

By Jim Bruene on February 2, 2010 5:42 PM | Comments (2)

image I've often wondered how many people use the same username/passwords at their bank as they do at other random websites. I figured it was a substantial number, but never expected it to be as high as the 73% Trusteer cited in a recent white paper (note 1). That's why most financial institutions have used "multi-factor authentication" for years.

One of the most common multi-factor techniques is to ask additional questions if the bank detects a login from an unknown computer. However, it's possible that these same people are also using the same "secret question" answers at non-secure websites, defeating this multi-factor approach.   

Luckily, it's still relatively difficult to remove money from most U.S. consumer accounts because online interbank transfers are more tightly controlled, or simply not offered. However, if crooks are able to log in to online/mobile banking and determine the user's account numbers (debit, credit, or checking), a number of more lucrative frauds can be engineered.

What's a bank to do:

  • Use secret questions that are not commonly used across the Web. Or allow users to create their own, but caution them not to use ones they see at other non-banking websites.
  • Create an additional out-of-band authentication process (e.g., text message an approval code) for moving funds out of an account.
  • Do not allow online banking users to see their own account numbers online
    (note 3)
  • Educate/encourage customers to use different username/password for online banking than for other non-financial sites
  • Financial institutions using Trusteer's Rapport service can identify which customers are sharing username/passwords at less-secure sites and ratchet up internal fraud control settings for these customers

And the most effective method, which we don't recommend because it's just too painful for the user experience:

  • Force users to make more challenging usernames and/or password such as those with a capital letter, number and/or special character

Silicon Valley Bank (SVB) offers Trusteer's Rapport (link, 2 Feb. 2010)

image

Notes:
1. While 73% shared banking passwords with other sites, less than half the total, 47%, shared BOTH username and password. Two other data points:
- 65% of user-selected banking usernames were used elsewhere
- 42% of bank-selected banking usernames were used elsewhere
2. Trusteer's data was compiled over 12 months using its plugin software running on more than 4 million computers (see previous post).
3. There's still the issue of the easy-to-read account number on check images; it would be nice to mask it, but that's probably not worth the expense) 
4. For more info on Trusteer and other security topics, see our previous reports such as, Online Banking Report: New Security Techniques (Sep. 2008)

Comments (2)

Most Recent Posts:

TrackBack

TrackBack URL for this entry:
http://www.netbanker.com/cgi-bin/mt/mt-t.cgi/2279

2 Comments

Secret questions not used on other sites might help. People need to use the Facebook security metric. If someone can find out the answer to an MFA question on Facebook, the website shouldn't use the question. IE, What was your first pet's name, the city you were born in, color of your first car, etc, etc

BoA has mandatory lengths and letter/number combination for their passwords. If you have a component that automatically displays the strength of the password, it can actually be fun to create a secure password.

Leave a comment

Sponsors

WorkLight Yodlee IntelliResponse Wesabe

Events

  • FinovateSpring 2010 -- Dozens of handpicked fintech companies demoing their newest innovations in the entrepreneurial hotbed of San Francisco. 7 minutes each on stage to demo. No slides. A single value-packed day on 5/11/2010. Get your early-bird ticket today!

  • FinovateFall 2010 -- Dozens of handpicked fintech companies showcasing their latest & greatest in the financial capital of the world -- NYC. 7 minutes each on stage to demo. No slides. A single value-packed day on 10/05/2010. Get your early-bird ticket today!

Research

  • NEW! The Case for Mobile Banking: Ten strategic reasons for investing in the channel - Find out more
  • NEW! Online & Mobile Banking Forecast: Current, future and historical usage: 1994 to 2019 - Find out more
  • Making the Case for Person-to-Person Payments: Does mobility provide the tipping point for bank-branded P2P? - Find out more
  • Attracting Small Businesses with Online & Mobile Banking: Underserved segment is prime candidate for alt-delivery - Find out more
  • 2010 Guide to Online & Mobile Banking Products, Pricing & Strategy: Your roadmap for business planning - Find out more
  • Improving Online Account Opening ROI: Ten strategies to increase online application conversion rates - Find out more
  • New Techniques in Secure Online Finance: Sandboxing, keyboard encryption, and real-time mobile integration could lock in more online customers- Find out more

Products & Services (Sponsored)

  • Online Banking Services: Compare online banking services and savings rates from the leading financial institutions at Credit.com.

 

   

RSS Subscribe via RSS
RSS Subscribe to Comments



Email:


@NetBanker Twitter Feed



See all @NetBanker tweets

Most Recent Comments


Dan Rosenfeld commented on Are You Still Frustrating Your Banking Customers to Save a Few Pennies?

anonymous commented on Launching: HelloWallet is First New PFM of 2010

Hildebrand, The Insurance Warden commented on Mobile Firsts: State Farm Offers Auto Insurance Discounts to Graduates of its Steer Clear iPhone App

David commented on USAA Makes Mobile Banking Better than Online Banking

Suman commented on PNC Bank Takes on Mint & Quicken with PNC Virtual Wallet

Kevin Lynch commented on Twittering Vantage Credit Union Taps Geezeo for Online PFM