New federal standard asks banks to double up security

Banks have until year’s end to implement ‘strong’ authentication

For as long as there has been online banking, financial institutions have faced attacks from hackers. As a result, they have beefed up their Web sites’ security systems to protect themselves and their customers.

Your Business Has Gone Global. Has Your Insurance?

A decade ago, “doing business internationally” was mostly a large-company concern. Today, a manufacturer in…

Learn More

Now, concerned that many banks’ efforts are inadequate, the Federal Financial Institutions Examination Council, an interagency body that sets standards and principles for the industry, has advised all banks to implement multi-layered security systems by the end of this year.

Most bank Web sites require a user name and password to log in. Under the council’s new standard, however, known as two-factor or strong authentication, they’ll soon have to require at least one more form of identity verification before providing access to an account.

- Advertisement -

Bank of America, which has the most online banking customers in the world, with 14.6 million subscribers, rolled out a new two-factor authentication system last year, SiteKey, and introduced it in Rhode Island and seven other Northeast states in January.

SiteKey asks customers to pick an image, write a brief phrase and select three challenge questions. When a customer logs in, he types in just his user name and is then directed to a second page that shows the image, confirming that he’s really on Bank of America’s site. Only then is he prompted to type in his password. If the Bank of America system doesn’t recognize the user’s computer, it will ask one of the challenge questions to verify his identity.

None of the other top five banks in Rhode Island, such as market leader Citizens Bank, Sovereign Bank, The Washington Trust Co. and Bank Rhode Island, have two-factor authentication on their Web sites yet, though all are preparing to implement it.

SiteKey-type systems aren’t the only way to comply with the new guidance – which isn’t mandatory, but is strongly recommended. In guidelines issued last October, the council said it wasn’t endorsing a particular way of boosting security, but listed several options, from images and challenge questions, such as in SiteKey to “smart cards” to biometrics.
Matt Buckley, corporate communications manager for RSA Security, a Bedford, Mass., company that helps many of the biggest banks in the world protect online identities and digital assets, said there are also products available that can verify a customer’s identity through cookies placed on her computer, passwords that change every 60 seconds and are updated on a user’s cell phone or PDA, and behind-the-scenes authentication that tracks a customer’s Web-browsing behavior.

“The onus is on financial institutions to take a look at the risks that are involved,” Buckley said. “There are going to be different levels of risk according to different individuals and scenarios. One size does not fit all.”

The business of protecting personal data during online banking has grown increasingly urgent due to the proliferation of “phishing” – a type of fraud in which cyber-criminals deceive customers into giving up private bank and credit account numbers, typically by luring them to fake Web sites that mirror the bank’s actual Web site.

Hackers also use “spyware” such as key-logging programs that track unsuspecting users’ keystrokes to steal their passwords and other private information.

A consumer survey conducted by First Data in May 2005 found that 43 percent of respondents had been contacted by a phishing scam, according to ConsumerAffairs.com. Of those contacted by a phisher, 5 percent – about 4.5 million people – divulged personal information.

Forty-five percent of the phishing victims reported that their information was used to make an unauthorized transaction, open an account, or commit another type of identity theft, ConsumerAffairs.com reported.

“The threat of online theft of assets and sensitive information is growing,” said Barbara J. Perino, senior vice president for operations and technology at Washington Trust, in an e-mail response to a reporter’s query. “The need to improve security and add additional layers of security will continue. Phishing has become very prevalent.”

Washington Trust recently decided on a two-factor authentication for its online banking service that will use a secure cookie placed on the user’s PC, Perino said, offering increased protection with minimal disruption to the customer experience.

Most Washington Trust customers will be able to register multiple PCs, so they can bank from home or work, and will be allowed single-use access from remote computers by answering a series of pre-determined “challenge” questions.

For more complex and risky transactions, additional methods of authentication will be employed, such as the use of USB tokens – hardware devices that plug into computers’ USB ports – for larger commercial customers, Perino said.

“The added layer of authentication should diminish the problem significantly,” Perino said.

“Financial institutions and their vendors are doing their part to fight the battle. However, careful password control and selection by the customer cannot be overemphasized. Trying to make online banking access convenient and user friendly, while maintaining an appropriate level of security … is an ongoing challenge.”

The cost of implementing two-factor authentication will be harder for smaller, independent financial institutions to bear, according to Cary Whaley, associate director of payments policy for The Independent Community Bankers of America.

“It’s going to be quite a challenge to implement,” Whaley said. “All of this comes with a cost. It’s up to community banks now to respond. It’s not a point where the regulation is up for negotiation. Community banks have to develop solutions that comply.”

No posts to display