German bank fights phishing with electronic signatures

Postbank will begin using electronic signatures to curb the theft of personal information.

German retail banking giant Postbank, the target of several phishing attacks, aims to curb the theft of online personal information with the help of electronic signatures.

The bank will begin attaching electronic signatures to all e-mail correspondence with customers, Postbank spokesman J├╝rgen Ebert said Thursday.

The Postbank mail certification service uses the Secure Multipurpose Internet Mail Extensions (S/MIME) standard, already integrated into numerous e-mail applications, including Microsoft's Outlook, according to Ebert.

The electronic signature, which the bank attaches to its e-mail, is issued by TC Trust, the German subsidiary of GeoTrust.

Only Postbank customers using e-mail applications with both S/MIME authentication and TC Trust certification will receive a certification symbol, confirming that the text message is from the bank, according to Ebert.

Currently, only Outlook supports the Postbank service, he said.

Phishing attacks use spoofed e-mail and fraudulent Web sites to fool respondents into entering personal financial data such as credit card numbers, account user names and passwords, which can then be used for financial theft or identity theft.

The attacks, which have hit Postbank and several other large German banks over the past couple of years, have resulted in more than 80% of online banking customers in the country doubting the authenticity of e-mail correspondence from their banks, according to a survey by German market researcher TNS Infratest Holding.

Under the Postbank certification system, users can verify an e-mail by clicking a certification symbol, which, when opened, provide details about the signature.

A warning symbol appears if any inconsistencies arise during the signature authentication process.

The system operates in a similar way to trusted Web pages, according to Ebert.

The T-Online e-mail service provided by local network operator Deutsche Telekom plans to support the Postbank service by July, he said.

Discussions are also underway with AOL, which offers another frequently used mail client in Germany, he added.

Customers using e-mail programs that currently don't meet the S/MIME and TC Trust requirements will receive a message that the signature is not recognized. If they wish to enable their programs to support both, they are advised to consult the Postbank Web site for details.

Postbank's electronic signature service isn't possible with Web-based e-mail services provided by local ISPs such as GMX and Freenet.de, according to Ebert. One exception is Web.de.

Plans are underway to switch the certification service from TC Trust to VeriSign, which already provides certification services for Postbank's Web pages, according to Ebert. "We started with TC Trust but we think it's better to have everything with Verisign, which is more widely used," he said.

Postbank, which was spun off from the former German public administration for post and telecommunications, is one of the country's largest consumer banks with 11 million customers, of whom nearly 1.7 million have online banking accounts.

From CSO: 7 security mistakes people make with their mobile device
Join the discussion
Be the first to comment on this article. Our Commenting Policies