The federal agency that regulates banks, the Federal Financial Institutions Examination Council (FFIEC), has finally released an update to its 2005 guidance on Internet banking authentication. This has been awaited since a draft of the document was leaked last winter.
The federal agency that regulates banks, the Federal Financial Institutions Examination Council (FFIEC), has finally released an update to its 2005 guidance on Internet banking authentication. This has been awaited since a draft of the document was leaked last winter.You can get all the details from Ellen Messmer’s story in Network World, but I want to focus on one aspect.
Oracle’s Nishant Kaushik, in an otherwise excellent review of the new rules, has a quibble with the recommendations for beefing up so-called “challenge questions” (e.g., “What’s your mother’s maiden name?”), suggesting the recommendations don’t go far enough and admitting to being completely puzzled by one recommendation.
BACKGROUND: The FFIEC guidance of today
The new guidance recommends:
1. increasing the number of challenge questions asked,
2. avoiding challenge questions that can be answered by mining the user’s information through online searches and social networks,
3. including a “red herring” question that a fraudster would attempt to answer but a legitimate user would not, and
4. using only a random subset of the challenge questions that the user has provided answers for in a single session.
It’s the third one that Nishant has trouble with, stating: “I don’t even know how the 3rd item is supposed to work.”
It’s not something I’ve seen often, but it strikes me as an excellent addition. Of course, it requires that the person being challenged have the option of stating that there is no answer. Then any question asked for which the legitimate account holder has not provided an answer should draw the response “not a valid question” (or something similar). Ideally, of course, this would be a question which could be correctly answered through online searches and social networks (e.g., “What city were you born in?”, “Which high school did you graduate from?”, etc.). Anyone providing an answer — especially a true answer — would be considered “at risk.”
It’s still my opinion, though, that you should lie about the answers you provide for potential challenge questions. Sure, that requires that you remember the wrong answer that you provided. But it does eliminate the possibility that data mining the Internet could reveal the proper answer to that question.
Still, as I recommended last week, something stronger than passwords and challenge questions should be mandatory for banking transactions. Next issue I’ll show you something that fills that bill, and is available now.




