Online banks strengthen security

Feature
Jun 26, 20066 mins

Financial firms tap multifactor authentication to give customers an added level of protection.

About five times a month, customers try to renege on purchases and transfers they’ve made through their SolidPay e-wallet accounts by claiming they’re victims of fraud. Each time the data gathered through SolidPay’s authentication system proves they’re lying, saving the company what could be tens of thousands of dollars per month in charge-backs to its customers’ accounts.

“Right off the top, we’re able to weed out people who don’t exist, which amounts to about 30% of new applicants who are only there to commit fraud,” says SolidPay President Rob Siegel. “And, with the telephone call-back authentication asking our consumers to type in a PIN to authorize each transaction, we’re able to prove that each transaction was authorized.”

AT A GLANCE: ONLINE BANKING

*A full 70% of the top 23 credit card issuers in the United States and 14% of the top 28 use multifactor authentication.

* A March survey of 2,000 U.S. adults reported that 42% of U.S. households did online banking and bill paying.

* Only 9% of all identity-theft cases occurred online. Of those, 5% came from automated attacks on victim computers averaging $5,858 per case for a total of $2.6 billion, and 3% stemmed from phishing, amounting to $7,294 per case, or $1.9 billion. The vast majority of losses were absorbed by the financial services providers.

SOURCE: JAVELIN STRATEGY AND RESEARCH

Just as important, the system protects customers from online fraud against their accounts, which is the main driver behind any multifactor authentication project in the financial sector. Multifactor authentication combines different types of authentication, such as smart cards, biometrics or cognitive passwords. The other driver is the year-end deadline for stronger authentication by the Federal Financial Institution Examination Council (FFIEC).

Like SolidPay, early adopters are using a variety of authentication methods in multiple layers along the transaction trail and tying authentication into their fraud-detection systems, according to a Gartner report on consumer multifactor authentication. So, say, an unusually large wire transfer sets off a fraud-detection alarm and a third form of authentication is requested.

A good example is e*Trade, which last year began offering free RSA SecurID tokens to its active customers and built an expandable framework to accommodate other forms of authentication down the road. In the near future, e*Trade will add another layer to service its authentication and fraud-detection systems using RSA transactional analysis software to fingerprint the computers trying to authenticate.

“There are a lot of attributes associated with an authentication – IP address, machine type, operating system version and so on – that can be passively fingerprinted without the customer ever knowing,” says e*Trade CIO Greg Framke. “If an authentication profile is not normal – say it logs in from a blacklisted IP address or an IP that doesn’t resolve right – then that person might get a note saying please call customer service.”

Framke won’t reveal how much e*Trade spent to build and integrate the system and roll out the tokens but says the costs were insignificant. He also says maintenance and help desk support costs are small, because e*Trade customers resolve most of their token problems through an online interface.

“For us, we weren’t thinking about ROI. We saw this as another innovative product to make our customers feel better about e*Trade,” Framke says of the Merrifield, Va., company. “And since we cater to a self-help online community, we’ve had very successful adoption.”

Most users and organizations aren’t so willing to embrace tokens, because of convenience issues, according to Gartner, which predicts wider adoption of software-based tokens than hardware over the next few years.

This is the case at Stonebridge Bank, an online lending and banking institution in West Chester, Pa., with $38 million in assets. Stoneridge went live last summer with SecurID tokens and shared secret authentication wherein customers are asked preset questions, such as, “What’s your favorite time of the year?” The vast majority adopted the shared secret, but only a handful of users accepted the tokens, which they give away the first year and will charge $25 for thereafter, according to George Rapp, vice president and IT director.

“Our customers say they don’t want the cost. Others say they’re afraid they’ll lose their tokens and then lose access to their accounts. Surprisingly, that hasn’t happened with any of our token users so far,” Rapp says.

Like e*Trade, Stonebridge has built its own modular authentication system to eventually accept other forms of authentication for a nominal investment of what Rapp says was “four figures.”

Unlike individual organizations building authentication frameworks for their own use, Digital Insight, an online banking application service provider with 1,750 financial services clients, is pouring considerable time and investment into its framework to support dozens of authentication methods for its clients.

“We have a diverse client base that demands flexibility,” says Scott Mackelprang, vice president of security and compliance at Digital Insight. “Our smaller financial customers want us to guide them through the FFIEC recommendations and give them seamless authentication their users never see. But our larger, more-sophisticated institutions want fingerprints to authorize wire transfers. The only way we can do this is through options and layerability.”

The company’s framework will roll out in three phases to ratchet up as threats increase. Phase 1, to be completed in time for its banks to meet the FFIEC’s end-of-2006 deadline, uses TriCipher’s Armored Credential System to handle a variety of secure cookie-based credentials on the customers’ browsers.

Phase 2 will enable financial institutions to offer their customers credentials stored encrypted on the operating system. Phase 3 will support USB tokens.

There’s no such thing as bulletproof security. But if done in layers and tied into fraud-detection systems, multifactor authentication might make online banking safer than banking offline, experts say.

“Added security should be talked about as a positive for customers,” says James van Dyke, founder and principal analyst of Javelin Strategy and Research. “Use it to show that they’re safer banking online. In the mail, you can’t encrypt the data. And online’s the only place you can catch fraud in real time.”

Radcliff is a freelance writer specializing in online safety and network security. She can be reached at www.debradcliff.com.

deb_radcliff

Deb Radcliff is an investigative journalist and analyst focused on computer crime and security. Her work has appeared on Security Boulevard, the SANS Cyber Security Blog, and SC Media, among other outlets. She stood up an analyst program for SANS Institute and ran it for 15 years before joining the Cyber Risk Alliance as strategic analyst on the business intelligence unit. She is author of the popular cyber thriller series, “Breaking Backbones,” available at Amazon.

Deb won two Neal Awards for investigative business reporting. She holds a Bachelor’s degree in journalism from San Jose State University.

More from this author