As cybercrime threatens online banking security and technologists debate the efficacy of two-factor authentication solutions, business and technical questions remain.In a Network World “Face-Off” last year, RSA Security’s Joe Uniejewski argued for two-factor authentication (which regulatory authorities recommend), while Counterpane’s Bruce Schneier pointed out that attackers would find ways around this and banks would be better off addressing transaction security. I believe stronger authentication will help, but the industry also must focus on user awareness, computer security, network hygiene and business questions around transaction security.I recently attended a meeting of NACHA-The Electronic Payments Association, at which it became clear that regulators are fairly open-minded about evaluating how banks address risk and that a ferment of creative energy and innovation is going into this area. The technical discussion is all about what one considers an authentication factor.Is Authentify’s voice recording, collected on the phone at the time of a transaction for audit purposes, a factor? Is Bank of America’s SiteKey from Passmark, which displays a picture chosen by the user to authenticate the site, a factor? How about RSA Security’s fraud network acquired from Cyota? Or 41st Parameter’s sophisticated real-time device identification? Or Strikeforce Technology’s plethora of plug-in functions? Could eWise’s innovative, human-only-readable watermark hold the key? The latter weaves a transaction description such as “Wire $5,000 to Shanghai” alongside an illustrated confirmation code for the user to enter (or not). Potentially, the answer to all of these questions is yes. From a business perspective, banks are much less concerned about losses to fraud than they are about scaring away customers. To them, online banking represents a Mecca of huge cost savings and revenue opportunities. The technical solutions that win out for them will be those that offer unobtrusive but effective protection.The question no one seems to be asking out loud is: Who owns the liability? Astute users remain uneasy about what happens if a fraudster cleans out their bank account in a world of strong authentication. Will the bank make good the user’s losses out of concern for its reputation, or will it hold the user negligent? A bank that invests in one-time password tokens will argue the devices are effective and thus, only the user could take money out of the account. A government representative told me, “I would interpret Regulation E [regarding electronic funds transfer] to make the bank responsible. The computer is just another access device, like an ATM.” But no one knows how the courts will rule when Regulation E is put to the test.Even with the best technical solutions, there will be residual risk. With the business question of transaction security still up in the air, vendors are placing their bets, but many banks seem to be waiting for clearer direction, and knowledgeable users are anxious.What do you think? Discuss in our forum. Related content news analysis Western Digital keeps HDDs relevant with major capacity boost Western Digital and rival Seagate are finding new ways to pack data onto disk platters, keeping them relevant in the age of solid-state drives (SSD). By Andy Patrizio Dec 06, 2023 4 mins Enterprise Storage Data Center news analysis Global network outage report and internet health check Cisco subsidiary ThousandEyes, which tracks internet and cloud traffic, provides Network World with weekly updates on the performance of ISPs, cloud service providers, and UCaaS providers. By Ann Bednarz and Tim Greene Dec 06, 2023 286 mins Networking news analysis Cisco uncorks AI-based security assistant to streamline enterprise protection With Cisco AI Assistant for Security, enterprises can use natural language to discover policies and get rule recommendations, identify misconfigured policies, and simplify complex workflows. By Michael Cooney Dec 06, 2023 3 mins Firewalls Generative AI Network Security news Nvidia’s new chips for China to be compliant with US curbs: Jensen Huang Nvidia’s AI-focused H20 GPUs bypass US restrictions on China’s silicon access, including limits on-chip performance and density. By Anirban Ghoshal Dec 06, 2023 3 mins CPUs and Processors Technology Industry Podcasts Videos Resources Events NEWSLETTERS Newsletter Promo Module Test Description for newsletter promo module. Please enter a valid email address Subscribe