U.S. banks urged to implement stronger security for online customers

Opinion
Oct 24, 20053 mins

* Federal financial council releases guidelines for safeguarding customer ID

As Network World Senior Editor Ellen Messmer reported last week, the Federal Financial Institutions Examination Council (FFIEC) has issued new guidance for how financial institutions should plan to authenticate customers’ online identities by the end of next year.

This little-known federal watchdog describes itself as “…a formal interagency body empowered to prescribe uniform principles, standards, and report forms for the federal examination of financial institutions by the Board of Governors of the Federal Reserve System (FRB), the Federal Deposit Insurance Corporation (FDIC), the National Credit Union Administration (NCUA), the Office of the Comptroller of the Currency (OCC), and the Office of Thrift Supervision (OTS) … to make recommendations to promote uniformity in the supervision of financial institutions.” As such, its “guidelines” are normally read as mandates by the financial community.

The rise in so-called “phishing” as an identity theft mechanism led directly to the FFIEC’s release of these new guidelines. The guidelines, entitled “Authentication in an Internet Banking Environment” (PDF), replace an earlier document – “Authentication in an Electronic Banking Environment” – issued four years ago. The latest document is explicit in stating that no particular authentication method is being suggested, but goes on to describe several (including digital certificates, smart cards, one-time passwords, USB plug-ins and biometric identification methods) as being more in line with the guidelines than the simple username/password combinations currently in use.

Major security and identity vendors were quick to jump into the discussion of how best to implement stronger authentication for online financial transactions. Both RSA Security and archrival Vasco Data Security were quick off the mark to try to get their spin out, contacting me within minutes of when the story broke.

According to an RSA spokesperson, the company “is continuing to 1) hear acute pleas from consumers who want more protection and 2) see interest from banks in flexible, convenient security solutions for their customers.” RSA also provided the results of a survey showing that European consumers have more confidence online than their U.S. counterparts, and provided a listing of a large number of banks around the world that have been purchasing hundreds of thousands of RSA SecurID strong authentication tokens for their customers. Less than a handful of those are U.S. institutions (on the list were American Bank, Credit Suisse, E*Trade Financial and Stonebridge Bank).

The Vasco spokesperson wanted to remind me, though, that the new rules put the burden on banks to avoid the inflated claims by some “not-completely-honest” authentication providers. According to Vasco President Jan Valcke: “Every security officer needs to know how to spot the false claims that could leave hidden gaps in their security net.”

When I asked RSA why so few U.S. financial institutions had adopted strong authentication (such as RSA’s SecureID on-time-password application), the response was that the reasons are twofold: convenience and cost. It’s felt that U.S. consumers would balk at the increase in fees needed to sustain the use of tokens and would also resist the change from the easily implemented username/password method.

That sounds bad: lazy, cheap American consumers who, according to Vasco, are about to be duped by not-completely-honest vendors. Could there be an upside to the foot-dragging by American financial institutions? Well, consider this question: What’s worse, having weak security and knowing it or thinking you have strong security when you don’t? We’ll try to answer that next time.