ellen_messmer
Senior Editor, Network World

Financial firms bolster authentication

News
Mar 7, 20054 mins

Financial institutions are strengthening their defenses against online fraud by adding security mechanisms that are better suited to prove the identity of customers than are simple, reusable passwords.

Brokerage firm ETrade Financial last week said it will give away RSA Security ‘s handheld token, which can generate a dynamic, changing password every minute, to online customers with at least $50,000 on account. ETrade will offer the token as a paid service to those with less. This comes after Bank of America’s promise last month to use two-factor authentication from VeriSign just weeks after facing a negligence lawsuit from a Miami businessman who says that because of online fraud, $90,000 was stolen from his account and diverted to a bank in Latvia.

“As an industry, we’re looking for a way to get some peace of mind,” said Josh Levine, CTO at ETrade.

Levine’s company will offer the RSA SecurID hardware token for free to the wealthiest of its 3 million clients, while devising a service fee for the balance who want strong two-factor authentication. ETrade already makes use of the SecurID authentication server internally for its employees.

It’s important for the financial services industry to move away from simple passwords on online accounts because “the dirty little secret in our industry is that most people use the same ID across sites,” Levine said. That means when a phishing scam or Trojan on the victim’s computer steals logon information, the captured re-usable passwords often provide a way to break into different banking Web sites to access accounts, not just one.

In the high-profile Bank of America case, businessman Joe Lopez filed a lawsuit claiming the bank should reimburse his loss because the bank didn’t alert him that malicious code could infect his computer and steal his password. According to the lawsuit, the Secret Service, an arm of the Department of the Treasury, often brought in to investigate financial crimes, determined a Trojan called Coreflood had done just that through keylogging.

A Bank of America spokeswoman said the bank couldn’t comment on pending litigation and that the bank has no specific time table to provide VeriSign’s strong authentication technology to customers. She added it was expected that bank employees first would use it internally.

The rising threat to banks and brokerages from Trojans and phishing attacks also is getting attention from federal regulators, who might institute tougher authentication rules. While strong two-factor authentication has long been used in big-portfolio investment banking circles, the average consumer seldom is offered more than a re-usable password and ID.

But that could change. The regulatory agency Federal Deposit Insurance Corp. (FDIC) in December issued a report called “Putting an End to Account-Hijacking Identity Theft .” The FDIC report flatly advises financial institutions they should be “upgrading existing password-based, single-factor customer authentication systems to two-factor authentication.”

In the report, the FDIC says it is considering making this a requirement. Last week, an FDIC spokesman said there’s no mandate currently that dictates online authentication requirements.

Financial services firms point out that dynamic-password tokens aren’t the only way to improve authentication.

There are also biometrics that use fingerprint or iris scans to prove identity.

Other measures include the type of two-way authentication software from PassMark Security , which goes beyond passwords without requiring specialized hardware. Stanford Federal Credit Union last month began using the PassMark System software to protect its 40,000 customers from phishing scams, says Sam Tuohey, vice president of technologies and e-commerce at the firm.

The PassMark System works by presenting a unique image and text to each credit union member as he begins the logon process.

In addition, PassMark software puts a simple ID onto the user’s PC in the form of a flash object with a cookie. The intent is to identify a home computer. If the customer does not happen to be on a home computer, a Web form drops down and asks a simple question the customer is expected to answer, such as “What is the name of a family pet?”

Most credit union members have adapted easily to the new security procedures, which augment the customary user ID and password, Tuohey says. “And seven days after we went with PassMark, we got phished,” he adds. To date, the credit union sees no evidence that the attack was successful.