Please could we have two-step authentication for e-commerce

Opinion
May 2, 20054 mins

* Using a password alone for authentication is a real gamble

On my way home from work yesterday, I stopped at one of my bank’s automated teller machines and withdrew $40. In order to do so, I had to insert my personal ATM card and then enter a password. This two-step authentication system is so simple that I hardly give it a thought.

After dinner last night, I sat at my computer to pay bills. I use my bank’s automated bill pay system, through which I authorize thousands of dollars worth of transactions every month. While I’ve used automated bill pay for several years now, I must admit that I feel very uneasy using it these days. I’ve become much more aware of the vulnerabilities of my bank account due to things like keystroke loggers and identity theft. 

What makes me especially nervous is that my bank only requires one layer of authentication – a password – to allow me access to my account and all my cash. Anyone in the security business will tell you that using a password alone for authentication is a real gamble today.

I’d be much happier if my bank would force me to use a second form of authentication. Perhaps the easiest method would be to require a session password in addition to the account password. The session password would only be valid for the specific transaction of a given banking session. A stronger measure that I would prefer is the use of an authentication device, such as a smart card or password token. The inconvenience of having to use a physical device as well as a password would pale in comparison to the peace of mind it would give me. (Of course, I know that even this kind of system can be compromised, but it takes more effort than stealing a password.)

Banks and other financial institutions might soon have an added incentive to improve online security for their customers. As I’ve mentioned in this newsletter before, a Miami businessman has filed suit against Bank of America over an electronic transaction that resulted in $90,000 being diverted from his account to a bank in Latvia. Joe Lopez accused Bank of America with negligence and breach of contract in not alerting him to a virus that would install a keystroke logger on his PC until after the alleged damage was done.

Bank of America does not expect to be held liable in this case, but it does raise the question of just how much responsibility a bank or merchant does have to help its customers protect themselves. The sad fact of the matter is that many PC-using consumers are naïve about security threats, and they don’t stay current with anti-virus and anti-spyware applications. If it helps to reduce even a few threats by adding secondary authentication to complete a transaction, I’m all for it and would be willing to pay for it.

Unfortunately, the Bank of America lawsuit isn’t a rare instance of a hacker logging other users’ keystrokes to gain access to financial accounts. In March of this year, New Zealanders were warned to be extra cautious when using Internet-based banking. The warning followed the discovery of a keystroke logger on PCs in a public Internet café in Wellington. The hacker gained access to usernames and passwords of unsuspecting people doing their banking online while at the café.  While there is no proof that accounts were breached, consumers’ confidence was surely shaken.

I use an ActiveCard token on my PC along with a password to access my network via remote access. I wish my bank would implement something like this. I’d feel a lot better about paying the mortgage electronically if it would.mailto:Linda.Musthaler@currid.com 

Linda Musthaler is vice president of Currid & Company.  You can write to her at