Feeling better about online banking security

Opinion
Feb 1, 20063 mins

Last autumn, I started ranting about my bank’s use of single-factor authentication for online banking.  This bank only uses a user ID and password to verify my identity before giving me access to my checking account and online bill pay service.  It occurred to me that it would be terribly easy for a hacker to obtain that information and use it to gain illegal access to my account.

This worried me.  A lot.  At the time, there was a lot of news about keystroke loggers being surreptitiously installed on unsuspecting users’ PCs, and I felt vulnerable.

As if responding to my rants, the Federal Financial Institutions Examination Council (FFIEC) issued new guidance for U.S. financial institutions: multi-factor authentication should be implemented by the end of 2006.

This is good, as it forces the fence-sitting banks to do something now.  In the mean time, I did my own digging to learn more about this topic.  As I talked to more people in the authentication business, I began to feel more at ease.

First of all, I learned that most identity theft as well as unauthorized access to online accounts results from the use of paper, not PCs.  Bruce Cundiff of Javelin Strategy & Research attributes about 70% of identity theft cases to physical documents.  A thief is much more likely to steal your account information by looking at your paper statements – the ones that sit unprotected in your mailbox while you’re at work.  Many financial institutions now allow you to receive all statements electronically, thus reducing the risk of paper theft.

By contrast, only about 10% of identity theft in 2004 resulted from phishing, key loggers and malware, and the percentage of instances is holding steady from previous years.  Though I hate that it happens at all, 10 percent represents low enough odds that I can less my worries about online banking.

Next, I learned from experts that most banks have implemented security measures around the online banking process that take place in the background, without any visibility to the casual user.  For instance, I access my bank account from basically two different computers – one at work and one at home.  Should someone (even me) try to access my account from a different unknown PC, a flag goes up.  Also, I mostly access my account online between the hours of 8:00 AM and 10 PM Central time.  Attempted access at other hours would raise a flag.  Such behavioral scrutiny complements the old user ID/password combo. 

For more technologies and techniques, read my newsletters Financial institutions consider multi-factor authentication, Part 1, Financial institutions consider multi-factor authentication, Part 2  and Financial institutions consider multi-factor authentication, Part 3.   

I’m still anticipating multi-factor authentication from my bank later this year.  Meanwhile, I’ve had my confidence in the online system restored, so I won’t go back to writing paper checks and stuffing envelopes with payments.

What about you?  Does using online bill pay make you sweat, or do you have confidence that security is adequate for online banking?