Home > Ask the Security Experts > Application Security Questions & Answers > How secure is online banking today?
Ask The Security Expert: Questions & Answers
EMAIL THIS

How secure is online banking today?

Michael Cobb EXPERT RESPONSE FROM: Michael Cobb

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 11 November 2007
Do you consider online banking in its current state to be secure? In your experience, what are the biggest mistakes that financial services providers -- and their customers -- make that expose them to security risks?

>
EXPERT RESPONSE
If you ask, "Is online banking in its current state secure enough?", then the answer is a qualified "Yes." While some banking customers have been defrauded through online channels, the extent of such problems is not enough to offset the advantages offered by online banking. (Just think of the number of miles of driving that online banking saves, thereby reducing the chance of a banking-related car accident!)

The fact is that most banks take the security of their online services seriously, realizing correctly that a significant percentage of customers are not going to use such services if the banks have a reputation for being unsafe. Banks also save a lot of money by offering online services, allowing them to afford security enhancements, such as the SiteKey implemented by Bank of America. Many smaller banks now offer similar authentication systems.

One of the biggest mistake banks have made is in not ensuring that enough people are Internet-savvy. Customers must recognize that the avoidable risks of online banking reside, namely, in email scams and phishing attacks.

Some banks, however, are making an effort to educate customers. At a small regional bank I visited recently, there is an interesting notice on the subject, readable by anyone who waits at the drive-thru. The notice lists the tell-tale signs of the major Internet scams, like a phony request for a deposit, overseas payment via Western Union and so on. I commend the bank on this educational initiative. Banks need to stop being nervous about the minimal risks customers face online, even though the threat does exist. Banks should be more proactive in educating their consumer base, because such scams undermine the benefits of online commerce for everyone, regardless of whether that risk is directly related to a bank's actions or not.

The other big mistake that financial service providers make is the failure to pressure email providers into implementing universally trusted email. The technology to do this has existed for at least five years, but petty proprietary wrangling among vendors has repeatedly killed efforts to implement simple email changes that would cut out most spam and phishing. Banks and other financial service providers need to realize that many risks of online activity could be removed almost overnight by responsible cooperation between the likes of Microsoft, Comcast, AOL, AT&T, Roadrunner, Yahoo and Google.

Bill Gates relied on hopelessly optimistic estimates by his analysts when, in January 2004, he said that spam would be solved within two years. In all its forms, including phishing, spam continues to inflict costs that arguably exceed $100 billion a year in the U.S. alone. But Gates was right when he said it could be solved. All we need is less greed, more collective corporate goodwill, and maybe some good old-fashioned bullying from financial service providers.

More information:

  • Senior News Writer Bill Brenner asks Panda Security's Gary Leibowitz how its offerings have catered to the online banking sector.
  • Visit SearchFinancialSecurity.com for more news and expert advice on online banking.


  • Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Application Security
    Can IBM's SMash technology secure Web applications?
    Why is backscatter spam so difficult to block?
    What are the risks of disabling the User Account Control (UAC) feature on Windows Vista?
    Protecting exposed servers from Google hacks (and Google 'dorks')
    Which automated quality assurance tools can be used to test software?
    Has proof-of-concept mobile device malware translated into any meaningful attacks?
    Is it possible to ban chat programs on an enterprise LAN?
    How to test the security of personal details submitted to a website
    Is security improved when the number of Internet gateways is reduced?
    Are Internet cafe users' email credentials at risk?

    Two-Factor and Multifactor Authentication Strategy
    Quiz: The new school of enterprise authentication
    The steps of privileged account management implementation
    The New School of Enterprise Authentication
    Trends in enterprise identity and access management
    Address Authentication and Transaction Validation Protocols to Stem Identity Theft
    Understanding multifactor authentication features in IAM suites
    SaaS Offering Handles SSO
    Identity Management Suites Enable Integration, Interoperability
    Product review: Secure Computing SafeWord 2008
    Keystroke recognition aids online authentication at credit union

    Phishing
    EV SSL certificates won't stop phishers, researchers say
    Apple iPhone mail, Safari prone to spoofing
    ING hopes to cut phishing attacks with encryption software
    Companies still monitoring email manually, survey finds
    Trojan downloaders, droppers skyrocket, Microsoft says
    New phishing, Zeus Trojan technique spreads crimeware
    New Storm attack exploits April Fool's Day
    Clinton, Obama campaigns used in spam blasts
    Google-Postini email services deliver security market message
    PDF spam reemerges in some inboxes
    Phishing Research

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    AAA server  (SearchSecurity.com)
    authentication  (SearchSecurity.com)
    authentication, authorization, and accounting  (SearchSecurity.com)
    federated identity management  (SearchSecurity.com)
    Kerberos  (SearchSecurity.com)
    password hardening  (SearchSecurity.com)
    typeprint analysis  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Find Security Solutions for Your Business
    Targeted Security Channel Tips for Resellers, Integrators and Consultants
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts