ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Jobs
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Security threats Toolkit

Lloyds TSB to trial two-factor authentication

Tom Espiner ZDNet.co.uk

Published: 14 Oct 2005 13:30 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Lloyds TSB has announced that 30,000 of its customers will trial a two-factor authentication device, in an attempt to fight online fraud.

The Access Code Device is keyring-sized and produces a randomly generated, one-time-only number that a customer enters when logging on, in conjunction with his or her password, explained Ken Farrow, group head of fraud at Lloyds TSB.

Users of the device are less likely to become victims of phishing and pharming, as the fraudsters would need both device and password in order to access a customer's account, according to Farrow.

"This protects against phishing and remote monitoring, because the device doesn't transmit any signals that can be intercepted," Farrow said.

Loss of the device would not in itself compromise the account, Farrow said, as the authentication is two-factor. "If the device is lost, it doesn't compromise security as you also need a password — this is the two-factor element. If it is lost, you inform the bank, and they cancel the device and issue another."

Lloyds is working closely with APACS (the Association of Payment and Clearing Systems) and other members of a working group to develop a standard authentication device for online banking and shopping, Lloyds said.

"We are working collectively within APACS to enhance security, and a standard is being developed which should be coming on-stream sometime next year," Farrow said. "We wanted to get ahead of the game and test whether our solution was right for our customers."

The 30,000 customers will be selected at random for the trial. "We will be offering the option of taking the device to a cross-section of the customer database," Farrow said.

The device will be modified following the trial, and the findings will feed into the APACS standards work. "We're looking at the impact on fraud levels, and working closely with APACS. If we decide to roll out a two-factor device, it would be this or something else (as part of a standard)."

Farrow was unwilling to say who developed the device because of security implications. "It's a proprietary device that has been made for us by a third party," he said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
109 out of 223 people found this useful



Company/Topic Alerts

Create a new alert from the list below:




Sentry Posts Blog

Nasa and the virus

Yesterday the BBC ran a story about a computer virus making it into orbit, which I read with incredulity. OK, it's a nice silly season story on the surface, but what really got me was... More

3 comments

Customer data found on eBay server hig...

The recent news about customer details being retrieved from a server sold on eBay is yet another story about the sorry state of information security in the electronic age (see: http://news.zdnet.co.uk/...m).... More

Post a comment

Does it matter if you are an aardvark...

In spam terms, apparently it does. According to Cambridge University security expert Richard Clayton, if your email address is aardvark at animal.net, you are more likely to receive... More

5 comments