Advertisement
Promo

Security threats Toolkit

UK banks failing the security challenge

Dan Ilet ZDNet.co.uk

Published: 15 Apr 2005 13:05 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Internet banks are failing to offer their customers secure online transaction facilities, despite the growing threat of cybercrime.

That is the finding of a study published on Friday that tested 18 UK online banks and found that none were providing customers with supplementary authentication tools on top of usernames and passwords. Thirteen of those banks were susceptible to long-term hacking attacks through the use of password-stealing programs and identity theft scams — sometimes known as phishing attacks.

"The time is right for the FSA [Financial Services Authority] to use its regulatory power to mandate standardised authentication mechanisms for online financial services," said Phil Robinson, chief technology officer at Information Risk Management (IRM), the company behind the study.

"The UK is falling behind the rest of the world and it is the users who are suffering financial loss as well as a growing lack of confidence. The government should consider plans to implement extra factors of authentication as part of the UK national identity scheme," Robinson added.

Online identity theft has become a serious problem for banks and their customers. Last month, it was reported that banks lost £12m last year through online identity theft scams.

IRM said the remaining five banks employed the use of "selective passwords", which ask a customer for only a section of their access code.

"It's not that [those banks] aren't vulnerable, it's that they aren't as vulnerable," said Robinson, warning that selective passwords don't offer complete security. "Some attacks are pretty opportunistic. If the same information is used each time the customer goes into an account, the moment that is logged, that information is immediately exposed."

The FSA's Hong Kong counterpart has issued guidelines that all online banks there must supply customers with two-factor authentication, such as fingerprint readers, smart cards, or one-time password tags.

IRM did not disclose which banks were less secure than others, but tested the following organisations: Abbey National, Alliance and Leicester, American Express, Barclays Bank, Barclaycard, Barclays International, Capital One, Direct Line, Egg, Goldfish, HSBC, Legal and General Pensions, Lloyds TSB, MBNA Europe, Nationwide, Natwest, Norwich and Peterborough Building Society and Yorkshire Bank.

UK banks are preparing to agree on a form of two-factor authentication, according to banking industry body the Association for Payment and Clearing Systems.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
87 out of 188 people found this useful



Company/Topic Alerts

Create a new alert from the list below:



Video icon

Video

Sentry Posts Blog

Official Organizations Losing Data

How does this article from earlier today make you feel? How many more government, health service, or military officials are going to lose pen drives, DVDs, USB hard disks and even entire... More

2 comments

Twitter hack was DNS redirect

Twitter has said an attack on Thursday which took the site offline for many users was the result of a DNS redirect. A group calling itself the Iranian Cyber Army redirected users... More

1 comment

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters