ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

UK banks failing the security challenge

Dan Ilet ZDNet.co.uk

Published: 15 Apr 2005 13:05 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Internet banks are failing to offer their customers secure online transaction facilities, despite the growing threat of cybercrime.

That is the finding of a study published on Friday that tested 18 UK online banks and found that none were providing customers with supplementary authentication tools on top of usernames and passwords. Thirteen of those banks were susceptible to long-term hacking attacks through the use of password-stealing programs and identity theft scams — sometimes known as phishing attacks.

"The time is right for the FSA [Financial Services Authority] to use its regulatory power to mandate standardised authentication mechanisms for online financial services," said Phil Robinson, chief technology officer at Information Risk Management (IRM), the company behind the study.

"The UK is falling behind the rest of the world and it is the users who are suffering financial loss as well as a growing lack of confidence. The government should consider plans to implement extra factors of authentication as part of the UK national identity scheme," Robinson added.

Online identity theft has become a serious problem for banks and their customers. Last month, it was reported that banks lost £12m last year through online identity theft scams.

IRM said the remaining five banks employed the use of "selective passwords", which ask a customer for only a section of their access code.

"It's not that [those banks] aren't vulnerable, it's that they aren't as vulnerable," said Robinson, warning that selective passwords don't offer complete security. "Some attacks are pretty opportunistic. If the same information is used each time the customer goes into an account, the moment that is logged, that information is immediately exposed."

The FSA's Hong Kong counterpart has issued guidelines that all online banks there must supply customers with two-factor authentication, such as fingerprint readers, smart cards, or one-time password tags.

IRM did not disclose which banks were less secure than others, but tested the following organisations: Abbey National, Alliance and Leicester, American Express, Barclays Bank, Barclaycard, Barclays International, Capital One, Direct Line, Egg, Goldfish, HSBC, Legal and General Pensions, Lloyds TSB, MBNA Europe, Nationwide, Natwest, Norwich and Peterborough Building Society and Yorkshire Bank.

UK banks are preparing to agree on a form of two-factor authentication, according to banking industry body the Association for Payment and Clearing Systems.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
79 out of 175 people found this useful



Company/Topic Alerts

Create a new alert from the list below:



Related Jobs

Transition Analyst

For our customers, it might be that we're the world's biggest building society and the UK's largest mutual organisation. You'll be able to manage a ...

Functional Consultant sought, ETRM / SAP TSW, 40k - 55k

My client implements their own products at leading commodity trading firms and investment banks globally. To get exposure to the front office with ...

CRM Technical Project Manager

Practical, experience-based evidence to justify PMI Senior Project Manager equivalency; - Experience of working on large programmes involving a 'Big ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment