ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

Online banking security standard 'by the end of 2005'

Tom Espiner ZDNet.co.uk

Published: 17 Oct 2005 15:45 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A UK authentication standard for online and telephone banking will be launched before the end the year, the Association of Payment and Clearing Systems (APACS) said on Monday.

The UK standard will take the form of a small device in which you insert a chip and PIN card, according to an APACS spokesperson. After the four-digit PIN is entered, a numeric, one-time-only password is generated according to an algorithm and displayed on the screen of the device. This password is then used to authenticate the users so that they may then access online or telephone banking.

All members and schemes signed up to APACS will use the general standard. These include all of the major UK banks, as well as credit card firms Visa and MasterCard.

The technological template will be a "platform for interoperability", and will mean users should not need "half a dozen different devices" if they use more than one bank or credit card, the spokesperson said.

Trial versions of the device will be tested "over the next couple of years" by banks. Exactly when they will be tested will be a competitive issue for individual banks, the spokesperson said.

Lloyds TSB announced a trial for 30,000 online customers on Friday for a one-time-only password generation device, although the new general standard device will be "slightly different," according to APACS.

Who foots the bill for the devices — consumers or the banks themselves — will also be a competitive issue between banks, according to APACS.

Banks will also need to take consumer reluctance to adopt this technology, as well as a more general fear of online banking into account, according to Unisys, which supplies IT systems to many UK banks.

"Despite the fact that banks issue communications about security, the view from consumers is that they don't know enough about it. Firewalls make consumers nervous," Paul Leckie, a partner in Unisys global financial services, said.

Leckie welcomed the Lloyds TSB one-time-only password device trial, as he believes it would address both consumer's worries and the overall question of security.

"We welcome the Lloyds TSB trial as it will give answers to questions such as: what if a consumer is [banks with different banks]? How can you ensure safe distribution of the devices? What if the device breaks, or is lost or stolen? How will making banking online more difficult affect consumers — will they be driven away?," Leckie said.

Banks, according to Unisys, should be aware that two-factor authentication by itself would not be a guarantee against fraud.

"Banks need to be aware that two-factor authentication makes fraud harder to perpetrate, but it's not a total solution. Banks have to monitor all of their customer interactions, not just transactions. Fraudsters might request an address change and a credit check before perpetrating a fraud," Leckie said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
81 out of 133 people found this useful



Company/Topic Alerts

Create a new alert from the list below:










Related Jobs

Financial Services - Risk and Compliance

Specific Technical Experience The individual will need change programme and systems implementation experience in a selection of the following areas: ...

Support Analyst - System Administration

Bank of America Bank of America (NYSE: BAC) is one of the world's largest financial institutions, serving individual consumers, small and middle ...

Credit Risk IT - Business Analyst - Tier 1 Banking **

The Credit Risk IT department is a global team tasked with the provision of providing risk solutions to the Banks Front Office Credit Business. ...

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

2 comments

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains