Thursday, December 27, 2007

Security with online banking, whats cool!

Today I was reading about how a few banks have started to adopt a creative solution to increase the security of their web portals for online banking. I was quite impressed by what they came up with. They were using cell phones; specifically they were transmitting a security code to your cell phone that you would then use along with your password to logon to their portal. To me this seems like a great way to achieve two-factor authentication without the typical impact a user would incur. Now to get access to your account an attacker would need what you have, your cell phone, and what you know, your password, which would greatly increase the difficulty of any brute force attack. As well as thwart any phishing scheme or keylogger you might come across.
Since the code is also transmitted out-of-band i.e. through your cell phone and not the web, it requires access to both your username/password and your cell. With the password expiring in a short (10 min) time and only good for one use, it serves as good as any token could. With the distinct differentiation that most users carry a cell phone by impulse, where a token they would not. Another great benefit to the bank and possibly lead to a more wide spread implementation would be that the user already has the equipment necessary, a cell phone, which is not the case with a Token. Providing a security code through a cell phone could be the strongest, and most usable form of authentication we’ve seen yet in online banking.

2 comments:

Blank said...

That is a great idea!

GPSWorldTraveler said...

Thanks for writing this - someday with securities in place as you outlined I may just try on line banking!