Newsletters Welcome, Guest Log In | Register

Data and Telecom

Companies’ communications strategies must be agile in a rapidly evolving market

About this Blogger RSS

Subscribe

Sign up now and get the best business technology insights direct to your inbox.

  • Daily Edge
  • CTO Edge Update
  • Business Tools & Templates
  • Aligning IT & Business Goals
  • Maximizing IT Investments

0

Two-Year-Old Study Slams Online Banking; Is it Still Relevant?

Posted by Carl Weinschenk Jul 30, 2008 10:36:19 AM

Last week, news hit several sites and publications, including IT Business Edge, that essentially said online banking is a disaster. More specifically, the study, written by Atul Prakash at the University of Michigan, said that 75 percent of 214 bank sites surveyed had design flaws and were insecure.

 

SC Magazine provided details about the flaws. Among them were forwarding users from secure to insecure pages without alerting the visitor; locating login options on insecure pages, and inadequate user IDs and passwords.

 

There are bits of good news amid the rubble, however. One is that the survey was done in 2006, so it is possible that some of the problems have been alleviated. The fact that the survey results are being released now, however, suggests the sponsors have good reason to believe the problems persist.

 

The other bit of good news is that vendors appear to be addressing online banking security.

 

One company with a new product is RSA Security, which now is part of EMC Corp. The company's SecureID Display Card is being tested by one bank in the United States and several overseas. The card, this Bank Systems & Technology story says, is a tool for meeting multi-factor authentication requirements created by the Federal Financial Institutions Examination Council (FFIEC). The story says that the companion software, RSA Authentication Manager 7.1, can be operated via a token embedded on a cell phone.

 

Another online-banking security-related product that made the news earlier is month was Kaspersky's Internet Security 2009. TechWorld reports that it features a virtual keyboard, which the site calls "a novel but simple" safeguard against keylogging. The story says details are not set, but it is believed that the virtual keyboard will cache passwords and other vital information entered by users. The caching will keep the data safe from software that logs keystrokes being entered into a physical keyboard. TechWorld says that the idea is not new, but that Kaspersky is the first to offer it in a standard security program.

 

Also this month, Aladdin Knowledge Systems and IdenTrust partnered to provide identity authentication for online banking and other financial transactions. The companies will offer certificate-based two-factor security.

 

In one sense, it is possible to overlook a study that is a couple of years old. It is important not to, however. Securing online banking is a tremendously important issue from the real and psychological points of view. The most obvious danger, of course, is that banking sites will be hacked and customer information stolen. In the bigger picture, the inability to protect banking and financial sites clearly is a poor reflection on the overall state of Internet security.

Add a comment Leave a comment on this blog post.

There are no comments on this post

Lowering Your IT Costs with Oracle Database 11g Release 2

This white paper identifies the key capabilities a database management solution needs to successfully deliver more information with higher quality of service, make more efficient use of IT budgets, and reduce the risk of change in data centers.

Software Forum: Information On Demand Virtual Experience

This interactive virtual forum presents leading IT experts providing the insights you need to turn your information into a strategic driver for innovation, business optimization and competitive differentiation.

Data Management Solutions

Data management and storage solutions, tips and best practices to improve the scalability, reliability, and accessability of your data.

Data Loss Protection

Data-loss prevention tactics, technologies and best practices to protect your sensitive and valuable company data.

Energy Efficiency

Best practices to optimize computing ability while minimizing power costs.

Application Grid

Learn more about this middleware layer that pools and dynamically provisions infrastruction application delivery resources to lower costs and improve efficiency.

All About Reducing Your IT Costs

Looking to cut costs? Use this research-driven Excel tool to pinpoint which IT cost reduction measures best fit your needs.

Learn more >

Strategic IT Planning & Governance Best Practices Guide

Use this guide — along with the more than 60 templates included — to ensure the overall success of your entire IT department.

Learn more >