Feeds

US regulators mandate extra eBanking security

Feds eye two-factors

Secure remote control for conventional and virtual desktops

US federal regulators want banks to adopt two-factor authentication as a means to combat the growing problem of online account fraud. Bank Web sites are expected to introduce systems that move beyond basic password access to accounts by the end of 2006, according to guidance issued by the Federal Financial Institutions Examination Council (FFIEC), AP reports.

"The (FFIEC) agencies consider single-factor authentication, as the only control mechanism, to be inadequate for high-risk transactions involving access to customer information or the movement of funds to other parties. Account fraud and identity theft are frequently the result of single-factor (eg ID/password) authentication exploitation," FFIEC said in a report (PDF) on Authentication in an Internet Banking Environment.

"Where risk assessments indicate that the use of single-factor authentication is inadequate, financial institutions should implement multifactor authentication, layered security, or other controls reasonably calculated to mitigate those risks," it added.

Two-factor authentication involves the use of password-generating device along with the funny list of codes you have on a Post-It note. That means a thief must know more than just a password to gain access to a user's account. Banks in the Netherlands and Scandinavia have been using the technology for years and it's generally credited with helping to make account fraud more difficult. However, security experts have pointed to man in the middle-style attacks that undermine the extra security layer offered by two-factor authentication; so although the technology helps guard against fraud, it would be rash to view it as a "silver bullet" solution. ®

Choosing a cloud hosting partner with confidence

More from The Register

next story
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
You really need to do some tech support for Aunty Agnes
Free anti-virus software, expires, stops updating and p0wns the world
Mozilla, EFF, Cisco back free-as-in-FREE-BEER SSL cert authority
Let’s Encrypt to give HTTPS-everywhere a boost in 2015
Meet OneRNG: a fully-open entropy generator for a paranoid age
Kiwis to seek random investors for crowd-funded randomiser
USB coding anarchy: Consider all sticks licked
Thumb drive design ruled by almighty buck
Attack reveals 81 percent of Tor users but admins call for calm
Cisco Netflow a handy tool for cheapskate attackers
prev story

Whitepapers

Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Choosing a cloud hosting partner with confidence
Download Choosing a Cloud Hosting Provider with Confidence to learn more about cloud computing - the new opportunities and new security challenges.
New hybrid storage solutions
Tackling data challenges through emerging hybrid storage solutions that enable optimum database performance whilst managing costs and increasingly large data stores.