All the latest UK technology news, reviews and analysis

Web banking risk down to human error

by Robert Jaques

08 Nov 2007

Be the first to comment

  • Tweet this
Hacking
Users are not taking basic steps to protect themselves from online hackers

The vast majority of internet banking users are not taking even basic steps to protect themselves online, according to a new study.

Mohammed AlZomai, of the Information Security Institute at the Queensland University of Technology, said that one-in-five online transactions is vulnerable despite added security methods such as SMS passwords.

AlZomai explained that the security threat had more to do with human error and the usability of advanced authentication systems than any technical security problem.

"In response to the growing threat to online banking security, most banks have implemented special methods for authenticating a transaction," he said.

"A typical method is sending a one-time password via SMS to the customer's mobile phone for each transaction. The customer must manually copy the password from their phone in order to confirm the online transaction."

But AlZomai maintained that customers were failing to notice when the bank account number in the SMS message was not the same as the intended account number, a clear sign that hackers had infiltrated the system.

As part of the study, the university developed a simulated online bank and asked participants to play the role of customers and undertake a number of financial transactions using an SMS authorisation code.

AlZomai then simulated two types of attack: an 'obvious attack' in which five or more digits in the account number were altered; and a 'stealthy attack' in which only one digit was changed.

"It is worrisome that obvious attacks were successful in 21 per cent of cases, and stealthy attacks in 61 per cent of cases," he said.

AlZomai claimed that the experiment showed that a "significant number" of users were unable to identify the attack.

"According to our study only 79 per cent of users would be able to avoid realistic attacks, which represents an inadequate level of security for online banking," he concluded.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

35%

0%

11%

54%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Software Programmer/Engineer; C#, Winforms, WPF, WF, WCF, SQL

APPLICANTS MUST BE A EU CITIZEN OR HAVE PERMANENT RESIDENCY...

C# Software Developer; C#, winforms, SQL

C# Software Developer/Programmer/engineer; C#, Winforms...

Linux Administrator / Senior Linux Administrator/ Debian Ubuntu

Linux Administrator / Senior Linux Administrator / Debian...

C#, WPF, Silverlight, UI Development, Software Engineers

C#, WPF, Silverlight, UI Development, Software Engineers...

To send to more than one email address, simply separate each address with a comma.