All the latest UK technology news, reviews and analysis

Consumer group slams online banking security

by Phil Muncaster

27 Aug 2009

Comments: 2

  • Tweet this
Login screen
Most online banking systems are still vulnerable to key-loggers that can record passwords

Consumer rights organisation Which? has criticised the online banking systems of some of Britain's biggest lenders, labelling them insecure in a new report released today.

Abbey and Halifax were singled out as particularly poor. The latter requests users to type in their log-in credentials in full, thus exposing customers to tracking by key-logging software.

The same two banks, along with HSBC and First Direct, were also found to have no visible security controls for money transfers.

Which? also found that users of Abbey, Alliance & Leicester, HSBC and Halifax are not immediately logged out after a session, leaving them vulnerable if they use online banking on a shared computer.

Alliance & Leicester and HSBC were rated as 'average', while First Direct, Lloyds TSB, Nationwide, NatWest and RBS were given a 'good' rating.

Barclays was the only one of the 10 banks surveyed to get a rating of 'excellent'. The company requires all its online customers to use a two-factor authentication system involving a PINsentry device which generates a one-time password for each session.

Users who forget their device must enter a five-digit passcode and two characters from a memorable word.

Tony Dyhouse, director of the government-backed Cyber Security Knowledge Transfer Network, said that banks face a difficult challenge in trying to balance security with convenience.

"Any security measures they incorporate need to be valid on a mobile phone too, as mobile account management is going to be a big part of the very near future," he added.

"Mobiles provide an excellent second-factor identification, but bring the added risk of being lost or stolen."

Dyhouse argued that banks should strengthen password log-in systems by requiring a password consisting of a range of alpha and numeric characters, using drop down menus asking for a random combination of password letters, and ensuring that all information is transmitted in an encrypted format.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

31%

1%

11%

57%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Support Analyst

IT Support Analyst (initial 6 month fixed term) Cirencester...

Java Developer - Grad / Web / Mobile - Manchester

Java Developer - Graduate / Budding Superstar opportunity...

Solutions Consultant - JEE, PHP, Project Lead - Midlands

Solution Consultant - JEE, Support, Project Lead, SQL...

C++ Developer - Financial Vendor

C++ Developer - C++, STL, Boost, Delphi, Concurrency...

To send to more than one email address, simply separate each address with a comma.