All the latest UK technology news, reviews and analysis

Banks urged to change security policies

by Ian Williams

22 Jan 2009

Be the first to comment

  • Tweet this
Hacker
ID information is often accessible through a few quick searches

Basic security questions, such as asking for a user's mother's maiden name or post code, can be circumvented far too easily and should not be used, according to Symantec.

The security firm said that this type of information is often readily available online and easy accessible through a few quick searches, and that these types of questions are no longer enough to confirm an identity.

"All you need to steal someone's identity can be obtained simply by looking at the Census data," said Guy Bunker, chief scientist at Symantec.

"Bank and credit card companies use information such as mother's maiden name as a standard security question, but it's no longer enough. They have to look at other ways to prove that you are who you say you are."

Bunker reckons that, although a lot of work has been done to improve security when accessing accounts online, telephone banking is wide open to abuse.

Operators who need to confirm a customer's identity should be seeking more random information, or asking for individual characters from a predefined pass-phrase, thereby mitigating the risk if someone overhears the conversation.

"Banks must start asking questions that no one else can find the information for. First pet's name or favourite film would be fine, as long as the answers to these aren't published on a social networking site. The ideal scenario would be for people to choose their own questions," he said.

Symantec's recent Underground Economy Report (PDF) found that full identities are the third most common specific item requested by online criminals, accounting for nine per cent of the requested total.

Full identities are very popular with fraudsters as it makes it easier to access existing accounts, and allows them to create new accounts in the victim's name, potentially giving them access to a much larger payout and extending the time until the fraud is detected.

To help combat this type of fraud, some financial institutions have implemented other authentication technologies, including voice identification, to help verify the caller's identity.

"Confidence in the banking system in the UK is at an all-time low. It is time banks took responsibility for ensuring the security of their customers online and over the phone," concluded Bunker.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

30%

1%

12%

57%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Procurement/P2P Transformation Consultant

Premier Consulting Firm - Procurement/P2P Transformation...

IT Strategy and Transformation Professional

Premier consulting firm - IT Strategy and Cloud Consulting...

C# Developer- Shropshire, West Midlands

Software developer/ C# developer, (ASP.NET, C#, MVC...

Oracle Developer/ Programmer- Forms, Reports, PL-SQL

Oracle Developer/ Programmer- Oracle ebusiness suite...

To send to more than one email address, simply separate each address with a comma.