Can you count on your online bank?

While the threat caused by recent security beaches at a raft of online banks may have been exaggerated, such organisations need to take the initiative in educating users about security procedures if they are to boost consumer confidence.

Jim Mortleman

If you believe all the press reports, banking online is about as secure as leaving your cash in a sack outside the front door. Everywhere, it seems, hackers are itching to infect your system with Trojan horse programs that can steal your account numbers and passwords.

You might also feel that the banks themselves are being a bit cavalier about adequately testing the security of their systems, making it relatively simple for anyone with a modicum of technical savvy to break into your account and start helping themselves to your money.

Advertisement

It is not hard to see why consumers lack confidence in internet banks. High profile names in the UK such as Prudential's Egg.com, Halifax, Abbey National and Barclays have all hit the headlines more than once this year due to problems with their online services.

And just over a week ago, the Observer claimed that the future of internet banking had been "thrown into chaos", after a UK security expert managed to gain access to millions of online accounts.

According to the report, Ralph Dressel found this supposedly secure information on the website of US company Fiserv which runs the software for dozens of online banks, including the UK's Abbey National.

But, in fact, an investigation by vnunet.com last week revealed that the information accessed by Dressel was nothing more than fictitious data used for staff training and demonstrations - not before the story had been repeated unchallenged by a number of other news services, however.

Exaggerated claims
Closer inspection of other e-banking scares reveals similar patterns of exaggeration. "Problems" at the Halifax and Abbey National earlier this year did not involve security breaches - the organisations simply had difficulties in getting their services to work properly. Embarrassing, perhaps, but hardly proof that customers' accounts were at risk from attack.

Egg.com suffered similar software problems earlier this year, but the online bank also found itself the centre of attention again in August when three people were arrested for defrauding it. Again, it turned out that the fraud did not involve a system security breach. And indeed, it was Egg's system that picked up the fraud in the first place.

At the end of July, reports of a "serious security breach" at Barclays' online banking service turned out to be a simple glitch that resulted in just four users being able to view another account holder's details. They were unable to carry out any transactions, however, and the problem was corrected just hours after it was spotted.

Days later, a "second security blunder" at the bank turned out to be a problem caused by the sharing of computers. After users had accessed their own accounts and completed a transaction, someone else using the same machine found they could access the account again by pressing the 'back' button on the machine's web browser.

And such problems at the user end certainly need to be addressed. As people use the internet for financial transactions more and more, they need to be aware of security issues and ensure they are protected by adequate systems and procedures.

It would be wise, for example, not to access your bank details from a shared PC - or at the very least to log out of the service, clear the browser's cache and shut it down before you leave the machine.

You should avoid passwords that someone else might be able to guess, be careful about leaving them written on Post-It notes by your PC, and never let them be 'remembered' by the Windows operating system. In addition, all machines used for online transactions should be fitted with regularly updated firewall or antivirus software.

Launch now, worry later
That said, online banks cannot totally escape blame for falling levels of user confidence. With analyst Datamonitor predicting earlier this year that 21 million Europeans will be banking over the internet by 2004, companies have been eager to quickly launch products and services in a bid to grab as big a slice of the pie as possible. Teething troubles - although inevitable but, in most cases, not critical - have undoubtedly been exacerbated by the banks' "launch now, worry later" mentality.

Robin Arnfield of e-finance consultancy Lafferty Group, believes the banks need to act now to restore consumer confidence and boost security. "Many people's fears over security are not justified if banks are using 128-bit encryption, but it would help even more if they were to issue digital certificates," he said.

While admitting that certificates are complex and more costly to implement than standard SSL security, Arnfield claims that the added protection they provide against fraud means that online finance houses will start adopting them more and more.

He added that password procedures also need to be improved to avoid interception by hackers. "For example, when you log on to Egg now, you have to click on the right figures rather than type them in, which is a lot more difficult for hackers to capture," he explained.

Other measures that Arnfield says online banks could introduce to help boost consumer confidence and reduce security risks include offering free antivirus software to customers, giving comprehensive guarantees against fraud and being proactive about ensuring that users understand - and stick to - good security procedures.

He pointed out that many such initiatives are already being introduced by Egg, Abbey National's Cahoot and the Co-op's Smile, among others.

Growing pains
Security problems will never disappear entirely, and some criminals will always find a way into banks whether they're traditional or clicks and mortar. But two concurrent developments in particular suggest that the current scares will only be a blip in the birth of e-banking.

The first of these is the widespread adoption of smart cards and smart card readers. This is likely to take off with the next generation of mobile phones, personal digital assistants and other internet-connected devices, and should give customers a secure way to trade online without having to remember passwords or complex security procedures.

The second is that interactive digital television will provide the mass medium needed to bring e-banking to a wider public, according to Datamonitor.

Godfrey Sullivan, a business analyst at the market researcher, said: "Interactive television presents a long-term solution to many of the problems facing retail banks. It combines the visual basis and low running costs of the internet with the convenience and usability of the telephone and the mass appeal of the television. As such, it offers retail banks a way of increasing the cost efficiency of their distribution, while enhancing levels of customer service."

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

IBM and Ericsson bank on mobile finance

IBM is working with handset giant Ericsson to develop integrated financial services technologies that they claim will address users' fears of doing banking over mobile devices.

Cahoot tops net credit card rankings

Cahoot has again topped a quarterly list of internet credit cards produced by the UK branch of ecommerce researcher Gomez.

Banking jobs go as A&L moves online

UK bank Alliance and Leicester has announced plans to web-enable its business, which it said will help it to cut its yearly costs, but will mean the loss of 1500 jobs by 2003.

Irish internet banking plan scrapped

The Allied Irish Bank has ditched plans to launch a standalone internet bank, saying that it sees more of a future in the development of 24-hour online services as a supplement to traditional banking.

Related whitepapers

Related jobs

Most watched

Samsung talks up 3D TV

The next big thing, but it will take some time

Views from the Valley, 9 March 2010

Batteries, browsers and recognition for PARC researchers

Analysis and Reports

Continuous Availability for Microsoft SharePoint

This paper examines how to create continuous availability for Microsoft SharePoint by implementing high availability and disaster recovery solutions.

Database security: Preventing enterprise data leaks at the source

This report looks at the challenge of information protection and control (IPC) and how enterprises must adopt database security best practices

Poll

International Women’s Day poll

International Women’s Day poll

Have measures to encourage women into the IT profession been successful?

View poll results

Advertisement

White paper library

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Spotlight

street view screenshot

V3.co.uk weekly debrief, 12 March 2010

We look at Street View's expansion, and new rumours of...

Internet Liberty

Global campaign seeks to crush web censorship

Reporters without Borders announces World Day Against Cyber Censorship

Microsoft Word

Top 10 articles, 12 March 2010

Microsoft's i4i court defeat and rumoured Courier tablet

Views from the Valley: Behind the top 10 list

Iain and Shaun explain why names like Carol Bartz, Safra...

Primary Navigation