Picture of Peter Cassidy
Cassidy: Banks do not compete on security

RBS begins two-factor authentication support

Bank will give customers card-reading devices to defend against phishing

Written by Tom Young

Royal Bank of Scotland (RBS) is to issue two-factor authentication card readers to its online customers this week.

The devices will protect against phishing attacks by providing a different password every time a customer logs on.

‘We will initially supply this enhanced security to business and personal customers who use e-banking to make frequent transfers or payments,’ an RBS spokesman told Computing.

The bank will then assess the technology’s success and roll it out to other customers.

The card readers, from vendor Xiring, are the size of a calculator and will be free of charge for customers who want them.

Barclays announced last month that it will start issuing similar devices later this year, while Alliance & Leicester has its own picture-based, two-factor systems in place. Lloyds TSB is testing a keyring-based system, but has not ruled out card readers as an eventual solution.

UK banking association Apacs defined the card readers as the UK standard for securing e-banking and e-commerce, despite the reticence of some banks.

Brendan Pickering, head of fraud technology at HSBC, says the system is unlikely to resolve fraud and security problems.

And George Hazell, information security manager at Alliance & Leicester, says the bank is uncomfortable with the practicality of a card reader, but would follow suit if the devices are adopted as the industry standard.

Two-factor is considered an effective defence against phishing, but is vulnerable to more sophisticated hacking attacks. Last year, US bank Citibank had its two-factor model cracked by a man-in-the-middle attack where a criminal sits between the user and their bank.

Banks have been criticised for using two-factor authentication as nothing more than a marketing device. But Peter Cassidy, from industry body the Anti-Phishing Working Group, says this attitude is unhelpful.

‘Phishing is low-tech and putting anything between the phisher and his goal is useful,’ he said. ‘Banks all face the same adversaries and it is an unspoken rule that they do not compete on security technology.’

Further reading

Two-factor buoys confidence

Introduction of two-factor authentication technology sees rise in customer transactions   More...

Experts rubbish two-factor authentication

Technology will not cut phishing, e-Crime Congress hears   More...

Pointsec adds two-factor authentication

Stronger encryption software for laptops and desktops   More...

RSA changes tack on two-factor authentication

Two-factor alone is no longer enough   More...

Related articles

NatWest now spammers favourite

Most popular company name used by fraudsters   More...

Abbey most targeted by phishers

UK bank takes the lion's share of attacks   More...

Online banking fraud on the decline

But credit card fraud abroad pushing up overall losses   More...

Third of UK surfers banking online

Brits seem unfazed by security concerns   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

18 Jul 2008

7.91 MBPodcast Special: Views from the Valley More...

17 Jul 2008

3.61 MBMalware explosion, nanotech fears and a jailed spammer More...

16 Jul 2008

4.17 MBiPhone 3G hacked, YouTube privacy deal and BT ad complaints More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Computer mouse

Computer mouse heading for extinction

Humble input device being usurped by touch screens and facial...  More...

Sony Vaio SR

Sony unveils Vaio business notebooks

Three new laptops aimed at 'out and about professionals'   More...

Advertisement

Firefox

Firefox gets security tune-up

Flaws patched for versions 2 and 3   More...

Apple iPhone 3G

Hold off on iPhone 3G, says analyst

Corporates should consider new handset a 'beta release'   More...

Advertisement