[Home]   [Full version]  

Human error puts online banking security at risk

Nov 07 ,Technology


Using an SMS password as an added security measure for internet banking is no guarantee your money is safe, according to a new Queensland University of Technology study which reveals online customers are not protecting their accounts.

Mohammed AlZomai, from QUT's Information Security Institute, said one in five online transactions was vulnerable to obvious attacks despite added security methods such as SMS passwords being adopted.

Mr AlZomai said the study had found that the security threat had more to do with the usability of the SMS system and human error, rather than any technical security problem.

"In response to the growing threat to online banking security, most banks have implemented special methods for authenticating a transaction," he said.

"A typical method is sending a one-time-password via SMS to the customer's mobile phone for each transaction.

"This means the customer must manually copy the password from their phone in order to confirm the online transaction."

But Mr AlZomai said customers were failing to notice when the bank account number in the SMS message was not the same as the intended account number.

He said if this occurred it was a clear sign hackers had infiltrated the system.

As part of the study, QUT developed a simulated online bank and asked participants to play the role of customers and undertake a number of financial transactions using an SMS authorisation code.

Mr AlZomai said he then simulated two types of attacks - an obvious attack which was where five or more digits in the account number were altered, and a stealthy attack which was where only one digit was changed.

"It is worrisome that obvious attacks were successful in 21 per cent of cases," he said.

"And when transactions faced a stealthy attack, 61 per cent of attacks were successful."

He said this study showed that a significant number of users were unable to identify the attack.

"This is a strong indication that the SMS transaction authorisation method is vulnerable," he said.

"According to our study only 79 per cent of users would be able to avoid realistic attacks, which represents an inadequate level of security for online banking."

Mr AlZomai said while this study highlighted the importance for customers to be vigilant when they were banking online, banks also had a responsibility to their customers.

"We hope this research will allow online banks and other online service providers to be better prepared for these emerging risks."

Source: Queensland University of Technology

Related stories:

Researcher: Tools Will Help Personalize ID Theft by 2010
A well-known security expert demonstrates a framework at the CanSecWest conference that makes it easier for criminals to steal identifying data.
Satellites help ensure safe sunning
Excessive exposure to ultraviolet radiation is responsible for up to 60 000 deaths a year worldwide, according to a report released this summer by the World Health Organisation. Many of those deaths, however, could be avoided through simple preventive measures such as seeking shade when the UV Index is high, the report says.
China's tech commissars target SMS porn
China's Ministry of Information Industry, the regulator of telecom, Internet and information-technology development, said it is targeting cell-phone smut.
Video telephony and home media via the Internet
Internet television, video telephony and music from the Internet – the living room of the future will become the communication center for the entire house. Siemens Communications has developed a range of innovative solutions for video telephony and home media – several prototypes of which will be introduced at CeBIT. These include a cordless telephone equipped with a digital camera and wireless local area network (WLAN) for video telephony on TV, as well as a new set top box that enables convenient access to streaming online video and music. An allin- one modem, Internet WLAN router and DECT base station was also developed jointly by Siemens and Telefonica Germany. The device is the basis for so-called triple-play services that will run on the Spanish/German carrier’s technical platform. The router and parallel set top box will enable high-quality TV via ADSL. The first triple-play offering will be introduced in summer 2005 in Europe.
Review: Tiny flash drives improve their security
(AP) -- Flash memory drives, the size of your thumb, are dirt cheap and offer gigabytes of storage. It's tempting to fill one of them with important computer files, clip it to a key chain and hit the road.
Google-sponsored satellite sends first image
A Google-sponsored satellite has beamed its first picture back to Earth in a successful test of a camera that will supply images for the Internet giant's free online map and navigation services.
Fake YouTube pages used to spread viruses
(AP) -- Savvy Internet users know that downloading unsolicited computer programs is one of the most dangerous things you can do online. It puts you at great risk for a virus or another time bomb from a hacker.
Yahoo! to do list: unveil new calendar
Internet giant Yahoo! on Wednesday rolled out an updated version of its Web-based calendar, in its latest bid to stay ahead of rival Google.

News discussion:

Technology news

[Home]   [Full version]