The fact is that most banks take the security of their online services seriously, realizing correctly that a significant percentage of customers are not going to use such services if the banks have a reputation for being unsafe. Banks also save a lot of money by offering online services, allowing them to afford security enhancements, such as the SiteKey implemented by Bank of America. Many smaller banks now offer similar authentication...
One of the biggest mistake banks have made is in not ensuring that enough people are Internet-savvy. Customers must recognize that the avoidable risks of online banking reside, namely, in email scams and phishing attacks.
Some banks, however, are making an effort to educate customers. At a small regional bank I visited recently, there is an interesting notice on the subject, readable by anyone who waits at the drive-thru. The notice lists the tell-tale signs of the major Internet scams, like a phony request for a deposit, overseas payment via Western Union and so on. I commend the bank on this educational initiative. Banks need to stop being nervous about the minimal risks customers face online, even though the threat does exist. Banks should be more proactive in educating their consumer base, because such scams undermine the benefits of online commerce for everyone, regardless of whether that risk is directly related to a bank's actions or not.
The other big mistake that financial service providers make is the failure to pressure email providers into implementing universally trusted email. The technology to do this has existed for at least five years, but petty proprietary wrangling among vendors has repeatedly killed efforts to implement simple email changes that would cut out most spam and phishing. Banks and other financial service providers need to realize that many risks of online activity could be removed almost overnight by responsible cooperation between the likes of Microsoft, Comcast, AOL, AT&T, Roadrunner, Yahoo and Google.
Bill Gates relied on hopelessly optimistic estimates by his analysts when, in January 2004, he said that spam would be solved within two years. In all its forms, including phishing, spam continues to inflict costs that arguably exceed $100 billion a year in the U.S. alone. But Gates was right when he said it could be solved. All we need is less greed, more collective corporate goodwill, and maybe some good old-fashioned bullying from financial service providers.
Dig deeper on Two-Factor and Multifactor Authentication Strategies
Related Q&A from Michael Cobb
A reported 43% of Microsoft XML users are running vulnerable versions of the software. Security expert Michael Cobb discusses how to mitigate the ...continue reading
Security expert Michael Cobb explains what Open Authorization or OAuth 2.0 is, its pros and cons, and how it is different from bring your own ...continue reading
While the fundamentals of securing an e-commerce website haven't changed in a few years, there are new threat vectors and security risks to be aware ...continue reading
Have a question for an expert?
Please add a title for your question
Get answers from a TechTarget expert on whatever's puzzling you.