Tuesday, September 23, 2008

Internet banking authentications

I guess that I am just like most of you, we have more than one internet banking account for we are usually dealing with more than one banks. Internet banking is really convenient and far more powerful as well, however, security is a great concern. Just like what people said, the more powerful you are, the more responsibilities which you will need to hold.

Some banks offer very simple authentications. A user name plus a password is all that is! I have experience of using one of these accounts, and later I found that my account was disabled suddenly, you know why? It is just someone or I myself, I don't know and I guess that I will never know, had attempted to login with wrong passwords for three times! Hey, what if some people just blindly guess the password, and then s/he can disable my account forever? I called the customer support and they insisted that I will have to go to the bank, to fill in the form personally, in order to re-activate that account! As you would know, I have never done that and I prefer to leave it disabled forever!

Another bank is just a little bit more interesting, other than user name and password, they will ask for my birthday... I guess that it's not that more secure, but then they also limited the range of services that I can do. If I need to do something more dangerous, they will need me to apply for a security device which generates a one time password whenever needed, and then I will need to bring along that (small) device and to use it every time I wanted to login. Secure, but still not very convenient, right?



A third bank uses a similar security device, but instead of using it only for dangerous operations, they request their users to use it every time even for operations as simple as checking the bank balance. Secure enough, but of course, it's troublesome to keep the device around with me always.

Finally, this is what I appreciate most. This bank uses simple user name and password for login, and you can do safer operations without anything else. However, when you are about to do some dangerous operations, they will send you an SMS which contains a one time password! Hey, that effectively replaced that small device, and I will always have my mobile phone with me. Not more extra burden. Quick and simple, and yet secure enough.