HSBC strengthens online fraud defences

07 Jan 2009

Comments: 4

A Computing logo
online fraud
Online banking fraud is on the rise

HSBC has deployed a new authentication system to protect online and remote transactions from fraud.

Using the system provided by Authentify, the authentication process is isolated from the web, and user or transaction details must be entered via a telephone call synchronised to online sessions, making it more difficult for criminals to hack into accounts even when using compromised personal information.

Further reading

The out-of-band system claims to offer the highest security with the most convenience, as opposed to two-factor authentication – whereby devices give customers automatically-generated one-time passcodes to use in conjunction with the password they already know – as a way to tackle fraud committed in cases where the cardholder is not present, such as online shopping.

A number of UK banks including Barclays, Lloyds TSB, Nationwide and Royal Bank of Scotland have introduced two-factor authentication schemes, while HSBC and Abbey have opted not to, saying the devices were considered impractical.

Figures released in October by UK payment service Apacs showed that online banking fraud losses totalled £21.4m during the six months to June 2008, a 185 per cent rise on the 2007 figure.

Reader comments

bANKS INCREASE ONLINE FRAUD DEFENCES

We are never happy. Let's give the banks a break - they are trying hard to protect us. Not enough for some and too much for others. Until biometric user authentication is implemented it's all down to user care to avoid cyber carelessness..and even then the cyber criminals will bite back.

Posted by: C. Coats  19 Jan 2009

a puny bank did it a long time before

wake up UK

tiny APSbank www.apsbank.com.mt have had sms confirmation codes since over a year for their online banking system.

indexed tan files have been common in Germany since many years.

Posted by: Albert  09 Jan 2009

Defensive complexity

While this might seem like a good and strong way to keep customers safe when banking online, it runs the risk of alienating more savvy users if it's a mandatory process. For people who keep a close eye on their bank accounts, are very familiar with phishing tactics and are therefore content with the two factor authentication, this just becomes an inconvenience.

Basically it panders to the lowest common denominator and is not ideal for everyone.

Posted by: David  09 Jan 2009

For the public's eyes

Maybe it's safer for the public's eyes, but excuse me, having access to the victim's computer, doesn't the 'hacker' also have access to the authentify.com account also?
It seems to me this, just like most of nowadays security 'improvements' are just there to fool the naive people, not for a real security purpose.

Posted by: Andrew Wiles  07 Jan 2009

Have your say on this article

All fields required. Your email address will not be displayed on the site.

By submitting a comment you agree to abide by our Terms & Conditions

  • Digg
  • Tweet

Newsletters

Sign up for our FREE newsletters

Technology Patent Wars

Large companies such as Microsoft, Facebook and Google have been hoovering up technology patents recently. Is this stifling innovation?

87 %

5 %

8 %