Security Software Zone Security Software Zone
Home Contact Us
Search in
Forum SecurityToolbox Submit Software
Security Software Zone Login
Security Software Categories
News - Articles - Reviews
Free Newsletter
Join our mailing list and receive
security software news and
advice from our experts.
Submit
  Security Software Zone » Software Reviews » General Security » Many Financial Institutions Still Have Not Implemented Multi-Factor Authentication For Their Websites

Many Financial Institutions Still Have Not Implemented Multi-Factor Authentication For Their Websites

Category: General Security
Published: 06/02/2007, 13:45  
Editor: Remus Zoica
 
Print article
Send to a friend
Search in reviews
    The fastest growing segment of multi-factor authentication customer base is comprised of organizations who had previously adopted challenge / response or site authentication image-based systems, according to Sestus Data Company. While many U.S. financial institutions still have not implemented multi-factor authentication for their websites, others are now discovering that challenge / response or image-based systems they rushed to implement before the deadline fail to meet recent regulatory guidelines. Under the weight of increased regulatory scrutiny, these financial institutions are now turning to Sestus, one of only a handful of vendors whose products meet the regulatory definition of multi-factor authentication.

    In August of 2006 the FFIEC published supplemental guidance in which it clarified what it considered to be true multi-factor authentication. In their supplement, the FFIEC wrote, "True multifactor authentication requires the use of solutions from two or more of the three categories of factors", i.e. something the user "knows" combined with something the user "has" or "is".

    In the months before the FFIEC issued their supplemental guidance, a host of solutions had been introduced to the market promoting variations of the challenge / response approach to authentication, usually mixed with image verification. Most important of these was Passmark Sitekey, a company that rode to notoriety largely on the strength of its early adoption by Bank of America.

    Many challenge / response systems make no pretense of retrieving anything the user "has" or "is", relying entirely on things the user "knows". They solicit login IDs, PINs, and personal data at different times in the process, obscure the entered data with on-screen keypads sliders and dials, and show pre-selected user images when finished. Their vendors assure ill-informed buyers that their solution will satisfy the regulatory requests and they cite well-known organizations such as Bank of America to substantiate their claims.

    Challenge / response systems work by asking information in response to challenge questions. Some of these systems try to retrieve cookie files and other information previously stored on the user's computer, thus retrieving something the user "has". When this information cannot be found, as would be the case for millions of internet users who regularly clear their web browser's internet cache, these systems fall back on soliciting more of what the user "knows" in the form of challenge questions, such as "What is your mother's maiden name?" If answered correctly, they often show a pre-selected image to the user, supplying yet another piece of information the user "knows". Even the most successful challenge / response systems are therefore only occasionally multi-factor, an inconsistency that falls short of the regulatory requirements.

For more information visit http://www.sestusdata.com/
Bookmark to:
Add 'Many Financial Institutions Still Have Not Implemented Multi-Factor Authentication For Their Websites' to Del.icio.us Add 'Many Financial Institutions Still Have Not Implemented Multi-Factor Authentication For Their Websites' to digg Add 'Many Financial Institutions Still Have Not Implemented Multi-Factor Authentication For Their Websites' to FURL Add 'Many Financial Institutions Still Have Not Implemented Multi-Factor Authentication For Their Websites' to reddit Add 'Many Financial Institutions Still Have Not Implemented Multi-Factor Authentication For Their Websites' to Technorati Add 'Many Financial Institutions Still Have Not Implemented Multi-Factor Authentication For Their Websites' to Yahoo My Web Add 'Many Financial Institutions Still Have Not Implemented Multi-Factor Authentication For Their Websites' to Stumble Upon Add 'Many Financial Institutions Still Have Not Implemented Multi-Factor Authentication For Their Websites' to Google Bookmarks Add 'Many Financial Institutions Still Have Not Implemented Multi-Factor Authentication For Their Websites' to RawSugar Add 'Many Financial Institutions Still Have Not Implemented Multi-Factor Authentication For Their Websites' to Squidoo Add 'Many Financial Institutions Still Have Not Implemented Multi-Factor Authentication For Their Websites' to Spurl Add 'Many Financial Institutions Still Have Not Implemented Multi-Factor Authentication For Their Websites' to Netvouz Add 'Many Financial Institutions Still Have Not Implemented Multi-Factor Authentication For Their Websites' to Rojo Add 'Many Financial Institutions Still Have Not Implemented Multi-Factor Authentication For Their Websites' to Bloglines Add 'Many Financial Institutions Still Have Not Implemented Multi-Factor Authentication For Their Websites' to Tailrank
Add comment
Security Software Zone is not responsible for the content of these User comments. The views and opinions expressed are those of the individual poster and not the Security Software Zone.
User comments (0):

There is no comment for this review.

 
Reviews related to Many Financial Institutions Still Have Not Implemented Multi-Factor Authentication For Their Websites
 

Automatic Forwards Of Email And Adds New Administrative Controls
 VersaEdge Software LLC, an email forwarding company, announced today major new features added to the email forwarding VersaForward Service. New administrative controls allow users to control settings such as advanced text reduction, custom filtering, pausing forwarding, spam blocking, and forwarding destinations.
Read More >
04/18/2008, 11:22
 

3 basic security measures for your site
  Anywhere you have a dynamically generated page, you could be "open" to attacks where malicious HTML is embedded into your pages.
Read More >
01/23/2007, 09:39
 

Battery-Assisted Passive Tag That Uses SecureRF's Security Technology That Authenticates and Encrypts Data
 Battery-assisted passive tag that uses SecureRF's breakthrough in security technology that authenticates and encrypts data communications.
Read More >
04/10/2007, 01:40
 

The Interlink ePad Signature Capture Device and Laser App Software Can Securely Capture clients e-signatures
 The goal is to define a set of standards and processes that offer electronic documents the possibility to circulate from the consumer to the broker-dealer and finally to the product companies.
Read More >
07/13/2007, 22:41
 

Commonwealth Legal And Wave Software Are Teaming Up to Offer Increased Efficiency
 Canada's largest and most trusted litigation support company and Orlando-based innovator in the de-duplication are teaming up.
Read More >
04/28/2007, 15:41

Sponsored