
'Of course I know my mother's maiden name, but do you, really?'
By silicon.com
Published: 11 January 2005 17:35 GMT
We've long taken for granted the processes in place when contacting our banks. We hand over account numbers, passwords, postcode, mother's maiden name and any number of other identifiers to prove who we are.
But who is on the other end of the line?
This isn't a diatribe about the integrity of call centre staff, that's a whole other issue, this is more about taking for granted that the person on the other end of the line is from the bank they claim to be.
If we call them, via a number on a bank statement or a number published on their website, then that's all well and good, but increasingly our banks have taken to contacting us and it's a situation which is causing great concern.
Banks need to be aware of the role they play in providing a consistent voice in the battle against phishing. Of course, they must also contact customers if they see any reason for alarm but this is why we believe they should adopt some of the security measures they have foisted upon us for so long.
With phishing a major worry for bank customers, unsolicited contact from their bank instantly raises suspicion. Egg and LloydsTSB, for example, have taken to contacting customers out of the blue via text or automated voice message, requesting the customer call a given number.
Upon calling customers will be asked for some degree of personal information - although the banks are quick to point out not enough information to complete a phishing scam. But how easy would it be for a scammer to replicate such a strategy, just pushing a little further the kind of information they require? Some companies now favour a method of asking for random characters from a password or log-in. It would only take a couple of calls asking for different 'random' characters before the scammer had pieced it all together.
The security dialogue should be two-way, challenge and response - 'I'll show you mine if you show me yours'.
Before you give them your mother's maiden name you should be able to check they are indeed sitting in front of a screen which has such details on it. They should have information which only they and you should know is used for such authentication and they should prove they know it.
Customers should tell banks that if ever they contact them out of the blue they will need to use 'code word X' to confirm they are indeed their bank.
It's not a silver bullet to eliminate fraud, but it's an extra level of authentication which has now become necessary. Banks used to be unchallenged and upheld as institutions of authority. The prevalence of phishing scams now mean no business, least of all the banks, are free from suspicion.
While banks have previously reimbursed customers stung by phishing attacks there are murmurings afoot about their intention not to reimburse customers who haven't taken appropriate measures to protect themselves. Essentially a lack of common sense could cost you dear. So it's only fair that customers be allowed to demand more reciprocity from their bank.
Simply saying 'this is your bank...' isn't even worth the time it takes to say it. Now they must prove it.
I now ask any "cold calls" from credit or storecar...
MikeW
Time for ATMs to use chip readers, too.
If it's...
MikeW
Totally agree. We don't know who is on the other e...
Anonymous
If you want to verify that the person you're talki...
Graham Shepherd
I am also in total agreement.
I was contacted b...
Kevin Inskip
An exciting opportunity has opened up within one of the Worlds Leading Investment Banks. Seeking a well-educated candidate (1st or 2.1 from a ...
Contacting you regarding a Java dev role within the Fixed Income derivative team in a leading investment bank. This role will involve working on the ...
A direct sales specialist company based in Portsmouth area currently has an urgent requirement for a SQL Server Developer to join their expanding ...
CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.
Stories from the web...
Copyright ©1995-2008 CNET Networks, Inc. All rights reserved. Top of page
Martin Brampton Brampton Factor: Open source stands up for its rights Copyright can keep the movement alive...
Bob Tarzey The rise and rise of Infor Quocirca's Straight Talking: Where next for the apps giant?