
Are banks just trying to impress us with newfangled security?
Published: 3 May 2005 13:40 BST
Banks may talk of using biometrics but doing so would hardly be a foolproof means of providing secure transactions, says Martin Brampton.
There seems to be as much window dressing as there is clear thinking in the security arena. Headlines say the banks are thinking of using biometrics to authenticate transactions. Yet how much thought has actually gone into this idea?
Maybe something of the kind is inevitable with banking, which has always involved a good deal of smoke and mirrors. For many years, we were impressed with the solidity of the banks, mainly on account of their grand buildings and the imperious looks of the managers. Of course, such features did not stop banks failing, especially in countries with a less substantial support regime than the UK.
So perhaps the latest moves are in the same vein: designed to give us a sense of security more than to actually achieve anything. The banks' efforts are built around the currently popular mantras of the IT security industry. Yet the reality is always more complex and a lot messier.
The favourite story nowadays is three-factor authentication: something you know, something you possess and something you are. The first has never been very effective because of people's inveterate tendency to blab.
Remember the researchers who stood on Liverpool Street station asking people for their computer passwords? Most people told them. And last week it came to light that bank customers were happily revealing their PINs to call centre staff, only to find their accounts promptly cleaned out.
Something you possess seems a more promising angle. For the banks, that used to mean magnetic strip cards. Nowadays it means smart cards with embedded chips. Increasingly, it is likely to mean ingenious security devices that generate single-use codes that are constantly changing. These would be used more if they were less expensive.
The trouble with all these technological fixes is that it is difficult to keep ahead of the enemy. Magnetic strip cards - and to a lesser extent smart cards - are vulnerable to the wide availability of readers, and the inevitable tendency for people to try to crack the systems for their use. The problem is that it is difficult to package up sophisticated security in a form that can be used millions of times a day by people all around the world.
So now there seems to be a lot of talk about biometrics for the 'something you are' level of authentication. Before we get to worries over the effectiveness of the technology, it seems to me there is a significant problem of user perceptions for organisations such as banks.
There is something quite offensive about being subjected to physical checks such as fingerprints and iris scans. We know who we are and sometimes the people we are dealing with know who we are too. So the implication tends to be that in circumstances where we have to be identified by some machine, we are being treated as an object and not a person.
Moreover, despite all the talk of the primacy of the customer, we tend to feel we are supplicants when we ask to receive some of our own money, the safe keeping of which we have entrusted to the bank. Is the bank providing us with a service or are we merely the tools of the bank?
However that may be, the thinking behind biometrics is confused. They make some sense in situations such as an airport, where it is necessary to be certain that a person matches their documents, such as their passport, and that the documents are genuine. But the vast majority of banking transactions now take place at a distance.
That opens up a plethora of possibilities. There was the Japanese man, Matsumoto, who made a false latex 'finger' for about £5 worth of materials, which was good enough to fool a fingerprint identification machine - albeit some years ago when the technology was less sophisticated. Then there is the simple fact that what is transmitted to the bank has to be a digital representation of the fingerprint or whatever biometric identifier is being used.
Anything that can be digitally transmitted can be copied and therefore can be perfectly forged. The only issue is getting hold of it. We know that spyware is becoming more of a threat than the old fashioned virus. It is hard to avoid the conclusion that biometrics in banking is just another variant of the grand façade.
Martin Brampton is founder of Black Sheep Research, an independent consultancy providing research, writing and speaking services on a wide range of business and technology issues. Martin was previously a director at Bloor Research, and has worked with IT as a user and analyst for over 20 years. He is a longtime contributor to silicon.com and his blog can be found on his website.
Most remote biometric checks are vulnerable to fra...
Stuart Moffat
Good article but a little off the mark. I have bee...
Terrence Gold
In the case of credit/debit card transactions face...
Anonymous
Mr. Gold has obviously had very little experience ...
Darrell E. Smith
I understand Mr. Brampton's position that he may b...
www.omniidentity.com
This will entail: PKI Public Key Infrastructures Smart cards and tokens Authentication technologies and techniques Identity management Single Sign on ...
The role in question is a Quantitative Commodity Desk Strategist working to structure and model transactions and to improve the profit making ...
The successful candidate must possess C++ / Windows with C#, SQL and OO design / analysis tools. You will work on a new high-profile C++ trading ...
CIO Agenda 2008
The exclusive silicon.com CIO Agenda 2008 survey looks at the CIO's tech shopping list for the year, examines whether IT budgets are rising or falling and reveals what the pain points are for tech chiefs this year. Find out more in our latest special report.
Staffing Service Coordinates Sales Activities, Utilizes Business Intelligence With...
Teachers Association Turns to Centralized Data Repository to Improve Member Service
Financial-Software Leader Credits Productivity Boost, Reduced IT Costs to 2007 Software
United States Coast Guard Explores Potential to Enhance Training With Digital Note-Taking...
Stories from the web...
Copyright ©1995-2008 CNET Networks, Inc. All rights reserved. Top of page
silicon.com Dear silicon.com... XP lives, the femtocell 'truth', BlackBerry bashing… Reader Comments of the Week
Martin Brampton The Brampton Factor: Open source 'brotherhood' closed to co-operation Where's the real sharing?