Barclays to launch two-factor authentication

Card readers secure online banking


All online banking customers of Barclays will be issued with handheld card readers next year that will read their bank cards and generate one-time passwords to better secure their transactions.

The announcement came in an interview between director of online banking Barnaby Davis and Computing magazine last week. Barclays is expected to be the first bank to apply a new standard from UK payments association Apacs.

Last year, Apacs issued guidance to banks that called for stronger security. "In view of the growing incidence of Trojans and phishing attacks directed at internet users, banks are recommended to move towards stronger authentication for their online banking customers," it said.

The association worked with a number of banks to develop a standard for devices that can read chip and PIN cards to better secure online banking and ecommerce. The customer inserts his card to a reader (which is not connected to his PC). The device will generate a unique 12-digit number that the customer enters on his keyboard.

Barclays spokesperson Elizabeth Holloway told OUT-LAW that its plans are at an early stage: while the intention is to follow the Apacs standard, the date of deployment in 2007 is undecided, as is the supplier of the card readers. Customers will not be charged for the supply of readers.

Holloway said Barclays already offers free anti-virus software to its online banking customers. It also sends SMS text messages to a customer's mobile phones when a third party payment is set up on his account. If the customer did not authorise the payment it suggests a fraudster has compromised his account – and he can contact Barclays immediately – as opposed to the common practice of only identifying and reporting suspicious activity when it appears on end-of-month statements.

A customer report received the same day or the following day in response to an SMS alert may be quick enough for the bank to block the transfer – although transfer times will depend on the destination account – but it also facilitates faster investigation.

Barclays will refund customers who lose money from their accounts through no fault of their own. Asked if the bank refunds victims of phishing attacks who revealed their security details to a fraudster, Holloway indicated that the professionalism of a particular attack will be relevant and each instance would be judged on a "case by case" basis. Barclays does not disclose how many of its customers have suffered such attacks.

Apacs spokesman Mark Bowerman said the Barclays card reader could be the first solution to market that conforms to its standard. Apacs does not know of any other banks currently deploying its standard. He noted that Lloyds TSB introduced a password generating token device for 30,000 online banking customers last October and that Alliance & Leicester account holders register an image that is displayed on subsequent visits to reassure users they are on the right site; but neither solution uses bank cards.

Bowerman said the advantage of the Apacs solution is that any card reader conforming to the standard will work with any card. "We have four cards each on average so we didn't want people to have to carry four different readers," he said.

However, many existing cards will not be compatible with the Apacs standard. It requires a particular script on the chip in the bank card, meaning some banks will need to issue new cards if they adopt the standard. Barclays was unable to confirm at the time of writing whether its customers will need new chip and PIN cards to use the new technology.

Copyright © 2006, OUT-LAW.com

OUT-LAW.COM is part of international law firm Pinsent Masons.


Other stories you might like

  • Dog forgets all about risk of drowning in a marsh as soon as drone dangles a sausage

    It's not the wurst idea in the world

    Man's best friend, though far from the dumbest animal, isn't that smart either. And if there's one sure-fire way to get a dog moving, it's the promise of a snack.

    In another fine example of drones being used as a force for good, this week a dog was rescued from mudflats in Hampshire on the south coast of England because it realised that chasing a sausage dangling from a UAV would be a preferable outcome to drowning as the tide rose.

    Or rather the tantalising treat overrode any instinct the pet had to avoid the incoming water.

    Continue reading
  • Almost there: James Webb Space Telescope frees its mirrors and prepares for insertion

    Freed of launch restraints, mirror segments can waggle at will

    NASA scientists have deployed mirrors on the James Webb Space Telescope ahead of a critical thruster firing on Monday.

    With less than 50,000km to go until the spacecraft reaches its L2 orbit, the segments that make up the primary mirror of the James Webb Space Telescope (JWST) are ready for alignment. The team carefully moved all 132 actuators lurking on the back of the primary mirror segments and secondary mirror, driving the former 12.5mm away from the telescope structure.

    Continue reading
  • Arm rages against the insecure chip machine with new Morello architecture

    Prototypes now available for testing

    Arm has made available for testing prototypes of its Morello architecture, aimed at bringing features into the design of CPUs that provide greater robustness and make them resistant to certain attack vectors. If it performs as expected, it will likely become a fundamental part of future processor designs.

    The Morello programme involves Arm collaborating with the University of Cambridge and others in tech to develop a processor architecture that is intended to be fundamentally more secure. Morello prototype boards are now being released for testing by developers and security specialists, based on a prototype system-on-chip (SoC) that Arm has built.

    Arm said that the limited-edition evaluation boards are based on the Morello prototype architecture embedded into an Armv8.2-A processor. This is an adaptation of the architecture in the Arm Neoverse N1 design aimed at data centre workloads.

    Continue reading

Biting the hand that feeds IT © 1998–2022