Mon 16 Apr 2007
Really Annoying Online Bank Security
Posted by RichSlick under Financial Safety, Rants
Thanks for visiting. This blog is intended for individuals with Net Annual Income of $105,000 or more. Get Rich Slow + Get Rich Quick = Get Rich Slick. If you're new here, you may want to subscribe to my RSS feed.
I’ve noticed a very disturbing trend with bank web sites over the past two years: Increasingly annoying bank security.
I have an account with a very large and familiar bank with a new “prescreening” process which essentially requires you to “register” your computer before you can access you account online. Most of these banks use COOKIES or FLASH Cookies to “store” your profile on your computer to “prove” that you are a “trusted” person/computer.

This may work fine for the average internet idiot but for those of us that actually are cautious when using online banking, it is very annoying. I regularly clear my cookies and flash cookies because in the event my machine is ever compromised, I don’t want someone accessing my accounts from my machine.
Worse yet are those annoying images you’re suppose to validate when logging on to your account. Does it occur to these banking security people that consumers may actually have more than one account with more than one image/password combination?
But what is really annoying are those stupid security questions:
1. What high school did you graduate from?
2. What is your favorite sport?
3. What city were you born in?
On and on. Where exactly are the answers to these questions stored? On a computer? Doesn’t that mean that if the bank computer gets hacked, the database with all these stored questions gets hacked too? I never answer those questions truthfully because of that reason -All the banks ask the same stupid questions so if bank A knows that I was born in Chicago, doesn’t that mean that Bank B, Bank C and Bank D are going to know it too if I enter in the same answer everywhere?
So let’s do a hypothetical. Hacker breaks into Bank A and gets my SSN and top secret city I was born in.
Hacker A: “Hey I got Rich Slick’s SSN and he was born in Chicago. He’s got ACH links setup to Bank B and Bank C. Let’s check it out”
Hacker B: Logs on to Bank B and requests password reset. Online Screen “What city were you born in”
Hacker B: Snickers and answer, “heh, CHICAGO!”
OK, perhaps its a bit simplistic but keep in mind that hackers have nothing better to do than sit at a computer and play these type of games in the hopes of scoring big money when hacking into someone’s account. If hackers can harvest 100,000 zombie computers then they can harvest account information and start breaking into bank accounts.
And the most irritating part is that despite all of these layers of security, all it takes is some idiot tossing out print outs of your records with your SSN and ID to cause ID theft problems or some off site tape storage company that loses the backup tapes with all your financial information to cause chaos.
The only thing banks are accomplishing is driving consumers away from their sites. I’m getting close to simply closing down all these extra accounts to avoid the hassle of maintaining a database with all the fake answers to the dumb questions I’ve answered over the years.
4 Responses to “ Really Annoying Online Bank Security ”
Comments:
Leave a Reply
Trackbacks & Pingbacks:
-
Pingback from Around the PF Blogosphere: April 16, 2007 | The Sun’s Financial Diary | A Personal Finance Blog on Saving and Investing
April 16th, 2007 at 7:13 pm[...] Get Rich Slick was annoyed by some online bank security features and so was I. Last time I was trying to make an transaction from my IGoBanking account from my work computer and failed twice because I couldn’t answer the three security questions. I eventually gave up my online access won’t be frozen. Now it seems every financial institution requires a bunch of security questions and offers to “remember” the computer you use to access your account so you don’t have to answer those questions every time. But can you remember them after one month, three month, or half a year? One time I also had to call TreasuryDirect to reset my password :((. [...]











April 17th, 2007 at 7:20 pm
Yep - I ranted about the same annoyance recently here.
Security through trivia is a BAD idea.
*grumble*
- chris // http://www.radven.net
April 23rd, 2007 at 10:34 am
You might be interested to know that a virus capable of getting all that picture/password info (along with your SSN and whatever else you submit to your bank/broker/…) is already there and the existing security software offers little protection from it.
Details:
April 23rd, 2007 at 10:36 am
the link
http://www.secureworks.com/research/threats/gozi/