This Is Much More Secure Than Passwords

image

CHESTERFIELD, Mo.—Most financial institutions will abandon the password as a means for customer/member authentication and turn to “more secure” approaches that don’t rely on existing data that can be stolen, according to one forecast.

But that transition will come with a risk, predicts Mitek, which predicts many credit unions will not move quickly enough to make the change, and draw the attention of crooks as they zero in on weaker defenses.

The company believes that security practices that rely on knowledge-based authentication are rapidly weakening, due largely to the number of data breaches occurring and the amount of stolen personal information in the hands of fraudsters today.

“We predict there will be more than one-billion consumer records breached in 2017—the same pace as in 2016; so this problem is not slowing down” said Kalle Marsal, Mitek chief marketing officer.

Marsal told CUToday.info the continuing onslaught from criminals will finally push FIs to jettison knowledge-based authentication solutions—based on passwords, challenge questions and personal data. “All of this kind of data is stored somewhere and can be compromised by crooks.”

Abundance Of Stolen Data

Marsal said Mitek believes there is so much stolen data in the hands of criminals that fraudsters can replicate passwords and challenge question responses even better than many of their victims.

“The bad guys have better records and can ‘remember,’ so to speak, more answers than the account-holders,” said Marsal. “They have so much data that they can easily create synthetic IDs—IDs for people that do not exist—and gain access to services and funds. It’s truly startling what they have and what they can do.”

The change companies need to make, according to Marsal, is finding ways to anchor their security systems to something that is a “proven identity,” so they can be certain the consumers they are doing business with are who they say they are.

“Then, once that is established the bank can provide the person with ongoing access via a biometric method that is almost impossible for crooks to breach,” he said.

Marsal said Mitek believes government-issued IDs, such as driver’s licenses and passports, that already have a high degree of security built into them are the best place to start in verifying a person’s identity.

“For example, if a person wants to join the credit union via a remote channel they can take a picture of their ID. Then it gets run through a back end that checks for a number of authenticators on the ID that are very difficult to duplicate,” said Marsal, whose company offers such a solution. “Then the member takes a selfie that is compared to the picture on the ID—and the system has to have lightness detection to make sure the selfie sent is not a picture of a picture. There is very secure facial comparison between the two images.”

Biometrics

Once a person’s identity has been “proven,” Marsal said that biometrics can be used for ongoing authentication.

He said a good method is using the “profile” created by how a person uses a smartphone or tablet.

“When we use a smartphone or tablet we have a very unique way we interact with our device,” explained Marsal. “Our devices have all kinds of sensors that collect a lot of different kinds of data. With this ‘profile’ a person’s footprint is established, an identity. Then, the security system at the bank or credit union can access this footprint and see if the person on the phone is behaving as they normally do with the device. The bank can tell if the person using the phone is who they say they are.”

Marsal said that is just one example of an ongoing authentication solution that could be used, adding there are others being worked on today.

“These all are authentication solutions that don’t rely on information sitting in a database somewhere that can be stolen,” said Marsal.

Big Banks Leading The Way

Many of the big banks have already started employing these approaches, said Marsal, adding that crooks are now turning their attention to smaller institutions to steal and launder money.

“Increasingly, the bad guys are targeting smaller banks and credit unions,” said Marsal. “That means credit unions are exposed the longer they wait to convert away from knowledge-based authentication solutions. I think some credit unions may assume that because they are smaller they are not a target and therefore they can wait. But there is a real danger in doing that.”

Marsal noted that the new authentication methods are not costly and offer greater consumer convenience.

“These approaches are less intrusive, and they don’t require that you remember a bunch of information and store it somewhere,” said Marsal.

Section: Standard
Word Count: 913
Copyright Holder: CUToday.info
Copyright Year: 2026
Is Based On:
URL: https://cuto-admin.flux5.ccplatform.net/THE-feature/This-Is-Much-More-Secure-Than-Passwords