Security3.05.2013

Internet banking fraud: what can be done?

Fraud binary data

Numerous Internet banking customers have lost thousands to criminals using SIM swap fraud and other methods to gain access to users’ accounts. Using a client’s cellphone as an additional level of security used to be good enough, but it may now be time to create a more secure system.

Currently most South African banks ask users for a password (something they know) to access an Internet banking account, and then require a Random Verification Number (RVN) sent to a user’s cellphone to create a beneficiary and transfer money to another account.

This system has proven to be vulnerable to fraud. SIM swap fraud is used to get access to a user’s cellular messages, and phishing or possibly other means (like rogue banking employees) are used to find the banking client’s username and password.

Capitec Bank is already using a token, given to Internet banking clients to generate a random number valid for a limited time to access to provide additional security to clients.

Capitec Bank is also using a smartphone app, linked to a user’s smartphone, for the same purpose as the token.

Security expert Regardt van de Vyver explains what can be done

Regardt van de Vyver

Regardt van de Vyver

MyBroadband asked Neology CEO and security expert Regardt van de Vyver what he thinks could be done by the banks to improve on their current Internet banking security. Here is what he said.

Banks have a difficult conundrum – how to make their service secure enough while still keeping it remotely usable for their average customer.

Every layer of security added to the system ups the likelihood of the customer having issues – or even giving up on using the service all together.

Going back to the basics of security it is typically about:

  1. Something you know (like a password)
  2. Something you have (like a cellphone)
  3. Something you are (like a fingerprint)

Traditionally banks focussed on ‘something you know’ as this was the simplest. Attackers however just as easily and quickly found ways to counter this – simply look over your shoulder or steal your information – remember the Javascript keypads that standard bank came up with to prevent key loggers?

So, we naturally evolve towards ‘something you have’ – this is a ‘out of band’ or ‘two factor’ authorisation in that its more complicated for an attacker in this case. Not only must they capture your initial info (something you know) but they must also get access to the (something you have) one time code.

Locally the SIM swap has been the simplest but there’s also a fair bit of malware out there (see Moneyweb article regarding this issue).

Working on getting ‘something you are’ integrated is a tough call at this point as we’d have to likely evolve additional technology to get this done. So, back to ‘something you have’.

SMS is used since it is the most widely usable technology across the full customer base – but we may need to look at more specialised approaches.

A number of the providers have introduced the one-time-pin FOB (details here) but those are expensive and unlikely to get the type of uptake one needs.

At this stage the next ‘evolutionary’ step may be a combination of the SMS and a local phone app.

The app would receive the SMS and use that as the seed for a new one-time code – which the user then actually enters into the website. The application gets is keying material during a phone registration session (similar to what FNB already does with its App).

This would force the whole phone to be taken for the attack to work, meaning that as long as a person has a simple/quick way to disable the app on theft it would dramatically reduce the window of opportunity.

An alternative – which is something Neology is starting to use for some of our high security clients – is a far cheaper version of the ‘key fob’ component combined with the SMS potentially.

Basically a one-time-pin is generated via the USB/NFC device (see details here) and you still enter the SMS key as well.

Sadly all these approaches have downsides in either complexity or availability to users at large.

More on SIM swap fraud and Internet banking

Shocking reality about SIM swap fraud and money lost

SIM swap fraud has been happening for years

Serious ABSA Internet banking security concerns

SIM swap banking scam: what you should know

How scammers hack your bank account

Show comments

Latest news

More news

Trending news

Poll

If you could only have one video streaming service, what would you choose?

View Results

Loading ... Loading ...
Sign up to the MyBroadband newsletter