{"id":76938,"date":"2013-05-03T10:03:35","date_gmt":"2013-05-03T08:03:35","guid":{"rendered":"http:\/\/mybroadband.co.za\/news\/?p=76938"},"modified":"2013-05-03T10:44:36","modified_gmt":"2013-05-03T08:44:36","slug":"internet-banking-fraud-what-can-be-done","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/76938-internet-banking-fraud-what-can-be-done.html","title":{"rendered":"Internet banking fraud: what can be done?"},"content":{"rendered":"<p>Numerous Internet banking customers have lost thousands to criminals using SIM swap fraud and other methods to gain access to users\u2019 accounts. Using a client\u2019s cellphone as an additional level of security used to be good enough, but it may now be time to create a more secure system.<\/p>\n<p>Currently most South African banks ask users for a password (something they know) to access an Internet banking account, and then require a Random Verification Number (RVN) sent to a user\u2019s cellphone to create a beneficiary and transfer money to another account.<\/p>\n<p>This system has proven to be vulnerable to fraud. SIM swap fraud is used to get access to a user\u2019s cellular messages, and phishing or possibly other means (like rogue banking employees) are used to find the banking client\u2019s username and password.<\/p>\n<p><a title=\"Capitec Bank\" href=\"http:\/\/mybroadband.co.za\/vb\/showthread.php\/370968-Capitec\">Capitec Bank<\/a> is already using a token, given to Internet banking clients to generate a random number valid for a limited time to access to provide additional security to clients.<\/p>\n<p>Capitec Bank is also using a smartphone app, linked to a user\u2019s smartphone, for the same purpose as the token.<\/p>\n<h3 class=\"my-4\">Security expert Regardt van de Vyver explains what can be done<\/h3>\n<div id=\"attachment_61308\" style=\"width: 610px\" class=\"wp-caption aligncenter\"><a href=\"http:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2012\/10\/Regardt-van-de-vyver.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-61308\" class=\"size-full wp-image-61308\" alt=\"Regardt van de Vyver\" src=\"http:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2012\/10\/Regardt-van-de-vyver.jpg\" width=\"600\" height=\"400\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2012\/10\/Regardt-van-de-vyver.jpg 600w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2012\/10\/Regardt-van-de-vyver-100x66.jpg 100w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2012\/10\/Regardt-van-de-vyver-185x123.jpg 185w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2012\/10\/Regardt-van-de-vyver-250x166.jpg 250w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><\/a><p id=\"caption-attachment-61308\" class=\"wp-caption-text\">Regardt van de Vyver<\/p><\/div>\n<p>MyBroadband asked <a title=\"Neology\" href=\"http:\/\/mybroadband.co.za\/vb\/showthread.php\/308453-Neology\">Neology<\/a> CEO and security expert <a title=\"Regardt van de Vyver\" href=\"http:\/\/mybroadband.co.za\/vb\/showthread.php\/249668-Regardt-van-de-Vyver\">Regardt van de Vyver<\/a> what he thinks could be done by the banks to improve on their current Internet banking security. Here is what he said.<\/p>\n<blockquote><p>Banks have a difficult conundrum &#8211; how to make their service secure enough while still keeping it remotely usable for their average customer.<\/p>\n<p>Every layer of security added to the system ups the likelihood of the customer having issues &#8211; or even giving up on using the service all together.<\/p>\n<p>Going back to the basics of security it is typically about:<\/p>\n<ol>\n<li>Something you <strong>know <\/strong>(like a password)<\/li>\n<li>Something you <strong>have <\/strong>(like a cellphone)<\/li>\n<li>Something you <strong>are <\/strong>(like a fingerprint)<\/li>\n<\/ol>\n<p>Traditionally banks focussed on \u2018something you know\u2019 as this was the simplest. Attackers however just as easily and quickly found ways to counter this \u2013 simply look over your shoulder or steal your information \u2013 remember the Javascript keypads that standard bank came up with to prevent key loggers?<\/p>\n<p>So, we naturally evolve towards \u2018something you have\u2019 \u2013 this is a \u2018out of band\u2019 or \u2018two factor\u2019 authorisation in that its more complicated for an attacker in this case. Not only must they capture your initial info (something you know) but they must also get access to the (something you have) one time code.<\/p>\n<p>Locally the SIM swap has been the simplest but there\u2019s also a fair bit of malware out there (<a title=\"Moneyweb\" href=\"http:\/\/www.moneyweb.co.za\/moneyweb-financial\/mobile-malware-and-your-money\" target=\"_blank\"><strong>see Moneyweb article regarding this issue<\/strong><\/a>).<\/p>\n<p>Working on getting \u2018something you are\u2019 integrated is a tough call at this point as we\u2019d have to likely evolve additional technology to get this done. So, back to \u2018something you have\u2019.<\/p>\n<p>SMS is used since it is the most widely usable technology across the full customer base \u2013 but we may need to look at more specialised approaches.<\/p>\n<p>A number of the providers have introduced the one-time-pin FOB (<a title=\"FOB\" href=\"http:\/\/www.rsa.com\/node.aspx?id=1159\" target=\"_blank\"><strong>details here<\/strong><\/a>) but those are expensive and unlikely to get the type of uptake one needs.<\/p>\n<p>At this stage the next \u2018evolutionary\u2019 step may be a combination of the SMS and a local phone app.<\/p>\n<p>The app would receive the SMS and use that as the seed for a new one-time code \u2013 which the user then actually enters into the website. The application gets is keying material during a phone registration session (similar to what FNB already does with its App).<\/p>\n<p>This would force the whole phone to be taken for the attack to work, meaning that as long as a person has a simple\/quick way to disable the app on theft it would dramatically reduce the window of opportunity.<\/p>\n<p>An alternative \u2013 which is something Neology is starting to use for some of our high security clients &#8211; is a far cheaper version of the \u2018key fob\u2019 component combined with the SMS potentially.<\/p>\n<p>Basically a one-time-pin is generated via the USB\/NFC device (<a title=\"USB NFC\" href=\"http:\/\/www.yubico.com\/products\/yubikey-hardware\/yubikey-neo\/\" target=\"_blank\"><strong>see details here<\/strong><\/a>) and you still enter the SMS key as well.<\/p>\n<p>Sadly all these approaches have downsides in either complexity or availability to users at large.<\/p><\/blockquote>\n<h3 class=\"my-4\">More on SIM swap fraud and Internet banking<\/h3>\n<p><a title=\"Shocking reality about SIM swap fraud and money lost\" href=\"http:\/\/mybroadband.co.za\/news\/security\/76904-shocking-reality-about-sim-swap-fraud-and-money-lost.html\"><strong>Shocking reality about SIM swap fraud and money lost<\/strong><\/a><\/p>\n<p><a title=\"SIM swap fraud has been happening for years\" href=\"http:\/\/mybroadband.co.za\/news\/banking\/76902-sim-swap-fraud-has-been-happening-for-years.html\"><strong>SIM swap fraud has been happening for years<\/strong><\/a><\/p>\n<p><strong><a title=\"Serious ABSA Internet banking security concerns\" href=\"http:\/\/mybroadband.co.za\/news\/banking\/76866-serious-absa-internet-banking-security-concerns.html\">Serious ABSA Internet banking security concerns<\/a><\/strong><\/p>\n<p><strong><a title=\"SIM swap banking scam: what you should know\" href=\"http:\/\/mybroadband.co.za\/news\/banking\/76366-sim-swap-banking-scam-what-you-should-know.html\">SIM swap banking scam: what you should know<\/a><\/strong><\/p>\n<p><strong><a title=\"How scammers hack your bank account\" href=\"http:\/\/mybroadband.co.za\/news\/security\/75807-how-scammers-hack-your-bank-account.html\">How scammers hack your bank account<\/a><\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Security expert shares his views on how banks can move forward to make Internet banking more secure<\/p>\n","protected":false},"author":23,"featured_media":77032,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_facebook_post_id":"","_sma_instagram_post_id":"","_sma_threads_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[27],"tags":[5376,35,1067,15950,12743,19260],"class_list":["post-76938","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-capitec-bank","tag-headline","tag-neology","tag-regardt-van-de-vyver","tag-sim-swap","tag-sim-swap-fraud"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/76938"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/23"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=76938"}],"version-history":[{"count":1,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/76938\/revisions"}],"predecessor-version":[{"id":76978,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/76938\/revisions\/76978"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/77032"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=76938"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=76938"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=76938"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}