Australia's big four banks are a house divided over the introduction of biometrics identifiers to control fraud, with the National Australia Bank pouring cold water on the introduction of fingerprint identification for its customers.
Speaking at a banking technology conference in Sydney, NAB's senior operational risk manager, Kayelene O'Neill, said that banks need to consider the possibility that when they moved customer authentication to a biometric standard - a standard where a customer literally carries an identification factor as part of their body - that the individual may be targeted by crooks as a means to gain access to either funds or other items of value.
"The risk with biometrics is that you increase the risk to the user," O'Neill said, adding that a recent incident in Indonesia had seen a wealthy businessman's finger "lopped-off" in an attempt to gain access to his luxury car, adding that the crime gang involved appeared to have "got sick of carrying him around".
Such horror stories do not appear to have daunted Westpac, which for the first time confirmed it is considering fingerprint technology to reduce fraud on high value Internet banking transactions.
According to reports, Westpac CIO Michael Coomer says his bank is in negotiations with competitors ANZ and the Commonwealth Bank to develop biometric standards for an upgrade of Internet banking which may cost as much as $700 million across the retail banking sector.
However, NAB's O'Neill expressed some caution over whether biometrics can be regarded as a technological magic bullet, or a panacea to fraud. Pointing out that users who wanted to use fingerprints for identity verification to conduct Internet banking would need new hardware, O'Neill stressed that once an identifier was sent over an the Internet it could become susceptible to a classic "man-in-the-middle attack"; where a user's log-on session is monitored by an unauthorized third-party who then obtains either a password or other authorization factor.
"Fingerprints on a PC can be compromised by a man-in-the middle attack," O'Neill said, adding that secure biometric identification over the Internet may prove "very hard" because "you have to make sure you have all the right body parts".
As fingerprints are unique to a user, and also limited in number literally by nature, any potential loss of fingerprint information has far wider implications for users because it could also be misused - meaning that a person's fingerprints could become effectively useless as an identifier for the rest of their lives.
O'Neill said a more functional approach in terms of risk was to look at "scalable security" where the higher the value of the transaction, the better the authentication protocols.
Professor Bill Caelli, Queensland University of Technology IT security expert and critical IT infrastructure adviser, speaking at the same conference, said PCs were simply not suitably secure for banking transactions.
Fitting external "PIN-pads" which were fitted with end-to-end cryptography for end users to securely type in their identification details was one way of beating man-in the-middle attacks, he said.
Read up on the latest ideas and technologies from companies that sell hardware, software and services. Taking On Demand CRM Integration to the Next Level
Mimosa™ NearPoint™ for Microsoft® Exchange Server: Email Archiving 101
Making the Business Case for IT Consolidation
Email Archiving 101—Customer Case Study
Controlling storage costs with Oracle database 11g
Business Intelligence and Enterprise Performance Management: Trends for Emerging Businesses
Delivering the Power of Choice with Microsoft Dynamics CRM
The state of Middleware
Zones provide focussed content from Computerworld and leading technology partners.Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
F-Secure: Growth In Internet Crime Calls For Growth In Punishment 2008-12-05 13:00:00+11
International researchers gather in Sydney to preview the clever web 2008-12-05 09:48:00+11
Borderless corporate networks to shift focus to secure content management in Australia in 2009 2008-12-04 16:06:00+11
IDC Says Asia/Pacific Excluding Japan IT Market Will Remain The Bright Spot... 2008-12-04 15:04:00+11
MySpot SOS "Panic Button" Smartphone Application could save lone worker lives 2008-12-04 13:34:00+11
Discover the advantages of an open architecture multi-vendor network solution
View this webcast and discover the drivers for changing network design practices, why many organisations are changing their approach to network architecture and how enterprises should be moving forward with open architecture multi-vendor network solutions. Register now and learn how your business can maximize the business value of the enterprise network.












