BOSTON, Mass. - Simple passwords for online banking security is passé, and now, a study by researchers at Harvard and MIT finds that a popular method where users are asked to select an image, such as a dog or chess piece, that they should see every time they log in to their account, also provides little protection from scammers. When the image doesn't appear, users are supposed to realize that the site may be fraudulent. The popular system is used by BofA, ING Direct and Vanguard, among others, including some credit unions. But when researchers tested the hypothesis using 67 BofA customers using computers where the images were removed, 58 keyed in their passwords anyway. Researchers said they could not recommend using the images as a protective measure against identity fraud.
Processing Content
Credit unions, like all financial institutions, have tried to stem such fraud and comply with the January 2007 requirements set by the Federal Financial Institutions Examination Council (FFIEC) while not requiring members/customers to download additional software, fearing added inconvenience.