AKRON, Ohio -
"Members can see that we are taking the extra effort to keep their data secure," said Charles Stanfield, information systems director at Buckeye State CU.
The $68-million credit union launched the Passfaces bidirectional authentication technology back in December through a partnership with R.C. Olmstead, a Dublin, Ohio-based company that provides data processing systems to credit unions.
Common image- and password-based authentication platforms have come under fire from the online security community.
Most recently, a study conducted by Harvard University and MIT cast a shadow of doubt on such platforms, as participants were found frequently to enter passwords even when their security images and indicators were missing.
Buckeye State CU's approach first requires members to enroll: members are assigned three images of different human faces from a library of 135 faces.
Then, during log-in, members identify their first assigned Passface, which appears in a random slot among eight other randomly-generated faces on a grid.
This grid of nine faces fronts the credit union's homebanking log-in screen in a format reminiscent of the opening titles for the Brady Bunch television show.
Members continue by identifying their remaining two assigned faces, which also appear in random slots in separate grids of randomly-generated faces.
Passfaces is stronger because it works to authenticate a person's memory rather than just the person's computing device or software, according to the Oak Hill, Va.-based company.
At the same time the user is verified, Passfaces also verifies the website against phishing-only a valid site will present the proper face images.
"With something like a log-in image that sits passively in the background before you enter your password, you don't know if the site has been phished or not," asserted Stanfield. "With Passfaces, you have active multi-layer authentication and kill two birds with one stone by adding website authentication."
Better yet, members can't ignore Passfaces. Every time members log-in, they must actively choose each assigned face in the three-step recognition process.
Of course, not all Buckeye State Credit Union members appreciate the more elaborate log-in.
"I've got a whole list of complaints from our members," said Stanfield. "Our society doesn't want to do anything extra."
Still, the credit union felt that going the extra mile was worth it.
"I knew it would be difficult, but I figure that by taking the active role, our members would eventually feel their data is secure," Stanfield explained.
Fewer than 100 online members walked away from Internet banking because of the Passfaces log-in requirement, he said.
"It has been a little bit of a rollercoaster, but we're starting to see the members who dropped come back now," Stanfield added.
More than 10% of the membership actively banks online, and 125 members sign up for online banking every month, he said.
In fact, the launch of Passfaces and, more recently, an e-statements platform, has attracted a lot of attention to the credit union's homebanking site, according to Sue Preston, CEO at Buckeye State CU.
The site saw more than 72,000 log-ins in three months, beating out an average of 45,700-log-ins per quarter in 2006, she said.
FOR MORE RESOURCES
Read more about multi-factor authentication at cujournal.com and search the following bolded terms in the archive:
Could Your Very Thoughts Be The Key To Data Security? For a story about Cogneto's approach to cognometric authentication.
CU Journal Roundtable: 'Pretty Scary' Security Threats Coming, for a story about the current threats that are challenging multi-factor authentication systems.
MFA: Secure Enough? for a story about the vulnerabilities inherent to most multi-factor authentication tools.
For info on this story:
* Buckeye State CU, www.buckeyecu.org
* Passfaces, www.realuser.com
* R.C. Olmstead, www.rcolmstead.com











