Multi-Factor Fallout: The Plusses And Minuses Of 'Security By The Regs'

AKRON, Ohio - Last year, credit unions rushed to meet NCUA deadlines and fortify the online branch with pricey multi-factor authentication (MFA) tools. This year, many say they're dealing with the fallout.

Processing Content

"Because the FFIEC and NCUA made it mandatory to put in stronger authentication, many financial institutions did so without knowing the real consequences of the application that they chose," said Charles Stanfield, information systems director at $68-million Buckeye State CU here.

The NCUA was unavailable for comment.

The problem started for many financial institutions when they followed the lead of the nation's big banks and launched challenge-response (C-R) and secret-image factors for log-in authentication, claimed Taun Willis, CEO at Sestus Data Company. Avondale, Ariz.-based Sestus provides Phishcops, an authentication solution that does not rely on C-R.

"We assumed everyone knew that challenge-response systems do not meet the regulatory definition of MFA," Willis explained. "By rejecting true MFA in favor of these less costly approaches, financial institutions have, instead, actually made the situation much worse. Through the widespread use of challenge-response, consumers are being conditioned to disclose their confidential personal information, such as maiden names and high-school names, on a scale never before seen.

"It doesn't take a rocket scientist to understand why this is unpopular with consumers," Willis continued, adding that he's seeing "unusually high" interest in Phishcops from organizations that are currently depending on C-R.

The C-R paradigm will be short-lived, agreed Rick Rhoads, senior vice president, eServices, at the $13.5-billion State Employees CU (SECU) in Raleigh, N.C., which implemented a C-R approach last year.

"These tools are a point-of-time solution for a point-of-time problem," Rhoads said. "We implemented them as a response to member convenience and competitive pressures put upon us by the Bank of Americas."

Buckeye State was one of the few credit unions that avoided C-R from the start, said Stanfield. Instead, members log-in by identifying a series of human faces as part of a cognometric approach to authentication provided by Oak Hill, Va.-based Passfaces Corp.

Passfaces has been criticized by a number of Buckeye State members, Stanfield said. However, "most of our members believe that we are doing the best we can to protect their data, which is the most important thing to me."

Meanwhile, "other credit unions have said their concern was to make it as easy and seamless for the members and staff," he said.

But even with "easy" C-R solutions, the road has been rocky.

"The biggest unintended consequence of MFA was the impact on the member," suggested Tripp Johnson, a senior director at Scottsdale, Ariz.-based Cornerstone Advisors. "I have heard nightmare stories from many clients about dramatically increased call center volumes regarding member logins."

Members don't like going through the additional C-R layer, and they balk at setting up security questions, Rhoads explained. "MFA causes a lot of backlash."

Not all is lost, however. SECU, like many others, had some trouble from keystroke loggers that steal user names and passwords when members log-in to wire money online, said Rhoads. But SECU's C-R solution has "all but eliminated online wire fraud," he said.

And at Clearview FCU in Moon Township, Penn., MFA has been "uneventful," said Ed Wood, director, network services, at the $615-million CU. "Members seem to have accepted the change as a necessary feature and recognize its value in protecting their accounts," Wood explained. "We are experiencing the same steady growth online that was occurring prior to MFA implementation."

In addition, MFA features help members confirm that they are at their legitimate credit union website as opposed to a phishing site, according to Erik Petersen, vice president, professional services at Atlanta-based SecureWorks, a managed security services firm.

"We do believe that the MFA guidance has helped protect one's Internet banking credentials," he said.

more cujournal.com

Read more about MFA at cujournal.com and search the following bolded terms in the archive:

MFA: Secure Enough? on vulnerabilities in image - and challenge-based tools.

It's 2 a.m.: Do You Know Where Your Members Are, on how Lockheed Georgia ECU learned that MFA is easy for members to use.

Anti-Phishing Solution Will 'Dominate,' on the Phishcops solution and the CUs using it.

How One CU Boosted Online Banking By Beefing Up Security, on Buckeye State CU and the Passfaces authentication tool.

FOR INFO ON THIS STORY

Buckeye State CU, www.buckeyecu.org

Clearview FCU, www.clearviewfcu.org

SECU, www.ncsecu.org

Cornerstone Advisors, www.crnrstone.com

Passfaces, www.realuser.com

PhishCops, www.PhishCops.com (c) 2007 The Credit Union Journal and SourceMedia, Inc. All Rights Reserved. http://www.cujournal.com http://www.sourcemedia.com


For reprint and licensing requests for this article, click here.
MORE FROM AMERICAN BANKER
Load More