Michigan State FCU may possibly have cornered the market on a multi-factor authentication tool that can save a CU $50,000 per year in user costs-because the credit union created it itself.
That tool is "TrulyU," the credit union's multi-factor authentication (MFA) platform, which also happens to be the only MFA developed and maintained by a credit union, explained April Clobes, MSUFCU's vice president of e-commerce.
"We realized we could tackle the project in-house and save on per-user costs, after evaluating the marketplace options and reading the FFIEC guidance" on authentication for Internet banking, she said.
Six months later, the $1.3-billion credit union had TrulyU, which is no simple rip-off of other authentication tools on the market, Clobes related.
Granted, MSUFCU homebanking members are authenticated using common factors, such as the settings, geographic location or Internet address of the member's electronic device.
And if the device profile or the member's behavior is atypical, then TrulyU asks the member a challenge-response question.
But TrulyU goes one step beyond other tools by allowing the users in joint-party accounts to select their own personalized set of challenge-response questions.
"That's where TrulyU stands out," said Clobes.
The problem with many other tools on the market, she suggested, is that when joint-account holders access their accounts from different computers, they aren't always able to answer the challenge-response questions set by the primary user, leading to a lot of heartache and frustration for the members.
"Third-party vendors didn't offer joint-account capabilities to the level we thought we'd need," Clobes explained.
About 10% of users-and growing-has set up accounts to accommodate more than one user, said Clobes.
TrulyU also stays away from image recognition, a security factor that requires users to select a personal image from a database of hundreds of images.
The line of thinking goes something like this: If the member sees the chosen image at the log-in site, the site may be deemed valid, and the member may safely log-in.
Despite the widespread use of image recognition in third-party technologies, Clobes said that "images don't protect members as much as they should be protected. Over time, it's not hard for criminals to duplicate images, even if you have one thousand of them in your database."
Instead, "we wanted to educate members to check for the validity of a site by looking at security factors such as the browser address bar and the security certificate," she said.
Other credit unions shouldn't inquire about running TrulyU for their members, Clobes continued.
"TrulyU is not for sale to other institutions," she explained. "We don't have the resources to install, troubleshoot, sell or accommodate multiple online banking applications."
Some MSUFCU members started using TrulyU in October, whereas enrollment for other members will continue through the first quarter of next year, said Clobes.
"Rolling enrollment" makes it easier for MSUFCU staff to manage members' problems or concerns as they start using TrulyU, Clobes said.
About 65% of MSUFCU's members use Internet banking.
"We had lots of conversations with other credit unions that had turned on a solution for all members at the same time, thinking it would be a piece of cake, she said. "But they ended up overwhelming staff."
In the future, TrulyU will adapt to changes in online fraud, Clobes said. A recent threat is the attacks that capitalize on dual-factor authentication log-ins (see related story, page 1).
"If we can enhance our program and accommodate all the changes in the fraud environment, we will," she said. "The fact that this program is in-house allows us to be agile enough to implement quickly and to suit our members' needs."
The next step for TrulyU? Most likely, a risk trigger that launches a phone-based authentication factor, said Clobes.
CUJ Resources
For info on this story:
* Michigan State University FCU at: www.msufcu.org











