Technology in Brief: Deals and deployments by financial institutions, and other news

Headlines:

Processing Content

Yodlee Adds 140 Billers Through Kubra

Bill-payment sites using Yodlee Inc.'s software can now connect to an additional 140 billers.

The 140 have relationships with Kubra Data Transfer Ltd. of Mississauga, Ontario, which sells electronic bill payment and presentment software. The Yodlee-Kubra partnership was announced Tuesday.

Many billers accept multiple types of payments, including credit card transactions, which banks' bill payment sites typically do not permit. America Online Inc., LowerMyBills.com Inc., and Morgan Stanley's Discover Financial Services Inc. use Yodlee software to run consolidated bill-pay sites that do.

The software already enabled those sites to present and pay bills from more than 2,800 billers. Yodlee is based in Redwood City, Calif.

Return to Headlines

Anti-Hijack Software from Digital Envoy

Digital Envoy Inc. of Norcross, Ga., said that next quarter it will offer financial institutions software to protect against "man-in-the-middle" attacks, which can take over online banking sessions.

Phishing, one of the most common online banking scams, uses spoof Web pages to trick customers into revealing personal account information.

But observers have long warned about a more devious scam: viruses that sense a log-on to a banking site and enable criminals to hijack the session and initiate their own transactions.

Such man-in-the-middle attacks require the use of an outside server. Digital Envoy's new software, called Website Authentication Module, is meant to spot such attacks by determining when a user's session connects to an additional server.

"Unsuspecting consumers just cannot tell … that a man in the middle has hijacked their session," said Dennis Maicon, the company's executive vice president for financial services solutions, in a press release Monday.

Website Authentication Module, which would reside on the customer's computer, will use a list of trusted bank servers. It would check to see if the server to which the customer is connected was on that list. If so, the session would be secure; if not, the session could have been hijacked.

Return to Headlines


For reprint and licensing requests for this article, click here.
Bank technology
MORE FROM AMERICAN BANKER
Load More