5 ms·
Clark Howard (the consumer radio personality) recommends that businesses use a separate computer for all bank related transactions. And that computer isn't used
by keltex 15y ago
Clark Howard (the consumer radio personality) recommends that businesses use a separate computer for all bank related transactions. And that computer isn't used for email or other web access.
You should also contact your bank and request double or dual authentication on any wires. If your bank doesn't offer this, then get a different bank.
http://www.clarkhoward.com/news/clarkhoward/business-entrepreneurs/simple-computer-safeguards-for-small-business/nFD8/ http://www.clarkhoward.com/news/clarkhoward/business-entrepr...
- chriserin 15y agoAnd the convenience of online banking just lost all of its convenience. I'd rather just drive to the bank to conduct all transfers... seems safer.
- shabble 15y agoMy bank has fairly lax login requirements (account ID, some random digits of a N digit PIN, some random letters of a longish password. But to make payments to new accounts, you have to add that account to your approved list, which involves inserting your debit card into a little calculator-style reader, entering your (different) PIN, and then doing CHAP style auth with a random number supplied on the webpage, which is (hopefully decently crypto) mangled by the device, giving you a confirmation code. It's a bit of a hassle when you need to send some money to someone quickly and can't find the little machine, but otherwise, I think it's a pretty decent level of security.
- run4yourlives 15y agoYou could probably just use a bank that utilizes tokens or some other two factor authentication.
- shabble 15y ago...Unless they're RSA SecurIDs. Although it seems that whoever got that info used it for poking into defence contractors, rather than banks. Still, I imagine it's perfectly possible they could have used it to defeat some multi-factor logins for large bank accounts. I wonder how long the recall and replacement will take; there's got to be a lot of those tokens out there.
- marshray 15y agoWhat if the malware on the PC lets you log in and then takes over the session? Yeah, it happens. I develop on a system (PhoneFactor) where the bank now confirms the details of a transaction (amount, dest account number, etc) over an out-of-band channel. I really think this is where the world is moving. The current concept of login sessions is going away, e.g., mobile phones keep browser sessions open practically forever. Login credentials will eventually only protect the viewing of data, things that could cost money will be subject to additional authentication. But the party who's interests are most protected will be the party that's purchasing and deploying the authentication system. This is usually not the party with the most to lose, and almost never the end user.