Slashdot Mirror


Banks Begin To Use RSA Keys

jnguy writes "According to the New York Times (free bacon required), banks are begining to look into using RSA keys for security. AOL has already begun offering its customers RSA keys at a premium price. Is this the future of security, and is it secure enough? How long before everyone needs to carry around 5 different RSA keys just to perform daily task?"

6 of 208 comments (clear)

  1. Heh? This is old news by zxSpectrum · · Score: 4, Informative

    I'm rather surprised: Several Norwegian banks have been using these RSA Hardware Tokens for a couple of years.

  2. Article not about "RSA Keys" -- Hardware tokens by Steven+Reddie · · Score: 5, Informative

    The article is really talking about using hardware tokens for extra security since the private data is stored on an external token and can't be stolen by viruses, trojans, or phishing scams. I don't even see RSA mentioned in the article -- there is an inset picture of an RSA SecurID but that's as close as it gets.

    1. Re:Article not about "RSA Keys" -- Hardware tokens by HotNeedleOfInquiry · · Score: 4, Informative

      Wells Fargo issues the RSA SecurID devices for security. Not a test, not a trial, My wife and I each have one.

      --
      "Eve of Destruction", it's not just for old hippies anymore...
  3. This is news? by Nehle · · Score: 5, Informative

    My bank (SEB, www.seb.se) has been using a hardware token system for years. I click the sign in button, enter my birthdate, receive two four-digit numbers, start the little device, enter my password and the two numbers and get a six-digit number that I enter in the login page and then I get logged in.
    Is this somehow different?

    Oh, and by the way, works like a charm and I feel a lot more secure than I do with static passwords

  4. This is new? by wfberg · · Score: 4, Informative

    I've been using physical tokens to log on to e-banking for years. Not only that, but tokens that are significantly more secure than securID fobs, in that they support challenge/response and using a PIN to unlock it (two-factor security, and the PIN is only used with the token so it needn't be known at all to the bank).

    In fact, most banks are now switching to keypads that you plug your existing bankcard in, so they can piggyback on the tamper-resistant chipcard that's already on there (although it's slightly less advanced than some tokens, since chipcards don't support a clock that's permanently ticking).

    Most devices are from Vasco who provide a wide range of tokens (some more secure than others). They even have challenge/response tokens that don't require you to copy the challenge; they have optical sensors that can read out a code that's blipped out by flashing blocks on your screen. Way cooler devices than those RSA securIDs.

    --
    SCO employee? Check out the bounty
  5. Re:Banks are the problem by Obiwan+Kenobi · · Score: 4, Informative

    I call FUD. I've worked in banks (and credit unions) as a network admin for over six years, and that is some bullshit.

    Now, understand that banks will use your information any way they can in-house, manipulate numbers and deposit totals and anything else analytical so they can sell a credit card or a loan (its called cross-selling). But what they cannot do is give your information to other 3rd parties without your direct consent unless its under federal mandate and/or decree (read: court order and/or the Patriot act).

    Now this is all fine and good, but when you do something substantial with your money and/or your financial outlook (say, investing or buying a home), you open up yourself to offers from 3rd parties. You sign a document saying so.

    Now the easiest thing is, before you sign something, ask them which companies are going to be behind this new venture. Whether it be an investing house (a lot of banks will farm out investing to a subsidiary and get kickbacks on it) or mortgages (who owns this loan? Can they sell it to a 3rd party mortgage company at a later date?), you need to simply be aware.

    Feel free to google "Bank Privacy" and read up on the hometown banks and the big boys: They all pretty much say the same thing. If they are under FDIC (for banks) or NCUA (for credit unions), they all fall under the same guidelines: Your information cannot be shared unless you say so. The federal privacy statements which are mandatory to be handed out upon opening an account, etc, say the same thing.

    Offshore data management services is simply a scarier way of saying Disaster Recovery. You want your bank to keep running even if the home office (or data center) explodes, right? Then don't start bitching about them backing up data in different places.