Australian Telcos Declare SMS Unsafe For Bank Transactions
littlekorea writes "Australia's telcos have declared that SMS technology should not be used by banks to verify identities for online banking transactions, in a bid to wash their hands of culpability for phone porting hacks. But three of Australia's largest four banks insist they will continue to use SMS messages to carry authentication codes for transactions."
Imagine if your thumb / palm / eye was worth ten million dollars to someone. In this sort of situation, it's better to implement 'somewhere you are', (Especially if that somewhere is somewhere people can look at you and confirm you are you visually.
Not always just you. Some years ago, the local media interviewed a member of Bill Gates' security team. It seems that Bill travels with minimal security. Meanwhile, his family is heavily protected. When asked why, the guard said, "Bill has to be free to visit the bank to make a withdrawal. We need to make sure his family is safe when he does so."
Have gnu, will travel.
Secure Computing and iTnews.com.au have led a campaign to convince Australia's telcos to include extra security questions during the mobile phone number porting process to ensure fraudsters can't take control of a victim's phone number to gain access to SMS verification codes.
Let me guess. Secure Computing and iTnews.com.au work closely with Telstra and Optus right?
Here in Australia, thanks to consumer protection legislation changing mobile providers is a breeze. You ring up the provider you wish to change to and you ask to be ported. They send you an SMS and ask your personal details and old providers account number and then switch you over. It's both secure and easy (they need your phone number, old provider details and personal details to switch you over). You're now with another provider. You don't need to cancel with your old provider, they do that for you. Your number stays the same. The two biggest Telcos (Telstra and Optus) hate it as there's no lock in. They have to compete on price and service.
So Telstra and Optus lobby hard to ban number porting. They make up bullshit such as "OMG allowing people to switch phone providers is dangerous!!!!". They get their friends in the media to chant the same thing. "Ban number porting!!!"
The reality is that the banks don't use SMS confirmations for anything more than a 3rd layer of security. They don't ask you to transmit anything over the SMS service, it's simply used by them to send you message that a transaction is taking place along with a key that you have to type into online banking (after logging in securly) to allow that transaction to proceed. Essentially it's traditional "login over https" style banking with an extra layer of SMS notifications when you do transactions. It doesn't need the SMS security itself to be bomb-proof as that's just the last step.
So all this talk of restricting number porting is ridiculous. Good on the Communications Alliance (who are mostly made up of smaller Telcos that like number porting) for not bowing to the pressure and bullshit spouted by here by iTnews.com.au. It really isn't an issue, in fact i think other countries should adopt similar consumer protection laws where switching providers whilst retaining the old mobile number is a breeze.