Showing posts sorted by relevance for query "ONLINE BANKING". Sort by date Show all posts
Showing posts sorted by relevance for query "ONLINE BANKING". Sort by date Show all posts

From Lita Epstein at Daily Finance:

"Based on a survey by the American Bankers Association,  25 percent of the population prefers to do its banking online and that number is growing. In fact, the survey found that the Internet is the preferred banking mode for all customers under the age of 55 and the popularity of ATMs has fallen in all age groups.

Through 2012, the number of online banking users is projected to grow at a compound annual rate of 20 percent, according to a report from the Tower Group. The Tower Group defines online banking as anything done once a person logs onto a bank's website.


All brick and mortar banks are experiencing growth in their online services.




  • Bank of America has 30 million online banking customers.

  • Chase has 13.9 million online bank customers.

Clearly, the trend is toward online banking.





Editor's Note:  Unfortunately, there is another trend.  This trend is called hackers and newly introduced online banking trojans.  Online Banking Trojans (OBT's) are created and designed to steal online banking credentials. 



Clampi, Zeus, and newly discovered (10/01) URLZone are designed to go undetected by anti-virus programs and wait for the user to reach a financial services site, 4500 of which are recognized by these malware programs. 



Upon reaching the site, the malware steals the user's online banking log-in details, including one-time passwords.  (OTP's) in real-time.  URLZone even rewrites the online bank statements to show that the money is still there.  See more about URL Zone in the "related articles section below)



 Prominently featured during last week's, "Online Banking is Weak Week," is talked about OBT's and stated that: "in order to remove the online banking consumer from the scope of such threats, the log-in procedure must be done outside the browser space."  



The best way to remove the online banking customer from the scope of these threats is to arm them them with weapons of Hack destruction, i.e.  the HomeATM SLIM.   (also eliminates the threats posed by Phishing, Pharming, DNS Hijacking, Cloned Bank Websites, Keyloggers and Malware...)





Simply put, HomeATM's SLIM "enables online banking customers to authenticate themselves in the exact same manner trusted by both banks and consumers to dispense cash in real time at an ATM."  









By mandating that online banking customers swipe their existing bank issued card and entering their existing bank issued PIN, the bank enjoy the security benefits of "True" Two-Factor Authentication as both the card information and the PIN would be instantaneously encrypted inside the SLIM and therefore the log-in credentials would NEVER enter or travel through browser space unencrypted.  (Think INSIDE the Box) 



But the HomeATM Slim is not done yet.  It's only beginning.



Not only does it instantaneously 3DES DUKPT E2E Encrypt the data (including the Track 2 data) to create an impenetrable online banking solution, it allows consumers to conduct bank-card to bank-card money transfers in "real-time"  (P2P, A2A, P2B and B2B) using ANY bankcard.  (Citi to Wells, BofA to Chase,  etc.)



Still not done:  HomeATM's SLIM "also" enables a "secure" conduit with which to conduct eCommerce credit, debit and PIN Debit transactions in a "card present" environment.  Both Visa and MasterCard define "card present" as any transaction which "captures the data on the magnetic stripe" (swiping vs. typing)



Simply Put: Although "card not present" transactions probably constitute less than 10% of all transactions, they definitely are responsible for over 50% of all card fraud...and growing.  Therefore, the Card Not Present environment is responsible for the MAJORITY of card fraud.  By creating an environment whereby customers could "Swipe" vs. "Type" we eliminate the "card NOT present" environment...thus eliminating CNP fraud. 

Maybe we should rename the "SLIM" the "Eliminator!"  Nah, as there are only "two" chances to secure our card holder data when it comes to online financial transactions: SLIM and None!  I do have a pet name for SLIM though...I call it "The Inevitable!"









From SC Magazine:  E-Commerce Security





Opinion: Take no chances with card security









Oct 2, 2009 4:14 PM



Time has run out for businesses that handle credit card information.



"Card companies should be re-investigating secure alternatives, such as PC-based (chip and) PIN terminals...












Reblog this post [with Zemanta]

Posted by John B. Frank Monday, October 5, 2009 0 comments



In a story published today in FierceFinance IT, they take a look at the fact that the bad guys are focusing their efforts at online banking.  Here's the article,  along with some of my comments on why it's happening and how it can be prevented.  



Bottom line.  Based on the fact that online banking customers are instructed to "key in" (type) their online banking credentials, the online banking industry is a ticking time bomb. 



The only explosive growth the online banking community will see (unless they provide a genuinely secure authentication procedures) is that of the online banking Trojans...which are designed to completely drain accounts and completely destroy any trust associated with online banking.     




October 23, 2009 — 8:53am ET | By Jim Kim







Cyber thieves have been targeting banks in more and more creative ways, usually involving retail customers, but the really big thefts are victimizing small government accounts. A customer of M&T Bank, a small bank with 650 branches in the mid-Atlantic region, was victimized recently to the tune of $479,000. The Cumberland County Redevelopment Authority Staff alerted the bank last month that it couldn't access its online banking site.



Apparently, the issue was a virus that allows for keystroke capture.



Let's "key" in on that for moment, shall we?  The "Key Word" here being "keystroke capture."  Let me oversimplify this.  What procedure does online banking mandate for online banking customers to log-in to their account.  Is it by "keying" (typing) in their username and password?  It is, isn't it?



Consumers type their username, their password (and more often now, in a lame attempt to add an additional layer of security, some banks require their customers to "key" in other information, such as a mother's maiden name, the make of their first car, etc.



But the fact remains...if the online banking customer has a virus that allows for keystroke capture, then it doesn't matter if banks require their customers to "key in" (type) the answers to 100 questions, does it?  It will ALL BE CAPTURED.  Wouldn't it? Make sense?  It does, doesn't it? 



Back to the story...







"At the time of the incident, the customer was using a bank-issued ACH house token, which was designed to protect against unauthorized access, specifically from keystroke logging fraud attacks. Obviously, it didn't."


Which is why we created our SLIM device...it eliminates typing, thus keystroke logging (and phishing) enabling online banking customers to Swipe their Bank Issued Card and Enter their Bank Issued PIN to authenticate themselves.  We utilize "existing bank rails" to authenticate the user.  (If that process sounds familiar, it is because it's the same process used to access cash from an ATM.)  100% seamless transition.



The story continues...



The stolen funds were transferred to accounts set up by the hacker, using names of LLCs and individuals, at 11 domestic financial institutions. So far, more than $100,000 has been recovered.  





Editor's Note:  Guess what.  The SLIM would also "prevent" any stolen funds from being transferred "anywhere" ...until the online banking consumer demonstrated "intent" to "authorized" the transfer by "Swipinig their Card" and "Entering their PIN" a second time!  Talk about doubly protecting the consumer.

 






To review: If somehow (for instance, a pre-existing infection from Zeus, Clampi or the urlZone banking Trojans) the bad guys were able to get into an online banking customers account, they "WOULD NOT" (let me state that again) "WOULD NOT" be able to transfer funds "ANYWHERE"  (let me state that again) "ANYWHERE"...UNLESS THE BAD GUYS HAD THE CONSUMERS BANK ISSUED CARD AND THEIR BANK ISSUED PIN. 





Therefore, we eliminate keystroke logging, we eliminate phishing, and we eliminate the threat of unauthorized money transfers to money mules.  Sounds elegant and sounds like a great online banking promotion.  Get a free SLIM.  We'll even put your bank's logo on it.  Where can your bank get them? Email me: jfrank@homeatm.net


The story continues:





In addition, the Washington Post reports that Bullitt County, Kentucky lost $415,000 to criminals using malicious code on the county treasurer's computer. The program diverted the funds via transfer to more than two dozen so-called "money mules." Editor's Note:  Did I mention that our log-in procedure is "Bullitt Proof!  (safer than ATM access because there is no threat of skimmers, hidden camera's or "card trapping") 



Read more: http://www.fiercefinanceit.com/story/more-bank-fraud-targets-government-accounts/2009-10-23#ixzz0UmFN8bVx





Reblog this post [with Zemanta]

Posted by John B. Frank Friday, October 23, 2009 0 comments

There's a great article today on Network World written by Ellen Messmer. Here's a sampling and my thoughts about the article (which I shared with Ms. Messmer)

Providing online bank customers with security software an imperfect cybercrime antidote
By Ellen Messmer, Network World  

In online banking and payments, customers' PCs have become the Achilles' heel of the financial industry as cyber-crooks remotely take control of the computers to make unauthorized funds transfers, often to faraway places. The dilemma for banks boils down to this:

How far can they go to help protect customer desktops that function like part of their shared network but aren't owned by the bank?

MY Answer: How about they provide something that IS owned by the bank (and uses existing bank rails) i.e.: Issue bank-owned PCI Certified PEDs...so they have a dedicated machine for online banking.

Banks are faced with the prospect that "customers own PCs that have been in the hands of Russian crime syndicates," says Jeff Theiler, senior vice president at Hancock Bank, which primarily operates along the Gulf Coast region. Like many other banks, Hancock finds itself getting more involved in helping customers defend their machines. <>

Editor's Note: Here's my response to Ellen's story (which was picked up by BusinessWeek today)...

Good morning Ellen: I enjoyed your article today on Network World and thought you might be interested in hearing that there is indeed a simple solution to the online banking problem to which you refer, specifically:  "The dilemma for banks boils down to this: How far can they go to help protect customer desktops that function like part of their shared network but aren't owned by the bank?"


Question: If you are 2000 miles from your bank, at 2:00 AM and need $200.00 what process is trusted to authenticate you and disperse the $200?
Answer: You insert/swipe your "bank issued card" then enter your "bank issued PIN" into a "bank owned ATM" and voilla. In seconds, you get your $200. That same trusted process is what should be used to authenticate online banking sessions.


Did you know that in Europe, almost 30% of consumers use a card reader for online banking (see graphic above) In America that number is ZERO.


Cost? WAY Less than what banks are already dishing out for "useless giveways. (When I say "useless" I am simply implying that the promotions they run don't "solve the problem.") The purpose of these give
aways is to attract customers. Well guess what? The purpose of "typing" is to provide online banking credential "giveaways" to the hackers, keyloggers and/or phishermen.


Consumers are already clamoring for a more secure online banking login process and they would "flock" towards the most secure online banking site in America, which is what a bank that deploys PCI Certified PED's to their online banking customers would become. Do you doubt me? Ask your friends. Would they rather type their online banking credentials into a box in a browser or swipe their card and enter their PIN?


Our device plugs into the USB port or smartphone and encrypts the cardholder data (including the Track 2 data) at the maghead using 3DES encryption. It then DUKPT encrypts the PIN for the only genuine end-to-end encryption.


The most important thing our device does is it "eliminates" typing "login" data into a box in a browser. That's the inherent problem. That's why (as you mention in your article) the Russian's get/got control of the PC's. (malware/phishing) Our PED eliminates the usage of inadequate and way obsolete "username/password" login...thus it eliminates phishing.


What do phishers phish phor? "Online Banking Credentials" AND "credit/debit card numbers. How do they get them? They fool people into thinking they are "typing" their card numbers/online banking authentication into a legitimate site when in fact it is not. That problem would be "eradicated" with our device.


Thus if all a banks customers securely login by doing what they do at an ATM, swipe their bank issued card, enter their bank issued PIN and do it on a bank issued PCI certified PIN Entry Device the problem created by "typing" would be eliminated by "swiping."I'd be happy to provide further insight as to why this is a "no-brainer" for banks to deploy.


Kaspersky Labs (which provides software security) knows that hardware is required as their recent proclamation calling for "mass adoption of card readers" professes. Software helps but at the end of the day it is simply a band-aid.


The internet was NOT designed to conduct financial transactions. It's called a "browser" for a reason and between malware, keylogging and phishing, the only solution to the problem is to replicate what we do at ATM's and/or brick and mortar retailers. Swipe vs. Type. As I like to say on the company blog. "If someone is going to "Swipe" your card information online, shouldn't it be you?


Question: Why would banks want to fork out $18 to give their customer a PCI Certified PED?
Answer: Well besides the obvious (they would save the millions of dollars lost to phishing) online banking is destined to fail. Most everyone is aware that fraud is running at epidemic levels and that what banks report is only a fraction of the real losses. (see graphic on right)


Other benefits: In addition to providing "True Two-Factor Authentication (and NO, a username and password is NOT really 2FA) Our device also completely eliminates the threats and fraud losses/costs created by typing...AND there is a return on investment in the form of Interchange revenue every time the device is used for online shopping or P2P payments.

Related articles by Zemanta


Read more: http://pindebit.blogspot.com/2010/06/bankings-big-dilemma-how-to-stop.html#ixzz0rEp43m6O
Enhanced by Zemanta

Posted by John B. Frank Friday, June 18, 2010 0 comments

There's a great article today on Network World written by Ellen Messmer. Here's a sampling and my thoughts about the article (which I shared with Ms. Messmer)



Providing online bank customers with security software an imperfect cybercrime antidote

By Ellen Messmer, Network World  



In online banking and payments, customers' PCs have become the Achilles' heel of the financial industry as cyber-crooks remotely take control of the computers to make unauthorized funds transfers, often to faraway places. The dilemma for banks boils down to this:



How far can they go to help protect customer desktops that function like part of their shared network but aren't owned by the bank?



MY Answer: How about they provide something that IS owned by the bank (and uses existing bank rails) i.e.: Issue bank-owned PCI Certified PEDs...so they have a dedicated machine for online banking.



Banks are faced with the prospect that "customers own PCs that have been in the hands of Russian crime syndicates," says Jeff Theiler, senior vice president at Hancock Bank, which primarily operates along the Gulf Coast region. Like many other banks, Hancock finds itself getting more involved in helping customers defend their machines. <<read more>>



Editor's Note: Here's my response to Ellen's story (which was picked up by BusinessWeek today)...



Good morning Ellen: I enjoyed your article today on Network World and thought you might be interested in hearing that there is indeed a simple solution to the online banking problem to which you refer, specifically:  "The dilemma for banks boils down to this: How far can they go to help protect customer desktops that function like part of their shared network but aren't owned by the bank?"





Question: If you are 2000 miles from your bank, at 2:00 AM and need $200.00 what process is trusted to authenticate you and disperse the $200?

Answer: You insert/swipe your "bank issued card" then enter your "bank issued PIN" into a "bank owned ATM" and voilla. In seconds, you get your $200. That same trusted process is what should be used to authenticate online banking sessions.





Did you know that in Europe, almost 30% of consumers use a card reader for online banking (see graphic above) In America that number is ZERO.





Cost? WAY Less than what banks are already dishing out for "useless giveways. (When I say "useless" I am simply implying that the promotions they run don't "solve the problem.") The purpose of these give

aways is to attract customers. Well guess what? The purpose of "typing" is to provide online banking credential "giveaways" to the hackers, keyloggers and/or phishermen.





Consumers are already clamoring for a more secure online banking login process and they would "flock" towards the most secure online banking site in America, which is what a bank that deploys PCI Certified PED's to their online banking customers would become. Do you doubt me? Ask your friends. Would they rather type their online banking credentials into a box in a browser or swipe their card and enter their PIN?





Our device plugs into the USB port or smartphone and encrypts the cardholder data (including the Track 2 data) at the maghead using 3DES encryption. It then DUKPT encrypts the PIN for the only genuine end-to-end encryption.





The most important thing our device does is it "eliminates" typing "login" data into a box in a browser. That's the inherent problem. That's why (as you mention in your article) the Russian's get/got control of the PC's. (malware/phishing) Our PED eliminates the usage of inadequate and way obsolete "username/password" login...thus it eliminates phishing.





What do phishers phish phor? "Online Banking Credentials" AND "credit/debit card numbers. How do they get them? They fool people into thinking they are "typing" their card numbers/online banking authentication into a legitimate site when in fact it is not. That problem would be "eradicated" with our device.





Thus if all a banks customers securely login by doing what they do at an ATM, swipe their bank issued card, enter their bank issued PIN and do it on a bank issued PCI certified PIN Entry Device the problem created by "typing" would be eliminated by "swiping."I'd be happy to provide further insight as to why this is a "no-brainer" for banks to deploy.





Kaspersky Labs (which provides software security) knows that hardware is required as their recent proclamation calling for "mass adoption of card readers" professes. Software helps but at the end of the day it is simply a band-aid.





The internet was NOT designed to conduct financial transactions. It's called a "browser" for a reason and between malware, keylogging and phishing, the only solution to the problem is to replicate what we do at ATM's and/or brick and mortar retailers. Swipe vs. Type. As I like to say on the company blog. "If someone is going to "Swipe" your card information online, shouldn't it be you?





Question: Why would banks want to fork out $18 to give their customer a PCI Certified PED?

Answer: Well besides the obvious (they would save the millions of dollars lost to phishing) online banking is destined to fail. Most everyone is aware that fraud is running at epidemic levels and that what banks report is only a fraction of the real losses. (see graphic on right)





Other benefits: In addition to providing "True Two-Factor Authentication (and NO, a username and password is NOT really 2FA) Our device also completely eliminates the threats and fraud losses/costs created by typing...AND there is a return on investment in the form of Interchange revenue every time the device is used for online shopping or P2P payments.



Related articles by Zemanta

Enhanced by Zemanta

Posted by John B. Frank 0 comments



PC World has an excellent article regarding Online Banking Trojans which are becoming increasingly more sophisticated.  As regular followers of this blog are well aware, I've long proclaimed that HomeATM can virtually "ELIMINATE" the threats posed by phishing.  When it comes to online banking trojans, they are simply data mining programs.  

What data would there be to mine if online banking customers were empowered with the same technology used to access cash at an ATM...i.e. Swipe their bank issued card and enter their bank issued PIN with a PCI 2.x certified PIN Pad?  The short answer is that we instantaneously encrypt the log-in session using 3DES/DUKPT encryption.  As the data NEVER enters the browser, there's nothing to "browse."  Encrypted data is useless.  The only problems ATM users experience are related to skimming devices and hidden cameras, neither of which is a threat to a HomeATM user who logs on to their online banking session in the safety and privacy of their own home. 

What they "don't" talk about is that online banking community uses SSL to secure the session and there are flaws in SSL which have the industry scrambling to put a band-aid on.  Later with the band-aids.  It's time to revamp the whole system.  In Europe, they are increasingly using hardware devices to authenticate the online banking session.  (see related article below
, Todos delivers 20 Millionth eBanking Security Product)





Oh...and don't forget what the Editor in Chief of Bank Technology News recently proclaimed: 
Online Banking is Dead - Bank Technology News Editor-In-Chief



Here's the article from PC World: 

Criminals today can hijack active online banking sessions, and new Trojan horses can fake the account balance to prevent victims from seeing that they're being defrauded.



Traditionally, such malware stole usernames and passwords for specific banks; but the criminal had to access the compromised account manually to withdraw funds. To stop those attacks, financial services developed authentication methods such as device ID, geolocation, and challenging questions. Unfortunately, criminals facing those obstacles have gotten smarter, too. One Trojan horse, URLzone, is so advanced that security vendor Finjan sees it as a next-generation program.

Greater Sophistication

Banking attacks today are much stealthier and occur in real time. (Translation: One-Time Passwords are at risk) Unlike keyloggers, which merely re­­cord your keystrokes, URLzone lets crooks log in, supply the required authentication, and hijack the session by spoofing the bank pages. The assaults are known as man-in-the-middle attacks because the victim and the attacker access the account at the same time, and a victim may not even notice anything out of the ordinary with their account.



According to Finjan, a so­­phisticated URLzone process lets criminals preset the percentage to take from a victim's bank account; that way, the ac­­tivity won't trip a financial institution's built-in fraud alerts. Last August, Finjan documented a URLzone-based theft of $17,500 per day over 22 days from several German bank ac­­count holders, many of whom had no idea it was happening.



But URLzone goes a step further than most bank botnets or Trojan horses, the RSA antifraud team says. Criminals using bank Trojan horses typically grab the money and transfer it from a victim's account to various "mules"--people who take a cut for themselves and transfer the rest of the money overseas, often in the form of goods shipped to foreign addresses.



URLzone also seems to detect when it is being watched: When the researchers at RSA tried to document how URLzone works, the malware transferred money to fake mules (often legitimate parties), thus thwarting the investigation.


Silentbanker and Zeus

Silentbanker, which appeared three years ago, was one of the first malware programs to em­­ploy a phishing site. When victims visited the crooks' fake banking site, Silentbanker in­­stalled malware on their PCs without triggering any alarm. Silentbanker also took screenshots of bank accounts, redirected users from legitimate sites, and altered HTML pages.



Zeus (also known as Prg Banking Trojan and Zbot) is a banking botnet that targets commercial banking accounts. According to security vendor SecureWorks, Zeus often focuses on a specific bank. It was one of the first banking Trojan horses to defeat authentication processes by waiting until after a victim had logged in to an account successfully. It then impersonates the bank and unobtrusively injects a request for a Social Security number or other personal information.



Zeus uses traditional e-mail phishing methods to infect PCs whether or not the person enters banking credentials. One recent Zeus-related attack posed as e-mail from the IRS. Unlike previous banking Trojan horses, however, the Zeus infection is very hard to detect because each victim receives a slightly different version of it.

Clampi

Clampi, a bank botnet similar to Zeus, lay dormant for years but recently became quite active. According to Joe Stewart, director of malware research for SecureWorks, Clampi captures username and password information for about 4500 financial sites. It relays this information to its command and control servers; criminals can use the data immediately to steal funds or purchase goods, or save it for later use. The Washington Post has collected stories from several victims of the Clampi botnet.



Clampi defeats user authentication by waiting for the victim to log in to a bank account. It then displays a screen stating that the bank server is temporarily down for maintenance. When the victim moves on, the crooks surreptitiously hijack the still-active bank session and transfer money out of the account.  Editor's Note:  If people would STOP TYPING their username and passwords to log-in and replaced the authentication with a Card Swipe and PIN Entry (which ensures you are on the genuine online banking website) then this threat would be eliminated as well. 



Defending Your Data

Since most of these malware infections occur when victims respond to a phishing e-mail (which we eliminate) or surf to a compromised site, SecureWorks' Stewart recommends confining your banking activities to one dedicated machine that you use only to check your balances or pay bills.



Good News People!  The HomeATM PCI 2.x Certified PIN Entry Device IS A SEPARATE AND DEDICATED MACHINE which online banking customers can use to:






1. Log In (Genuine Two Factor Authentication)


2. Check Balances

3. Pay Bills

4. Conduct Real-Time Money Transfers



5. Conduct Secure Online Transactions with Credit and Debit Cards.



Alternatively, you can use a free OS, such as Ubuntu Linux, that boots from a CD or a thumbdrive. Before doing any online banking, boot Ubuntu and use the included Firefox browser to ac­­cess your bank site.



Editor's Note:  That seems like a tremendously huge pain in the ass.  I thought the financial industry was focusing on "convenience."  Besides...as reported last week on this blog... 50% of American's don't even know what phishing is, so what percentage are going to know how to use or boot up with a Ubuntu thumbdrive?   I would venture a guess that close to 100% of Americans know how to swipe their card and enter their PIN.



Most banking Trojan horses run on Windows, so temporarily using a non-Windows OS defeats them, as does (TEMPORARILY) banking via mobile phone.  (I say temporarily, because when hackers set their sights on mobile banking, smart phones use browsers, which is the root of the problem in the first place.  Think outside the browser...think encryption "inside the box."






The key step, however, is to keep your antivirus software current; most security programs will detect the new banking Trojan horses.  Editor's Note:  Even if you have the most up to date Anti-Virus programs installed, Zeus bypasses detection 77% of the time.  So...that ain't happening.





There is an online banking Trojan out there that is bypassing up-to-date anti-virus programs as much as 77% of the time, according to security company Trusteer. The Zeus Trojan is also known as Zbot, WSNPOEM, NTOS and PRG. It is the most prevalent financial malware on the web, Trusteer says. (Editor's Note:  Others say it's Clampi



According to Trusteer: "When we set out to measure the efficiency of anti-virus products in the wild against Zeus, we had no idea what kind of results we would get," said Amit Klein, CTO of Trusteer and head of the company’s research organization.



"The findings, that up-to-date anti-virus programs were only effective at blocking Zeus infections 23 percent of the time, are disturbing".



This is bad news for consumers and banks, since the vast majority of Zeus infections are going unnoticed."






Reblog this post [with Zemanta]

Posted by John B. Frank Tuesday, November 24, 2009 0 comments

Downtown Core, Singapore's business centre.Image via Wikipedia
Author: Bharat Book Bureau



Online Banking in Singapore 2010



 The Singaporean online banking market is among the most advanced in the world, with a high proportion of the population using the online channel. However, there remains several issues for online banking providers. Singaporeans show a high level of security concern and are hesitant to apply for financial products online. ( http://www.bharatbook.com/detail.asp?id=141522&rt=Online-Banking-in-Singapore-2010.html )



 Scope



 * Includes a comprehensive overview of the Singaporean online banking market.

 * Provides online banking customer numbers, forecasts and market share of top competitors.

 * Discusses security issues and two-factor authentication.

 * Based on a global consumer survey covering 9,000 respondents.



 Highlights



 Consumer trepidation about buying more complex financial products online exists in all countries, not just Singapore, but there is data to suggest that the aversion toward online applications is stronger in Singapore than in comparable countries, especially when it comes to loan products.



 Security concerns still constitute a potent barrier for online banking customers, and with new threats as well as solutions for two-factor authentication emerging, providers need to constantly reassess their security solutions and communications with users.



 The number of online banking customers is forecasted to increase over the next three years, although growth in the market is gradually slowing down as it becomes more saturated. As an example, customer numbers grew by 49% between 2004 and 2005, but grew by less than 6% between 2009 and 2010.



 Reasons to Purchase



 * Improve your strategic position using in-depth analysis of the Singaporean online banking market.

 * Understand the unique challenges the online banking market is facing, and benefit from forecasts of future product trends.

 * Plan for the future by learning from one of the most innovative financial markets in the world.



 To know more and to buy a copy of your report feel free to visit : http://www.bharatbook.com/detail.asp?id=141522&rt=Online-Banking-in-Singapore-2010.html   

 Related Reports



 Security in Online Banking Strategic Focus

 http://www.bharatbook.com/detail.asp?id=103359&rt=Security-in-Online-Banking-Strategic-Focus.html



 Consumer Attitudes to Security in Online Payments and Banking

 http://www.bharatbook.com/detail.asp?id=129778&rt=Consumer-Attitudes-to-Security-in-Online-Payments-and-Banking.html



 Or



 Contact us at :



 Bharat Book Bureau

 Tel: +91 22 27578668

 Fax: +91 22 27579131

 Email: info@bharatbook.com

 Website: www.bharatbook.com

 Follow us on twitter: http://twitter.com/3bbharatbook



About the Author:

Bharat Book Bureau, the leading market research information aggregator provides reports, company profiles, newsletters, country info. and online databases for the past twenty two years to corporate, consulting firms, academic institutions, government departments, agencies etc., globally, including India. Our reports help global companies to know different market before starting up business / expanding in different countries across the world.



Article Source: www.linkroll.com -

Online Banking in Singapore 2010

Enhanced by Zemanta

Posted by John B. Frank Friday, June 18, 2010 0 comments

There's writing on the wall and then there is writing on the wall! 



Take a look at the chart on the left. Specifically, take a gander at the dramatic rise in Trojans over during the months of July, August and September.



Wow! Right?  So what are the chances we can defeat this growing threat?  SLIM & NONE!



First, the NONE:  Take into account that Clampi was only discovered in July.



Now take into account that URLZone was only discovered "Yesterday!"



URLZone, which not only steals online banking log in credentials, but then actually has the audacity to rewrite the text in the HTML code in order to cover up the fact that money is being siphoned out. Yes, the online statements show that money is still there!





The only good thing about his particular online banking Trojan (URLZone) is that it appears to have ended the argument about which online banking trojan (Clampi, Zeus, Conficker) posed the gravest danger to the online banking sector. Hands down...URLZone Wins. (for now...what will the bad guys come up with next?)







Speaking of winning.  The only way to "win" the "War of the World Wide Web" is to authenticate the online banking customer outside the browser WITHOUT typing.  Eliminate Typing...Start Swiping.



If I've said it once, I've said it a hundred times.  Browsers are not safe for eCommerce transactions. 



Agree or disagree with this statement:  If your cardholder data is going to be
swiped wouldn't you prefer being the one doing the swiping? 





The SLIM Argument:  Doesn't it make 100% logical sense to log in to your online banking account the same way you access cash at an ATM?  HomeATM's SLIM 100% replicates that procedure for online banking, using Existing bank rails, Existing cards, Existing PINs, "Better Than" Existing Security. 



In fact, the "only" difference between accessing cash in real-time at an ATM and logging on to your online banking session is that there is no risk of "skimmers" or "hidden cameras" to record your PIN entry.






Our chances to beat the hackers and these online banking trojans? 

SLIM and NONE.












Reblog this post [with Zemanta]

Posted by John B. Frank Thursday, October 1, 2009 0 comments

Payments Industry News Blog

Search the PIN Debit Blog by Subject

Kapersky Calls for Mass Adoption of Card Readers

Kapersky Calls for Mass Adoption of Card Readers