Categories
Uncategorized

UK Financial Institution in “Not Getting It” Shocker

I am so pleased that the Nationwide building society has decided to implement new internet banking security measures. Yesterday, on logging in, I was prompted to submit my answers to five questions from a choice of twenty, and I can now be asked to answer these questions at any time when using the online service. Fantastic: more stuff to remember. This is in addition to the 10 digit customer number, the memorable place, date and person, and PIN that I already needed to remember in order to use the service.

The more stuff they require me to remember, the more secure the system must be, right? Surely now I have five extra things to remember, it must be five times as secure…

They have massively missed the point. If they really cared about security, they’d implement proper two-factor authentication, which is about using at least two different methods of verifying that the user is who he says he is. Typically, that means verifying that the user knows something (like a password) and verifying that the user has something (like one of those security token/fob things that generates a really long number when you press the button). But clearly issuing every customer with a token would be far too expensive, so instead they’ve decided to implement a security system that verifies that the user knows something, and, er, verifies that the user knows some more stuff.

Fantastic.

This provides no additional security whatsoever over their existing authentication methods, and it’s actually worse, because the more stuff you ask people to remember, the more likely it is that they will start writing it down.

Of course, Nationwide claim:

These security questions offer additional peace of mind when you carry out transactions on our Internet Bank as only you will know the answers.

But this is nonsense. The questions are either going to have answers so obvious that anyone who knows me could work them out, or they are going to have answers I’ll need to think about, in which case I’ll either need to remember what I happened to think was the best answer to that question when I filled in the form in October 2007, or I’ll need to write down the answers somewhere.

Out of the full list of 20 questions I could not find a single one to which I could give an unambiguous answer that I wouldn’t need to remember. The questions included the likes of:

“Where did you first go on holiday?” (I was probably 1 at the time. I don’t know)
“What’s your father’s middle name?” (He’s got two: which one should I put?)
“What team do you support?” (Ok, so the answer’s “everton”, but should I write it as “everton”? “everton fc”? “the blues”? “the toffees”?)
“What was the name of your first employer?” (my first employer was the guy who ran the restaurant I washed dishes in when I was 16; I can’t remember his name, so should I put the name of the restaurant? Maybe I should put the name of my employer for my first proper job? How will I remember which one I chose?)
“What is your favourite colour?” (Seriously: is this a Smash Hits interview? Who has a favourite colour?)

They go on to say:

The questions were chosen to meet the needs of our diverse membership. We have listened to the views of people across a variety of age ranges and lifestyles. We have also taken into account industry standards.

Questions should not be taken too literally, if you feel you’re unable to answer a question, either choose a different one, or provide an answer that means something to you. E.g. If you don’t have a favourite song, you could answer with a song that is memorable to you, such as the song played at your wedding.

You can type what ever answer you like, it’s not a test, as long as you give an answer that you will remember.

Yes, but that’s the whole point: how will I remember which song I picked at the time I answered your question? You’re not the only financial institution I have an account with, and it’s only a matter of time before they all start asking me to answer some silly questions of their own. I’m never going to remember all the answers I gave unless I start writing them down…

[The Nationwide cares so much about security that it was fined £980,000 by the FSA earlier this year when a laptop containing 11 million customer account details was stolen from an employee’s house.]

4 replies on “UK Financial Institution in “Not Getting It” Shocker”

Issuing a token isn’t expensive. A bit of paper with several hundred random numbers on it would suffice, if the bank was able to tell you the coordinates of the number it wanted. Anyone who remembers the days when copy protection was merely annoying can tell you that :)

These “tokens” would be easier to copy than a fob or dongle, which is slightly worse than being easy to steal, but that can be mitigated using funny coloured inks, fancy rotating wheels, or that pattern of dots that stops you copying banknotes… besides, you still have your secret to protect it.

Why don’t you just answer “I don’t know” to every question?

Listen to Radio 4’s Moneybox item on this on 27/10/07.

As predicted, post-it notes with all the answers written down are beginning to appear next to PCs… For everyone else, Nationwide can look forward to a tsunami of support calls in x months time when people call in to say that they have forgotten the answers that they gave. And what will they do? They will go back to the beginning, asking the caller “What’s your mother’s maiden name/date of birth/postcode” in order to by-pass the problem (oh, and that will the ID thief calling, BTW).

I like Rob’s suggestion, although I’d go for “MYOB”.

Funny. I notice that the bloke from Nationwide defends it by claiming to only have had 5 complaints. I must remember to write to them…

Comments are closed.