Online Banks Do Not
Offer Sufficient
Security on Money
Transfers
The problems that led to
customers bank accounts
being ransacked by
criminals using the
method of "phishing" is
made possible due to the
local banks low security
in allowing transfer of
funds from one account
to another.
Currently, a customer of
either private or state
banks, needs only to
login, using a
"username" and
"password", to access
their account and make
transfers to other
accounts.
Few online banks advise
customers when a
transfer has been
initiated. In addition,
a hacker can change the
login password and the
owner of the account
does not have a clue
until they try to login,
at which time they are
forced to call their
financial institution.
Notwithstanding, Carlos
Melegatti, director of
the División de
Servicios Financieros
del Banco Central,
responsible for the
creation of SINPE (Sistema
Nacional de Pagos
Electrónicos) - a system
operated by Central Bank
to allow transfers of
funds between accounts
of different banks -
defends his position
saying that the system,
up to now, has been
secure.
The SINPE is a system
where national banks, by
way of the internet, can
allow their customers to
move funds from their
account to the account
of another person at any
bank in the system. The
communication, according
to Melegatti, is on a
private network.
Melegatti added that the
security of customer
accounts is a question
of each individual bank
and not of the Central
Bank.
The way SINPE works is
that a customer has to
register for the service
with his or her bank.
Once the registration is
complete, anyone with
access to account
knowing the login
information, can now
access the SINPE service
in the account and
transfer funds without
additional security in
the majority of the
cases.
Some banks like the BAC
San José allows only
transfer of funds to
persons or accounts
pre-authorized with the
bank. In the case of
Banco HSBC, formerly old
Banco Banex, the bank
issues its customers a
set of "testkeys" in a
booklet, which contain
the necessary codes to
make transfers.
The majority of the
other banks are working
on additional security,
according to Melegatti,
beyond the simple login
of username and
password.
One of the forms of
providing additional
security is the "digital
signature", which would
replace the traditional
login system.
A digital signature or
digital signature scheme
is a type of asymmetric
cryptography used to
simulate the security
properties of a
signature in digital,
rather than written,
form.
Digital signature
schemes normally give
two algorithms, one for
signing which involves
the user's secret or
private key, and one for
verifying signatures
which involves the
user's public key. The
output of the signature
process is called the
"digital signature."
Other forms of securing
accounts is the use of
tokens contained in a
portable USB card or the
use of a "chip" card
that the customer has to
plug in to access his or
her accounts.
The digital signature
can not only be used by
banks, but also by
governments. The Banco
Cental, Poder Judicial,
Registro Nacional and
Tribunal Supremo de
Elecciones (TSE) are
currently assessing the
use of a digital
signature to secure
their information.
However, for the time
being, it is best not to
protect your login
information and
constantly keep changing
your password and to
review your account on a
period basis, even
though there is no
activity on your part.
The Banco de Costa Rica
and Banco Interfin (soon
to be Scotiabank), for
instance prompt a change
of password between 30
and 120 days and once a
password is used, it
cannot be used again in
the future. |
|