Monday, January 28, 2008

Comparative Review of Internet Banking

While we're on the topic of security and privacy, let's do a comparison of Internet Banking security features in American vs Singaporean banks.

I hate to admit this... but one has to be objective at some point. DBS beats the shit out of the No. 1 bank in America... you guess it the Bank of Americunt. Hell, why is the Bank of America so successful? They're a piece of shit. I'll take DBS any day of the week... Did I just say that? Damn... heresy from my mouth. Oh well... facts are facts.

Firstly, DBS (and UOB too) have a 2-factor authentication for internet banking. This means you need your password and a token (a device that generates some random string of numbers valid for about 5 minutes). In place of a token, you can also use your HP, they will SMS you the number. To login to internet banking you thus enter your User ID, Password and Token Number (or the SMS number sent to you). Thus, in theory, to be hacked, the hacker needs to know your User ID and Password and steal your token or your HP. Of course, the random number is generated by some algorithm, so in theory somebody who cracks the algorithm can generate the random token number... but that's probably gonna take more skill than your petty password stealer.

Now in Bank of America there is only User ID and Password. They have some kind of Passkey, in which they will show you a picture of your choice before you enter the password... but the purpose is more to tell you that you are on the right website and not on some phising website. They do have a Token/SMS feature, but sadly my fucking T-Mobile line can't receive SMS from the bank (reference to the complaint post way back). And more importantly, it's not a compulsory feature.

Phone Banking in America is worse! The only authentication challenge they do to ensure that you are who you say you are simple shit like your birthday and mother's maiden name and address. Hell fuck! If my roomate wanted to impersonate me he can... I was talking to the bank the other day and he entered the room. Fucked up!!!

You know why DBS is better? Cause they don't use such lame authetication. They ask questions like:
1) How many accounts you have?
2) Single or Joint? Joint with who?
3) How much money you have in your account approximately?
4) How often do you use your account?
5) Recall the last few transactions?

As you can see, in order to fake identity to DBS you must really know alot about the account holder. Oftentimes I myself am also challenged to recall such details to prove that I am who I say I am.

Yeah, so thumbs up for DBS. Fuck you Bank of Americunt.

No comments: