Wednesday, October 30, 2013

One Time PassCodes - Why They Are Important

As cyber criminals become more sophisticated, KFCU and our partners continue to seek out ways to protect our members.  Account takeover is on the rise.  The bad guys are gaining online banking credentials by capturing the keystrokes on your PC as you log in to online banking and then using them to log on as you, the member and commit fraud.  Typically this occurs when a piece of software, called a Trojan Horse, is unknowingly downloaded to an unsuspecting member's computer, capturing the member's keystrokes including the User ID and password to their online banking account.

Several years ago, the Federal Financial Institutions Examination Council, (FFIEC) published some best practices for financial institutions on how to protect members and customers against account takeover fraud through the online banking channel.  The biggest portion of the recommendation was the use of "out of band" authentication in the online banking sign on process.

Out of band authentication is simply the concept of providing another way to make sure that you are who you say you are when you sign on to online banking.  When a member uses their debit card to get cash from an ATM, we use a form of out of band authentication when we ask for a PIN number to be entered.  Even if someone had possession of your debit card they would need to know your PIN to use it.

The use of one time passcodes delivered to a cell phone or land line phone is the way that we ensure that you are who you say you are when you sign on to online banking.  If a criminal were to obtain your User Id and Password for your online banking account, they could not sign on without that one time passcode.  Receiving and inputting that one time passcode keeps online banking secure.

The safest, most secure way to bank online is to receive a one time passcode each time you sign on to online banking.  We realize that it can be a nuisance to receive that code each and every time and key it in, but it really does offer the highest degree of protection and security for banking online.

So the next time you are prompted for a one time passcode, remember KFCU is just trying to keep your online banking safe and secure!

Your Wingman GW

2 comments:

  1. Once again, you have succeeded in making banking with you impossible on both my federal work computer as well as my new personal computer. I used to love KFCU because of ease of navigation and access. Since November of 2012, your site has been an absolute disaster for me. I was unable to access my account while deployed to Afghanistan and now I am unable to provide my chain of command even the most rudimentary feedback about whether or not I have been paid. So much for being my "wingman". You continue to compound the problem by putting up even more barriers to access. Security should not come at the expense of customer convenience. If I can't have access to my own money, what good are you to me? And don't try to tell me that all of this is being done with my interests in mind. You are making access more difficult with only your interests in mind becauae you alone are responsible for any losses resulting from unauthorized access to accounts.

    Sincerely yours,

    Joseph Quintana

    ReplyDelete
    Replies
    1. Hello Mr. Quintana,

      First let me thank you for your service to our Country.
      Im very sorry that you are having difficulty using online banking. If you wouldnt mind emailing me at KFCU (cto@kirtlandfcu.org) with a little more detail on the issues you are having I would very much like to understand the issues you are having and see if we can help get them resolved and get some good feedback on our online security.

      George Walker

      Delete