Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Lloyds Launches Selfie Technology
News & Analysis

Lloyds Launches Selfie Technology

ISBuzz TeamBy ISBuzz TeamOctober 11, 2016Updated:July 4, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Beautiful young woman holding a chalkboard / blackboard saying Selfie. Caucasian young girl isolated over grey background.
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Following the news about the Lloyds Banking Group has launched selfie technology to enable Bank of Scotland customers to open a current account seamlessly online. As the ID verification technology is web based customers can use a web browser on their smartphone or tablet to submit images.

Cyber security experts from MIRACL, AlienVault, Lieberman Software, Redscan and ESET commented below.

Brian Spector, CEO at MIRACL:

brian-spectoreic“The volume of financial fraud has risen dramatically in the past year as hackers have become more sophisticated and are managing to bypass traditional methods of security with alarming ease. A range of tactics which once seemed secure – such as identity verification via text message – are become easier for hackers to exploit.

As the payments market has become more open, with a plethora of third parties now sitting between banks and their customers, it has become paramount to accurately verify the identities of people accessing the data and systems involved. Fortunately, the European payments market is on the cusp of a radical change.  Rather than being just a swathe of red tape, the revised Payment Services Directive (PSD2) is a much-needed attempt to prevent our entire banking system from being exploited by hackers.

Real digital security requires the complete elimination of centralised security technology. By distributing trust across multiple locations, the web can continue to grow and expand more securely to meet its needs for the future.”

Javvad Malik, Security Advocate at AlienVault:

Javvad Malik“The use of a selfie as an authentication mechanism may seem like something that a millennial cooked up whilst browsing Instagram one night.

However, payments have always been about risk management. Banks have typically been good about walking the line between convenience and security.

From a security viewpoint, financial fraud will never be completely eradicated, and increasing security too much will inconvenience users – so for banks it’s a fool’s errand. Rather, the controls needed should be sufficient to keep fraud within tolerances whilst providing customers with a convenient experience.

This is where selfie pay seems like it is trying to bridge the gap between a fully authenticated method, such as chip and Pin – and an unauthenticated method such as contactless.

The issues that are present are similar to any of the issues that exist with any biometric technology, in that there will be a number of questions users and privacy advocates will be asking. Such as how will the pictures be used; will they be saved? Will the data be shared with advertisers, or other online channels?”

Jonathan Sander, VP of Product Strategy at Lieberman Software:

Jonathan Sander“Lloyds’ selfie technology is a good marketing name for all established biometric security. Apple introduced biometrics in the iPhone years ago with the fingerprint reader and Microsoft’s “hello” uses facial recognition, similar to what Mastercard has just rolled out and now Lloyds is doing the same.

Calling it a selfie is genius because it’s skipping right past technology to a concept most users will immediately understand. From a security standpoint, biometrics like selfie pay have many advantages over passwords. Though not impossible, it’s much harder to steal someone’s face than to guess their password. Users can’t forget their face like a password, or use an insecure face because they’re lazy. These biometrics are essentially very complex, unique passwords – the kind of pharos experts have begged users to create for years.”

Robert Page, Lead Penetration Tester at Redscan:

“User passwords are typically the easiest point of attack in computer systems and this is driving increased adoption of biometric authentication systems.  These systems, whilst typically more secure, can pose their own set of issues however.

For instance, if biometric information is captured and used by an attacker, it’s not possible for a user to change his or her imprint as they would a password. The effectiveness Lloyds’ new solution is yet to stand the test of time however.”

Mark James, Security Specialist at ESET:

mark-james“Biometric security will appeal to the public because it enables and often encompasses their mobile technology. If done correctly it can offer a level of security far above that given by a simple password. It accomplishes two goals; the first is not having to remember your password each time you want to access those services (we encourage unique fairly complicated passwords but also want the user to remember them for daily use). Secondly they also negate the need to enter them onto small mobile devices that may be easily seen by others.

As for risks we need to pair them side by side with the risks of using simple passwords. Anything in my opinion that encourages uniqueness should be embraced, if biometrics encourage or even force users to have a much more secure password as a base then that’s a good thing right?

We are seeing more and more companies embrace different methods to help the end user with their security. Fingerprints and face recognition is easily integrated into our mobile devices that have now become an integrated part of our daily lives. As long as we encourage multi-layered security those could include passwords, passcodes, security questions and answers plus biometrics, all together forming a much more secure environment for the user to access what they want to access on the move, we will definitely see more and more options to integrate forms of biometrics into our mobile digital world.”

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The Real Cost of Inconsistent Third-Party Access

December 18, 20255 Mins Read

What Happens When Devices Cross Borders? The Role of Geofencing in Global IT

August 7, 20256 Mins Read

The Evolving Importance of Identity Governance in FinTech

July 10, 20258 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}