Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Why Banks Need Consumers To Detect Imposters
Articles

Why Banks Need Consumers To Detect Imposters

ISBuzz TeamBy ISBuzz TeamNovember 9, 20165 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

In the first half of 2016 alone, there were more than one million incidents of financial fraud, an increase of 53 per cent on the same period last year; with identity fraud against individuals costing an estimated five billion pounds last year.

Identity fraud occurs when an imposter pretends to be someone else. To prevent this, banks ask customers for passwords, but judging from the fraud figures, this isn’t working and things are getting worse. The reason is simple: data cannot differentiate. A password provided by the true customer is exactly the same when that same password is provided by an impostor.

Banks need to reconsider the security practices they put in place so as to allow consumers to tackle this fraud. Rather than continuing to impose a practice that everyone acknowledges is fundamentally flawed, banks need to reach out to consumers for help.

 Why banks are not doing enough

 Over the past ten years or so, the response to the rise in identity fraud has exemplified Einstein’s definition of insanity: keep doing the same thing, just more of it. Passwords had to be longer, then they had to contain numbers, then with upper and lower case letters, and symbols. Along the way we had to provide random characters from a ‘memorable’ word, and ‘secret’ answers to an array of personal questions.

To be fair, banks are not alone in persisting with this broken method. They inherit an information technology practice that has persisted for fifty years. Passwords were first used in a system called CTSS developed at MIT in 1961, and we’ve barely moved ever since.

Attempts to try something different have involved the introduction of card readers, dongles and using your phone to send you a PIN. This so-called two factor authentication (2FA) is intended to make it harder for those secrets to fall into the hands of impostors. The problem is that ultimately it’s still just data, to which the golden rule applies: if you can know it, a fraudster can know it too.

Although 2FA represents an improvement, it is not widely adopted. This has been highlighted in the last month, with five of the UK’s biggest banks scoring poorly in security tests and failing to invest in systems to better protect their customers. This is not without reason: apart from the weakness inherent in using data to distinguish between customers and impostors, these methods are costly and require customers to perform awkward tasks, such as fiddling with card readers and copying PINs from one device into another.

I believe banks have been trying to solve the problem, but in the wrong way. Attempts to fix it to date have made a bad situation worse. Consumers are unwilling or unable to remember long and complex passwords and instead choose to use the same password for everything, or write it down. Consumers are also warned not to put information on social networks, such as their date of birth, where they were born, went to school… But why shouldn’t they? The real question is this: Why is any bank using personal information as a guarantor of personal identity? The current system has always been destined to fail.

Banks can help not hinder

To increase identity protection, detect imposters and make consumers lives easier, banks need to disrupt the security industry, turn it on its head and drive change towards a better system. To do this, they need to consider the origins of identity itself.

People already have an excellent identity system that has been refined over thousands of years of human evolution. The ability to tell friend from foe has been a matter of survival. When someone comes in your house and you see your partner, you know it’s them. You don’t need them to wear a badge or give a password. It is all based on visual identity – our inbuilt facial recognition software, if you will.

Remarkably, information technology has overlooked this natural capability. By capitalising on visual identity, banks can help transform the practices around online identity and leave our broken system behind. A few years ago it would have been impossible to do online identity visually. However, with almost every consumer having a digital camera connected to the internet in the form of a mobile, now is the perfect moment to put this practice into place.

People know people

This means that a person requesting access can present themselves to the camera on their mobile, so allowing natural, real-world identity to be brought into play. Verifying identity becomes a social activity – as it always has been. If the account holder shows up they will be recognised, but if anyone else shows up, the imposter will be detected. This not only prevents fraud from occurring, it also catches the criminal in the act – a significant deterrent.

By relying on visual identity, banks can help people protect one another from fraud using the identity system they have been using for millennia – their eyes. The reality is that organisations don’t know people, people know people. When it comes to personal identity, the customer really does know best.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The Real Cost of Inconsistent Third-Party Access

December 18, 20255 Mins Read

What Happens When Devices Cross Borders? The Role of Geofencing in Global IT

August 7, 20256 Mins Read

The Evolving Importance of Identity Governance in FinTech

July 10, 20258 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}