Password reuse threatens online banking security

By
Follow google news

Data gleaned from four million PCs.

A report into the security of internet banking systems has found that one of the biggest problems is the reuse of log-in passwords on multiple sites.

Online security firm Trusteer monitored over four million computers for a year, and found that 73 per cent of internet banking customers used the same password for their online banking services as they did for other, less secure, sites.

"Using stolen credentials remains the easiest way for criminals to bypass the security measures implemented by banks to protect their online applications, so we wanted to see how often users repurpose their financial service user names and passwords," said Amit Klein, chief technical officer at Trusteer, and head of the company's research organisation.

"Our findings were very surprising, and reveal that consumers are not aware, or are choosing to ignore, the security implications of reusing their banking credentials on multiple web sites."

The Reused Login Credentials report (PDF) found that part of the blame lies with banking web sites that allow users to choose their own IDs, as almost two thirds of customers use the same ID for other sites. This figure falls to less than half when users are allocated an ID by the bank.

The research also found that nearly half of banking customers use their ID and password for a non-financial web site.

The use of the same password for multiple sites raises serious security risks. If a hacker can get one password from a less secure web site by a 'brute force' dictionary attack, for example, there is a good chance that it can be used on other sites.

Password reuse threatens online banking security
Got a news tip for our journalists? Share it with us anonymously here.
Copyright ©v3.co.uk
Tags:

Most Read Articles

National photo licence recognition system set to go live in 2025

National photo licence recognition system set to go live in 2025

Age verification IDs taken in Discord data breach

Age verification IDs taken in Discord data breach

Qantas says customer data released by cyber criminals

Qantas says customer data released by cyber criminals

NSW gov contractor uploaded Excel spreadsheet of flood victims' data to ChatGPT

NSW gov contractor uploaded Excel spreadsheet of flood victims' data to ChatGPT

Log In

  |  Forgot your password?