Editor
Forum Page
Straits Times
I use internet banking to transfer money to the other people through their bank account. I find this service to be convenient, compared to sending a cheque to them.
However, I find that the actual implementation of this service by my bank to be a hassle in the following aspects:
1. The bank requires the customer to create a record for each new payee and to authenticate it through a PIN sent through the mobile phone.
2. The bank requires the customer to enter the IB Secure PIN for every payment
These layers of security measures are duplicative, as the customer already has to enter user ID, PIN and an IB secure PIN to gain access to the internet banking facility.
The real risk to the customer is by entering the wrong account code of the payee or the wrong amount. The bank is not helping the customer to mitigate this risk.
By giving hassle and distracting the customer, these duplicative tasks actually increases the risk to the customer of making mistakes in entering the wrong bank account or amount. The inconveniences are aggravated when the computer system or internet is slow.
I believe that these security features may have been mandated by the regulator. I hope that the banks and the regulator should re-look at these requirements and simplify the process for the customer, while maintaining an adequate level of security. This will allow the customer to focus on ensuring that the entries are correct.
Tan Kin Lian
Tuesday, July 07, 2009
Subscribe to:
Post Comments (Atom)
Blog Archive
-
▼
2009
(1548)
-
►
November
(157)
- Emergency jobs program
- Location map - fast and easy
- Keynesian Economics
- False wealth
- Get Ready for Half a Recovery
- EPL matches for 2010
- Buy term insurance directly through internet porta...
- Termination of Living Policy
- Life insurance can serve a useful purpose
- Payout under CPF Life
- Family Income Benefit
- Keep cash, and be safe
- New immigrant's loyalty to Singapore
- An alternative to the free market economy
- Confucianism
- Pension planning
- Economic problems of Ireland
- Dubai is unable to repay its debts
- Ideals of communism
- Communism - theory and practice
- Misleading arguments by life insurance agents
- Watch out for signs of a bad financial adviser
- Review of existing life policy
- SCMP:Objections to new rules on minibonds look fli...
- Over reliance on ratings
- Tax burden around the world
- Level the playing field
- Survey: EPL matches on Pay TV
- Quality of service
- Loss of human touch
- Lending to small businesses
- Zero interest rate
- Common Sense Investing - John Bogle
- Credit card bills
- Recession and opportunity to change
- Excellent train service in UK
- Oligopoly
- New York Times to Goldman Sachs
- Low interest rate
- Motley Fool
- Better citizens
- Bailout of AIG
- Full employment and welfare state
- Charity and the retrenched
- Marketing of Portals
- Law Society - Speech by Michael Hwang
- Yield on a Life Insurance Policy
- The Big Squander
- Wonderful scenes of Paris
- SCMP:Ex-DBS broker suspended over Lehman debacle
-
▼
July
(192)
- Great Eastern Announces One-time Redemption Offer ...
- SCMP:Investors set for legal fight over lost milli...
- Features of life insurance policies
- Coops in focus in US healthcare debate
- Aging, inequity and poverty
- Expensive car park in Singapore
- Health care realities
- The Health Debate: At a Fever Pitch
- Permits required to appeal to the public for funds...
- Petition to PM on credit linked note (6)
- Pelosi lashes out against insurance companies
- Promote the use of car sharing
- No parking space in HDB estates
- Online Donation towards Gathering on 22 August
- Waiting for the stockmarket to bottom
- BBC; Car insurance premiums rising
- Are you sure democracy cannot help you financially...
- 50% compensation for Minibond
- Company Y not wanting to pay out my insurance clai...
- Gathering on 22 August at Hong Lim Park (2)
- Books and puzzles
- The Standard:Bank wiped out my $260m
- NJ sues Merrill Lynch over $300 mln stock purchase...
- Work near your home
- For the benefit and welfare of the people
- Honesty in Politics
- What is the future for this country?
- Free market - success and failure
- Reuters: Investors dump brokers to go it alone onl...
- NY Times: Of banks and bonuses
- Lehman victims international/ planning for Sep. 15...
- Why markets can't cure health care
- The Standard:61pc of minibond investors undecided ...
- TODAY:We should follow HK's example ; Protect indi...
- Honesty and fairness
- SCMP:Monetary Authority director clarifies minibon...
- Advice on individual shares
- Pensioner Health Benefits
- Interest rate on 25 July 2009
- Winners of Intelligence Quiz and Name The Shape co...
- Develop your mind
- SCMP:Lehman inquiry to call SFC chief again
- Broadcast this message: Petition
- Cheated in a good reputation country
- Where the jobs are
- Health care systems around the world
- Journalists refused to cover the Petition
- Unsightly flyover in the center of town
- Pinnacle Notes - many series in trouble
- CPF Life - does it need to be compulsory?
- SCMP:Minibond decision heartens investors similarl...
- The Standard:Protests ease, investors come to term...
- China Daily:Investors continue minibond fight
- Parliament Answers to Lehman Structure Products - ...
- SCMP:Some sympathy for the devils
- CPF Life
- Coverage of HK settlement
- Minimum wage spurs optimism and debate
- The Emperor's Clothes and Singapore
- SCMP:How swift lobbying ended a dispute that had d...
- SCMP:Legco inquiry to proceed despite agreement on...
- SCMP:The right rules, and the facts to invest prud...
- The Standard:Deal tones down minibond anger
- The Standard:Nightmare nears end
- Blog: Diary of a Singapore Mind
- Help Minibond investors to secure the collateral
- Petition to Prime Minister (5)
- Survey Results: The Emperor's Clothes
- Interesting puzzle
- Q&A US Health Reform
- In South Korea, a new worker's grievance
- SFC, HKMA and 16 banks reach agreement on Minibond...
- The Petition is NOT a futile effort
- Gathering in Hong Lim Park on 22 Aug 09
- Minibond - misconceptions and unfair criticisms
- NY Times: Temasek scraps plan for American chief
- SCMP:Investors want full refund, not 70pc
- Bloomberg: HK banks agree to repurchase Lehman Min...
- Investing in gold
- Investing in a property for rental
- Bird Nest Industry in Kedah, Malaysia
- Personal accident insurance
- Existing whole life policy
- Winners of MySudoku contest
- A Collosal Failure of Common Sense
- Petition to Prime Minister (4)
- NMP Siew Kum Hong expresses his views on the credi...
- SCMP:Treat us the same as minibondvictims, say Oct...
- The Standard:Banks facing China claims
- Kedah, Malaysia
- Petition to Prime Minister (3)
- Financial invention vs Consumer Protection
- SCMP: Clear up the mess
- 6 day detox programme (3)
- TODAY: On the issue of responsibility
- MySudoku Contest 17 July
- Petition to Prime Minister (2)
- Shape Quiz book is now ready
- 6 day detox programme (2)
- When do you say the Emperor has no clothes
- SCMP:Cleaning up the mess after a big player falls...
- SCMP:Tsang's disapproval rating at record high
- Earthquake and tsunami
- Singapore GIC, Temasek, and Transparency
- 6 day detox programme
- True cost of life assurance
- Financial consumers need new watchdog: Obama admin...
- The New Paper:The real problem? Underwriters hidin...
- Petition to the Prime Minister
- MySudoku Contest 10 July 2009
- Logic9 (Sudoku pocket books)
- Maximise shareholder value
- Low interest rate
- Tiered interest rate
- Ask for investigation report through FIDREC
- The Emperor's Clothes
- Brain Workout in The New Paper
- Serangoon North HUDC Privatisation
- Idling ships clog up Singapore shores
- Rebuttals to editorial in Straits Times
- Issues not addressed by MAS investigation findings...
- Law Suit on DBS High Notes
- Coverage of Lehman cases in Hong Kong
- MySudoku Contest in MyPaper
- A fair solution to the toxic product crisis
- Part Time Work Portal
- Name the Shape Contest
- TKL Intelligence Quiz Contest
- The Standard:Ip supports banks' offer in minibond ...
- Relevance of Animal Farm
- Tyranny and liberty
- Cheyenne does Shape Quiz (2)
- SCMP:SFC does not need to complete all minibond in...
- SCMP:Chief keeps quiet over calls for his resignat...
- A Doctor by Choice, a Businessman by Necessity
- Ban on selling structured notes
- Let your views be heard
- Gathering at Speaker's Corner, 22 Aug at 5 pm
- Section 27 of Financial Adviser's Act
- A fair compensation
- Follow up action on MAS investigation report
- The Standard:Illegal Lehman protest targets Tsang ...
- Singapore bars 10 firms from selling structured no...
- MAS Investigation Findings
- 100 fun and information personality quizzes
- Simplify Internet Banking
- Prevent Mis-selling of Financial Products
- Funds Transfer
- Diverse Views
- A poor return on savings in life insurance
- A note of encouragement
- No-fault motor insurance
- Are we over-reacting to Influence A (H1N1)
- The hidden ugly side of Singapore
- Consumer Finance Protection Agency
- SCMP:Lehman investments recouped
- FISCA Research: Interest Rates on Savings Accounts...
- Cheyenne does the Shape Quiz (T Puzzle)
- Allow lawyers to act on contingency fee
- Automated car
- Gathering in Speaker's Corner in August (4)
- Mis-representation on Credit Linked Notes
- Can you solve these 4 shapes?
- Checks and balances
- ATE (After The Event) Insurance
- Credit cards availabe in Singapore as at 15 May 20...
- Fixed deposit interest rate as at 15 May 2009
- Is this negligence?
- Local Transport Service
- Create jobs to help recovery of Global Economy
- SCAM: A bounced cheque
- Request for another Petition to MAS
- Show of support?
- The Standard:New deal to settle minibond buyback
- Was there an attempt to cheat?
- Gathering at Speaker's Corner in August (3)
- Best use for electric car
- Invest in Singapore Government Securities
- What is cheating?
- Politics of Fear
- Australia: List the names of underlying securities...
- Best fixed deposit rates
- SCMP:Minibond victims try to storm bank in protest...
- MRT train lines to come under a single operator
- Cheating and negligence
- Vista Plan (from Zurich)
- Administration of Justice (2)
- Gathering in Speakers Corner
- Compensation should not solely be based on vulnera...
- SCMP:Policy chief expects march to reflect increas...
- Buying a property - facilities
- Administration of Justice (1)
-
►
November
(157)
10 comments:
My experience with internet banking in the UK (with HSBC) is as follows:
The customer is given a 10 digit login username. Also, the customer has to choose a unique 6-10 digit numerical code. After you enter the username, you are asked for your birthdate and specific 3 digits of your code e.g. they might ask for first, second and last digit.
After you are logged in, you can do any transfer to anyone without having to re-enter your code or PIN. No handphone or token is needed for any transactions.
Imagine my surprise at the relative simplicity when I first started using this in the UK!
I agree with Shen Ting that the HSBC system is very user friendly.
But they have a clever way to beat the hacker as well:
(1) At each login, the user is asked to provide 3 digits randomly chosen (e.g. first, third and last digits) from his 6-10 digit passwords.
(2) The method of inputing the 3 digits is by means of clicking the mouse on a picture of the keyboard displayed on the screen.
(3) The location of the picture keyboard is slightly on the screen is shifted slightly from one login session to another login session.
The above 3 methods are a clever way to use technology to beat any hacker waiting to capture user login information. They imposes no additional burden on the user to carry any electronic gadgit to generate a random security code or a handphone to receive any SMS password.
Hello here is REX commenting.
I have been using the POSB funds transfer internet banking for a long time. Actually, the requirement to key in the 2FA Token code a second time during a fund transfer transaction is only introduced recently. About 2 months ago i estimate, the procedure was the same as what was described by Shen Ting. When the POSB introdcued the new procedure they didnt even make any announcement. The user just follow the screen instruction on the website and key in the code a second time if a fund transfer is to be done. Perhaps it is necessary to prevent fraud, i do not know. Basically i think the problem is a PR issue. Nobody likes changes in the system without at least a decent explanation. More often then not, customers just follow and are not duly informed, that is typical DBS style.
REX
The extra precautions are necessary.
There are ways in which the initial login can be hijacked by someone else and then subsequent transactions done as though came from you.
The additional steps minimise the risk (as the person who hijacked the session does not have the token to respond).
Try citibank, need to enter only once for multiple payment.
I also find that the internet banking site is well designed.
i been using internal banking for year(DBS and Maybank). i don't it a hassle at all.
It just took me less than a minute to key in the IB secure,pin and user id to transfer the money. it is more convenient than to queue for hours in bank or ATM
it's only DBS that does that to you
Actually, these additional 2FA challenges for monetary transactions are required by MAS. Banks, in an effort to stay compliant with the regulations, have to invest a lot of resources in implementing such changes.
Thus, do spare a thought for the banks as it is a thankless job. It is perhaps better to direct suggestions on 2FA implementation to MAS instead.
Not too long ago, DBS token only need to enter once for internet banking. Now, DBS token needs to enter as many times as the transactions you make.
May be this is just to "cover somebody's ass" in case of internet security lapses.
Same for the "water parade" in SAF.
as i mentioned earlier, these additional 2FA challenges at transactions level are mainly not banks' own initiatives. it is in response to MAS's internet banking security requirement.
although banks can choose to not follow the guidelines, i'm not sure what the consequences are. perhaps a rebuff from the regulator?
perhaps with additional activities on the token, banks will now have to replace them more frequent, thus spending more $. one day, they may decide to pass costs to consumers.
Post a Comment