{"id":264573,"date":"2010-02-02T06:00:00","date_gmt":"2010-02-02T11:00:00","guid":{"rendered":"tag:redtape.msnbc.com:\/\/e959b4fb2d029d46bfcad386171df4b3"},"modified":"2010-02-02T06:00:00","modified_gmt":"2010-02-02T11:00:00","slug":"study-73-use-bank-password-everywhere","status":"publish","type":"post","link":"https:\/\/mereja.media\/index\/264573","title":{"rendered":"Study: 73% use bank password everywhere"},"content":{"rendered":"<p class=\"MsoNormal\" style=\"MARGIN: 0in 0in 10pt\"><span style=\"COLOR: black; mso-themecolor: text1\"><font size=\"3\"><span style=\"FONT-SIZE: 13px; FONT-FAMILY: Verdana\">For years computer security experts have been preaching that users should never share the same password across their connected lives &#8212; at online banking sites, at Amazon, on their Web mail services, even on their cell phones. <o:p><\/o:p><\/span><\/font><\/span><\/p>\n<p class=\"MsoNormal\" style=\"MARGIN: 0in 0in 10pt\"><span style=\"COLOR: black; mso-themecolor: text1\"><font size=\"3\"><span style=\"FONT-SIZE: 13px; FONT-FAMILY: Verdana\">Apparently, most people ignore that advice. <o:p><\/o:p><\/span><\/font><\/span><\/p>\n<p class=\"MsoNormal\" style=\"MARGIN: 0in 0in 10pt\"><span style=\"COLOR: black; mso-themecolor: text1\"><font size=\"3\"><span style=\"FONT-SIZE: 13px; FONT-FAMILY: Verdana\">A new study by security firm Trusteer found that 73 percent of Web users take their online banking password and use it at other Web sites.<span style=\"mso-spacerun: yes\">&#0160; <\/span>And about half of all consumers utilize the same password and user name at online banking sites and other sites.<o:p><\/o:p><\/span><\/font><\/span><\/p>\n<p class=\"MsoNormal\" style=\"MARGIN: 0in 0in 10pt\"><span style=\"COLOR: black; mso-themecolor: text1\"><font size=\"3\"><span style=\"FONT-SIZE: 13px; FONT-FAMILY: Verdana\">&quot;I must say I was very surprised,\u201d said Amit Klein, chief technology officer of Trusteer. \u201cIt is surprisingly sad that such a large portion of users use their banking credentials at other sites. &#8230; It exposes those users to attacks that would otherwise be impossible. I thought that people would take banking credentials more seriously, but it turns out that in this digital age, this is not the reality.&quot;<\/span><\/font><\/span><\/p>\n<p class=\"MsoNormal\" style=\"MARGIN: 0in 0in 10pt\"><span style=\"COLOR: black; mso-themecolor: text1\"><font size=\"3\"><span style=\"FONT-SIZE: 13px; FONT-FAMILY: Verdana\"><o:p><\/o:p><\/span><\/font><\/span><\/p>\n<p class=\"MsoNormal\" style=\"MARGIN: 0in 0in 10pt\"><span style=\"COLOR: black; mso-themecolor: text1\"><font size=\"3\"><span style=\"FONT-SIZE: 13px; FONT-FAMILY: Verdana\">When consumers use the same password across multiple sites, hacking becomes trivially easy. If a criminal breaks into a smaller Web site &#8212; say a site created by a local grocery store &#8212; and grabs a cache of passwords, their next step is always the major banking Web sites.<span style=\"mso-spacerun: yes\">&#0160; <\/span>When you consider that 40 percent of U.S. consumers&#39; checking accounts are tied up in the four largest banks, odds are good that the stolen credentials will work for <s>in <\/s>one of them.<o:p><\/o:p><\/span><\/font><\/span><\/p>\n<p class=\"MsoNormal\" style=\"MARGIN: 0in 0in 10pt\"><span style=\"COLOR: black; mso-themecolor: text1\"><font size=\"3\"><span style=\"FONT-SIZE: 13px; FONT-FAMILY: Verdana\">Password overlap also creates an easy end run around sophisticated banking security technology, which is only as strong as the weakest site where the password is used. Banks might enforce strong password creation requirements, for example. But if a consumer uses a bank password <s>it<\/s> at a poorly defended small site, a hacker can break into the small site, steal the log-in information and essentially crack the bank&#39;s high-tech system.<o:p><\/o:p><\/span><\/font><\/span><\/p>\n<p class=\"MsoNormal\" style=\"MARGIN: 0in 0in 10pt\"><span style=\"COLOR: black; mso-themecolor: text1\"><font size=\"3\"><span style=\"FONT-SIZE: 13px; FONT-FAMILY: Verdana\">&quot;This is something that should be of huge concern both to banks and to users,&quot; said Klein.<o:p><\/o:p><\/span><\/font><\/span><\/p>\n<p class=\"MsoNormal\" style=\"MARGIN: 0in 0in 10pt\"><span style=\"COLOR: black; mso-themecolor: text1\"><font size=\"3\"><span style=\"FONT-SIZE: 13px; FONT-FAMILY: Verdana\"><img decoding=\"async\" alt=\"Small msnbc\" border=\"0\" class=\"asset asset-image at-xid-6a00d83451b0aa69e2012876fc4503970c \" src=\"http:\/\/onthescene.msnbc.com\/.a\/6a00d83451b0aa69e2012876fc4503970c-800wi\" style=\"FLOAT: left; MARGIN: 3px\" title=\"Small msnbc\" \/>Trusteer unearthed the data through use of its Rapport security software, which is designed to warn users when they are about to enter a critical banking password into a site where it doesn&#39;t belong &#8212; a phishing site, for example. The tool was used to examine the behavior of 4 million computer users during a 12-month period. During that span, the firm found that 73 percent used their online banking password on at least one non-financial Web site. <o:p><\/o:p><\/span><\/font><\/span><\/p>\n<p class=\"MsoNormal\" style=\"MARGIN: 0in 0in 10pt\"><span style=\"COLOR: black; mso-themecolor: text1\"><font size=\"3\"><span style=\"FONT-SIZE: 13px; FONT-FAMILY: Verdana\">And it didn\u2019t help much when the banks enforced strict password controls. When a bank allowed consumers to pick a user ID, 65 percent used it on other sites. When a bank assigned a customer ID, 42 percent used it at other sites and 42 percent used both the ID and the password on at least one other site.&#0160;<span style=\"mso-spacerun: yes\">&#0160;<\/span><\/span><\/font><\/span><\/p>\n<p class=\"MsoNormal\" style=\"MARGIN: 0in 0in 10pt\"><span style=\"COLOR: black; mso-themecolor: text1\"><font size=\"3\"><span style=\"FONT-SIZE: 13px; FONT-FAMILY: Verdana\"><span style=\"mso-spacerun: yes\"><strong>&#39;They don&#39;t think it&#39;s worth the trade off&#39;<br \/><\/strong><\/span><\/span><\/font><\/span><span style=\"COLOR: black; mso-themecolor: text1\"><font size=\"3\"><span style=\"FONT-SIZE: 13px; FONT-FAMILY: Verdana\">Last year, analyst firm Gartner released a survey that reported similar results. It said two-thirds of consumers use the same one or two passwords across all Web sites they access.<span style=\"mso-spacerun: yes\">&#0160; <\/span><o:p><\/o:p><\/span><\/font><\/span><\/p>\n<p class=\"MsoNormal\" style=\"MARGIN: 0in 0in 10pt\"><span style=\"COLOR: black; mso-themecolor: text1\"><font size=\"3\"><span style=\"FONT-SIZE: 13px; FONT-FAMILY: Verdana\">But Avivah Litan, who directed the Gartner survey, said that choice might not be as unreasonable &#8212; or as unsafe &#8212; as it seems.<o:p><\/o:p><\/span><\/font><\/span><\/p>\n<p class=\"MsoNormal\" style=\"MARGIN: 0in 0in 10pt\"><span style=\"COLOR: black; mso-themecolor: text1\"><font size=\"3\"><span style=\"FONT-SIZE: 13px; FONT-FAMILY: Verdana\">&quot;They are making a choice for convenience over security,&quot; she said. &quot;They are using a cost-benefit equation &#8230; and they don&#39;t want to try to remember 10 different passwords for everything they do. They don&#39;t think the trade-off is worth it, honestly.&quot;<o:p><\/o:p><\/span><\/font><\/span><\/p>\n<p class=\"MsoNormal\" style=\"MARGIN: 0in 0in 10pt\"><span style=\"COLOR: black; mso-themecolor: text1\"><font size=\"3\"><span style=\"FONT-SIZE: 13px; FONT-FAMILY: Verdana\"><a href=\"http:\/\/www.msnbc.msn.com\/id\/11605721\/ns\/business-personal_finance\/\"><img decoding=\"async\" alt=\"Herbbox\" border=\"0\" class=\"asset asset-image at-xid-6a00d83451b0aa69e20120a6792d57970c \" src=\"http:\/\/onthescene.msnbc.com\/.a\/6a00d83451b0aa69e20120a6792d57970c-800wi\" style=\"FLOAT: left; MARGIN: 4px\" title=\"Herbbox\" \/><\/a>While password sharing isn&#39;t a safe practice, Litan said, complicating your life with multiple passwords isn&#39;t exactly a cure-all.<o:p><\/o:p><\/span><\/font><\/span><\/p>\n<p class=\"MsoNormal\" style=\"MARGIN: 0in 0in 10pt\"><span style=\"COLOR: black; mso-themecolor: text1\"><font size=\"3\"><span style=\"FONT-SIZE: 13px; FONT-FAMILY: Verdana\">&quot;The truth is criminals steal your passwords lots of ways, such as recording keystrokes, and if they do that, it doesn&#39;t matter whether your password is 15 characters and unique or 7 characters and the same for every site. People have figured this out,&quot; she said.<o:p><\/o:p><\/span><\/font><\/span><\/p>\n<p class=\"MsoNormal\" style=\"MARGIN: 0in 0in 10pt\"><span style=\"COLOR: black; mso-themecolor: text1\"><font size=\"3\"><span style=\"FONT-SIZE: 13px; FONT-FAMILY: Verdana\">Using multiple passwords is a good idea, but Litan said it is important that consumers understand the risks that remain even if strong passwords are used.<o:p><\/o:p><\/span><\/font><\/span><\/p>\n<p class=\"MsoNormal\" style=\"MARGIN: 0in 0in 10pt\"><span style=\"COLOR: black; mso-themecolor: text1\"><font size=\"3\"><span style=\"FONT-SIZE: 13px; FONT-FAMILY: Verdana\">&quot;It is another lock on the door but a lock that is easily picked,&quot; she said. &quot;Still, it&#39;s always better to put as many blocks in the road you can.&quot;<o:p><\/o:p><\/span><\/font><\/span><\/p>\n<p class=\"MsoNormal\" style=\"MARGIN: 0in 0in 10pt\"><span style=\"COLOR: black; mso-themecolor: text1\"><font size=\"3\"><span style=\"FONT-SIZE: 13px; FONT-FAMILY: Verdana\">Large banks don&#39;t rely on simple user\/password combinations to identify users anymore, she added.<span style=\"mso-spacerun: yes\">&#0160; <\/span>Numerous technologies are used to prevent fraud through a strategy called &quot;layered security.&quot;<span style=\"mso-spacerun: yes\">&#0160; <\/span>Device fingerprinting of PCs is a key tool, she said. Web sites tag computer hardware by monitoring unique characteristics, such as exact processor speed or time and date settings. Sites that use device fingerprinting see fraud rates drop 15 to 20 percent, she said. <o:p><\/o:p><\/span><\/font><\/span><\/p>\n<p class=\"MsoNormal\" style=\"MARGIN: 0in 0in 10pt\"><span style=\"COLOR: black; mso-themecolor: text1\"><font size=\"3\"><span style=\"FONT-SIZE: 13px; FONT-FAMILY: Verdana\">Banks also look for suspicious behavior, such as attempted transfers to unusual accounts. Another hacker giveaway: clicks through Web sites that occur at high speed, showing an automated PC &#8212; and not a person &#8212; is attempting a transaction.<span style=\"mso-spacerun: yes\">&#0160; <\/span>Humans take, on average, about 10 seconds before they click &quot;confirm payment.&quot;<span style=\"mso-spacerun: yes\">&#0160; <\/span>Computers controlled by hackers racing through stolen login accounts barely wait at all. <o:p><\/o:p><\/span><\/font><\/span><\/p>\n<p class=\"MsoNormal\" style=\"MARGIN: 0in 0in 10pt\"><span style=\"COLOR: black; mso-themecolor: text1\"><font size=\"3\"><span style=\"FONT-SIZE: 13px; FONT-FAMILY: Verdana\">&quot;That&#39;s best-of-breed security,&quot; Litan said.<span style=\"mso-spacerun: yes\">&#0160; <\/span>&quot;If you as a bank are relying on passwords for security then you have a poor security system.&quot;<o:p><\/o:p><\/span><\/font><\/span><\/p>\n<p class=\"MsoNormal\" style=\"MARGIN: 0in 0in 10pt\"><span style=\"COLOR: black; mso-themecolor: text1\"><font size=\"3\"><span style=\"FONT-SIZE: 13px; FONT-FAMILY: Verdana\"><strong>RED TAPE WRESTLING TIPS<br \/><\/strong><\/span><\/font><\/span><span style=\"COLOR: black; mso-themecolor: text1\"><font size=\"3\"><span style=\"FONT-SIZE: 13px; FONT-FAMILY: Verdana\">It should be comforting to know that your user ID and password are not all that stands between a hacker and your money. Still, that&#39;s no reason to let your guard down. Your banking passwords should be handled with great care, and shouldn&#39;t be shared with other Web sites.<o:p><\/o:p><\/span><\/font><\/span><\/p>\n<p class=\"MsoNormal\" style=\"MARGIN: 0in 0in 10pt\"><span style=\"COLOR: black; mso-themecolor: text1\"><font size=\"3\"><span style=\"FONT-SIZE: 13px; FONT-FAMILY: Verdana\">And remember, many Web firms that store your critical personal information do not use best-of-breed security on their back end &#8212; meaning you are still at risk.<span style=\"mso-spacerun: yes\">&#0160; <\/span>A criminal who stole your Facebook credentials <a href=\"http:\/\/redtape.msnbc.com\/2009\/10\/on-the-web-its-not-always-easy-to-know-who-your-friends-are-mistakes-in-judgment-can-be-very-costly--internet-imposters.html\">could easily wreak havoc with your life<\/a>, so protect those accounts, too. <o:p><\/o:p><\/span><\/font><\/span><\/p>\n<p class=\"MsoNormal\" style=\"MARGIN: 0in 0in 10pt\"><span style=\"COLOR: black; mso-themecolor: text1\"><font size=\"3\"><span style=\"FONT-SIZE: 13px; FONT-FAMILY: Verdana\">Klein concedes that the vast majority of computer users will never create unique user\/password combinations for all their sites. As a more practical goal, he recommends maintaining three &quot;families&quot; of passwords &#8212; one for critical financial sites, a second for sites that store your personal information, and a third for generic log-ins.<o:p><\/o:p><\/span><\/font><\/span><\/p>\n<p class=\"MsoNormal\" style=\"MARGIN: 0in 0in 10pt\"><span style=\"COLOR: black; mso-themecolor: text1\"><font size=\"3\"><span style=\"FONT-SIZE: 13px; FONT-FAMILY: Verdana\">&quot;And you don\u2019t want to mix those passwords,&quot; he said. <\/span><\/font><\/span><\/p>\n<p class=\"MsoNormal\" style=\"MARGIN: 0in 0in 10pt\"><span style=\"COLOR: black; mso-themecolor: text1\"><font size=\"3\"><span style=\"FONT-SIZE: 13px; FONT-FAMILY: Verdana\"><\/span><\/font><\/span>&#0160;<\/p>\n<p class=\"MsoNormal\" style=\"MARGIN: 0in 0in 10pt\"><span style=\"COLOR: black; mso-themecolor: text1\"><font size=\"3\"><span style=\"FONT-SIZE: 13px; FONT-FAMILY: Verdana\"><span style=\"FONT-SIZE: 14px; MARGIN: 0in 0in 10pt; FONT-FAMILY: Verdana\"><span style=\"FONT-SIZE: 12pt; LINE-HEIGHT: 115%\"><span style=\"COLOR: black; mso-themecolor: text1\"><font size=\"3\"><span style=\"FONT-SIZE: 12px; FONT-FAMILY: Verdana\"><span style=\"FONT-SIZE: 12px; COLOR: black; FONT-FAMILY: Verdana\"><span style=\"FONT-SIZE: 13px; FONT-FAMILY: Verdana\"><span style=\"COLOR: black; mso-themecolor: text1\"><span style=\"FONT-FAMILY: Verdana\"><span style=\"FONT-FAMILY: Verdana\"><span style=\"FONT-FAMILY: arial, helvetica, clean, sans-serif\"><strong><span style=\"FONT-SIZE: 14px; FONT-FAMILY: Arial\"><font face=\"Verdana\">Become a&#0160;<\/font><\/span><\/strong><a href=\"http:\/\/www.facebook.com\/pages\/Bob-Sullivan\/78714223105?_fb_noscript=1\" style=\"CURSOR: pointer; COLOR: blue; text-decoration: underline\" ><strong><span style=\"FONT-SIZE: 14px; FONT-FAMILY: Arial\"><font face=\"Verdana\">Red Tape Chronicles Facebook fan<\/font><\/span><\/strong><\/a><font face=\"Verdana\">&#0160;<span style=\"FONT-SIZE: 14px; FONT-FAMILY: Arial\"><strong>or follow me at <\/strong><a href=\"http:\/\/twitter.com\/RedTapeChron\"><strong>http:\/\/twitter.com\/RedTapeChron<\/strong><\/a><\/span><\/font><\/span><\/span><\/span><\/span><\/span><\/span><\/span><\/font><\/span><span style=\"FONT-SIZE: 9px; FONT-FAMILY: Verdana\"><\/span><\/span><\/span><o:p><\/o:p><\/span><\/font><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>For years computer security experts have been preaching that users should never share the same password across their connected lives &#8212; at online banking sites, at Amazon, on their Web mail services, even on their cell phones. Apparently, most people ignore that advice. A new study by security firm Trusteer found that 73 percent of [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[],"class_list":["post-264573","post","type-post","status-publish","format-standard","hentry","category-news"],"_links":{"self":[{"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/posts\/264573","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/comments?post=264573"}],"version-history":[{"count":0,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/posts\/264573\/revisions"}],"wp:attachment":[{"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/media?parent=264573"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/categories?post=264573"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mereja.media\/index\/wp-json\/wp\/v2\/tags?post=264573"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}