Wednesday, April 28, 2010

Password in online banking

A password is a secret word or string of characters that is used for

authentication, to prove identity or gain access to a resource (example: an access code is a type of password). The password must be kept secret from those not allowed access.

The use of passwords is known to be ancient. Sentries would challenge those wishing to enter an area or approaching it to supply a password or watchword. Sentries would only allow a person or group to pass if they knew the password. In modern times, user names and passwords are commonly used by people during a log in process that controls access to protected computer operating systems, m

obile phones, cable TV decoders, automated teller machines (ATMs), etc. A typical computer user may require passwords for many purposes: logging in to computer accounts, retrieving e-mail from servers, accessing programs, databases, networks, web

sites, and even reading the morning newspaper online.

Despite the name, there is no need for passwords to be actual words; indeed passwords which are not actual words may be harder to guess, a desirable property. Some passwords are formed from multiple words and may more accurately be called a passphrase. The term passcode is sometimes used when the secret information is purely numeric, such as the personal identification number (PIN) commonly used for ATM access. Passwords are generally short enough to be easily memorized and typed.

For the purposes of more compellingly authenticating the identity of one computing device to another, passwords have significant disadvantages (they may be stolen, spoofed, forgotten, etc.) over authentications systems relying on cryptographic protocols, which are more difficult to circumvent.

Contents

  • 1 Easy to remember, hard to guess
  • 2 Factors in the security of a password system
    • 2.1 Rate at which an attacker can try guessed passwords
    • 2.2 Form of stored passwords
    • 2.3 Methods of verifying a password over a network
      • 2.3.1 Simple transmission of the password
      • 2.3.2 Transmission through encrypted channels
      • 2.3.3 Hash-based challenge-response methods
      • 2.3.4 Zero-knowledge password proofs
    • 2.4 Procedures for changing passwords
    • 2.5 Password longevity
    • 2.6 Number of users per password
    • 2.7 Design of the protected software
  • 3 Password cracking
    • 3.1 1998 incident
  • 4 Alternatives to passwords for access control
  • 5 Website password systems
  • 6 History of passwords
  • 7 See also
  • 8 References
  • 9 External links

Feature of online banking

Electronic bill payment is a feature of online banking, similar in its effect to a giro, allowing a depositor to send money from his demand account to a creditor or vendor such as a public utility or a department store to be credited against a specific account. The payment is optimally executed electronically in real time, though some financial institutions or payment services will wait until the next business day to send out the payment. The bank can usually also generate and mail a paper cheque or banker's draft to a creditor who is not set up to receive electro

nic payments.

Electronic billing can also feature invoices sent by e-mail or viewed on a secure web site (with notices of new invoices being sent by e-mail).

Most large banks also offer various convenience features with their electronic bill payment systems, such as the ability to schedule payments in advance to be made on a specified date, the ability to manage payments from any computer with a web browser, and various options for searching one's recent payment history: when did I last pay Company X? To whom did I make my most recent payment? In many cases one can also integrate the electronic payment data with accounting or personal finance software.

Peer-to-peer payment systems are extremely popular. The best and most widely known example is PayPal. PayPal allows you to pay for just about anything online as long as the seller also has a PayPal account. Many online sellers use PayPal such as 75% of eBay sellers, overstock.com,

ritzcamera.com, and Walgreens.com (Traver, 2004).

Pal is also sometimes used to pay for personal debts in situations where both parties have an account.

Electronic bill payment and presentment (EBPP) includes an electronic bill payment system (EBPS). Electronic bill payment and presentment is “the electronic bill presentment to the consumer and the electronic initiation of payment by the consumer” (Alexandria Andreeff). This was done completely by postal mail before the internet. Sending bills electronically via the internet is much faster and cheaper though. Although this technology was available before December in 1998, only 26.2% of U.S. households had internet access at that time according to the U.S. Department of Commerce in 2000 (Alexandria Andreeff). By August 2000, electronic bill

payment and presentment systems started to dramatically increase in popularity because 41.5% of U.S. households had internet access by then according to the U.S. Department of Commerce in 2000 (Alexandria Andreeff). In this model, the one who is charging the consumer, notifies the customer (usually) through e-mail (Alexandria Andreeff). The customer is then responsible to log on to the biller’s website to pay the bill (Alexandria Andreeff).

Online saving accountant in banking


Some financial institutions offer online-only savings accounts. These usually pay higher interest rates and sometimes carry higher security restrictions. Those with high interest rates have risen in popularity with the rise of the internet.

One time password in online banking




A one-time password (OTP) is a password that is only valid for a single login session or transaction. OTPs avoid a number of shortcomings that are associated with traditional (static) passwords. The most important shortcoming that is addressed by OTPs is that, in contrast to static passwords, they are not vulnerable to replay attacks. This means that, if a potential intruder manages to record an OTP that was already used to log into a service or to conduct a transaction, he will not be able to abuse it since it will be no longer valid. On the downside, OTPs cannot be memorized by human beings. Therefore they require additional technology in order to work.

Contents

OTPs in the context of online banking


paper-based OTP web-site login

In some countries OTPs that are used in the context of online banking. In some of these systems, the bank sends to the user a numbered list of OTPs that are printed on paper. For every online transaction, the user is required to enter a specific OTP from that list. In Germany, those OTPs are typically ca

lled TANs (for 'transaction authentication numbers'). Some banks even dispatch such TANs to the user's mobile phone via SMS, in which case they are called mTANs (for 'mobile TANs').

Telephone online ban king

Telephone banking is a service provided by a financial institution, which

allows its customers to perform transactions over the telephone.

Most telephone banking services use an automated phone answering system with phone keypad response or voice recognition capability. To guarantee security, the customer must first authenticate through a numeric or verbal password or through security questions asked by a live representative (see below). With the obvious exception of cash withdrawals and deposits, it offers virtually all the features of an automated teller machine: account balance information and list of latest transactions, electronic bill payments, funds transfers between a customer's accounts, etc.

Usually, customers can also sp

eak to a live representative located in a call

centre or a branch, although this feature is not always guaranteed to be offered 24/7. In addition to the self-service transactions listed earlier, telephone banking representatives are usually trained to do what was traditionally available only at the branch: loan applications, investment purchases and redemptions, chequebook orders, debit card replacements, change of address, etc.

Banks which operate mostly or exclusively by telephone are known as

mobile online banking in world

Mobile banking has come in handy in many parts of the world with little or no Infrastructure development,

especially in remote and rural areas. This part of the mobile commerce is also very popular in countries where most of their population is unbanked. In most of these places banks can only be found in big cities and customers have to travel hundreds of miles to the nearest bank.
Countries like Sudan, Ghana and South Africa received this new commerce very well.
In Latin America countries like Uruguay, Paraguay, Argentina, Brazil, Venezuela, Colombia, Guatemala and recently Mexico started with a huge success.
In Colombia was released with Redeban.
In Iran banks like Parsian, Tejarat, Mellat, Saderat, Sepah, edbi and bankmelli offer this service. Guatemala have the support of Banco industrial.
Mexico released the mobile commerce with Omnilife, Bancomer and a private company(MPower Ventures). Kenya's Safaricom (Part of the Vodafone Group) has had the very popular M-Pesa