Community
Reaction to the article of TowerGroup
https://www.finextra.com/fullstory.asp?id=20137
Regarding the usage of "traditional" account information (name, address, birthdate...) as authentication factor, I guess we can say that, at least in Finextra Community, we know that this type of data has been compromised long before being put on the spot by the successive data breaches.
Even before the series of data breaches, this type of "traditional" information was already easily available on the web via the social networks and deep web search tools. There is always a trace somewhere even if you never enter your info on a website.
Concerning the recommendation of using knowledge-based authentication and one-time passwords delivered via SMS, I could not agree more.
The type of information that needs to be used for the authentication has to be dynamic, and the process itself must include an out-of-band channel to be insensitive to the latest hacking techniques.
This content is provided by an external author without editing by Finextra. It expresses the views and opinions of the author.
Elena Vysotskaia Founder & CEO at Astra Global
03 January
Joris Lochy Product Manager at Intix | Co-founder at Capilever
31 December
Nkahiseng Ralepeli VP of Product: Digital Assets at Absa Bank, CIB.
30 December
Carlo R.W. De Meijer Owner and Economist at MIFSA
Welcome to Finextra. We use cookies to help us to deliver our services. You may change your preferences at our Cookie Centre.
Please read our Privacy Policy.