ANZ to replace online banking system

update The Australia and New Zealand Banking Group (ANZ) will replace its online banking system later this year in an attempt to improve security and add new functionality.

An ANZ spokesperson said on Thursday that the bank plans to push the new service live by the middle of this year.

"The whole system is going to be replaced in a couple of months. The first implementation will be a mirror of our current functionality -- as we stabilise the new system. We will then look to add functionality. It is a bit early to say when it will hit but certainly in the next three or four months," the spokesperson told ZDNet Australia .

He refused to release any further details about the project.

ANZ's online banking site was criticised earlier this week by Internet security firm SurfControl. The company highlighted weaknesses in the way ANZ has made use of JavaScript because it could help criminals create authentic looking copies of the Web site for use in phishing attacks.

Charles Heunemann, general manager of SurfControl APAC, on Wednesday highlighted the same vulnerability in both ANZ and rival Westpac's online banking sites.

"We had a close look at a number of major banks. The ANZ and Westpac both have some basic password validation, you can easily download most of the JavaScript code for the main banks without too much trouble.... From this it would be very easy... to create a phishing Web site that behaved in exactly the same way as the genuine one," Heunemann told ZDNet Australia .

According to Heunemann, the code could be used in conjunction with a phishing kit to create fraudulent sites.

"By not locking this down the banks just make it a little bit easier for criminals to ply their trade,' added Heunemann.

Paul Jennings, Westpac's head of channel and systems management, told ZDNet Australia  that the bank is investigating the JavaScript issue.

"Westpac takes customer security very seriously, and as a part of this, we are enhancing our fraud prevention through continuous process improvement. The issue that has been raised has been taken into account, and will be actively monitored," said Jennings.

Westpac is is already under pressure to improve its online bank's log-in interface after customers slated the new on-screen keypad.

In response to a ZDNet Australia  news story in February describing the introduction of Westpac's on-screen keypad, users of the system have been critical of the keypad's functionality and even suggested it could make logging onto the online services less secure.

Typical comments from ZDNet Australia  readers are summed up by someone identifying themselves as Ross: "When I use the ATM I cover the buttons with my hand for security. If I can't cover the monitor for security from prying eyes, how can I use Westpac's services in public, at work or overseas in an Internet cafe?"

Westpac's Jennings said the tool was designed purely to reduce the risk from keyloggers stealing customers' passwords: "The new sign on page does not attempt to prevent a standard phishing attack, nor is it designed to comprehensively mitigate all potential avenues of attack, but rather to help mitigate the risk presented by generic keylogging trojans deployed on customer PCs."

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

ZDNet Australia Live

A user from Brisbane measured 3631kbps @ Broadband Speedtest.

3 minutes ago, Click here to find out how fast your internet speed is.

Gadget News In the world of consumer electronics, smart = green http://ow.ly/18WZ5x

RT @hyken: Good article on CEM: Building brands and revenues: Changing attitudes on customer experience http://tinyurl.com/2dm8uap

Apple lets in Java and Flash; should Android be worried? | ZDNet http://lnkd.in/jJu6MX

RT @ZDNet: Complete coding for NHIN Direct may be done this month http://zd.net/9GB3C8

Nook for Android updated again, now with a better reading experience http://bit.ly/dpCwbD

OSS Security (ggl): Apple lets in Java and Flash; should Android be worried? - ZDNet (blog): http://bit.ly/ba1Rb3

Download: neoSearch 2.12 http://bit.ly/an2KA8

Two positive smart meter progress reports: ... had this to say in the press release: “The OPOWER energy efficiency... http://bit.ly/a2tqe3

games: Medal of Honor game banned from US military bases and why that might be ... - ZDNet (blog): Telegraph.co.uk... http://bit.ly/auJK5w

RT @hyken: Good article on CEM: Building brands and revenues: Changing attitudes on customer experience http://tinyurl.com/2dm8uap

An interesting point of view, but the last thing we need is more middlemen in the provision of internet services via the NBN. More middle...

28 minutes ago by Zerophitus on Dodo thinks NBN wholesale

Vogel's intros 'Mount & Cover' system for iPad anywhere, including cars: By Rachel King | September 10, 2010, 7:05... http://bit.ly/auWLx8

BT details expansion plans in Asia http://ow.ly/2Cg6Z

You're already lugging around, at the minimum, a "netbook", and all you want to do is update your diary--who in their right m...

2 hours ago by Treknology on NSW govt looks into the cloud

Similar products with the same functionality are already in use in Australia, one of which was demonstrated to me just this week; rather ...

3 hours ago by crashdr on Corporate social spy tool to come to Aus?

@ "far as i am aware the only country that has agreement's in place with security vendor's is the USA,". Check out the U...

8 hours ago by jtan163 on NSW Police to get hacking powers

By your "first storm" logic, can't the same be applied to wireless access points causing multiple client failure? Wouldn'...

8 hours ago by xtatic on Much cheaper NBN wins it by a whisker

... Zdnet speedtest just gave me a reading of 61,874 kbps - fastest in the world!! Must be a mistake somewhere...

9 hours ago by jahmon on Broadband Speedtest

Pretty sure they are going to hang it like foxtel in suburbs with poles. only those new subdivisions in McMansionville will get dug up. ...

9 hours ago by walmillard on NBN roll-out rejig adds no cost: Conroy

walmillard, the election is over. The liberal party lost. You can stop the spin and fear mongering about the cost making out as if the wh...

9 hours ago by JimmyJack on Much cheaper NBN wins it by a whisker

Corporate social spy tool to come to Aus? - Security - News http://bit.ly/ds4Nkt

We are talking about one of the most important items in terms infrastructor since the copper telephone system was built. Telecommuncat...

9 hours ago by The Macross on Much cheaper NBN wins it by a whisker

It will be more relaible until the first storm. Stringing a phone cable from a pole is a solution rooted deep in the 18th century, Or is ...

9 hours ago by walmillard on Much cheaper NBN wins it by a whisker

Isn't this exactly what Conroy is doing, spending $43Bn on whatever he wants....

10 hours ago by Scott W on NBN roll-out rejig adds no cost: Conroy

Announcing a maximum cost does not equate to any form of budgetting one would expect from any professional Project Manager, particularly ...

10 hours ago by Scott W on NBN roll-out rejig adds no cost: Conroy

You write "Labor leader Julia Gillard is now set to become Australia's first elected female Prime Minister.." Politics Studie...

10 hours ago by Kneil on Gillard slides in on back of NBN

RT @blackbobs: Gottliebsen: Real cost to Gov of #nbn considerbaly less than $43 milliard http://tinyurl.com/2wvjpv2 #ausvotes #ozcot

RFID to bring alpine traffic relief http://bit.ly/cwwpbg

RFID and Alpine tourism; another interesting application for #rtls via Aussie gov't grant: http://bit.ly/cwwpbg

RT: @zdnetaustralia: RFID chips to manage traffic flow in Victoria's snow fields http://bit.ly/cQ16Kh

AFP has backed a proposal for a controversial data retention scheme that aims to catch cybercriminals http://ow.ly/2C3PF

Gobiernos locales de Australia negocian provisión de servicios de telecomunicaciones, soporte IPv6 está en cláusulas http://bit.ly/9gTmCC

RT @zdnetaustralia: Hostech nabs another company this year, adding Netrics to its long list of company buyouts http://bit.ly/d6vFlV

Cash-Strapped Start-ups Asked to Pitch Big:... http://fb.me/sruhRYki

RT @zdnetaustralia: Telstra completes the majority of a $280m fibre-optic broadband roll-out for NSW DET http://bit.ly/aBmMVm

Internode's Simon Hackett says his company will lose customers to BigPond because of wholesale port costs. http://bit.ly/cDosCu

NBN roll-out ramps up post election and rejig adds no cost: Conroy http://bit.ly/cnNdET

NBN roll-out rejig adds no cost: Conroy http://bit.ly/d4LIDI via @zdnetaustralia #NBN #openinternet

photos of the NBN rollout - http://bit.ly/dy7vrC

Telecoms giant BT is hiring 300 staff across the Asia Pacific region http://bit.ly/bKRHRD http://fb.me/GHfzPjUU

Check out Google Instant search. They say it's going to make searching easier, but is it distracting? Let us know... http://fb.me/DIPEBhCz

RT @fugazied: Fibre in Tasmania #NBN http://www.zdnet.com.au/houses-linked-up-in-tassie-nbn-photos-339304569.htm?omnRef=NULL

This story has been liked 5 times in the last 24 hours!

TechLines 6: email is a jack of all trades http://zdnet.com.au/339305877/ - so I have too much email because I have no process???

RT @zdnetaustralia: Telstra completes the majority of a $280m fibre-optic broadband roll-out for NSW DET http://bit.ly/aBmMVm

Realestate.com.au adopts cloud email http://zdnet.com.au/339305876/

Internode: leave us, but it's not our fault http://zdnet.com.au/339305865/

Internode: leave us, but it's not our fault http://zdnet.com.au/339305865/

really? i'll believe it when i see it ... "ACTA warms to ISPs?" http://j.mp/bcu7uh

Information security systems failed to prevent a Police analyst from leaking information on raids to bikie gang? http://ow.ly/2AYYA

Qld Uni start-up scores MRI grant: Magnetic resonance imaging (MRI) research is about to get another boost in Quee... http://bit.ly/bFw6fk