1 Web banking: It's time to write down your password - Security - News - ZDNet Australia

Web banking: It's time to write down your password

Get Adobe Flash player

Banks should stop forcing customers to create long, alphanumeric passwords because they can't protect against today's threats, according to AT&T computing researcher William Cheswick.

Speaking at AusCERT 2008 on the Gold Coast this week, Cheswick told delegates to stop inflicting staff and consumers with old-fashioned rules on password management, including advising consumers not to write them down or imposing strict rules about what characters can be used.

Requiring passwords to be at least seven characters long, but not more than 15, that are case sensitive with at least one number but no spaces, is simply "arcane password fascism", said Cheswick.

"The problem is of course is that people violate [these rules]. They're going to write it down ... they have to get their jobs done," he said.

"It is simply poor engineering to expect people to create and remember passwords that computers cannot guess and in a reasonable amount of time."

"My biggest complaint is that we're insisting on very strong passwords, but we're not getting strong security for those passwords," Cheswick told ZDNet.com.au after his keynote.

Many password rules imposed on staff and consumers today were drawn from a standard written in the 1980s, called Federal Information Processing Standards (FIPS) 112 — the US standard for password usage.

"The rules that people made those up under — we don't face those threats today," he told ZDNet.com.au. "There wasn't much of an Internet, you didn't have Russian spies trying to ex-filtrate your data. There were different kinds of attacks," he added.

As a result, Cheswick believes banks should relax the rules on passwords for customers, since they typically have to remember several passwords to manage their daily affairs — and for simplicity's sake, often use the same password across several systems.

"For the guys at the bank, they can ease up on their rules a lot. Why can they ease up on their rules? Because you don't need a strong password. Why don't you need a strong password? Because you're only making a few guesses," he said.

Typically after three incorrect guesses an ATM will destroy the card and failed attempts to log-in to an online bank account often produces a similar result. However, Cheswick said password stealing keyloggers pose a new problem, which only reinforces why writing down passwords is not such a threat today — that rule was created when someone physically looking over your shoulder was a greater threat than malware installed on a computer.

Cheswick encouraged the move by Australian banks to adopt two-factor authentication technologies.

"When it counts, you should use two-factor authentication — something you have and something you know. A third factor is usually something you are, which is biometrics, which is ok, but I'm not a fan of it," he said.

For people that have trouble remembering passwords, Cheswick recommended using the same password across several accounts, and writing them down, adding however, that accounts should be graded according to low, medium and high levels of security.

"I have a password I don't care about. You log into the New York Times, and they want you to have a password, and I don't care if someone steals my New York Times' password. There's one password I use for all those accounts. Then there are the accounts that are important to me such as Amazon.com, but if you got them, then you wouldn't be able to drain my bank account ... it's not the end of the world. Then there's bank accounts, and stock account management, where if you got in you might be able to leave me a pauper. But even then you only get three or four chances," he said.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

Quick Poll

What is the biggest data management challenge in your organisation?

ZDNet Australia Live

Internet won't always be anonymous: ITU http://t.co/mSlVBG3K

RT @zdnetaustralia Hey Buddy! Did you Follow @smo4s #FF #FollowFriday #teamfollow #teamfollowback #500ADay

Why a $25 computer means revolution: By Nick Heath, TechRepublic on February 10th, 2012 (7 hours ago) In the las... http://t.co/gELzDmqd

What is the exact proportion when you say “many ICT staffers are finding themselves re-employed as contractors”? I’m guessing it i...

30 minutes ago by lebelinoz on Firing and rehiring doesn't make sense

The New York Time article and subsequent CBS piece where cheap sensationalistic fluff aimed at the less educated. I suggest a follow-up ...

40 minutes ago by 58kiwi on Aussie activists call for 'ethical iPhone'

@ashleybcox Std accounting practise for returning investments to be off-budget. http://t.co/TwbdOWXi

Sadly, data privacy and protection seems to count for nothing in the minds of legislators and politicians in this country.

42 minutes ago by Yoda7 on Lax data privacy laws hurt Australia

Please enlighten us all, what is the mark?

46 minutes ago by omega on Satellite-hating Libs blow policy free kick

IMAX replaces world's largest screen: pics: Go behind the scenes with our photo tour, and find out why the CEO o... http://t.co/eKH1lHfH

Take an early tour of Windows 8's Office 15: I see the significance of the NBN as being equal to building railwa... http://t.co/yw32J0ah

Twitter now available in emergencies with satellite providers http://t.co/yHD7oY0q

You're spot on with your comment re: hollywood. I'd bet my dogs they had HD 5.1 multi-angle video footage of the whole thing (not yet re...

58 minutes ago by Powerpup on From copyright to a world without borders

Have a look at powershop.co.nz - we definitely save money overall, and have the abillity to purchase discounted power in advance and see ...

1 hour ago by Powerpup on NZ energy prices fall, websites thanked

"The number of people that believe they understand security, but don't, far exceed the number of people that do," http://t.co/rYMdWA0P

Who knew they had online shopping? These guys dont have a clue. Just bought a toaster for $67 from Appliances Online. Same one with ...

1 hour ago by xBeanie on IBM to fix David Jones' online sales

I see the significance of the NBN as being equal to building railways, ports and surfacing the roads. The efficiencies in the economy of ...

1 hour ago by H.Digitalis on Satellite-hating Libs blow policy free kick

David, your article is so poorly written and one sided that either you're incompetent or your post is a troll to gain plenty of hits for ...

1 hour ago by tjb on Satellite-hating Libs blow policy free kick

The future of browsing...[video] http://t.co/HBbD8vo1

More change at the top for RIM http://t.co/xJEYc6WZ

As usual, the libs miss the point and show their ignorance. Wonder how their rusted-on RARA constituency will react? http://t.co/jep0yDrA

RT @dmbieg: The end of an era as Kodak discontinues camera business http://t.co/dl7yyd7t

Why a $25 computer means revolution: ... In the last 60 years, the computer has evolved from a machine that fill... http://t.co/qrAGAXbb

And let's not forget that the sky is probably gunna fall in so there's another pile of cash down the drain. And the NBN modem sitting o...

2 hours ago by omega on Satellite-hating Libs blow policy free kick

Glad you asked that redrover, I was going to ask that myself.

2 hours ago by clive49 on Satellite-hating Libs blow policy free kick

David, the distraction is Turnbull's incompetence. Turnbull now believes he can predict 30 years into the future because he believes that...

2 hours ago by omega on Satellite-hating Libs blow policy free kick

Yeah, and let's not forget the $4000 in services costs per site to get it in. Thats $10K. The we have 20% great big new carbon tax, that...

2 hours ago by Ocker on Satellite-hating Libs blow policy free kick

Are your children, grandchildren and great grandchildren 'fetching emails' are they? For every 1 dollar spent on the NBN, Australian tax...

2 hours ago by omega on Satellite-hating Libs blow policy free kick

RT @zdnetaustralia: Watch as the world's largest screen, IMAX, be replaced http://t.co/b0G2rPle

Guys if a product can be sold cheaper after the 10%GST then this over time will change our current approach to running a business. Additi...

2 hours ago by value spotters on Shopping online: so much more than GST

What I've been wondering is if NBN Co can lease the excess capacity on the satellites to other players in the SE Asia/Pacific region and ...

2 hours ago by redrover on Satellite-hating Libs blow policy free kick

I think David hit the nail on the head pretty much. Even as a Liberal supporter, I'll vote Labor just to get the continued investment int...

3 hours ago by GrahamK on Satellite-hating Libs blow policy free kick

The MaxJu5t1c3 Daily is out! http://t.co/uONV9w5S ▸ Top stories today via @zdnetaustralia

Thats why i had to watch FTA TV last night, grrrr RT @zdnetaustralia: Optus fibre cable cut in ACT: http://t.co/zDu6vTE4

RT @timbo2002: IBM to bring David Jones into the 90s r.e. it's online & ecommerce capabilities: http://t.co/lHv2ZInA

Take an early tour of Windows 8's Office 15 http://t.co/Jr1WAXhG via @zdnetaustralia

I live in suburban Melbourne, not within 3km of an exchange. On a good day my Internet is about 3.8Mbps. It used to be closer to 5 but as...

3 hours ago by GregE on Satellite-hating Libs blow policy free kick

RT @Asher_Wolf: UK to announce website blocking proposals “imminently”
http://t.co/WlByuQtG #censorship

...satellite isn't a solution for everyone. VOiP telecom is big here in North America, I use Vonage as my primary phone, and the huge ban...

3 hours ago by MortimerSnerd on Satellite-hating Libs blow policy free kick

RT @timbo2002: IBM to bring David Jones into the 90s r.e. it's online & ecommerce capabilities: http://t.co/lHv2ZInA

AFL fights Optus for its copyright - ZDNet Australia http://t.co/TK4ml3Jg

Satellite-hating Libs blow policy free kick http://t.co/PF5S8dgP

RT @Asher_Wolf: UK to announce website blocking proposals “imminently”
http://t.co/WlByuQtG #censorship

They're the cialis across them reflected been, but though said. The cheap cialis. Kamagra toward uk requiring because cliffs not cheap yo...

4 hours ago by solleyinceshy on Broadband Speedtest

RT @Asher_Wolf: UK to announce website blocking proposals “imminently”
http://t.co/WlByuQtG #censorship

RT @NewtonMark: UK #sopa. RT @Asher_Wolf: UK to announce website blocking proposals “imminently”
http://t.co/LdVdlLkh #censorship

UK to announce website blocking proposals “imminently”
http://t.co/WlByuQtG #censorship

RT @Asher_Wolf: UK to announce website blocking proposals “imminently”
http://t.co/WlByuQtG #censorship

RT @Asher_Wolf: UK to announce website blocking proposals “imminently”
http://t.co/WlByuQtG #censorship

UK #sopa. RT @Asher_Wolf: UK to announce website blocking proposals “imminently”
http://t.co/LdVdlLkh #censorship

RT @NewtonMark: UK #sopa. RT @Asher_Wolf: UK to announce website blocking proposals “imminently”
http://t.co/LdVdlLkh #censorship

[plug] Satellite-hating Libs blow #NBN free kick http://t.co/PwDfr7BR. @TurnbullMalcolm policy benefits if birds deliver 12Mbps to 2m homes

IT jobs update | One podcast with the lot - ZDNet Australia - One podcast with the lotZDNet AustraliaWe ask if the I... http://t.co/01f2SzCV

@engochick ahh ok. Keep up the good work. I really enjoy the articles on @zdnetaustralia

RT @zdnetaustralia: Telstra will move 4.2 million BigPond customers onto Microsoft's Windows Live email service: http://t.co/kcGsdC0m

FBI releases Steve Jobs' background check: What's inside http://t.co/eYGD57Ba

This story has been voted 20 times in the last 24 hours!

3 days ago, Symantec confirms hacker extortion

This story has been voted 10 times in the last 24 hours!

3 days ago, Symantec confirms hacker extortion

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar