Web banking: It's time to write down your password

Get Adobe Flash player

Banks should stop forcing customers to create long, alphanumeric passwords because they can't protect against today's threats, according to AT&T computing researcher William Cheswick.

Speaking at AusCERT 2008 on the Gold Coast this week, Cheswick told delegates to stop inflicting staff and consumers with old-fashioned rules on password management, including advising consumers not to write them down or imposing strict rules about what characters can be used.

Requiring passwords to be at least seven characters long, but not more than 15, that are case sensitive with at least one number but no spaces, is simply "arcane password fascism", said Cheswick.

"The problem is of course is that people violate [these rules]. They're going to write it down ... they have to get their jobs done," he said.

"It is simply poor engineering to expect people to create and remember passwords that computers cannot guess and in a reasonable amount of time."

"My biggest complaint is that we're insisting on very strong passwords, but we're not getting strong security for those passwords," Cheswick told ZDNet.com.au after his keynote.

Many password rules imposed on staff and consumers today were drawn from a standard written in the 1980s, called Federal Information Processing Standards (FIPS) 112 — the US standard for password usage.

"The rules that people made those up under — we don't face those threats today," he told ZDNet.com.au. "There wasn't much of an Internet, you didn't have Russian spies trying to ex-filtrate your data. There were different kinds of attacks," he added.

As a result, Cheswick believes banks should relax the rules on passwords for customers, since they typically have to remember several passwords to manage their daily affairs — and for simplicity's sake, often use the same password across several systems.

"For the guys at the bank, they can ease up on their rules a lot. Why can they ease up on their rules? Because you don't need a strong password. Why don't you need a strong password? Because you're only making a few guesses," he said.

Typically after three incorrect guesses an ATM will destroy the card and failed attempts to log-in to an online bank account often produces a similar result. However, Cheswick said password stealing keyloggers pose a new problem, which only reinforces why writing down passwords is not such a threat today — that rule was created when someone physically looking over your shoulder was a greater threat than malware installed on a computer.

Cheswick encouraged the move by Australian banks to adopt two-factor authentication technologies.

"When it counts, you should use two-factor authentication — something you have and something you know. A third factor is usually something you are, which is biometrics, which is ok, but I'm not a fan of it," he said.

For people that have trouble remembering passwords, Cheswick recommended using the same password across several accounts, and writing them down, adding however, that accounts should be graded according to low, medium and high levels of security.

"I have a password I don't care about. You log into the New York Times, and they want you to have a password, and I don't care if someone steals my New York Times' password. There's one password I use for all those accounts. Then there are the accounts that are important to me such as Amazon.com, but if you got them, then you wouldn't be able to drain my bank account ... it's not the end of the world. Then there's bank accounts, and stock account management, where if you got in you might be able to leave me a pauper. But even then you only get three or four chances," he said.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

Tech Blueprint

ZDNet Australia Live

Android fragmentation steers Vic Health: Fragmentation issues in Android were a key concern for the Victorian De... http://t.co/HLdurfS5

Mining the social data stream for deeper customer insight | via @ZDNet http://t.co/x4xouPQh)

Android fragmentation steers Vic Health http://t.co/A6SJkfJw

Android fragmentation threw a spanner into Victorian Health's app strategy: http://t.co/4pkmnkMB ^LH

Android fragmentation steers Vic Health - Software - News - ZDNet Australia | @scoopit http://t.co/bpZN1EP8

http://comprareviagracl.com/#7836 bosentan sildenafil viagra naturale urgente ricetta viagra

17 minutes ago by Soobaqualay on Top alternatives to Microsoft Outlook

But this is the thing. There are still plenty of good-quality graduates whose skills can raise seasoned professional eyebrows... if they ...

21 minutes ago by techkid on Skills shortage: companies being too picky?

Govt CIO praises budget's $1bn IT investment - ZDNet Australia http://t.co/HqLE8HTK

Govt CIO praises budget's $1bn IT investment http://t.co/S7fxuowb

McAfee sees 'malware explosion' across desktop, mobile platforms http://t.co/3a8e1u61

I wouldn't have called Vista cheesy. Its GUI was pretty slick (and indeed handed on to Windows 7). It was, however, poorly implemented, h...

41 minutes ago by techkid on Microsoft admits Vista was 'cheesy'

CIOview Govt CIO praises budget's $1bn IT investment - ZDNet Australia http://t.co/cn11RoxJ

Thanks Nelson, it should be right now.

-Michael.

49 minutes ago by Mukimu on Ausgrid network to talk back to operators

Govt CIO praises budget's $1bn IT investment: Despite a tighter 2012-13 Federal Budget, the government's chief i... http://t.co/4sYpLvu8

Govt CIO praises budget's $1bn IT investment http://t.co/2vHl0Q7W

by http://t.co/vmlLt4bh: Govt CIO praises budget's $1bn IT investment: Despite a tighter 2012-13 Federal Budget, ... http://t.co/SBsAK839

Govt CIO praises budget's $1bn IT investment: Despite a tighter 2012-13 Federal Budget, the government's chief i... http://t.co/uB6PeV5e

Govt CIO praises budget's $1bn IT investment http://t.co/VyIAMrNZ

In praise of #Oracle #Virtualbox http://t.co/YokgSTAr -good enough to tide us #microsoft peeps over until #windows8 at least

beats by dre pas cher suisse casque beats by dre beats by dre solo ou studio casque beats by dre beats by dre quality review bea...

1 hour ago by ichfaheqnbia on Don't add Telstra deal to NBN cost: Quigley

Why don't the underpants of the lover of shock jock Adam Willis fit so well any more? http://t.co/0MHEGxLE

I guess the mouse was a necessary evil at the time. I mean, yes, keyboard shortcuts in the right hands are faster than any mouse action (...

1 hour ago by techkid on Microsoft admits Vista was 'cheesy'

Govt CIO praises budget's $1bn IT investment: Despite a tighter 2012-13 Federal Budget, the government's chief i... http://t.co/qTAJGRTl

fyi google may always lie

1 hour ago by rt luvs youh on Google shows we're killing our language

they probaly always lie about in4mation bout people

1 hour ago by rt luvs youh on Google shows we're killing our language

Despite a tighter 2012 Budget, the Federal Govt CIO has said IT is still an important factor, making up $1.5 billion. http://t.co/Qz5xuGu5

クリスチャンルブタンの靴は、ルブタン靴は以下から入手できます。香港から世界中ブティックや小...

1 hour ago by Zimernereen on Reservoir blogs: Fan fakes Tarantino diary

Govt CIO praises budget's $1bn IT investment - ZDNet Australia: Govt CIO praises budget's $1bn IT investmentZDNe... http://t.co/Co3DkOE8

Despite a tighter 2012 Budget, the Federal Govt CIO has said IT is still an important factor, making up $1.5 billion. http://t.co/idcuxOua

RT @zdnetaustralia: Now that Google has closed its acquisition of Motorola Mobility, what's next? http://t.co/er8mBa4g

by http://t.co/vmlLt4bh: Ausgrid network to talk back to operators: Ausgrid is rolling out upgrades to the electr... http://t.co/GWTVbrJH

The Ark Group Australia Daily is out! http://t.co/oIk1F9iK ▸ Top stories today via @SmartCompany @harleyw @zdnetaustralia

RT @johnW3LLS: #NSW Govt announces shopfront in Silicon Valley + 7 consortia to dev #mobile for public sector http://t.co/daWWcUAw #gov2au #govcampNSW

Ausgrid network to talk back to operators http://t.co/iInEt1Tb

Ausgrid network to talk back to operators: Ausgrid is rolling out upgrades to the electricity grid in Port Steph... http://t.co/ildzefOl

$6.7million, now we know the price to the tax payer of a government IT project clean up. You've got to ask the question don't you: why o...

2 hours ago by Takenforgranted on Vic scraps HealthSMART system

Ausgrid network to talk back to operators http://t.co/bUNLQq7t

Ausgrid network to talk back to operators - Hardware - News - ZDNet Australia | @scoopit http://t.co/skOaWNt0

#NSW Govt announces shopfront in Silicon Valley + 7 consortia to dev #mobile for public sector http://t.co/daWWcUAw #gov2au #govcampNSW

VMware nabs turnkey desktop cloud provider Wanova: VMware is building out its end user product portfolio with th... http://t.co/9pzyjSBE

RT @johnW3LLS: #NSW Govt announces shopfront in Silicon Valley + 7 consortia to dev #mobile for public sector http://t.co/daWWcUAw #gov2au #govcampNSW

why some mp4 files with higher frame width can not be played in my 3m mp180??

2 hours ago by cyrusmann_ymail.com on 3M MP180 Pocket Projector

Fed Govt steps up on shared cloud plan http://t.co/u3CLkHwm via @zdnetaustralia

Unfortunately there is NO such place as Nelson's Bay. It's Nelson Bay!! Probably not your fault for the error, as your Media Release prob...

2 hours ago by Nelson on Ausgrid network to talk back to operators

Ausgrid is trialling tech that allows the electricity grid to report back on what might be wrong. http://t.co/vSqIh8Gm ^ML

Ausgrid network to talk back to operators http://t.co/LiC0teCs

It's taken some time, but Ausgrid is sticking some better smarts on the electricity network. The EE in me says yay. http://t.co/oHbr82y2

@Wow - thats one of the benefits of the iPad (and tablets in general). They are one of the most generation neutral products ever made. ...

4 hours ago by Gav on Westpac board goes paperless with iPads

and why is this such a super idea? http://www.itnews.com.au/News/301778,thousands-affected-in-billing-cloud-breach.aspx oh, yeah, right...

4 hours ago by btone on Fed Govt steps up on shared cloud plan

Wow, seems like a fantastic initiative that helps to save the environment. It must have taken a lot of convincing to get the Board to mov...

5 hours ago by Wow on Westpac board goes paperless with iPads

I'm a payed up lib member who has voted Labor in the last 2 federal elections. I had the previlege of speaking to Mr Turnball 3 months ag...

6 hours ago by spazmanaught on NBN contracts may be left alone: Turnbull

Good to see Westpac's concentrating on the real IT issues !

6 hours ago by jeff_syd on Westpac board goes paperless with iPads

I am not sure how this issue becomes an attack on Mr Turnbull. But I guess he is fair game. In any event I would have thought a Ddos woul...

16 hours ago by Doubt on National Botnet Network coming: Earthwave

I still use 98SE. Windows ME was an abortion in a bucket and Vista was ME without the bucket. My screen may look boring, but I jumped str...

16 hours ago by Treknology on Microsoft admits Vista was 'cheesy'

This story has been voted 10 times in the last 24 hours!

17 hours ago, CeBIT 2012 opens: photos

This story has been voted 15 times in the last 24 hours!

17 hours ago, Lenovo ThinkPad 3G tablet (32GB)

Well I don't know what they have done with their EFTPOS machines, local one in WA Coles Express I used this morning and I normally do "ch...

17 hours ago by harryinthesoup on Coles ditches PINs in payment pilot

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar