On January 12, Sumitomo Mitsui Banking Corporation announced that it would adopt one-time passwords for user authentication on its “One’s Direct” Internet banking service. As part of measures against spyware that hides on computers and steals user IDs and passwords, the bank adopted RSA Security’s “SecurID.” This is the first adoption of one-time passwords for Internet banking in Japan.
The service will begin in February. Dedicated SecurID tokens (password-generation devices) will be distributed to customers who request them. Customers can access the One’s Direct website from a computer or mobile phone and log in by entering the string of digits displayed on the token in the password field. No dedicated software needs to be installed. Because the SecurID password changes every 60 seconds, there is little risk of unauthorized access even if it is intercepted. The monthly fee for SecurID is ¥105.
As measures against phishing and spyware, an increasing number of banks have adopted software keyboards that allow users to enter characters by clicking with a mouse on a keyboard displayed on the computer screen. Sumitomo Mitsui Banking Corporation has also already adopted a software keyboard. However, data entered through a software keyboard can technically be intercepted as well, so it is not a fundamental solution. The bank therefore decided to adopt one-time passwords as the strongest security measure currently available.
(Yasuhiro Kawai, Nikkei Computer)
So they say.
Hmm. Perhaps I will subscribe and try it.
In the United States, national regulations are pushing things in this direction.
Like many others, my company is also developing this kind of functionality, but….
