FREE NEWSLETTER

Articles › Abuse

On Guard Online

IN AN ARTICLE last year, I wrote about the importance of strong online account security wherever you keep your savings and investments. I shared habits that should help you avoid the potentially huge financial losses caused by a cybercrime. I also urged readers to weigh a company’s commitment to security when choosing a home for their money.

I’d like to give kudos to Bank of America for providing a good example of this commitment. It recently added proactive, structured guidance to its security center. It’s a combination of education and guided “nudging” to take steps like creating strong passwords, enabling two-factor authentication, using the company’s mobile app with push notifications, and agreeing to receive alerts if the bank notices unusual activity. Below is an example of the feedback that Bank of America’s site offers.

The bank recently added support on its website for two-factor authentication using industry standard hardware security keys, such as YubiKey, which I use on my computers. The bank’s mobile app, an early adopter of biometrics such as Apple’s Touch ID or Face ID, now supports relatively simple two-factor authentication, too. Even if hackers manage to crack your password, it would be incredibly hard for them to access your account if you’ve enabled two-factor authentication.

While I’d love to get a higher yield on my savings, it’s more important to me that my cash remains in my accounts and I don’t face the hassle of a security incident. Reaching for yield? Think about risk—including the risk that a financial firm’s security isn’t up to snuff.

More On This Topic

Email Alerts for this Comment Thread
Notify of
9 Comments
Newest
Oldest Most Voted
sher chap
4 years ago

Bank of America may be doing the right things now, but just yesterday I discovered they are the #1 bank for customer complaints stemming from Zelle scams cleaning out their BofA accounts, of which most banks just shrug their shoulders and say, “Sorry, take it up with zelle…” So, this is probably a knee-jerk reaction to having so many incidences. Please, everyone, make sure you turn off, deactivate, and never use Zelle services with your bank! There are no customer protections and no customer service when the bad guy gets a hold of your account info and cleans you out. Zelle = BAD.

Peter Blanchette
4 years ago

If you are someone who is intensely worried about security they should install a vpn on their computer. 1)It encrypts your sensitive data before it even leaves your device and connects to the web. This means that no one can see your traffic, 2) it changes your ip address and your apparent location (if desired). This new information goes to your online destination (in this case, your bank’s website) and back. As a result, the receiver of your data will not be able to see where the data originally came from, 3) do not use public Wifi unless using vpn on laptop

Last edited 4 years ago by Peter Blanchette
OldITGuy
4 years ago

Thanks for the reminder to consider our online security. As with many things complicated things in life, a few simple habits can serve us well. In my career I specialized in application development and not cyber security, so I don’t pretend to be a cyber expert. That said, here’s a few things I do to minimize my online risk, especially with my financial applications:

  1. I have separate email accounts for my “social” things and my “financial” things. I get lots of junk mail and such in my social email account, but my financial email account gets all my financial emails, which I always look at. Plus my financial email account doesn’t have my identity in it at all. Finally, I only use my financial email account for important accounts. So when an email shows up on my smartphone, I read it much sooner than if it was in my social email account. It isn’t masked by the vast amount of stuff that floods my social email account every day. Plus if my social email account gets hacked, none of my financial information is in it.
  2. I use a password manager. There’s several excellent free password managers. I use lastpass. Having a password manager makes it easy to have very long and unique passwords for my financial accounts. Many financial institutions allow passwords of 40 to 64 characters. I strongly recommend making use of this feature by having long, unique random passwords as this virtually eliminates password guessing. A password manager also makes it easy to change the passwords regularly.
  3. A password manager also means your user account name on the financial accounts can be long and random as well. Don’t use the same user account name at different financial institutions. If someone is trying to target you, now they’ve got 2 things they have to figure out (ie. the account name and the account password) rather than just the password.
  4. My wife and I like to travel. I’m wary about logging into financial accounts while on travel unless several conditions are met. To minimize login’s to my financial accounts while in less safe computing environments, I enable alerts with very low thresholds. Hence I rarely have to login while on travel to know what transactions are hitting my bank and credit card accounts.

I don’t go through this level of rigor for my “social” accounts. For example, accounts that I don’t really care if someone breaks into (ie. Netflix, social blogs, etc) I’ll just use the same account name and simple passwords that I’m comfortable typing by hand. That makes logging in on a motel tv into my Netflix account easy to do. But that info gives a hacker no insight into my financial accounts in any manner.

None of the above are “perfect”. I can certainly construct scenario’s where any of these techniques will prove inadequate. However, collectively they do help me move towards a safer online presence as compared to the alternative.

Good luck!