IN AN ARTICLE last year, I wrote about the importance of strong online account security wherever you keep your savings and investments. I shared habits that should help you avoid the potentially huge financial losses caused by a cybercrime. I also urged readers to weigh a company’s commitment to security when choosing a home for their money.
I’d like to give kudos to Bank of America for providing a good example of this commitment. It recently added proactive, structured guidance to its security center. It’s a combination of education and guided “nudging” to take steps like creating strong passwords, enabling two-factor authentication, using the company’s mobile app with push notifications, and agreeing to receive alerts if the bank notices unusual activity. Below is an example of the feedback that Bank of America’s site offers.
The bank recently added support on its website for two-factor authentication using industry standard hardware security keys, such as YubiKey, which I use on my computers. The bank’s mobile app, an early adopter of biometrics such as Apple’s Touch ID or Face ID, now supports relatively simple two-factor authentication, too. Even if hackers manage to crack your password, it would be incredibly hard for them to access your account if you’ve enabled two-factor authentication.
While I’d love to get a higher yield on my savings, it’s more important to me that my cash remains in my accounts and I don’t face the hassle of a security incident. Reaching for yield? Think about risk—including the risk that a financial firm’s security isn’t up to snuff.

Bank of America may be doing the right things now, but just yesterday I discovered they are the #1 bank for customer complaints stemming from Zelle scams cleaning out their BofA accounts, of which most banks just shrug their shoulders and say, “Sorry, take it up with zelle…” So, this is probably a knee-jerk reaction to having so many incidences. Please, everyone, make sure you turn off, deactivate, and never use Zelle services with your bank! There are no customer protections and no customer service when the bad guy gets a hold of your account info and cleans you out. Zelle = BAD.
If you are someone who is intensely worried about security they should install a vpn on their computer. 1)It encrypts your sensitive data before it even leaves your device and connects to the web. This means that no one can see your traffic, 2) it changes your ip address and your apparent location (if desired). This new information goes to your online destination (in this case, your bank’s website) and back. As a result, the receiver of your data will not be able to see where the data originally came from, 3) do not use public Wifi unless using vpn on laptop
Thanks for the reminder to consider our online security. As with many things complicated things in life, a few simple habits can serve us well. In my career I specialized in application development and not cyber security, so I don’t pretend to be a cyber expert. That said, here’s a few things I do to minimize my online risk, especially with my financial applications:
I don’t go through this level of rigor for my “social” accounts. For example, accounts that I don’t really care if someone breaks into (ie. Netflix, social blogs, etc) I’ll just use the same account name and simple passwords that I’m comfortable typing by hand. That makes logging in on a motel tv into my Netflix account easy to do. But that info gives a hacker no insight into my financial accounts in any manner.
None of the above are “perfect”. I can certainly construct scenario’s where any of these techniques will prove inadequate. However, collectively they do help me move towards a safer online presence as compared to the alternative.
Good luck!