Consumers' Reuse of Passwords Will Speed Adoption of Biometrics: Report

Consumers' loose habits around their account passwords and mobile devices will force banks to take stronger securitymeasures, a recent study suggests.

The findings come at a time when mobile banking adoption and usage are expected to continue growing rapidly — Aite Group expects 96.1 million Americans to be using mobile banking by 2016 — and as phishing and hacking attempts on bank customers escalate.

Mobile device users are about 25% more likely than the general population to use the same password to access more than one online account, according to the survey of 5,634 U.S. adults, which was conducted by Javelin Strategy and Research and sponsored by Nok Nok Labs. This motivates criminals to seek to steal bank account credentials from mobile device users with the expectation that they will provide an entree to a variety of the victim's valuable accounts and services, the report's author, Al Pascual, said.

"Generally folks are doing a really poor job of securing their devices and any accounts associated with that device," he said.

The repurposing of passwords is easy to understand. It ishard to enter long passwords on small devices. Consumers tend to access more apps and online services through their mobile devices than from full-sized computers, making password discipline harder to maintain.

It is notjust consumers who are apathetic about mobile device security, Pascual notes. "Device manufacturers and carriers often provide updates haphazardly, or they don't consider the effect an update has on consumers' willingness to upgrade their devices — they'll just wait until they can afford a new one. That means security vulnerabilities aren't addressed."

Banks got called out in the report for providing one-time passwords through text messages, which can be intercepted by certain types of malware. Using one-time passwords to authenticate a user was once considered a decent form of second-factor authentication.

"It was a good idea until two years ago, when it started to become really popular, then you knew it was done in," Pascual said. "As soon as it became ubiquitous, it was done for."

In short, when it comes to mobile security, nothing is working.

"No one is doing nearly enough," Pascual said.

The way forward, many in the industry believe, is biometrics.

Fingerprint recognition is the most popular form of biometric authentication among consumers — more than a third said they would prefer to use a fingerprint to authenticate their identity online.

Apple's building of fingerprint recognition into some of its phones has helped raise awareness and acceptance of the technology, which was once associated with criminals.

Some security experts have pointed out that fingerprints can be lifted off a phone, glass or other object and reproduced, and that consumers cannot simply call a call center to change a fingerprint the way they can a password. And once a fingerprint is transmuted into a data string, as all biometric identities eventually are, it could be stolen from a database like any other data element.

But the odds of someone going to the trouble of stealing a physical fingerprint are low, Pascual noted.

The far greater problem is criminals are compromising accounts en masse over the Internet, using stolen information such as passwords and Social Security numbers. "We really need to deal with that problem first," he said. "Fingerprints are worlds more secure than we are today."

Eye (iris or retina) recognition is also well received among the consumers Javelin surveyed — more than 13% said eye scanning would be their preferred method of biometric authentication. Pascual chalks this up to the many popular fiction books and movies featuring the technology.

"It conjures up a certain image," Pascual said. "Over the next few years, I think we'll see that come into its own."

In fact, Pascual believe that within a few years, passwords will disappear, at least for high-risk transactions.

For reprint and licensing requests for this article, click here.
Bank technology
MORE FROM AMERICAN BANKER

Acting CFPB Director Russ Vought has managed to neuter the Consumer Financial Protection Bureau through a series of actions. Senate Banking Committee Chairman Tim Scott, R-S.C., played a major role by cutting funding in half.

2h ago
7 Min Read
CFPB exterior no signage 4

Federal Reserve Chair Jerome Powell said there was a "high degree of unity" among committee members during this week's Federal Open Market Committee vote. Out of 12 FOMC members, 11 voted for a 25 basis point cut.

11h ago
4 Min Read
Jerome Powell

The Federal Open Market Committee's decision to reduce interest rates for the first time in nine months lifted bank stocks Wednesday. The 25-basis-point reduction could lead to net interest income headwinds now, but loan growth later, analysts said.

September 17
4 Min Read

Community Financial in Syracuse has made its biggest investment ever in an outside company, taking a $37.4 million equity stake in an insurance provider that focuses on the rental housing market.

September 17
4 Min Read
syracuse, new york

St. Cloud Financial Credit Union will be issuing its own stablecoin at the end of this year, becoming one of the first U.S. credit unions to do so.

September 17
4 Min Read
BankThink on increased need for AML with stablecoins

The two BNPL giants' pay-over-time loans will now be available for in-store purchases on Apple Pay in a move to capture more sales at brick and mortar stores.

September 17
3 Min Read
Apple Pay