More than 75 percent of bank Web sites have at least one design flaw that could make customers vulnerable to cybercriminals after their money or even their identity, a University of Michigan study says.
Atul Prakash, a professor in the Department of Electrical Engineering and Computer Science, said some banks may have taken steps to resolve these problems since the data was gathered, but overall he still sees a need for improvement.
“To our surprise, design flaws that could compromise security were widespread and included some of the largest banks in the country,” Prakash said. “Our focus was on users who try to be careful, but unfortunately some bank sites make it hard for customers to make the right security decisions when doing online banking.”
Pinpointing the Flaws
These design flaws aren’t bugs that could be fixed with a patch. They stem from the flow and layout of these Web sites, according to the study. The flaws include placing log-in boxes and contact information on insecure Web pages and failing to keep users on the site they initially visited.
The flaws leave cracks in security that hackers could exploit to gain access to private information and accounts. The Federal Deposit Insurance Corporation says computer intrusion, while relatively rare compared with financial crimes like mortgage fraud and check fraud, is a growing problem for banks and their customers.
A recent FDIC Technology Incident Report, compiled from suspicious activity reports banks file quarterly, lists 536 cases of computer intrusion, with an average loss per incident of $30,000. That adds up to a nearly $16 million loss in the second quarter of 2007. Computer intrusions increased 150 percent between the first quarter of 2007 and the second. In 80 percent of the cases, the source of the intrusion is unknown but it occurred during online banking, the report…