George Gardiner

First Direct upgrade scores low marks

One bank’s attempt to toughen up online security has left users battered, bemused and feeling insecure

Written by George Gardiner

First Direct recently “upgraded” its online security, which is to be applauded. After all, criminals are really creative so you need to respond to new threats all the time. In principle it’s a good idea, so I was looking forward to receiving something like a little fob that generates a random six-digit number or some other clever piece of technology.

Instead, when I embarked on the upgrade I quickly found myself bogged down in crashing web sites and glaring security anomalies. For example, when I started the upgrade I was redirected to a web site that immediately set an alarm bell off in my head. The site looked like one I’ve used before but it had a hyphen in the name whereas before it didn’t. Which is a typical hacker ruse.

So, mistake No 1: First Direct should have informed users of any changes to web addresses.

I would have moved on to the next step in the process except that the new web site was unstable all weekend, so another own goal by First Direct. If you invite your entire customer base to upgrade then you need to make sure you can cope with the demand. Two weeks later I tried again.

So I’m now on the “new” web site and am immediately asked to provide information that First Direct already has (admittedly, not all of it and probably not enough to hack into the account there and then, but with a key logger in operation, it would only be a matter of time). I was astounded. What should have happened is that the customer logs into the existing system and then, once all the security has been dealt with, the upgrade takes over. In other words, we identify each other properly before making changes.

Imagine my delight when I’d finished the entire process without any apparent errors only to discover that I could not log on. Apparently my data had not been committed to their databases, so I had to start all over again.

By the way, the new “security” is nothing more than just another question. And it is the same question every time. Looking at the new improved system, I cannot see anything that makes it any more secure. I can only conclude that the upgrade was not to address security issues, but rather it is an operational fix.

What really disappointed me was that the electronic services team at First Direct was unable to provide me with even basic assurance, and I spoke to quite a few of them. They not only weren’t able to provide assurance but also failed to understand my concerns.

I am hoping First Direct has made some crucial changes which will protect me, but I have to say that the complete hash that the firm has made of this process does not fill me with confidence.

Tags:

reader comments

related articles

Why websites go down

Cheap-skating companies make no allowances for hardware failures, say experts 26 Feb 2007

 

Majority UK of web sites vulnerable to attack

A third of sites contain critical vulnerabilities 21 Mar 2007

Government web sites hit and miss on services

Socitm's Better Connected review paints mixed picture of e-government success 08 Mar 2007

Shopping sites vulnerable to Christmas rush

Attacks likely to multiply during yuletide rush, security firm predicts 06 Dec 2006

VAR hits back at government security apathy

Nebulas Group managing director claims government attitude will open the floodgates for hackers 05 Nov 2008

Experts predict rise in 'virtual' malware

Botnet shutdowns will force attackers to change tack next year 25 Nov 2008

Criminals keep PCs under surveillance

Attacks on PCs launched with military precision 24 Sep 2008

related whitepapers

today's top stories

CIOs must embrace collaboration tools

Author Don Tapscott gives Angelica Mari his reasons for promoting social networking tools and says transparency is the key to security 04 Dec 2008

On a quest to build a connected society

BT Design’s JP Rangaswami talks to Gareth Morgan about his pivotal role in the telecoms giant’s efforts to deliver universal broadband and his plans to tap into the creativity of the open source community 04 Dec 2008

IT leaders must stand by India

A sense of perspective is the most important response from IT leaders to the attacks in Mumbai 04 Dec 2008

Case study: Clifford Chance

Law firm implements Sun platform and reduces datacentres to gain efficiency and cost synergies 03 Dec 2008

Should CRM be more sociable?

As vendors rush to add more social networking bells and whistles to their CRM products, some experts warn that users must tread carefully when venturing into online communities 03 Dec 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Will the terrorist attacks in Mumbai affect your offshoring plans?

Will the terrorist attacks in Mumbai affect your offshoring plans?

Is India becoming a risky destination?

Previous poll results

Latest audio and video articles

Padlocked CDVideo

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

Podcast imageAudio

Computing podcast - Standard Life's offshoring plans; and the prospects for government IT

The insurance giant outlines its new outsourcing strategy; and we ask if the government's economic bailout will affect its IT plans 28 Nov 2008

Latest in-depth articles

Doctors looking at a computerAnalysis

Watchdog wants IT to cure privacy woes

Information Commissioner Richard Thomas is urging organisations to put privacy protection at the top of their procurement and development criteria 04 Dec 2008

Colin McDonaldComment

Web 2.0 has potential to transform staff training

Employees can sharpen their IT skills through using the latest interactive training tools, writes Colin McDonald 04 Dec 2008

Advertisement

Primary Navigation