Fintech

Are banks promoting phishing?

Comment

Image Credits: wk1003Mike (opens in a new window) / Shutterstock (opens in a new window)

Jonathan Lister

Contributor

Jonathan Lister is CTO at online pension manager PensionBee.

I’ve recently seen a few examples of services that ask customers to type in their online banking usernames and passwords so the service can access their bank accounts on their behalf. The applications are fairly broad and definitely useful — making payments, ID verification and analyzing data, for example.

This is a security anti-pattern. This is bad news.

Banks regularly email their customers to say they will never ask for your password in an email and that attempts to do so should be reported as phishing. I’m a Metro Bank customer and the footer of each of their emails says:

We’ll never send you an email, text or a website link asking you to enter your Internet Banking or card details. If you’re suspicious […] contact us immediately and we’ll get our security team on the case.

Phishing is a serious security issue for banks. Industry data suggests that losses from online banking fraud were up 64 percent to £133.5 million in 2015 from £81.4 million in 2014. A Google search for “bank phishing” turns up results from all the major high-street banks, with titles like “Recognising & Preventing Phishing” and “Phishing & email scams.” Barclays has even started producing videos on the subject. So if the industry is, rightly, concerned with educating people about the risks of phishing, why on earth are they happy for their customers to put their login details into any other website than their bank’s website?

Unintended consequences of legislation

I’ve spoken to the service providers about how they are able to offer this service to customers, as my first assumption was that it would be against the terms and conditions of the various online banking services. Having checked a few online banking terms and conditions, customers are not protected against fraud if they have not kept their passwords safe. Lloyds even references information “aggregators” explicitly — Lloyds can close your online banking account if you give your security details to the service provider.

The response from the service providers is interesting — and unnerving.

All the service providers quoted “PSD2,” the revised Directive on Payment Services, a European law that came into force in November 2015. This is timetabled to pass into U.K. law in January 2018 (although Brexit…) and requires that banks open digital access to customers’ bank accounts to other companies. This is a huge deal. One of the people I spoke to about this said that the “banks could see the writing was on the wall with PSD2,” so they did not put up any objection to the service provider taking the username and password of the bank’s customer.

But access is not the only thing PSD2 is meant to promote. Commissioner Jonathan Hill said at the launch of PSD2 that:

European consumers want to know that their payments are safe when they shop or make a payment online. The new Payment Services Directive will ensure that electronic payments in Europe become more secure and more convenient for European shoppers.

Of course, the arrival of PSD2 in early 2018 is providing a stimulus for companies to build services on bank accounts. If early adopters use a method of customer login that is indistinguishable from phishing, the problem that currently looks limited to a handful of services will burst into a million pieces when access to bank accounts is not only encouraged, but legislated for.

Hang on, we’ve seen this before

When Twitter first took off, it was not uncommon for a new website to ask for your Twitter username and password in order to, say, tweet on your behalf. Back in 2006, Blaine Cook, Twitter’s architect at the time, started working on an alternative that allowed you to grant access to certain information or capabilities, such as tweeting as you, without giving away the keys to your whole account.

What Blaine and his collaborators worked on eventually became the OAuth standard and now powers all the “login with” Facebook/Twitter/LinkedIn/Google buttons you see on websites all over the internet.

So why not OAuth for banks? The Open Bank Project advocates for OAuth, but, unfortunately for us U.K. customers, its adoption has been limited so far to German banks (however, this in itself is a great success). The U.K. government commissioned the Open Banking Working Group (OBWG) in late 2015, to explore the question of opening up data held by banks. The OBWG published their findings as the Open Banking Standard in August this year. Happily, they have also recommended the use of OAuth*. The only U.K. bank that has taken up the OAuth gauntlet so far is Monzo.

So the outlook at this point is mixed. The Open Banking Standard is not expected to be implemented in its full glory until 2019, although initial services that only read information are expected in 2017. If you’re reading this as a consumer, be vocal in demanding safe and secure access to your bank account. If you are responsible for building an online product, make a point of not making poor choices for your customers. Between now and 2019, there is still plenty of time for keen fintech startups to open services that train bad habits into people and leave them vulnerable to fraud.

* Technical caveat: There are some credible issues with their choice of the particular version of the standard — Teller.io is being particularly proactive in response.

More TechCrunch

Google has found a way to bring a variation of its clever “Circle to Search” gesture to iPhone users. The new interaction, launched in January, allows Android users to search…

Google brings a variation on ‘Circle to Search’ to iPhone users

A new sculpture going live on Wednesday in the Flatiron South Public Plaza in New York is not your typical artwork. It combines technology, sociology, anthropology and art to let…

Always-on video portal lets people in NYC and Dublin interact in real time

Apple’s iPad event had a lot to like. New iPads with new chips and new sizes, a new Apple Pencil, and even some software updates. If you are a big…

TechCrunch Minute: When did iPads get as expensive as MacBooks?

Autonomous, AI-based players are coming to a gaming experience near you, and a new startup, Altera, is joining the fray to build this new guard of AI agents. The company announced…

Bye-bye bots: Altera’s game-playing AI agents get backing from Eric Schmidt

Google DeepMind has taken the wraps off a new version AlphaFold, their transformative machine learning model that predicts the shape and behavior of proteins. AlphaFold 3 is not only more…

Google DeepMind debuts huge AlphaFold update and free proteomics-as-a-service web app

Uber plans to deliver more perks to Uber One members, like member-exclusive events, in a bid to gain more revenue through subscriptions.  “You will see more member-exclusives coming up where…

Uber promises member exclusives as Uber One passes $1B run-rate

We’ve all seen them. The inspector with a clipboard, walking around a building, ticking off the last time the fire extinguishers were checked, or if all the lights are working.…

Checkfirst raises $1.5M pre-seed to apply AI to remote inspections and audits

Close to a decade ago, brothers Aviv and Matteo Shapira co-founded a company, Replay, that created a video format for 360-degree replays — the sorts of replays that have become…

Controversial drone company Xtend leans into defense with new $40 million round

Usually, when something starts to rot, it gets pitched in the trash. But Joanne Rodriguez wants to turn the concept of rot on its head by growing fungus on trash…

Mycocycle uses mushrooms to upcycle old tires and construction waste

Monzo has raised another £150 million ($190 million), as the challenger bank looks to expand its presence internationally — particularly in the U.S. The new round comes just two months…

UK challenger bank Monzo nabs another $190M as US expansion beckons

iRobot has announced the successor to longtime CEO, Colin Angle. Gary Cohen, who previous held chief executive role at Timex and Qualitor Automotive, will be heading up the company, marking a major…

iRobot names former Timex head Gary Cohen as CEO

Reddit — now a publicly-traded company with more scrutiny on revenue growth — is putting a big focus on boosting its international audience, starting with francophones. In their first-ever earnings…

Reddit tests automatic, whole-site translation into French using LLM-based AI

Mushrooms continue to be a big area for alternative proteins. Canada-based Maia Farms recently raised $1.7 million to develop a blend of mushroom and plant-based protein using biomass fermentation. There’s…

Meati Foods bites into another $100M amid growth to 7,000 retail locations

Cleaning the outside of buildings is a dirty job, and it’s also dangerous. Lucid Bots came on the scene in 2018 with its Sherpa line of drones to clean windows…

Lucid Bots secures $9M for drones to clean more than your windows

High interest rates and financial pressures make it more important than ever for finance teams to have a better handle on their cash flow, and several startups are hoping to…

Israeli startup Panax raises a $10M Series A for its AI-driven cash flow management platform

The European Union has deepened the investigation of Elon Musk-owned social network, X, that it opened back in December under the bloc’s online governance and content moderation rulebook, the Digital Services Act…

EU grills Elon Musk’s X about content moderation and deepfake risks

For the founders of Atlan, a data governance startup, data has always been at the heart of what they do, even before they launched the company. In fact, co-founders Prukalpa…

Atlan scores $105M for its data control plane, as LLMs boost importance of data

It is estimated that about 2 billion people, especially those in lower and middle-income countries, lack access to quality and affordable essential medicines. The situation is exacerbated by low-quality or even killer…

Axmed raises $2M from Founderful to streamline drug supply chains in underserved markets

For decades, the Global Positioning System (GPS) has maintained a de facto monopoly on positioning, navigation and timing, because it’s cheap and already integrated into billions of devices around the…

Xona Space Systems closes $19M Series A to build out ultra-accurate GPS alternative

Bankruptcy lawyers representing customers impacted by the dramatic crash of cryptocurrency exchange FTX 17 months ago say that the vast majority of victims will receive their money back — plus interest. The…

FTX crypto fraud victims to get their money back — plus interest

Google on Wednesday launched its digital wallet in India with local integrations, nearly two years after the app was relaunched as a digital wallet platform in the U.S. As TechCrunch exclusively reported last month,…

Google Wallet is now available in India

Bluesky has launched a new product roadmap for the coming months. The decentralized social network said on Tuesday that it is planning to introduce direct messages, support for videos, improved…

Bluesky to add DMs, video support and in-app custom feed curation

Samsung Medison, a medical device unit of Samsung Electronics that specializes in developing diagnostic imaging devices, said on Wednesday it plans to acquire Sonio, a Paris-based startup that makes AI-powered software…

Samsung Medison to acquire French AI ultrasound startup Sonio for $92.7M

Kyle Kuzma is a lot of things. He’s a forward for the Washington Wizards NBA team and a 2020 NBA champion. He’s also a style icon — depending on who…

NBA champion Kyle Kuzma looks to bring his team mentality to Scrum Ventures

Ofcom is cracking down on Instagram, YouTube and 150,000 other web services to improve child safety online. A new Children’s Safety Code from the U.K. Internet regulator will push tech…

Ofcom to push for better age verification, filters and 40 other checks in new online child safety code

Lipids are fatty, waxy or oily compounds that, for instance, typically come in the form of fats and oils. As a result they are heavily used in the production of…

After a $20M Series A funding, Germany’s Insempra plans eco-friendly lipid production

Tesla CEO Elon Musk has said that lidar sensors are a “crutch” for autonomous vehicles. But his company has bought so many from Luminar that Tesla is now the lidar-maker’s…

Tesla is Luminar’s largest lidar customer

U.S. realty trust giant Brandywine Realty Trust has confirmed a cyberattack that resulted in the theft of data from its network. In a filing with regulators on Tuesday, the Philadelphia-based…

Brandywine Realty Trust says data stolen in ransomware attack

Rivian lost $1.45 billion in the first quarter, showing that its recent company-wide cost-cutting measures have a ways to go before it can approach profitability. The EV-maker brought in $1.2…

Rivian loses $1.45B as cost-cutting measures continue

Meta is rolling out an expanded set of generative AI tools for advertisers, after first announcing a set of AI features last October. Now, instead of only being able to…

Meta’s AI tools for advertisers can now create full new images, not just new backgrounds