Friday, June 17, 2011

Brazilian bank evaluating biometric system for online banking

Bradesco looking into developing device that would identify account holders on the Internet (SecurityInfoWatch.com)
According to Bradesco executive VP Laercio Albino Cezar, the bank is evaluating developing a device with Fujitsu to identify accountholders on the internet. "We want to create something that isn't integrated into the client computer to use separately, as happens today with the tokens," he was quoted as saying.
Mr. Cezar appears to grasp a very subtle point of networked biometric identity management solutions. The hardware is a part of the security. If a hacker steals your banking password, she can just type it into the proper field and she's in. If she steals your unencrypted biometric template (a long character string), she can't just type it in even if she finds the place in the bank's programming that handles the template. In some ways the template is like a password that must come through the sensor.

A biometric template by itself isn't enough to gain access.