Mobile Banking Security and Risk Assessment Considerations

Tuesday, August 5th, 2008 @ 10:15 am | Banking and EFTPoS, Security

When considering Mobile and the associated risk, the an assessment approach depends greatly on the solution being created or provided.
Generally the approach is based on layered supporting and surrounding the technologies and techniques used.

Here are some things to consider.

assessments generally focuses on two main things.

1/ Sensitivity of the
What is being sent. eg. , numbers, account balance, home address, account number, etc.
may not be sensitive to the , but may be considered by the client as sensitive.
etc……….

2/ Opportunity to the .
What medium is being used?
Is it easy to ?
What is being used?
Are all paths secure (client and back end)?
Is there a 3rd party involved in the switching of the transactions?
etc………

Things to consider:

  • resets sent via to client, should not be used as the only method of accessing accounts. An additional client specific (possibly static) pass word/phrase should be used in addition to a dynamically generated . can be sniffed (depending on mode and location).
  • If WAP is used, are all devices capable of ? If devices are not capable of , do we deny to these devices? If client side or (win CE, etc), ensure this can not be compromised by a Trojan’s and other techniques.
  • Has the organisation considered client side certificates to verify the device prior to transactions being accepted? Consider multiple device and user methods (very solution dependant).
  • Most mobile POS terminals encrypt the client entered number, but do not encrypt everything within the . If the medium is compromised, we should consider if the can be cracked and if unencrypted is sensitive. Consider additional i.e. use of all of message (SSL, ) or use a terminal that utilises Derived Unique Key Per ().
  • Many applications have been affected by typical hacks such as session hijacking, SQL , non random session keys (client side and side), etc… These typical hacks should be considered in your Secure SDLC and QA Processes once you are aware of the used and/or deployed.
  • PBX systems and cabling distribution frames can have devices connected to collect transactions. Wireless devices are now being connected to these systems. The attacker sits in their car in the car park outside. This is often done in super markets.
  • Wireless gateways if not encrypted are easily collected by anyone within wireless range. 802.11 and other wireless/infra-red mediums are being used (assess the and medium being used).
  • Has the organisation considered dynamic keys for mobile users? There are some very low cost SecureID solutions available today, but customers need to have these devices on them when they want to do a .

 

Recently

  • Amateur Radio and Radhaz
  • Secure Application Development links
  • Kathy’s School - a school building project in Cambodia.
  • EFT Syetms and Device Considerations
  • Internet Banking Security Assessment Considerations
  • Mobile Banking Security and Risk Assessment Considerations
  • DNS Hack Needs Patching - Serious Problem
  • Cisco Command Cheat Sheet
  • Hidden Skype Emoticons
  • Breaking VISA PIN
  •  

    Leave a Reply

    XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>