<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">

 <title>Dave Dash</title>
 <link href="http://davedash.com/tag/banking/atom.xml" rel="self"/>
 <link href="http://davedash.com/tag/banking"/>
 <updated>2010-08-29T14:12:50-07:00</updated>
 <id>http://davedash.com/</id>
 <author>
   <name>Dave Dash</name>
   <email>dd+atom1@davedash.com</email>
 </author>

 
 <entry>
   <title>Dear Banks, Stop Encouraging Bad Security</title>
   <link href="http://davedash.com/2008/12/16/dear-banks-stop-encouraging-bad-security/"/>
   <updated>2008-12-16T00:00:00-08:00</updated>
   <id>http://davedash.com/2008/12/16/dear-banks-stop-encouraging-bad-security</id>
   <content type="html">&lt;p&gt;I use an online personal finance site that connects to all my financial accounts and aggregates my transaction history.  I love it, it's very useful, and it keeps me financially organized.&lt;/p&gt;

&lt;p&gt;The part that annoys me is that most of these personal finance sites require you to supply your username and password for all your bank accounts.  For some banks it also requires your social security number, the last five people you've slept with, your home town, your favorite color, etc, etc.  Basically all the pesky sign in questions your bank might ask you when you log in.&lt;/p&gt;

&lt;p&gt;This is a cruel necessity for companies like &lt;a href=&quot;http://geezeo.com/&quot;&gt;Geezeo&lt;/a&gt;, &lt;a href=&quot;http://mint.com/&quot;&gt;Mint&lt;/a&gt;, Ameriprise and Quicken Online in order to provide this aggregation service and a scary proposition for people like us who use these services.  You're giving full unfettered access to companies you may not have ever heard of to all your finances.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Security questions, and personalized security questions are the wrong way to fix bank security.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;!--more--&gt;
People want online personal finance sites.  They want all their data in a single place without having to jump through a bazillion hoops for each and every 401K, savings account, checking account, online stock trading system and mortgage account.  They will gladly sacrifice security for a chance to better their financial management capabilities.&lt;/p&gt;

&lt;p&gt;Banks need to create APIs so third-party software can access transaction data.  The authentication for this should be secure, limited and revokable.  Meaning, I may authorize &lt;a href=&quot;http://mint.com/&quot;&gt;Mint&lt;/a&gt; to see my Bank of America account, but at any time I can log on to BoA and deny Mint's ability to see my transaction data.  OAuth may be one mechanism to achieve this.&lt;/p&gt;

&lt;p&gt;This will achieve a few things:
* People won't give out their passwords online to anybody but their bank.
* Getting data into these aggregating sites will be reliable and secure.
* At any time you can see who has access to your transaction data and revoke it.&lt;/p&gt;

&lt;p&gt;Please banks, do your part to keep the internet secure.  &lt;a href=&quot;http://mint.com/&quot;&gt;Mint&lt;/a&gt;, &lt;a href=&quot;http://geezeo.com/&quot;&gt;Geezeo&lt;/a&gt; and anybody else, please do your part of turning up the pressure on financial institutions and when the time comes... please start using these APIs.&lt;/p&gt;
</content>
 </entry>
 
 <entry>
   <title>Dear Bank</title>
   <link href="http://davedash.com/2008/02/04/dear-bank/"/>
   <updated>2008-02-04T00:00:00-08:00</updated>
   <id>http://davedash.com/2008/02/04/dear-bank</id>
   <content type="html">&lt;p&gt;I can't do simple things because they inevitably make me ranty.&lt;/p&gt;

&lt;blockquote&gt;&lt;p&gt;Dear Small Bank in MN,&lt;/p&gt;

&lt;p&gt;Your online banking system is difficult to log into and yet insecure.&lt;/p&gt;

&lt;p&gt;I have to jump through so many hurtles trying to log into the [Small Bank in MN]  eBiz &gt; bank, yet it still isn't that secure.&lt;/p&gt;

&lt;p&gt;Instead of entering in my password, it's easier to just reset my password... but the scary thing is... resetting my password means you email me my old password in the clear!  Instead of just providing a temporary link, you give me my old password.  That's crazy!  That means anybody snooping into my email could find it out.  Or worse, someone could steal my computer and have all my online banking info.&lt;/p&gt;

&lt;p&gt;My bank information should be secure even when my email gets compromised.  And it shouldn't be so hard to log into.  Look at ING, they have a sufficiently secure and accessible system.&lt;/p&gt;

&lt;p&gt;Also... your HTML is inaccessible.  checkboxes and radiobuttons should have &amp;lt;label&amp;gt; tags.&lt;/p&gt;

&lt;p&gt;Sincerely,&lt;/p&gt;

&lt;p&gt;Dave Dash&lt;/p&gt;&lt;/blockquote&gt;

&lt;p&gt;I hate online banking.  &lt;!--more--&gt; It's so frustrating.  Each company has a weird set of rules on login ids:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;A random Number that they provide&lt;/li&gt;
&lt;li&gt;A username which you choose must have at least two numbers&lt;/li&gt;
&lt;/ul&gt;


&lt;p&gt;I get it... but really?  Is it all that necessary.  All it means for me is I only check those bank accounts when I have to, or I write those account numbers in an easy to remember place, like on the palm of my hand.  Or it means I call customer support like an idiot and waste more money and time.&lt;/p&gt;

&lt;p&gt;Then there's the magic questions:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Where were you born?&lt;/li&gt;
&lt;li&gt;Who's your daddy?&lt;/li&gt;
&lt;li&gt;Who's your mommy?&lt;/li&gt;
&lt;li&gt;Which of your two cats do you like better?&lt;/li&gt;
&lt;li&gt;What's your best friends name? (I know &quot;friends&quot; should be &quot;friend's&quot; but that's not what the bank knows)&lt;/li&gt;
&lt;li&gt;What is the date that your second girlfriend started holding your hand?&lt;/li&gt;
&lt;/ul&gt;


&lt;p&gt;Okay... less annoying, but seriously, how many times do I have to answer them to log into my account?&lt;/p&gt;

&lt;p&gt;And then finally passwords:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Passwords must contain numbers, letters, bears, tigers&lt;/li&gt;
&lt;li&gt;Passwords cannot be any of the passwords you've used in the last 9 months&lt;/li&gt;
&lt;li&gt;Passwords cannot be your daughter's name&lt;/li&gt;
&lt;/ul&gt;


&lt;p&gt;And then the inevitable... I give up and click forgot password... and without question it emails my email account with the password I couldn't remember... no questions asked... just a simple request to change my password again.&lt;/p&gt;

&lt;p&gt;Um... yeah that's real secure.  Thanks Bank!&lt;/p&gt;

&lt;p&gt;Oh and never mind that their forms are hard to use because they don't know proper HTML.  If you don't use &amp;lt;label&amp;gt;s it's like trying to pee in a Cheerio using your mouse.&lt;/p&gt;
</content>
 </entry>
 

</feed>
