Commentary

Elena Malykhina
 

Securing Your Mobile Wallets

Losing a credit card is scary, but losing a cell phone that stores your bank account information is even scarier. Once cell phones come pre-loaded with mobile banking apps, some of your personal information will be stored on them. Naturally that poses a huge security hazard.

Losing a credit card is scary, but losing a cell phone that stores your bank account information is even scarier. Once cell phones come pre-loaded with mobile banking apps, some of your personal information will be stored on them. Naturally that poses a huge security hazard.But before you rule out mobile banking completely from your list of innovative services to try out in the next few years, here's what the banks and their partners are doing to secure these services:

- Citibank: Transactions conducted using its Citi Mobile service are secured with 128-bit encryption, the same technology that's used at Citibank.com. The cell phone doesn't store any bank account information.


More Mobility Insights

White Papers

More >>

Reports

More >>

Webcasts

More >>

- Bank of America: Customers using its mobile banking service are protected by the bank's SiteKey security technology, where they would have to answer a series of questions to access their account. Information remains encrypted when it's sent between the phone and the bank.

- AT&T: Once the carrier rolls out mobile devices with a pre-loaded banking application, which will include access to banks like Wachovia, BancorpSouth, Regions Financial, and SunTrust Banks, it will have the ability to remotely wipe the device clean of personal data if it's lost or stolen.

Separately, MasterCard and Visa are testing cell phones with embedded Near Field Communication technology, which enables short-range wireless communications between devices for contactless payments. Using the technology, you can make purchases with a cell phone at concession stands, fast-food restaurants, and stores. But the same security rules apply here as they do in the credit card world. Visa, for example, will de-activate the wireless account if a phone is lost or stolen. Visa says it will also guarantee zero liability, which means you won't be liable if someone conducts fraudulent transactions using your stolen phone.

Earlier this week, digital security company Gemalto began providing a Belgian wireless carrier with technology that will let its subscribers perform secure payments using the Short Message Service (SMS). Here's how it works: A payer specifies the amount and the name of the payee on his or cell phone screen and accepts the transaction by entering a secret code he or she selected when the service was activated. Then, both the customer and the merchant receive an SMS confirming the transaction. It doesn't look like the service is yet available in the United States, but is a glimpse into what's to come in the near future.

In summary, the banks are viewing mobile banking as an extension of their online services, which means all the same security policies apply. The major difference here is that your home PC is not likely to go anywhere, but you can easily lose your cell phone, whether it's in a cab or at a restaurant. So a piece of advice for anyone thinking about using their cell phone as a payment device: Treat it with the same care as you do your credit card; don't leave it unattended!


Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
T-Shirt Giveaway T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting!
Subscribe to RSS

Resource Links