Jump to content

AOL Moves Beyond Passwords for Log-Ons


Alpha

Recommended Posts

By ANICK JESDANUN, AP Internet Writer

 

NEW YORK - Passwords alone won't be enough to get onto America Online under a new, optional log-on service that makes AOL the first major U.S. online business to offer customers a second layer of security.

 

The so-called two-factor authentication scheme, being unveiled Tuesday, will cost $1.95 a month in addition to a one-time $9.95 fee. It is initially targeted at small businesses, victims of identity theft and individuals who pay a lot of bills and conduct other financial transactions through their AOL accounts.

 

Subscribers get a matchbook-size device from RSA Security Inc. displaying a six-digit code that changes every minute. The code is necessary to log on, so a scammer who guesses or steals a password cannot access the account without the device in hand.

 

Two-factor authentication — whether through the RSA device, biometrics or cards printed with rotating lists of passwords — is common in Scandinavia, Brazil, Singapore and selected countries. In the United States, its use is largely limited to employees accessing office networks remotely, or people with high-value financial portfolios.

 

AOL spokesman Andrew Weinstein said the time was ripe to offer it as subscribers move more of their sensitive personal, business and financial information online.

 

The offering also comes as scammers increasingly find ways to trick subscribers into giving their passwords by sending e-mail disguised as legitimate information requests.

 

And with so many sites now requiring passwords, many Internet users have become careless: They create easy-to-remember passwords that tend to be easy to guess — or they write them down on sticky notes and post them at their computers.

 

By requiring the second, rotating password, "you don't have to remember complicated passwords to still have good security," said Scott Schnell, a senior vice president at RSA Security.

 

The second password will be required for checking e-mail and accessing services tied to the AOL account, including calendars, stock portfolios and AOL's Bill Pay.

 

It won't protect services offered by third parties on the open Internet, outside AOL's walled gardens, except in cases where their statements and other sensitive information are sent to the AOL e-mail account. Nor is the second password needed to use AOL Instant Messenger.

 

Gartner analyst Avivah Litan believes a "very narrow set of consumers" — perhaps 5 percent to 15 percent of AOL's 30 million subscribers — would sign up, but "you have to start somewhere."

 

She said AOL's offering likely would prompt other Internet service providers and banks to consider such systems more seriously, though the prevailing belief these days is that customers will find them difficult to use.

 

Just this summer, HSBC Bank USA began requiring a second password to access its bill-payment services.

 

That password is entered using an on-screen keypad to thwart snoops who secretly install software that records keystrokes as they are typed on a regular keyboard.

 

Unlike AOL's service, though, neither password automatically changes, nor is there a charge.

This is pretty cool to say the least, I wonder when they are going to scan our eyes for security. ;)

Link to comment
Share on other sites

I want biometrics now. When I turn my computer on, I want to do a key card scan, a thumb print scan, AND a retina scan. And then it should say "*Beep* *boop*, have a nice day" in a sexy voice. And then I want it to reach out and fondle my...time to stop right there. ;)

Link to comment
Share on other sites

I want biometrics now. When I turn my computer on, I want to do a key card scan, a thumb print scan, AND a retina scan. And then it should say "*Beep* *boop*, have a nice day" in a sexy voice. And then I want it to reach out and fondle my...time to stop right there. :P

You forgot hair sample.

Link to comment
Share on other sites

Sheesh, I don't want biometric identification just to use my computer! I mean, sure, additional security against h4x0rs would be useful, but talk about a big-brother way to do it! I'm really surprised this is happening in Europe, too, what with their restrictive privacy laws!

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...