Online Banking Also Known As Internet Banking, E-Banking, or Virtual Banking, Is An Electronic Payment System That Enables Customers of A Bank or
Online Banking Also Known As Internet Banking, E-Banking, or Virtual Banking, Is An Electronic Payment System That Enables Customers of A Bank or
Online Banking Also Known As Internet Banking, E-Banking, or Virtual Banking, Is An Electronic Payment System That Enables Customers of A Bank or
Advantages[edit]
There are some advantages on using e-banking both for banks and customers:
Access anywhere
No security problems
Security[edit]
The PIN/TAN system where the PIN represents a password, used for the
login and TANs representing one-time passwords to authenticate
transactions. TANs can be distributed in different ways, the most popular one
is to send a list of TANs to the online banking user by postal letter. Another
way of using TANs is to generate them by need using a security token. These
token generated TANs depend on the time and a unique secret, stored in the
security token (two-factor authentication or 2FA).
More advanced TAN generators (chipTAN) also include the transaction
data into the TAN generation process after displaying it on their own
screen to allow the user to discover man-in-the-middle attacks carried out
by Trojans trying to secretly manipulate the transaction data in the
background of the PC.[6]
Another way to provide TANs to an online banking user is to send the TAN
of the current bank transaction to the user's (GSM) mobile phone via SMS.
The SMS text usually quotes the transaction amount and details, the TAN
is only valid for a short period of time. Especially in Germany, Austria and
the Netherlands many banks have adopted this"SMS TAN" service.
Usually online banking with PIN/TAN is done via a web browser using SSL
secured connections, so that there is no additional encryption needed.
Signature based online banking where all transactions are signed
and encrypted digitally. The Keys for the signature generation and
encryption can be stored on smartcards or any memory medium,
depending on the concrete implementation (see, e.g., the
Spanish ID card DNI electrnico[7]).
Attacks
Attacks on online banking used today are based on deceiving the user
to steal login data and valid TANs. Two well known examples for those
attacks are phishing and pharming.Cross-site
scripting and keylogger/Trojan horses can also be used to steal login
information.
Countermeasures
There exist several countermeasures which try to avoid attacks. Digital
certificates are used against phishing and pharming, in signature
based online banking variants (HBCI/FinTS) the use of "Secoder" card
readers is a measurement to uncover software side manipulations of
the transaction data.[11] To protect their systems against Trojan horses,