Passe passwords

  • Associated Press
  • Tuesday, June 1, 2004 9:00pm
  • Business

To access her bank account online, Marie Jubran opens a Web browser and types in her Swedish national ID number along with a four-digit password.

For additional security, she then pulls out a card that has 50 scratch-off codes. Jubran uses the codes, one by one, each time she logs on or performs a transaction. Her bank, Nordea PLC, automatically sends a new card when she’s about to run out.

As more Web sites demand passwords, scammers are getting more clever about stealing them. Hence the need for such “passwords-plus” systems.

Scandinavia countries are among the leaders as many online businesses abandon static passwords in favor of so-called two-factor authentication.

“A password is a construct of the past that has run out of steam,” said Joseph Atick, chief executive of Identix Inc., a Minnesota designer of fingerprint-based authentication. “The human mind-set is not used to dealing with so many different passwords and so many different PINs.”

When a static password alone is required, security experts recommend that users combine letters and numbers and avoid easy-to-guess passwords such as “1234” or a nickname.

Stevan Hoffacker follows those rules but commits a different faux pas: He uses the same password everywhere, including access to multiple e-mail accounts, Amazon.com, The New York Times’ Web site and E-ZPass electronic toll statements.

In such cases, should hackers or scammers compromise one account, they potentially have one’s entire online life.

“This is one of these things that if I stop and think about it, it is not good, but I do my best not to stop and think about it,” said Hoffacker, an information technology manager in New York.

But it’s difficult to remember dozens of strong passwords – so many sites now require them. Alternatives include writing them down on a sticky note attached to a monitor or in an electronic spreadsheet – practices security experts also deem unsafe.

With two-factor authentication, having a password alone is useless.

“We will never play the fear factor here, but still it stays a fact that with our products, ‘phishing’ (cracking a password code) is no longer an issue,” said Jochem Binst of Vasco Data Security International Inc.

The Belgian company issues devices the size of pocket calculators or keychains. You type your regular password into the device for a second code that is based on the time and the unit’s unique characteristics. That’s the code you type into the Web site.

Someone who steals your device won’t have your password; someone who steals your password won’t have your device.

MasterCard International Inc. has been testing similar systems in Britain, Germany and Brazil. Swipe a credit card with a smart chip into a special reader, enter your PIN and obtain a password good only once at Office Max, British Airways and a dozen other merchants.

In Singapore, bank customers wishing to designate new accounts for fund transfers must likewise obtain a second password – through a phone call, e-mail or mobile text messaging.

Biometric systems are similar, except a fingerprint or iris scan replaces one or both passwords.

In the United States, use of two-factor authentication remains limited.

U.S. banks and e-commerce companies have focused, for now, on making sure passwords are strong. EBay, for instance, now rejects attempts to create passwords such as “eBay” or “password.”

Before two-factor authentication becomes commonplace, laptops must come standard with biometric readers, or manufacturers must bring down costs for password-generating devices.

Outfitting 1 million customers with such devices could cost $20 million, while Internet fraud for those customers amounts to “tens of thousands at most,” said Tony Chew, director of technology risk supervision at the Monetary Authority of Singapore. Singapore banks thus limit dynamic passwords to fund transfers, he said.

Associated Press

Marie Jubran of Stockholm refers to a code from a scratch-off card that she uses to get access to her bank account.

Talk to us

> Give us your news tips.

> Send us a letter to the editor.

> More Herald contact information.

More in Business

Lily Lamoureux stacks Weebly Funko toys in preparation for Funko Friday at Funko Field in Everett on July 12, 2019.  Kevin Clark / The Herald)
Everett-based Funko ousts its CEO after 14 months

The company, known for its toy figures based on pop culture, named Michael Lunsford as its interim CEO.

The livery on a Boeing plane. (Christopher Pike / Bloomberg)
Former Lockheed Martin CFO joins Boeing as top financial officer

Boeing’s Chief Financial Officer is being replaced by a former CFO at… Continue reading

Izaac Escalante-Alvarez unpacks a new milling machine at the new Boeing machinists union’s apprentice training center on Friday, June 6, 2025 in Everett, Washington. (Olivia Vanni / The Herald)
Boeing Machinists union training center opens in Everett

The new center aims to give workers an inside track at Boeing jobs.

Some SnoCo stores see shortages after cyberattack on grocery supplier

Some stores, such as Whole Foods and US Foods CHEF’STORE, informed customers that some items may be temporarily unavailable.

People take photos and videos as the first Frontier Arlines flight arrives at Paine Field Airport under a water cannon salute on Monday, June 2, 2025 in Everett, Washington. (Olivia Vanni / The Herald)
Water cannons salute Frontier on its first day at Paine Field

Frontier Airlines joins Alaska Airlines in offering service Snohomish County passengers.

Amit B. Singh, president of Edmonds Community College. 201008
Edmonds College and schools continue diversity programs

Educational diversity programs are alive and well in Snohomish County.

A standard jet fuel, left, burns with extensive smoke output while a 50 percent SAF drop-in jet fuel, right, puts off less smoke during a demonstration of the difference in fuel emissions on Tuesday, March 28, 2023 in Everett, Washington. (Olivia Vanni / The Herald)
Sustainable aviation fuel center gets funding boost

A planned research and development center focused on sustainable aviation… Continue reading

Helion's 6th fusion prototype, Trenta, on display on Tuesday, July 9, 2024 in Everett, Washington. (Olivia Vanni / The Herald)
Helion celebrates smoother path to fusion energy site approval

Helion CEO applauds legislation signed by Gov. Bob Ferguson expected to streamline site selection process.

Pharmacist John Sontra and other employees work on calling customers to get their prescriptions transferred to other stores from the Bartell Drugs Pharmacy on Hoyt Avenue on Wednesday, July 2, 2025 in Everett, Washington. (Olivia Vanni / The Herald)
Bartell Drugs location shutters doors in Everett

John Sontra, a pharmacist at the Hoyt Avenue address for 46 years, said Monday’s closure was emotional.

Support local journalism

If you value local news, make a gift now to support the trusted journalism you get in The Daily Herald. Donations processed in this system are not tax deductible.