HSBC deploys 'simple' anti-fraud measure using the phone
Rather than fiddle around with authentication devices like card readers, HSBC customers will be able to prove who they say they are just by speaking into the telephone.

HSBC has implemented a new anti-fraud measure to authenticate online users attempting certain transactions against the bank's online accounts, simply by using the telephone.
The new Authentify system will use out-of-band' authentication, which here means using the phone to verify the identity of a user involved in the transaction. This is opposed to other banks such as Nationwide, who have used two-factor' authentication, which usually involves devices generating one-time passcodes.
Nick Staib, Senior Manager of Digital Security at HSBC, spoke to IT PRO about the new system. He said that the bank considered the notion of two-factor authentication to be fundamentally flawed
This was because although the passcode could be generated from a device or token which was perfectly fine, it could still be typed into a computer that was compromised by malware.
The out-of-band process involves user specific details being entered into the telephone separately from the internet side of the exchange, which means that the authentication process is isolated from internet threats.
The system will be used when a customer makes a payment to somebody that they have never sent money to before.
The system works like this. HSBC provides users with an on screen code.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
The customer provides their phone number, waits for the phone to ring, answers the call and speaks the onscreen code into the handset.
Staib said of Authentify: "I don't believe that there are many other companies who offer this, and they have worked with other companies we respect in the past."
"As a user, I believe that PayPal uses this mechanism, and I believe that Halifax were in discussions with them as well."
Of HSBC's future plans for online security he said that there was obvious difficulty in revealing what the future was. However, he said: "I think everybody in this business knows that it isn't an arms race, but a dynamic threat environment.
"We do not just rely on this mechanism. We adopt a layered approach to security. We try to do the work ourselves so our customers don't have to do it."
-
Bigger salaries, more burnout: Is the CISO role in crisis?
In-depth CISOs are more stressed than ever before – but why is this and what can be done?
By Kate O'Flaherty Published
-
Cheap cyber crime kits can be bought on the dark web for less than $25
News Research from NordVPN shows phishing kits are now widely available on the dark web and via messaging apps like Telegram, and are often selling for less than $25.
By Emma Woollacott Published
-
Microsoft Authenticator mandates number matching to counter MFA fatigue attacks
News The added layer of complexity aims to keep social engineering at bay
By Connor Jones Published
-
As Google launches passwordless authentication for all, what are the business benefits of passkeys?
News Google follows Apple in its latest shift to passwordless authentication, but what are the benefits?
By Ross Kelly Published
-
There's only one way to avoid credential stuffing attacks
Opinion PayPal accounts were breached last year due to a credential stuffing attack, but can PayPal avoid taking responsibility?
By Davey Winder Published
-
Google Authenticator 2FA update accused of making service less secure
News Lack of end-to-end encryption in code backup has some developers worried
By Rory Bathgate Published
-
Five things to consider before choosing an MFA solution
In-depth Because we all should move on from using “password” as a password
By Rene Millman Published
-
What is multi-factor authentication (MFA) fatigue and how do you defend against attacks?
In-depth Strong authentication is key to security, but it needs to be properly managed to avoid MFA fatigue
By Sandra Vogel Published
-
Beyond Identity strikes up strategic partnership with World Wide Technology
News WWT will implement Beyond Identity’s authentication platform internally while also acting as a global channel partner
By Daniel Todd Published
-
Implementing strong authentication across your business
In-depth Strong authentication is hugely important, but implementing any regime at scale is not without its challenges
By Sandra Vogel Published