Saturday, May 17, 2008

The Push and Pull of Consumer Authentication

Blogger: Mark Diodati I was speaking with a colleague at a large financial institution. The topic: can organizations “push” information (e.g., bank statements) to consumers via email and still be compliant with the FFIEC guidelines (on the insufficiency of single factor authentication)? After thinking about it, I believe the question is broader: Is security adequate when pushing sensitive information via email? Some financial institutions email their customers to let them know that their st