It's quite laughable really, if I'm logging into my bank I type HSBC.co.uk first, anything following that is my International Banking number, following that is my password (which is the best defence you state) and date of birth. If I was required to enter all 8 numbers my password would be the easiest thing to catch.
The only better defence I can think is to have a user enter 3 genuine numbers from their password and 3 randomly generated numbers given to you, but it the 6 numbers are requested randomly. Requesting only random genuine numbers gives you encryption by hiding the sequence of the numbers, if you are also hiding the genuine numbers it's two levels of deceit.
Some banks in South Africa used to bring up a little image keyboard and you click the letters (ie no keyboard) in my mind this is still one of the best ways to protect against keylogging.
Storing the password in a truecrypted file and copy pasting also works. Though, for someone going to those lengths, a keylogger is a very unlikely to be a problem for someone paying that much attention.
Comments
It's quite laughable really, if I'm logging into my bank I type HSBC.co.uk first, anything following that is my International Banking number, following that is my password (which is the best defence you state) and date of birth. If I was required to enter all 8 numbers my password would be the easiest thing to catch.
The only better defence I can think is to have a user enter 3 genuine numbers from their password and 3 randomly generated numbers given to you, but it the 6 numbers are requested randomly. Requesting only random genuine numbers gives you encryption by hiding the sequence of the numbers, if you are also hiding the genuine numbers it's two levels of deceit.
I wish hsbc gave you the numbers it wanted you to enter as images too. Makes it a little more difficult to parse.
Some banks in South Africa used to bring up a little image keyboard and you click the letters (ie no keyboard) in my mind this is still one of the best ways to protect against keylogging.
Storing the password in a truecrypted file and copy pasting also works. Though, for someone going to those lengths, a keylogger is a very unlikely to be a problem for someone paying that much attention.
A software key-logger can also typically snoop the contents of the clipboard.
which is what my bank does. (Lloyds).