In Internet banking, as with traditional banking methods, security is a primary concern. We have taken precautions to ensure your information is transmitted safely and securely. This Level of Security is achieved in part by:
- Protecting the privacy and the confidentiality of the communications between your browser and our servers.
- Verifying that only authorized persons are allowed to access online banking.
- Maintaining isolation of our computers from the Internet.
The privacy of the communications between you (your browser) and our servers is ensured using encryption. Encryption scrambles messages exchanged between your browser and our online banking server. Encryption happens as follows: When you go to the sign-on page for online banking, your browser establishes a secure session with our server. The secure session is established using a protocol called Secure Sockets Layer (SSL) Encryption. This protocol requires the exchange of what are called public and private keys. Keys are random numbers chosen for that session and are only known between your browser and our server. After the keys are exchanged, your browser will use the numbers to scramble (encrypt) the messages sent between your browser and our server. Both sides require the keys because they need to de-scramble (decrypt) the messages when they are received. The SSL protocol not only ensures privacy, but also ensures that no other web site can “impersonate” your SCU Credit Union’s web site, nor alter any of the information sent. You can tell whether your browser is in secure mode by looking for the secured lock symbol at the top of your browser window.
The numbers used as encryption keys are analogous to combination locks. The strength of encryption is based on the number of possible combinations that a lock can have. As the number of possible combinations grows, it becomes less likely that anyone would be able to guess the combination in order to decrypt the message. SCU Credit Union uses an Extended Validation certificate that operates at an encryption level of 256-bit. Users will be unable to access online banking functions at lesser encryption levels. This may require some end users to upgrade their browser to the stronger encryption level in order to access online banking functions.
It is also important to verify that only authorized persons log into online banking. This is achieved by verifying your password. When you submit your password, it is compared with the password we have stored in our secure data center. We allow you to enter your password incorrectly a limited number of times. If you enter your password incorrectly too many times, your online banking account will be locked until you call us to reinitialize the account. We monitor and record “bad-login” attempts to detect any suspicious activity (i.e., someone trying to guess your password). You play a crucial role in preventing others from logging on to your account. Never use passwords that are easy to guess. Examples of bad passwords are: Birth dates, first names, pet names, addresses, phone numbers, social security numbers, etc. Never reveal your password to another person. You should periodically change your password in the User Option screen of online banking.
We provide a number of additional security features in online banking. Online banking will “timeout” after a specified period of inactivity. This prevents curious persons from continuing your online banking session in case you have left your PC unattended without logging out. You may set the timeout period in the User Options screen of online banking. However, we recommend that you always sign-off (log out) when you are done with your online banking. The network architecture used to provide the online banking service was designed by the brightest minds in network technology. While the architecture is too complex to explain here, it is important to point out that the computers that store your actual account information are not hooked up to the Internet. The transactions that you initiate through the Internet are received by our online banking Web servers. These Web servers route your transaction through firewall servers, which act as a traffic cop between segments of our online banking network used to store information, and the public Internet. This configuration isolates the publicly accessible Web servers from data stored on our online banking servers and ensures that only authorized requests are processed. Various access control mechanisms, including intrusion detection and anti-virus, monitor for and protect our systems from potential malicious activity. Additionally, our online banking servers are fault-tolerant, and provide for uninterruptible access, even in the event of various types of failures.