FAQs for Two-factor Authentication



Similar documents
Foreign Taxes Paid and Foreign Source Income INTECH Global Income Managed Volatility Fund

Report on Government Information Requests

Configuring DHCP for ShoreTel IP Phones

Supported Payment Methods

Quantum View Manage Administration Guide

Supported Payment Methods

BT Premium Event Call and Web Rate Card

Reporting practices for domestic and total debt securities

World Consumer Income and Expenditure Patterns

.com. Table of contents. Fax to

Appendix 1: Full Country Rankings

Vodafone Traveller and Vodafone World


OCTOBER Russell-Parametric Cross-Sectional Volatility (CrossVol ) Indexes Construction and Methodology

Visa Information 2012

41 T Korea, Rep T Netherlands T Japan E Bulgaria T Argentina T Czech Republic T Greece 50.

Report on Government Information Requests

How many students study abroad and where do they go?

How To Get A New Phone System For Your Business

Report on Government Information Requests

CMMI for SCAMPI SM Class A Appraisal Results 2011 End-Year Update

Global Effective Tax Rates

Cisco IOS Public-Key Infrastructure: Deployment Benefits and Features

Brochure More information from

Schedule R Teleconferencing Service

Global Economic Briefing: Global Inflation

Report on Government Information Requests

DIR Contract #DIR-TSO-2610 Amendment #1 Appendix C Price Index

Electronic Citizen Identities and Strong Authentication

Microsoft Dynamics CRM Online. Pricing & Licensing. Frequently Asked Questions

Connected Life. Connected Life TNS

Preventing fraud and corruption in public procurement

E-Seminar. Financial Management Internet Business Solution Seminar

Cisco Conference Connection

CISCO CONTENT SWITCHING MODULE SOFTWARE VERSION 4.1(1) FOR THE CISCO CATALYST 6500 SERIES SWITCH AND CISCO 7600 SERIES ROUTER

IOOF QuantPlus. International Equities Portfolio NZD. Quarterly update

Get the benefits of Norgren s unique range of Online services

Microsoft Dynamics CRM Online. Pricing & Licensing. Frequently Asked Questions

Agilent Mobile WiMAX R&D Test Set Solutions: Software and Technical Support Contract

Lawson Business Intelligence. Solutions for Healthcare

Trends in Digitally-Enabled Trade in Services. by Maria Borga and Jennifer Koncz-Bruner

GE Grid Solutions. Providing solutions that keep the world energized Press Conference Call Presentation November 12, Imagination at work.

A free call from your Roadpost satellite phone: A free call from North America:

Overview menu: ArminLabs - DHL Medical Express Online-Pickup: Access to the Online System

Credit & Debit Card Payments. Factsheet

International Call Services

CNE Progress Chart (CNE Certification Requirements and Test Numbers) (updated 18 October 2000)

The Role of Banks in Global Mergers and Acquisitions by James R. Barth, Triphon Phumiwasana, and Keven Yost *

The VAT & Invoicing Requirements Update March 2012

Hong Kong s Health Spending 1989 to 2033

DSV Air & Sea, Inc. Aerospace Sector. DSV Air & Sea, Inc. Aerospace

Table of Contents. Conferencing Basics 3. Ready Bridge Set Up Options 4. Call Control Features 5. Security Features 6. Call Control Commands 7

Global AML Resource Map Over 2000 AML professionals

Brochure More information from

Office 365. Service Overview with a focus on Identity Federation and Directory Synchronization. Jono Luk, Program Manager jluk@microsoft.

THE CISCO CRM COMMUNICATIONS CONNECTOR GIVES EMPLOYEES SECURE, RELIABLE, AND CONVENIENT ACCESS TO CUSTOMER INFORMATION

Installation Guide E Dielectric Probe Kit 85071E Materials Measurement Software

BROWN BROTHERS HARRIMAN (LUXEMBOURG) S.C.A. Wells Fargo (Lux) Worldwide Fund

Theatres/Channels All theatres. Indirect channel. Author/Owner

The face of consistent global performance

SunGard Best Practice Guide

Lawson Talent Management

Delegation in human resource management

Please note all PSTN & ISDN lines will be provisioned will all outgoing calls barred unless otherwise agreed.

THE WORLD S LEADING CAR DESIGN MAGAZINE

TOWARDS PUBLIC PROCUREMENT KEY PERFORMANCE INDICATORS. Paulo Magina Public Sector Integrity Division

Microsoft Voucher Ordering Processes

July Figure 1. 1 The index is set to 100 in House prices are deflated by country CPIs in most cases.

Release Notes: PowerChute plus for Windows 95 and Windows 98

Global Dialing Comment. Telephone Type. AT&T Direct Number. Access Type. Dial-In Number. Country. Albania Toll-Free

Know the Facts. Aon Hewitt Country Profiles can help: Support a decision to establish or not establish operations in a specific country.

FedEx is the preferred and primary courier company for BP small package, parcel and express envelope (up to 150 lbs.) requirements worldwide.

The value of accredited certification

MANDATORY PROVIDENT FUND SCHEMES AUTHORITY

Responding to Healthcare s Most Urgent Business Issues. Gundersen Lutheran Health System Case Study

E-Seminar. E-Commerce Internet Business Solution Seminar

Accuracy counts! SENSORS WITH ANALOG OUTPUT

STATISTICS FOR THE FURNITURE INDUSTRY AND TRADE

Vodafone encourages customers to go on roamin holiday. ~ Vodafone uses worldwide scale to slash international data roaming charges ~

Expenditure and Outputs in the Irish Health System: A Cross Country Comparison

The big pay turnaround: Eurozone recovering, emerging markets falter in 2015

MAUVE GROUP GLOBAL EMPLOYMENT SOLUTIONS PORTFOLIO

Senate Committee: Education and Employment. QUESTION ON NOTICE Budget Estimates

Triple-play subscriptions to rocket to 400 mil.

THE ETHICS HELPLINE Worldwide Dialing Instructions April 2012

Consumer Credit Worldwide at year end 2012

Cisco CNS NetFlow Collection Engine Version 4.0

Motion Graphic Design Census. 10 hrs. motiongraphicdesigncensus.org. 9 hrs.

ishares MSCI ACWI ex US Consumer Discretionary Sector Index Fund ishares MSCI ACWI ex US Energy Sector Index Fund

Higher education institutions as places to integrate individual lifelong learning strategies

Quantum View Manage User Guide

Guide. Axis Webinar. User guide

Quantum View SM Manage Administration Guide

Agilent N5970A Interactive Functional Test Software: Installation and Getting Started

CISCO IP PHONE SERVICES SOFTWARE DEVELOPMENT KIT (SDK)

- 2 - Chart 2. Annual percent change in hourly compensation costs in manufacturing and exchange rates,

Corporate Office Von Karman Ave Suite 150 Irvine, California Toll Free: Fax:

Voice Internet Phone Gateway

Transcription:

FAQs for Two-factor Authentication Two-factor Authentication 1. What is two-factor authentication? Two-factor authentication is an authentication scheme that increases online security by relying on a combination of two different factors, something you know (e.g. user ID and password) and something you have (e.g. digital certificate or mobile phone SIM card) in the verification of a user s identity. 2. Why is two-factor authentication needed for internet banking transactions? Although they may be able to illegally obtain your user ID or password, fraudsters cannot steal something you have in your physical possession, such as a digital certificate or mobile phone, over the internet. 3. When do you need to use a one-time password or digital certificate? You need to use either a one-time password or digital certificate when conducting any of the following designated transactions: Fund transfers to non-registered BEA accounts in Hong Kong or China Fund transfers to non-registered accounts at other local banks through CHATS or Electronic Clearing Bill payments to merchants, except when the receiving merchant falls under the Government or Statutory Organisation, Utilities, Education: Primary or Secondary School, or Education: Post-secondary or Specialised Institution categories Set-up of scheduling instructions or templates for the above-mentioned transactions Any new transaction types prescribed by BEA from time to time 4. After I have used two-factor authentication to create my templates, do I need to use two-factor authentication again when I perform transactions using the authenticated template? You do not need to use one-time password/digital certificate to complete the transaction unless you change the deposit account or bill account number for the transaction. 5. Do I need to use one-time password/digital certificate to authenticate my templates created before 23 June 2005? No. All templates, which have been created before 23 June 2005, will not be affected by the two-factor authentication arrangement. 6. Do I need to go to a BEA branch to register for one-time password or digital certificate? This is not necessary. You can register for a one-time password or digital certificate by directly accessing Cyberbanking internet service. 7. Can I register for both a one-time password and a digital certificate? Yes. In fact, we strongly recommend that you register for both. Page 1 of 5

One-time Password 8. What is a one-time password? A one-time password is an SMS-based password generated by a bank and sent to your registered mobile phone number as an additional form of identity authentication. A onetime password enables you to perform designated transactions through Cyberbanking internet service. Each password is used only once for a designated transaction and expires after 100 seconds. 9. How do I use a one-time password? When you perform a designated transaction through Cyberbanking internet service, a one-time password will be sent to your registered mobile phone. You must input the password on the web page to complete your transaction. 10. What is the use of BEA Authentication Message? The BEA Authentication Message will appear on your mobile phone or PDA to identify the sender (BEA) of SMS Communications in future. 11. Why am I unable to successfully register for a one-time password? When you register for a one-time password, the mobile phone number that you use must be the same as the one you have registered with BEA. If not, please approach any BEA branch to have your record updated and then try again. 12. What should I do if I receive an SMS containing a one-time password on my mobile phone but am not performing any internet banking transactions? Please contact the Cyberbanking Customer Services Hotline on 2211 1345 immediately. 13. Is there any charge for using one-time password in Cyberbanking? It is free of charges at the time being. On the other hand, your mobile network operator may charge you for SMS usage fee for accessing the services. Details please refer to your mobile network operator. 14. Do I need to enroll the service for receiving SMS messages with telecommunication companies in order to receive SMS messages? Customer does not need to apply for the SMS with your telecommunication company as all mobile phones or PDAs are capable of receiving SMS. Page 2 of 5

15. Can I register an overseas mobile phone number for using the service? You can register an overseas mobile phone number for using the service. Mobile phone numbers of the following countries would support the service currently: Country Country Code Country Country Code North America Asia USA, Canada 1 Malaysia 60 Europe Philippines 63 Russia 7 Singapore 65 Greece 30 Japan 81 Netherlands 31 South Korea 82 Belgium 32 Vietnam 84 France 33 China 86 Spain 34 India 91 Hungary 36 Hong Kong 852 Italy 39 Macau 853 Switzerland 41 Taiwan 886 Austria 43 Israel 972 United Kingdom 44 Oceania Denmark 45 Australia 61 Sweden 46 New Zealand 64 Norway 47 Poland 48 Germany 49 Portugal 351 Luxembourg 352 Ireland 353 Finland 358 Czech Republic 420 Remarks: Not all the mobile phone numbers from the above-mentioned countries can receive an international SMS messages. Prior to the service registration, please confirm with your mobile network operator whether your mobile phone number/service plan can receive an international SMS. 16. Can I register a pre-paid SIM card mobile phone number for using the service? You cannot register a pre-paid SIM card mobile phone number for using the service. Page 3 of 5

Digital Certificate 17. What is a digital certificate? A digital certificate is a form of electronic identification that helps establish your identity online. A digital certificate enables you to perform designated transactions through Cyberbanking internet service. It can be stored in a Hong Kong Smart ID card or USB Token. 18. How do you use a digital certificate when making an internet banking transaction? When you perform a designated transaction through Cyberbanking internet service, you need to insert your Hong Kong Smart ID card/usb token storing your digital certificate into a smart card reader/usb drive and type the e-cert PIN/USB token PIN to complete the transaction. After the transaction is completed, please remove the Hong Kong Smart ID card/usb token from the device immediately. 19. Why I need digital certificate? Digital certificate provides: Confidentiality: the information contained in the message is kept confidential and only the sender and the intended recipient will be able to read and understand it; Authenticity: proof of identity of the parties to an electronic transaction; Integrity: assurance that the contents of a message have not been tampered with or modified; Non-repudiation: proof of agreement to the terms of the transaction and prevention of denial of commitment. 20. Which kind of digital certificates are accepted by Cyberbanking? You can use any one of the following digital certificates for Cyberbanking: Hongkong Post e-cert (Personal) for Smart ID Card Hongkong Post e-cert (Personal) Digi-Sign Personal ID-Cert Class 1 21. Is there any charge for using digital certificate in Cyberbanking? It is free of charges at the time being. 22. How can I register my digital certificate in Cyberbanking? First of all, you shall log in to Cyberbanking and register your digital certificate under Two-factor Authentication option of Settings function. Then, you can use your registered digital certificate to conduct designated transactions in Cyberbanking. 23. Can I use my digital certificate to log in to Cyberbanking? If you want to use digital certificate for login, please log in to Cyberbanking and register/update your digital certificate by selecting the Login to Cyberbanking with digital certificate option. Afterwards, you can use digital certificates to log in to Cyberbanking and confirm designated transactions prescribed by BEA. Page 4 of 5

24. If I have a joint account, do I need to register all account holders digital certificates in Cyberbanking? Each account holder shall register his/her digital certificate one by one in Cyberbanking. After the first account holder is registered his/her digital certificate, the other account holder can then register his/her digital certificate. 25. If my registered digital certificate will be expired soon, what should I do? You should renew your digital certificate with your Certification Authority one month before the expiry date of your digital certificate. Then, you should log in to Cyberbanking and update it with your renewed digital certificate under Two-factor Authentication option of Settings function. 26. If my registered digital certificate is expired, what should I do? You should visit any of BEA branches in person to cancel the use of digital certificate in your Cyberbanking account. 27. What certificate storage devices can I use to log in to Cyberbanking? You can choose one of the following devices: Smart ID Card USB Token 28. What do I need to install if I want to use Smart ID Card for Cyberbanking? You should install the e-cert Control Manager software provided by Hongkong Post before you use Smart ID Card in Cyberbanking if you are using Windows 98/NT/ME, you are also required to install a Microsoft Management Console in your PC. For details and download the softwares, please visit Hongkong Post website (http://www.hongkongpost.gov.hk/). (Notes: e-cert Control Manager software is not yet supported Windows Vista.) 29. Why the browser screen will be erased when I drag the e-cert PIN input box for input Smart ID Card PIN? You should not drag the box and enter your Smart ID Card PIN into the box directly to complete the transaction. 30. What should I do if I input wrong Smart ID Card PIN for 5 times? Your Smart ID Card might be blocked. You are advised to visit Hongkong Post in person to unblock the Smart ID Card. 31. Why I can conduct another designated transactions again without entering Smart ID Card PIN just after successful execution of a designated transaction for less than 1 minute? This is a default setting of Password Timeout in e-cert Control Manager. The system will request you to input Smart ID Card PIN after 1 minute. Page 5 of 5