Imran Khan · · 5 min read

How secure is your customers’ sensitive data?

Sponsored by Clickatell

Internet security is crucial to protecting our data

Photo credit: Esther Vargas

Online security has become a hot button issue ever since the Snowden leaks. Users are demanding greater security of their data, and vendors and service providers are ramping up the sophistication of their firewalls. The idea of online security is not new of course, but no solution has ever been 100 percent secure. Governments, businesses, and personal users have all struggled with implementing stronger security. Here’s a quick rundown of some of those solutions over time.

Enter username and Passw0rd$

The password has been our primary barrier for decades. Most aren’t sure when the first computer password was developed, but research points toward MIT and its Compatible Time-Sharing System machine from way back in the 1960s. It’s a machine that has impressive legacy, with its involvement in the development of email, messaging, virtual machines, and file sharing. At a time when knowledge-based authentication also could have been implemented (with the machine asking you personal questions like your first pet’s name), passwords were a much easier – and much cheaper – fix.

That machine was also a surprising foreshadowing of our current relationship with the password: it didn’t really work. One day in 1966, a computer error caused everybody’s passwords to become public knowledge, rendering that protective layer obsolete.

Password required

Photo credit: Elias Bizannes.

We’ve come a long way since then, but, even with the rapid changes in technology and a proliferation of devices, passwords are only as good as they are complex. And while businesses have been offering tips and tricks on how to make passwords more intricate and complex, even showcasing how secure your password is, people are still using 123456 as a password in 2015.

And that’s the problem with passwords. You have to make them complex to be more secure, but that makes remembering them a pain. And with an increased number of services moving online, the number of passwords the average person has to remember has moved into the double digits. It’s no wonder that on average, each inbox has 37 ‘forgotten password’ emails. So how do businesses ensure that their customer data remains secure?

CAPTCHAs enter the picture

CAPTCHA

Photo credit: Phil Whitehouse.

You might be very familiar with this image. Online services have been using CAPTCHA (fun fact: it stands for Completely Automated Public Turing test to tell Computers and Humans Apart) to authenticate users for a few years now, and the amount of sophistication that can be built into CAPTCHAs nowadays is quite impressive. In an effort to combat the problem of making CAPTCHAs too difficult for humans to read, options like audio alternatives to the text, allowing users to load different CAPTCHAs, using numbers instead of letters, have all made using CAPTCHAs that little bit easier. But the truth is that users still find this system a difficult and cumbersome method to authenticate their humanness. Keeping bots out of your secure data is crucial to protecting the integrity of your data, but how else can service providers do so successfully?

Online security gets some new ideas

In an effort to make the user journey more secure online, two-step authentication was introduced to provide an extra layer of security during online transactions. The process involves you entering your password, then having a code sent to a secondary device to enter into the system before you’re allowed in. This provides a more stringent security barrier, as you require two devices to log in to a service. Simply stealing somebody’s password is not enough. You would have to steal multiple devices to be able to maliciously access somebody’s data, and faking such a process for bots can be difficult.

A natural evolution of this system has been Clickatell’s new Secure Grid service, where users are asked to interact with a grid of pictures rather than being sent a pin. For example, customers log into their bank account, they are redirected to their phone, where an SMS awaits them. But the SMS doesn’t contain a code, rather a link. Clicking on the link takes them to a secondary authentication page where they are asked to answer questions that are simple enough for human logic but difficult for machines to mimic. It asks users to do something like “Select the horse” from six different pictures, allowing the system to authenticate your customers’ humanness without them having to remember another password or having to decipher unreadable CAPTCHAs.

The process is quite simple.

Data breaches aren’t new, but the technology for ordinary people to tackle them is improving, making it easier to be safe while you surf online.


Since 2000, Clickatell has been at the forefront of global mobile messaging. Through our powerful bulk SMS Gateway and reliable, easy to integrate SMS APIs, businesses are empowered to connect with their customers anywhere in the world, on even the most basic phones. Each day, we help companies to benefit from the phenomenal 98% open-rate of SMS messages, and give them the tools to grow and accelerate their brands across 220+ global destinations.

Headquartered in Redwood City, California, Clickatell was named among the 100 Most Innovative Companies in America in 2012 by Redherring.com.

Get started with a free account at www.clickatell.com.

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.

How would you feel if you could no longer use Tech in Asia?

Editing by Steven Millward

(And yes, we’re serious about ethics and transparency. More information here.)

Community Writer

Imran Khan

Imran heads the Branded Content team at Tech in Asia. He is also a proud member of the Third Culture Kid club. Drop him a line at imran@techinasia.com to find out more about TIA.