Regulators have given banks until the year’s end to strengthen sign-on beyond user name and password. 90 percent of participants in focus groups said they didn’t want to use a token to access accounts online or by phone. The emerging approach generally consists of somehow recognizing a customer’s computer, asking additional challenge questions for risky behavior and putting in place back-end fraud detection. But whether these layers of security combine to create something betteror worsethan traditional two-factor authentication is still anyone’s guess.”]

