Security
 

Security and Protecting Your Account
MPO Federal Credit Union is strongly committed to protecting the security and confidentiality of our member account information. We use state of the art technology in the ongoing development of its MPO Online and MPO Online Bill Payment Service to ensure security and privacy.

About Security
We are pleased to offer MPO Online and MPO Online Bill Payment Service via the Internet. Delivering these services requires a solid security framework that can protect you and our institution from outside intrusion. The information below summarizes our security framework, which incorporates the latest proven technology. A section at the end also summarizes your responsibilities as a user of the Internet Banking System with regard to security.

There are several levels of security within our security framework. User Level deals with cryptography and Netscape’s Secure Sockets Layer (SSL) protocol, and is the first line of defense used by all members accessing our Internet Banking Server from the public Internet. Server Level focuses on firewalls, filtering routers, and our trusted operating system. Host Level deals specifically with our Internet Banking Services, and the processing of secure financial transactions.

Is MPO ONLINE safe? Are my accounts secure?
MPO ONLINE uses a Secure Socket Layer (SSL). SSL provides authentication to ensure that you are always in communication with an MPO ONLINE server. It also provides encryption that scrambles the data transmissions to prevent them from being read by others. Additionally, SSL is used to ensure data integrity, confirming that any data transmitted to you by MPO ONLINE has reached you without being altered or tampered with. If SSL detects any alterations or tampering to data, the connection is broken.

In addition to SSL, MPO Online also utilizes Enhanced Authentication. Enhanced Authentication is a new tool that provides extra protection for your online data and helps guard against fraudulent online activities like phishing scams (malicious requests for personal information) and identity theft.

How does it work?
In addition to your Logon ID and Security Code, the system recognizes your computer and usage patterns. If a questionable logon attempt is detected, the system will require additional identity verification before allowing access.

How does it protect against phishing?
When you enroll in Enhanced Authentication, you choose a secret image and phrase combination. You will see this image and phrase each time you log on. When you see your secret image and phrase, you can be reassured that you are logging on to your actual Internet banking or bill payment site.

In order to be able to utilize Enhanced Authentication, it is important that your web browser be configured correctly.

  • Listed below are the official supported browsers. Other browsers may work; however, you may need to modify your settings. There is no guarantee that a non-supported browser will work with this application.
  • Accepted forms of internet browsers are as follows:
ACCEPTED INTERNET BROWSERS  
PC MAC
Internet Explorer 6.0 Internet Explorer for Mac V 5.2
Internet Explorer 7.0 Safari
Netscape Navigator 8.0  
Netscape Navigator 8.1  
AOL 1.5  
AOL Open Ride 1.1.8.1  
Firefox 2.0.0.1  
Firefox 1.5.07  

When you are in an encrypted portion of MPO ONLINE, and using Netscape, an image of a key appears solid with a blue background in the lower right hand corner of the browser window. This means your browser is secure.

With Microsoft Explorer, look for a closed lock next to web address in your browser window. When you are on an encrypted portion of MPO ONLINE, the padlock appears in yellow.

Server Level
All transactions sent to our Internet Banking Server must first pass through a filtering router system. These filtering routers automatically direct the request to the appropriate server after ensuring the access type is through a secured browser and nothing else. The routers verify the source and destination of each network packet, and manage the authorization process of letting packets through. The filtering routers also prohibit all other types of Internet access methods at this point. This process blocks all non-secured activity and defends against inappropriate access to the server.

The Internet Banking Server is protected using the latest and most powerful firewall platform. This platform is based on a government-rated B1 trusted operating system, in use for many years by high-security government agencies including the U.S. Department of Defense. This platform defends against every kind of system intrusion and effectively isolates all but approved member financial requests. The platform secures the hardware running the Internet Banking applications and prevents associated attacks against all systems connected to the Internet Banking Server.

Additional measures to ensure the security of information involve the separation of server applications from host data. This means that information of value does not physically reside on the Internet Banking Server. Logging of security information occurs at all times and there is always a backup of the information logged about every attempt made to access the system. These security logs allow us to constantly monitor for a wide range of anomalies and to determine if attempts have been made to breach our security framework.

Host Level
After passing through the Internet Banking Server, the transaction is sent via secure dedicated communication lines to our Transaction Server, which verifies member identity. Once authenticated, the member is allowed to process authorized Internet Banking and bill payment transactions using host data. No direct database access occurs between the Internet Banking Server and the Transaction Server. Only specific transactions in the proprietary format are allowed into the Transaction Server. Protocol conversions have also been implemented to ensure that information does not remain in a single state of existence, further securing the information at any given point in the transaction process. In addition, communication time-outs ensure that the request is received, processed, and delivered within a given time frame. Any outside attempt to delay or alter the process will fail. Further password encryption techniques are implemented at the host level, as well as additional security logging and another complete physical security layer to protect the host information itself.

Your Responsibility

  • Not to give out your identifying information such as your PC password to any other person.
  • Never to leave your account information displayed in an area accessible by others.
  • Never leave your PC unattended while using MPO Online and MPO Online Bill Payment Service.
  • To always exit and sign off the system properly.
  • To notify the MPO Federal Credit Union at 845-343-2850 immediately if you suspect that your password has become known to any unauthorized person.
  • That you understand that by using MPO Online and MPO Online Bill Payment Service you have agreed to the terms and conditions of this agreement.
  • To use MPO Online and MPO Online Bill Payment Service solely as provided in this agreement.
  • That MPO may download certain information to your computer or other access device, including customer identification information.
  • To properly maintain any accounts you have with MPO Federal Credit Union, to comply with the most recent membership account agreement information brochure governing these accounts.
  • To pay any fees incurred by the use or maintenance of your accounts.

MEMBER LIABILITY
If you fail to maintain security of your User ID and Security Code and the Credit Union suffers a loss, we reserve the right to terminate service to you under this agreement, as well as to terminate other deposit and loan services. MPO Federal Credit Union will not be responsible for any losses you suffer due to your failure to maintain the security of your User ID and Security Code. Users of the service should use such other security code protection precautions as may be appropriate under any particular set of circumstances to ensure proper security over system access and access to account and transaction information.

This service provides the capability for you to change your security code. To help safeguard your security, you should change your security code. If you forget your security code or your system access is disabled due to the use of an incorrect security code, you must contact the MPO Federal Credit Union to request that a temporary security code be issued to you. We reserve the right to require written re-application for a new and/or replacement security code.