How does the enrollment process work?
When you enroll for PenFed Online, you will select a user name and password to access your accounts online. You will also select a personal security image and phrase. Whenever you log in, we display your image and phrase so you can be assured that you are not accessing an imposter site.
PenFed also checks the computer you are using. Typically, you will access PenFed Online from one or two computers, such as your work and home systems. The system remembers your computers. Should you need to log in from a different computer, such as an Internet café, the system takes additional steps to verify your identity, by asking you to answer a secret question that you selected during enrollment.
The system remembers your computer(s) by assigning a unique identifier (a standard secure cookie) to each computer you use to access PenFed Online. The cookie is used to store the identification only. No personal or private data is stored in any way.
How is this more secure?
The PenFed Online logon process protects you from accidentally revealing your user name and password to a fake site. In addition, if someone does get your user name and password, they still cannot access your account because the computer they are using is not one of your registered computers. The system will then challenge the hacker to answer one of your secret questions, which they will not know, and they will be turned away.
Can't someone steal my security image and phrase?
No. Your personal security image is only shown to you if you log in from a registered "safe" computer, or, if you have answered a challenge question. So, it is not possible for an unauthorized person to get access to your personal security image.
What are challenge questions? Why do I need to set them up?
Challenge questions allow you to log in to PenFed Online from a new computer. When we detect that you are logging in from a new computer, you are asked a challenge question before allowing you access. Because you are the only one who knows the answer, we know it is really you. If someone has stolen your username and password, they cannot log in because they do not know the answers to these questions.
Why am I being asked a challenge question when I try to access PenFed Online?
There are several reasons why you might be challenged. These challenge questions are meant to keep phishers and hackers out because only YOU know the answer to these questions. Some reasons you might be challenged: you are logging in from a different computer, you are using a different browser, or you cleared all the cookies on your computer. If you are challenged, answer the question with the correct answer, and you will then be shown your personal security image and phrase.
After you answer the question, you will be asked whether we should remember this computer for future log-ins. If you are using a personal computer, you can answer "yes". If you are using a public computer, you should answer "no".
Should I register my computer?
PenFed highly recommends registering computers you regularly bank from as a strategy against unauthorized logon attempts.
There are a rapidly growing variety of illegal programs called Trojans that may be silently operating on your computer. Trojans are written to intercept your keystrokes (including the password or challenge question answers you type) while on financial sites.
PenFed has designed our logon security to protect against this by not challenging logins from registered, “trusted” computers so your answers are not presented or exposed to this illegal software. Should the illegal Trojan capture your password, a criminal would not have the answers to your challenge questions should they attempt to logon. Since their computer wouldn’t be registered, they will be challenged but won’t have access to the answers.
What if I log in at work, or from other computers?
If you use multiple computers to check your account (such as your work computer), you can "register" any computer that you know is safe. You will just need to go through one extra step of answering a challenge question. Once you have successfully answered your question, you are shown your personal security image and phrase, and asked for your password.
There is no limit to the number of computers you can register.