- Bank Web sites full of security holes
- SCO Group: Its future is all used up
- Maligned feature being added to IPv6
- I returned my iPhone 3G after six days!
- VPNs: Six burning questions
News | Newsletters | Podcasts | Chats | Opinions | RSS Feeds | This Week In Print | IT Careers | Community | Reports | Downloads | Slideshows | New Data Center
Partner Sites:App Performance | On Demand Security | Networking Solution | SOA | Value of WDS
PayPal has 133 million customers that use its Internet-based money-transfer service, which handled $37 billion in transactions last year. Michael Barrett, who is CISO at the eBay subsidiary, recently spoke with Network World senior editor Ellen Messmer about new approaches PayPal is taking to combat online fraud.
Almost every day I get a fake PayPal e-mail that’s obviously a phishing scam. How do you deal with this phishing fraud or even use e-mail to communicate with PayPal customers?
There’s a lot of spoofing of eBay.com and PayPal.com. We get e-mail from customers asking questions about this and other topics and we respond within 15 minutes. We use our own Web-based e-mail to communicate. The problem with phishing and spoofing generally is there’s no magic bullet. So it’s classic defense in depth.
How much fraud hits PayPal each year?
As a class of operational loss, it’s 0.41%. In the industry, that’s known as 41 basis points, which is pretty low. When our customers are victimized, their user ID and password are compromised, we compensate them.
What are some of your defensive strategies?
If the consumer actually never actually saw the phish e-mail, it’s hard for the criminal to victimize you. We’re working with people who make e-mail clients and the ISPs, such as Yahoo, MSN and AOL, on a technical strategy that says if the e-mail is not signed by us, drop it. We’re having good discussions, but we have nothing to announce now.
What specifically do you do today?
We believe in consumer training, and we have a “Think before you click on a link” program. We’ve also begun supporting the Extended Validation SSL certificate for safe browsing, which gives consumers the green glow in the Internet Explorer 7 browser. The Internet Explorer 7.0 antiphishing filter works very well with black lists of sites updated regularly. If there’s a big red URL bar, you’re attempting to browse a URL site it would recommend you not.
This week we’re also launching the PayPal Security Key in the United States, Australia and Germany. You log on with your PayPal ID and password and then also use a dynamic password generated by a keyfob made by VeriSign. Use of this is voluntary and we’re supplying the keyfob on request for a nominal $5 charge, which doesn’t even cover the cost. It will even be free for certain business customers, and we may decide it’s mandatory for specific business segments.
If the IT manager is knowledgeable regarding Cisco technology, he would have 2 options. Option 1 - Consult...- Anonymous
Partner Content
Brilliantly simple security and control solutions for email, web and endpoint
www.sophos.com
Stopping data leakage
Learn how to exploit your current security investment to control the information that flows into, through and out of your network.
Download the white paper.
Why detection rates aren't enough
Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask to prospective vendors to get the right endpoint solution.
Download the white paper.
Unauthorized applications: Taking back control
Employees installing and using unauthorized applications like IM, VoIP, games and peer-to-peer file-sharing applications cause many businesses serious concern. How do you control these applications?
Download the white paper.
Comments (3)
One Word....Class Action LawsuitBy Anonymous on August 11, 2007, 5:39 amI and (I'm sure I am speaking for thousands of other silent victims of paypals ingenious scam) totally agree with the statement left by Peter Joseph Donaghue.Paypal...
Reply | Read entire comment
Totally Agree-Paypal Has Too Much AuthorityBy Anonymous on August 11, 2007, 5:20 amI and (I'm sure I am speaking for thousands of other silent victims of paypals ingenious scam) totally agree with the statement left by Peter Joseph Donaghue.Paypal...
Reply | Read entire comment
PayPal owes usBy Anonymous on May 11, 2007, 7:37 amWe are a victimised customer of eBay & Paypal and have not been compensated. Re: Q&A: PayPal CISO outlines anti-fraud strategy. We have not had our questions...
Reply | Read entire comment
View all comments