- What does Cisco have against Quebec?
- Attrition.org nails another nitwit
- Diary of a deliberately spammed housewife
- Seven cloud-computing security risks
- 20 great Windows open source projects
News | Newsletters | Podcasts | Chats | Opinions | RSS Feeds | This Week In Print | IT Careers | Community | Reports | Downloads | Slideshows | New Data Center
Partner Sites:App Performance | On Demand Security | Networking Solution | SOA | Value of WDS
My friend and colleague Jurgen Pabel was one of our first graduates from the Norwich University Master of Science in Information Assurance. He is an active participant in our alumni discussion group and a frequent and welcome correspondent. Here, I present his latest suggestions (entirely his with minor edits and additions).
* * *
Bank of America's SafePass program described in the Jan. 3 issue of this newsletter prompted the following proposition.
Just a few years ago every credit-card transaction was authenticated by two factors: the actual credit card (possession) and either the correct PIN or a valid signature (knowledge / capability). The Internet broke this security scheme in that it was no longer possible to verify the possession of the actual credit card.
Banks responded by adding the credit-card verification (CCV) numbers on the back of the cards, but if the card is stolen that doesn’t help stop fraud either.
Adding a second factor to the login process for online banking portals is a good measure to reduce the risks of unauthorized access through compromised credentials. The SafePass program introduces the customer's mobile phone as a second factor for authentication to Bank of America's online banking portal.
However, millions of credit-card users still depend solely on the secrecy of their credit-card information to guard them against online credit-card fraud. A new universal second factor would be useful, even though in most cases customers are liable only up to a certain amount in case of provable fraud; someone's got to pay the bill, and it isn’t the banks: it’s people who pay finance charges on late credit-card payments.
The problem with incorporating a second factor in online credit-card transaction processing is the backend process. Changing the data formats would require millions of vendors to adapt the new process - so expensive that it’s unlikely to be implemented. An interesting idea to overcome this massive redesign problem would be to include authenticating information for the transaction in the credit-card owner's name field.
Any bank issuing credit cards would be able to extend its transaction-authorizing process either to require the physical card to be present (swiped) or to require a one-time code to be included in owner's name field. These changes would not require any modifications outside of the issuing bank's infrastructure. The authenticating information might be transmitted via text-message to the customers mobile phone number - transforming the mobile phone into the second factor as in the SafePass program.
There is no way their store and forward switches (or s2410 - fulcrum trash) can deliver that performance....- Anonymous
Comments (9)
How to Get Good Credit Gab blogBy Alton J. Jones on March 20, 2008, 4:59 pmMy blog, How To Get Good Credit Gab, provides the opportunity to share thoughts, ideas and experiences about obtaining good credit and emphasizes the importance...
Reply | Read entire comment
What about something likeBy John S on February 26, 2008, 6:19 pmWhat about something like PhoneFactor? It's realtime out-of-band authentication using a voice channel as a 2nd factor. For example any purchase over a certain...
Reply | Read entire comment
Single use numbers are greatBy Anonymous on February 22, 2008, 5:08 amSingle use numbers are great - they are all I use for online shopping.
Reply | Read entire comment
One-time credit card numbersBy Juergen Pabel on February 22, 2008, 4:15 amThe concept of one-time credit card numbers is really interesting - I hadn't heard of this approach.
Reply | Read entire comment
One thingBy elle fagan on February 21, 2008, 1:50 pmthank you for the important writing...a major issue for all of us.... one thing: you said "A new universal second factor would be useful,"....and I thought: probably...
Reply | Read entire comment
View all comments