Phil Muncaster

Fraudsters may be about to meet their match

After some false starts, has the security industry finally come up with an antifraud scheme that works?

Written by Phil Muncaster

I’m reading a rather good book at the moment. Of course, it’s not as good as Bravo Two Zero by Andy McNab, which actually gets better with every read, but I guarantee that anyone who’s responsible for risk management or fraud prevention would find it highly absorbing.

Other People’s Money is the true story of Elliot Castro, Britain’s answer to Frank Abagnale, of Catch Me If You Can fame. In it he gives a rip-roaring account of his time living the high life ­ all at the expense of the credit card companies. Reading about his exploits, it’s hard not to admire someone prepared to take on the banks and card giants with such relish. What is also remarkable about his story is just how poor many of our major institutions’ fraud prevention systems were.

Castro applied classic social engineering techniques to steal the identities of innocent cardholders, and on numerous occasions was able to take advantage of a chaotic and disjointed international enforcement regime to escape long jail sentences.

Things might have improved a bit since then, but there’s still a lot more industry could be doing to mitigate the risk of fraud.

Castro did most of his dirty work over the phone, whereas today the web is the main battleground in the war against fraudsters. One of the solutions in businesses’ anti-fraud arsenal is 3-D Secure protocol, commonly known as Verified by Visa and MasterCard SecureCode. This is the card companies’ grand answer to threats such as phishing and identity fraud. But there’s a problem. 3-D Secure certainly makes life harder for the criminals, but it also causes extra hassle for the customer.

There’s clear evidence now from the merchants that the scheme is proving to be a major barrier to the transaction process ­ Lastminute.com in particular springs to mind as one that has suffered in this respect. The old adage in fraud prevention is that you must try to balance the three prongs of security, cost and usability. Well, despite the card companies promising to cover any fraud losses incurred as a result of 3-D transactions, the scheme comes a cropper on the usability front.

Another real barrier to the scheme’s success is that it just doesn’t inspire confidence in nervous shoppers. As Greg Pierson, founder of anti-fraud firm Iovation, pointed out recently, these schemes whisk users away to an unusual URL from either Visa or MasterCard. Having a strange screen suddenly interfere with the ordering process is increasingly likely to get the phishing alarm bells ringing in consumers. And then there’s the password itself: still static, and still vulnerable to harvesting if your PC is unlucky enough to have had a keylogging Trojan downloaded on it.

So is the one-time password generating device the answer? Well, not really. A new survey by high-street bank Abbey found that out of 1,000 customers, only 32 per cent said they wanted such devices to protect their online transactions. Merchants are hardly likely to go to the great expense of rolling out devices to their customers if all it is going to do is put them off the checkout experience so much that they move to a rival that offers more flexible authentication options.

Another problem with this approach, which closely relates the issues of cost and ease of use, is that there is no standard password-generating device that can work across all e-commerce sites. Without such a system, people will need different devices for different merchants, which is hardly ideal.

The answer to all these problems may lie with VeriSign’s Identity Protection scheme. It features a one-time passcode-generating card as slim as a credit card and is a shared authentication network, which means the user only needs one card. Of course, it will require industry-wide support to offer real value, but there are already some big e-commerce names set to announce that in the UK, according to VeriSign.

Watch this space.

Tags:

reader comments

related articles

hacker

Industry lays into 3-D Secure

Verified by Visa and MasterCard SecureCode are flawed, say experts 11 Apr 2008

 

Apacs hails drop in online banking fraud

Losses fall by a third to just £22.6 million, according to the latest figures 12 Mar 2008

ID cards scheme wobbles

Accenture and BAE decide not to compete to help run the project 28 Jan 2008

Industry lays into 3-D Secure

Verified by Visa and MasterCard SecureCode are flawed, say experts 11 Apr 2008

3D Secure uptake soars to 25 million

Apacs claims major milestone for authentication standard 22 Sep 2008

Fraudsters exploit card protection system

Warning issued over flaw in Address Verification System 12 Jun 2008

related whitepapers

today's top stories

Solid as a rock - business continuity in a global manufacturer

From power supply problems in Nigeria to email availability in Stockport, PZ Cussons is prepared for anything 02 Dec 2008

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

IT staff desperate to keep their jobs

Most would work longer hours for less pay 02 Dec 2008

VMware View 3 enhances virtual desktops

Virtual clients now take up less storage space and can be 'checked out' to a laptop 02 Dec 2008

Technology and privacy

Watch part one of a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 01 Dec 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Will the terrorist attacks in Mumbai affect your offshoring plans?

Will the terrorist attacks in Mumbai affect your offshoring plans?

Is India becoming a risky destination?

Previous poll results

Latest audio and video articles

Padlocked CDVideo

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

Podcast imageAudio

Computing podcast - Standard Life's offshoring plans; and the prospects for government IT

The insurance giant outlines its new outsourcing strategy; and we ask if the government's economic bailout will affect its IT plans 28 Nov 2008

Latest in-depth articles

Parcel being packedFeatures

Case study: eSpares and business continuity

Online electricals business has managed to decrease its downtime 02 Dec 2008

Royal Blackburn HospitalFeatures

NHS trust recovers from server overdose

Virtualisation technology breathed new life into East Lancashire's cost-intensive system 02 Dec 2008

Advertisement

Primary Navigation