It was 20 years ago today, again

Greyscale backing image
[Dave Birch] You’ve probably already read about Visa Europe’s new trial with “PIN cards”.

The Visa PIN card features an alpha-numeric display and a 12-button keypad built into the back of a conventional credit, debit or prepaid card. The card, developed using technology from Australia-based Emue technologies, promises a three-year battery life, overcoming a potential stumbling block to such schemes in the past.

[From Finextra: Four banks to trial Visa PIN code cards]

I was playing around with one of these cards a few weeks ago, and I can tell you that they are as far as I can tell exactly the same thickness as “normal” chip cards and fit in a wallet properly (a key factor, if you ask me). Could I imagine using them? Yes, and clearly people at MBNA in the UK, Cornèr Bank in Switzerland, Cal in Israel and IW Bank in Italy are assuming that their customers will think the same, since each is to begin pilots of the PIN card in the next few months.

The cards contain two microprocessors, one of them containing the standard EMV application to support “chip and PIN” transactions, the other implementing a one-time-password (OTP) application that takes in the PIN from a keypad on the cards itself and presents the OTP on the screen that is also built in to the card itself. Thus, you can use the card to provide 2FA through the 3DS interface: instead of registering a password and then trying to remember it, you use the OTP from the card.

This isn’t a perfectly secure solution — it doesn’t defend against certain kinds of man-in-the-middle attacks — but it’s certainly considerably more secure than using phisable passwords. If the banks could offer the OTP infrastructure as a cost-effective option to third parties (including their own internet banking services), it would be even better, as I’d much rather log on to the Inland Revenue and Barclays internet banking using a debit card that worked this way than passwords buried and at the bottom of draws or dongles that I always forget!

2.5D Secure

Greyscale backing image
[Dave Birch] The 3D Secure (3DS) schemes — Visa’s Verified by Visa and MasterCard’s SecureCode — have come in for a lot of criticism (from, eg, me) and it’s been getting worse recently. Card-not-present (CNP) fraud continues to climb

According to the latest statistics from banking association APACS late last month, more than 25 million UK-issued credit and debit cards are registered with either Verified by Visa or MasterCard SecureCode,

[From Merchants and punters cry foul over Verified by Visa • The Register]

I have to say that, personally, I’ve never bothered to register either of my credit cards, but plenty of people have. Here’s the issue, from my perspective as a rational consumer. I’m protected from fraud by my credit card issuer, so I have no incentive to use 3DS of any kind. Any 3DS means more hassle for me for no return. The people who do benefit from 3DS — merchants, since merchants are protected against fraud by offering me 3DS even if I don’t use it — don’t insist on it and, crucially in my opinion, don’t incentivise me to use it. If I got air miles for using 3DS, I’d use it.

I didn’t want to write about fraud yet again, but…

Greyscale backing image
[Dave Birch] The U.K. remain Europe’s largest exporter of card fraud, and it looks as if this year we’re going to do even better than last year. Total card fraud last year was UKP 535 million (about a billion dollars) but the half-yearly figures for 2008 are predicting a full year well in excess of UKP 600 million. The prospects of fraud reducing remain, I think, slightly gloomy. SDA clones (of French cards, luckily) have already been found in Europe and I would imagine that we’ll begin to see SDA cloning on a large scale over the next twelve months as the ICVV base expands. When you add this to the lack of a mass market solution for EMV in the Internet/MOTO environment, there is no possibility of U.K card fraud falling over the next year. 3D-Secure technology (Verified by Visa and MasterCard SecureCode) has not even dented the problem. Despite the fact that nearly 20 million cards have been registered for 3DS in the U.K., and the fact that a tenth of e-commerce transactions are already 3DS verified, the CNP fraud figures are increasing remorselessly. I have heard some anecdotal evidence that some customers are switching from cards that are 3DS to cards that are not, simply because they can’t be bothered with the 3DS authentication when they’re buying online. And, rationally, why should they even care? Consumers are protected whether the transaction is 3DS or not so unless the retailers the incentivise them to use 3DS instruments, why would they bother?

At some point, I assume, fraud will get so bad that banks will be worried about it. That’s some way away, of course, since in the U.S. fraud is well under 1% in card portfolios that have bad debt well in excess of 6%, so I know which area will be attracting most management attention for the foreseeable future. It’s clear that chip and PIN isn’t going to crack the problem by itself, so we’ll have to start looking around for the next generation of card technology. Since the cards themselves will be disappearing into mobile phones, that would suggest that the banking sector begin ramping up their efforts in mobile. Which, of course, they already are.

Coin of the Realm

Greyscale backing image
[Dave Birch] All of the newspapers, radio and TV are full of the news that 1 in 50 of the £1 coins in circulation in the U.K. are now counterfeit.

The number of fake £1 coins in circulation has doubled in the last five years and now stands at more than 30 million, the BBC has learned.

[From BBC NEWS | UK | Number of fake £1 coins ‘doubles’]

It seems like a reasonable business to be in, if the figures given in respect of the recent arrest of a counterfeiter are correct:

It is thought that at one stage he was making 10,000 to 12,000 coins per day and was paid about £2,000 in cash a week by the two men.

[From BBC NEWS | England | London | Man jailed over 14m fake £1 coins]

I wonder how much it costs the Royal Mint to make a £1 coin? Anyway, the reason why this story is worth mentioning here, is because one of the experts quoted in, Mr. Robert Matthews (until recently the Queen’s “Assay Master”), says that 2% is the threshold at which people become nervous and begin to feel uncomfortable about accepting coins. At this point, Gresham’s Law steps in to drive the good coins out of the marketplace and confidence in the circulating coin of the realm collapses. The Royal Mint rather unhelpfully say that if you find yourself with a counterfeit coin you should not attempt to spend it, but that is of course precisely what any sensible person will do with it, since as a rational economic actor I want to dump bent coins on mug punters at the first opportunity, carefully stashing away the coins that I know to be authentic. Oddly, The Royal Mint also say that this counterfeit incidence is “comparatively low” by global standards, which it may be when compared to some developing countries but it is not when compared to the forgery rate for euro coins, which is down at 0.1%. More to the point, it’s considerably higher than the retail card fraud rates, which are well under 1% (card-not-present fraud is much higher).

Stoking up the debate on data sharing

Greyscale backing image
[Dave Birch] At the beginning of the year I proposed Stoke's Law as the back-of-the-envelope law for estimating the amount of new crime enabled by government data collection and sharing:

I propose Stoke's Law, which is that as the amount of data that the government collects grows, so will the number of people who are victims of crimes that were made possible by unauthorised access to government databases.

[From Digital Identity Forum: A new law]

We never really settled on the shape of the Stoke's Law curve, leaving it as a square law (ie, the amount of crime goes up as the square of the amount of data collected) but I'm really beginning to wonder if this is steep enough. This is because, in the U.K. at least, civil servants and management consultants appear obsessed with data sharing, which of course makes the problem much worse. It's no surprise to see stories about the abuse of government databases appearing with apparently increasing frequency. For example, I read only last weekend of a case in which a civil servant was tapping into databases to pass a woman's details on to her violent ex-partner so that he could track her down. This wasn't for money — the civil servant was the new girlfriend of the violent man in question — but could have had a much more serious outcome than the kind of identity crime (ie, credit card fraud) that the government says is a priority with respect to the national ID card scheme.

As someone who believes that cock-up rather than conspiracy is the guiding principle of government IT, I have to say that corrupt civil servants passing on information to criminals is unlikely to be the biggest problem with the joined-up administration imagined by the designers of new public sector infrastructure:

Government records are notoriously inaccurate. If a person is wrongly listed in a database, the problems of that error are now amplified.

[From Concurring Opinions]

When government databases were inaccurate and distinct, the errors were there but it was difficult for them to propagate. Now they will be able to zoom around at the speed of light.

Jonathan Craymer and Stephen Howes, GrIDsure

Greyscale backing image
[Dave Birch] Jonathan Craymer and Stephen Howes are the inventors of the GrIDsure system and founders of GrIDsure Limited. GrIDsure is a “visual PIN” system, which replaces a simple numeric PIN with a pattern-based alternative. In this podcast, they tell us where the idea came from and where they hope it might go.

More data hilarity

Greyscale backing image
[Dave Birch] Last week it was PA Consulting who were on the front page for losing masses of personal data, partly because the newspapers love stories about government data getting lost (I’m surprised they’re not bored with it, since it happens absolutely all the time) and partly because PA Consulting are designing Britain’s new ID card. The Home Office said back in March that the first cards will be issued by “day 330 of 2008”, which I think is their way of saying 1st December. SInce that’s only two months away, I’m sure that the first-class design is all squared away and the media are making a mountain out of a molehill over PA Consulting losing a USB memory stick full of data — this has nothing to do with the ID card scheme, as far as I know.

PA Consulting – which on Tuesday told ministers it had misplaced the unencrypted names, dates of birth and expected release dates of the inmates, as well as the addresses of 33,000 prolific criminals – has won £240m of government contracts since 2004, including one as the Home Office’s “development partner” to “work on the design, feasibility testing, business case and procurement elements of the identity cards programme”.

[From Consultants who lost data are working on ID cards – UK Politics, UK – The Independent]

Today, however, PA Consulting have vanished from the papers, having been swept away by the hilarious blunder by one of RBS’ suppliers, who sold a disk drive on eBay without erasing it first.

The computer hard drive was sold for a paltry £35 but the information on it was priceless, as it contained highly sensitive documentation on American Express, NatWest and Royal Bank of Scotland customers.

[From Customers’ bank data sold through eBay | News | TechRadar UK]

Now, while the newspaper anger is, to my mind, slightly misplaced — while RBS losing peoples’ personal details including mother’s maiden name is bad, what’s worse is that you can use personal details including mother’s maiden name to execute transactions because RBS (like many other banks) have no consistent two- or three- factor security across channels, so the paper should be angry at banks for not implementing digital identity rather than losing hard drives — it must at some level lead to even further erosion of trust in banks.

Risk analysis and just rewards

Greyscale backing image
[Dave Birch] Who has stolen the most money through the fraudulent use of Oyster cards recently? The brainbox super-hackers from the Netherlands who reverse-engineered a smart card chip in order to create cloned Oyster cards that can be used for a day, or Transport for London staff? Well, risk analysis would tell you that it’s odds-on to be the later. And sure enough…

A former Transport for London employee has been banged up for nine months after conning £18,000 out of the Oyster card system.

[From www.thelondondailynews.com]

Her master plan? Liquid nitrogen and micro-lathes? No. She worked in the ticket office and gave her mates cards with two grand pre-loaded! It’s important to do the risk analysis for payments systems properly (ie, systematically) and keep the pathological cases in context. Insiders are always a problem when it comes to designing secure payment schemes, but the need for proper risk analysis is even greater now that there are many different kinds of insider to consider: it’s no longer simply bank employees and retail staff, but telco employees, outsourcer and call centre staff, bureau staff and more.

Industrial-scale identity theft

Greyscale backing image
[Dave Birch] Well, not really identity theft at all, but stealing credit card details on a massive scale then using them to obtain goods or services fraudulently. These ones got caught.

Federal prosecutors have charged 11 people with stealing more than 41 million credit and debit card numbers, cracking what officials said on Tuesday appeared to be the largest hacking and identity theft ring ever exposed.

[From 11 Charged in Theft of 41 Million Card Numbers – NYTimes.com]

Judging by the ever escalating figures for credit card fraud, however, plenty of others are still getting away with it. Are the figures telling us something very specific about authentication: that online PINs and passwords are not only not a particularly good authentication mechanism but may actually make matters worse? The prosecutors allege that the criminals stole card details and PINs as they were passing (apparently unencrypted) over wireless networks and then used the fake card to details to manufacture cards and then used the PINs with the cards to withdraw cash from ATMs. No PINs, no cash out of the ATM.

You’ve got my identity, now what?

Greyscale backing image
[Dave Birch] Let’s suppose you are a master identity criminal and you’ve pulled off a heist: You’ve got away with the HMRC disks, or the POS keylogger or the hospital laptop. You’ve got my identity. Now what are you going to do with it? Open a bank account? Pretend to be me to commit acts of international terrorism?Take out a mortgage? Stalk someone via social networks? Get a credit card? Actually, it’s none of the above.

Wireless-phone accounts were the most frequent types of new accounts opened using ID theft, according to the report. These criminal cellphone account openings increased from 19 percent to 32 percent of new account fraud last year, exceeding fraudulently opened credit cards, loans, checking or savings accounts.

[From Javelin Strategy and Research » The Savvy Consumer: Don’t be taken in by drop in identity theft]

Generally speaking, most kinds of identity theft are really financial frauds of one form or another. If you want to sneak into NORAD, then you’re unlikely to find a useful ID floating around on the Net, you’d be targeting a more specific identity, blackmailing someone, that kind of thing. So if run-of-the-mill identity theft is about getting a bank loan in a bogus name, then I wonder if it might be economically more efficient for society as a whole to make getting bank loans harder to get rather than racking up costs defending against identity theft. if, in the U.S., you needed more than a plausible name, address and social security number combination to get a loan, then stealing the name, address and social security would presumably become less interesting to criminals.

Subscribe to our newsletter

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

By accepting the Terms, you consent to Consult Hyperion communicating with you regarding our events, reports and services through our regular newsletter. You can unsubscribe anytime through our newsletters or by emailing us.