2.5FA

Greyscale backing image
[Dave Birch] 2FA is clearly important. But what kind of 2FA? At the moment, the "something you know" plus "something you have" version is in vogue, and a great many organisations have been rolling out tokens of one form or another. In the U.K., Barclays (to name but one) have already rolled-out 2FA to the mass market:

 

Gemalto announced it has passed the 1 million mark for Barclays customers using PINsentry, its cryptographic smart card reader. The bank started deploying its authentication program in July 2007 and since then not one PINsentry online customer has suffered fraud.

[From 1 million Barclays customer using smart card reader : SecureID News]

As I’ve said before, I’m a happy PINsentry customer, even though I know it doesn’t provide total security. But it’s a bit limited. I can’t use it to log in to anything else: I’d much rather that Barclays offered a 2FA OpenID login using the PINsentry and then I could use my Barclays OpenID to log in not only to the bank but to any other sites that needed that kind of security (eg, the government). Simon Willison’s excellent OpenID blogged alerted me to the fact that other people are already thinking in that direction.

 

Microsoft are accepting OpenID for their new HealthVault site, but with a catch: you can only use OpenIDs from two providers: Trustbearer (who offer two-factor authentication using a hardware token) and Verisign.

[From Simon Willison’s Weblog]

So OpenID/2FA is not only feasible, it’s a good idea. But we don’t want to end up with a 2FA necklace — with the tokens from half-a-dozen banks plus eBay plus our corporate networks plus plus plus — that we have to carry with us at all times and this could happen if banks and other service providers don’t accept each other’s OpenIDs in a rich enough way.

Out of band, out of mind

Greyscale backing image
[Dave Birch] Using SMS to provide an out-of-band 2FA scheme for access to online services sounds like a reasonable idea. But it depends on customers to do the right thing, and this is generally a bad idea in security terms. One study of a scheme that required customers to copy a pass code from their phone to a web page (to confirm online transactions) found that customers did not notice when the message included incorrect details. My guess is that this is a general result: once you train customers to perform some simple action in order to obtain security, they won’t do any of the other cross-checks and because they think (for no reason) that SMS is somehow secure, then SMS-based approaches may be even more exposed. This is a shame, because it may hinder the development of mobile services, such a banking. People are increasingly comfortable with using their mobiles for banking, we all know that. According to TowerGroup, 90% of those who tried mobile banking at Bank of America have remained active with 99% checking balances, 87% looking at transaction history, 10% making funds transfers, and 5% paying a bill. But if they begin to read in the newspapers about mobile security being subverted, those numbers will fall.

Opportunity knocks

Greyscale backing image
[Dave Birch] Our friend David Poe from Edgar Dunn gave a presentation at the recent Chicago Fed conference on payment fraud on

Identifying Security Issues in the Retail Payments System

[From – , Federal Reserve Bank of Chicago]

He sums up an important aspect of managing fraud in the retail e-payments world when he says that “Players often make suboptimal fraud risk management business decisions because the true cost of fraud is often misunderstood.” While we all understand that some costs of fraud end up hidden away in bad debt, he points out that there are other, just as important, substantial costs to be taken into account. These include the opportunity cost of dealing with fraud when management time and effort could be going into growing the business instead. The more I think about it, the more I’m sure he’s right. On the one hand, fraud stimulates new product and service ideas all the time: just pick a recent one at random,

Online shoppers in the UK will be able to pay direct from their online bank account rather than via a credit or debit card, thanks to a new service. The POLi online bank payment platform aims to increase payment choice while reducing card-not-present fraud, a category of fraud covering ecommerce transactions which is on the rise. UK card-not-present fraud rose from £212.7m in 2006 to £290.5m in 2007, an increase of 37 per cent… According to merchants in Australia using POLi, the service now accounts for an average of 23 per cent of their total online payment transactions.

[From Online banking payment system aims to reduce fraud | The Register]

I would never use this of course because I want to pay for everything using a credit card since that frees me from all worry: it’s not my problem if something goes wrong, but that’s besides the point. The point I wanted to make is that there’s considerable intellectual effort going into dealing with online payment fraud, but if that problem were to be fixed then this energy and initiative could be freed up to develop cheaper, better, more inclusive payment systems instead and give a greater boost to net welfare.

It’ll never catch on

Greyscale backing image
[Dave Birch] Well, we’ve all made some predictions that didn’t really work out, but Clifford Stoll’s 1995 Newsweek article stands out from the crowd for completely misunderstanding the nature and direction of change. In a general diatribe about how the Internet is useless and will never amount to much, he says that

Even if there were a trustworthy way to send money over the Internet–which there isn’t–the network is missing a most essential ingredient of capitalism: salespeople.

[From Clifford Stoll: Why Web Won’t Be Nirvana | Newsweek Technology | Newsweek.com]

Well, we still don’t have a completely trustworthy way of sending money over the Internet, although PayPal is doing a pretty good job, but there’s no shortage of salespeople. True, most of them seem to be selling Viagra, but there’s an awful lot of commerce going on nonetheless.

“Real” and “virtual”

Greyscale backing image
[Dave Birch] At the 21st European e-Identity Conference, there was a presentation on the regulation of virtual worlds by Bart Schermer from the University of Leiden. I know we’ve discussed it here many times before, but I mention the presentation here because In the Netherlands (where the conference was taking place), the first virtual theft case is now being prosecuted. The case concerns the theft of €4,000 worth of Habbo Hotel furniture stolen by a “phisher” who obtained account passwords. Not only does this confirm that phishing in virtual worlds is going to be just as much of a problem as phishing in the sort-of-real world, it confirms that the virtual world might be a good customer for bank authentication systems. Of course, as a consumer I don’t care if phishers get in to my bank account, because my bank will give me the money back. But I do care if they take over my virtual world avatar: Will I get my magic sword back?

Zero hour

Greyscale backing image
[Dave Birch] Part of my Bank Holiday reading this year was book dropped on my desk by our head of Software Development. He’d been working with a customer on helping some of their people to develop a better understanding of phishing (and similar threats) by developing a bogus web site to show how easy it is, and had been reading it on the train. The book is Zero Day Threat by Acohido and Swartz. It’s an O.K. read and at the end makes a few sensible suggestions. For example, they say that a priority is to do something about payments.

Jettisoning magnetic stripe payment cards and online authentication systems that rely soley on user names and passwords, and replacing them with technologies that actually hinder counterfeiting and impersonation — not make it mere child’s play — is also a must… In short, the credit-issuing and card-based payment systems are due for a massive overhaul that will take us beyond the current solutions now on the table.

They also go on to say that

One can only hope that political leaders will emerge to champion the greater public good, not be bulldozed by probusiness interests.

What they are saying here is that banks prefer to have payments insecure because it’s cheaper. This is true, but it’s important to see why, and why the goals for the payment system might diverge from public policy goals. The designers of payment systems do not have as a goal the eradication of fraud but the management of fraud down to acceptable (ie, financially acceptable) levels. The few hundred million that goes to card fraud in the U.K. is a tiny fraction of the amount spent on cards. But the money earned through this fraud, while not a big deal to the banks, may well lead to larger social problems that do not figure in the banks’ cost-benefit analysis, which is why we should still try to reduce it even if it doesn’t make business sense for our particular organisations or systems.

Systematic calculations

Greyscale backing image
[Dave Birch] I’m reading up to try and learn more about banking as I think this will improve my understanding of the payments business, but I’ve been side-tracked today because I’m considering joining in with the lawsuit to stop CERN from switching on their Large Hadron Collider (LHC). Apparently, there is a concern that when the assorted euro-boffins start their atom-smashing antics, they may create “strangelets” and mini-black holes:

The builders of the world’s biggest particle collider are being sued in federal court over fears that the experiment might create globe-gobbling black holes or never-before-seen strains of matter that would destroy the planet.

[From Atom-smasher fears spark lawsuit – Science- msnbc.com]

These mini-black holes would suck matter out of this universe and send it into other dimensions, where it would never been seen again. I was wondering if this might be what happened to the THIRTY SEVEN BILLION DOLLARS that’s gone missing from UBS recently. It certainly cannot be explained by conventional physics. If the chairman of UBS had stood in front of a roaring bonfire and thrown $100 bills into the flames at the rate of one a second for the last two years, he would have lost a mere $6.3 billion. Oh wait, perhaps he was burning 500 euro notes not $100 bills. They have much higher money density: in that case I stand corrected and he could just about have done it without string theory or 11 additional dimensions coming into play.

All he had to do was resign though. The Hong Kong Standard reports a more robust line on gambling bankers who pick the wrong horse. Two employees of the Agricultural Bank of China came up with a better strategy than UBS. They took about three million quid from the bank vaults. They then used the money to buy lottery tickets: their plan was to replace the missing money with the lottery winnings and hope that no-one noticed (much the same plan as Jerome Kerviel of Societe Generale fame as far as I can tell). Generally speaking, Chinese bank employees are not familiar with the work of Adam Smith:

Adventure upon all the tickets in the lottery, and you lose for certain; and the greater the number of your tickets the nearer your approach to this certainty.

[From Adam Smith Quotes]

In the U.K you get to keep the Porche and the massive pension and take a few weeks gardening leave. In China, the rogue traders with the novel asset management strategy were executed.

Yet another dumb headline about contactless card security

Greyscale backing image
[Dave Birch] I had a few e-mails from people about the story in Engadget that was titled “RFID cards hacked easily with $8 reader”…

the crew at BoingBoing TV has posted up a little demo of how easy cracking the RFID encryption on an American Express card can be. All it takes is an $8 dollar reader easily available on eBay

[From RFID credit cards easily hacked with $8 reader – Engadget]

The actual title should have been “Well-designed American Express contactless cards work exactly according to specification and non-hacking non-exploit does not actually result in losses to either cardholder, retailers or American Express themselves”. Anyway, the reason I got a few e-mails was because people wanted to know where to get these $8 readers. I just checked on eBay (US) and the cheapest pre-owned contactless terminal I could find was over $60. The video actually shows him using a Vivotech Vivopay 5000 (which is a couple of hundred quid in the UK), so if this guy really can get them for $8 he’ll make far more money from reselling the terminals than he will from “hacking” ExpressPay cards.

UK Card Fraud – gosh, shock, horror

Greyscale backing image

We’re told that fraud migrates – push it down here and it goes up over there.  The introduction of Chip & PIN in the UK has squeezed out counterfeit, lost & stolen, and mail interception fraud.  This is countered by a rise in card-not-present fraud and overseas use of skimmed cards is on the up.  This trend has been clear over the last few years.  The net result is that overall UK card payment fraud has been flat at £400-450 million for 2001 to 2006.

The release of the latest UK card fraud statistics for 2007, by APACS, the UK payment clearing association, has created headlines.  It’s up 25% to £535m, they scream.  A quick glance reveals the usual trends, but chip & PIN in the UK has reduced fraud as much as it can whilst the CNP and overseas fraud continue to grow apace.  Hence the overall rise.

So, where is this fraud coming from?  It may be a blip – it hit £500m in 2004, for example.  Or perhaps fraud is migrating from elsewhere.  What happens to VAT carousel fraud when it is squeezed, for example?  [VAT carousel fraud is a peculiar wealth support mechanism dreamed up by the EU that costs UK taxpayer £8.4bn a year.]

What can be done to stem this rise?  CNP fraud is being tackled by 3-D Secure (branded Verified by Visa and SecureCode).  To stem skimmed card fraud overseas and skim & PIN fraud (whereby fake magnetic stripe cards are used with a captured PIN to withdraw cash at ATM), UK banks have gone so far – by introducing ICVV and declining technical fallback at ATM.

But they could go further.  Why not an opt-in for all but the most frequent travellers whereby my card is automatically declined for all overseas (non-chip & PIN) payments and cash withdrawals?  Before I go on holiday, I tell the bank where I’m going and for how long.  It’s easy to implement and easy for the cardholder.  Mandate 3-D Secure?

Sadly, inconveniencing the cardholder gets in the way and we can’t possibly have that.  And fraud is still only ~0.1% of total card spending.  So, perhaps it’s not such a big issue for the banks, anyway.  Afterall, card fraud was projected to be £1bn by 2010 were it not for Chip & PIN.

Another perspective on chip & PIN fraud in the UK

Greyscale backing image
[David Griffiths]  I think it’s all good and proper that academics at world class universities have our (and I speak now as a punter) best wishes at heart, and I am grateful to the BBC for bringing it it, once again, to everyone’s attention.  Taxes and licence fees well spent.  I only wish that the spin revolved around reality rather than headlines!   

Once again Ross Anderson has got the BBC all excited.  If there was real hole in Chip and PIN, the boffins at Cambridge would have spotted it, and the the BBC could then really get excited.  The reality is that Professor Ross Anderson has huge technical resources at hand, is surrounded by some very clever people, but they haven’t cracked the system – not even com close.  They have, as we were told, found some vulnerabilities, but they have not found any that the banks were not aware of.

Subscribe to our newsletter

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

By accepting the Terms, you consent to Consult Hyperion communicating with you regarding our events, reports and services through our regular newsletter. You can unsubscribe anytime through our newsletters or by emailing us.