Tomorrow's Transactions » » Crime & Fraud http://tomorrowstransactions.com Thought leadership from Consult Hyperion Thu, 30 Apr 2015 13:28:42 +0000 en-US hourly 1 http://wordpress.org/?v=4.1.5 Doing something about cybercrime, cyberterrorism and cybersubversion (not) http://tomorrowstransactions.com/2014/11/doing-something-about-cybercrime-cyberterrorism-and-cybersubversion-not/ http://tomorrowstransactions.com/2014/11/doing-something-about-cybercrime-cyberterrorism-and-cybersubversion-not/#respond Fri, 07 Nov 2014 17:42:07 +0000 http://tomorrowstransactions.com/?p=4687 Dgwb blog white border

Cybercrime, cyberterrorism, cybersubversion and so forth are all serious issues. Defending critical infrastructure from attackers ranging from Eastern European gangsters to agents of foreign powers and from management consultants to the HR department is obviously crucial to organisations that want to prosper in the digital economy. But we need new tools to help.

The nice people at the Fraud Advisory Panel invited me along to their expert stakeholder roundtable on “Protecting Consumers and Reducing Opportunities for Cybercrime”. The roundtable was held under the Chatham House Cyber-Rule, so I won’t be forever excluded from polite society by tweeting, blogging or whispering who said what, although I will say that the stakeholders represented included government and law enforcement. Here I only want to highlight a few key points from the discussion.

Naturally the conversation began with tales of the Dark Net, pedophile exchanges and assassination marketplaces but it quickly turned into a discussion about Bitcoin. My suggestion that we persuade all criminals to start using Bitcoin right away so that we could at least monitor and measure criminal activity didn’t gain much traction, and neither did my plan to prosecute the Bank of England for conspiracy to defraud Her Majesty’s Revenue and Customs by printing £50 notes. But I digress.

One aspect of the issue that I hadn’t considered before the meeting was the issue of consumer education. As was pointed out by some of the law enforcement people present, there are plenty of criminals out there right now using things like Western Union and people seemed to fall for the cons all too easily. Even those of a more libertarian bent (e.g., me) must be forced to think about how to protect people from themselves. This (to my mind) makes the appeal of sort-of-anonymous and non-reversible transactions even less appealing. Given that some of the projects we are working on for clients in the financial services sector are providing more input to thinking around this topic, I think I’ll put it to one side for the moment and return to this important topic into a future blog.

Anyway, to be completely honest I’m not sure that we got any closer to understanding what emerging cybercrime threats we should be factoring in to our risk analysis nor which technological vulnerabilities we needed to assess further. This reminded me that I had similar thoughts last year, when the organisers of the University of Cambrige’s Rustat conference on “The Cyber Revolution in Global Finance” were kind enough to invite me along to their event and take part in a panel discussion about Bitcoin and the future of money. The event had three main themes:

  1. The future of UK financial regulation and British competitiveness post-FSA.
  2. Cyber Innovation: for example, behavioural analytics; the rise of private cyber cash, new payment platforms, mobile banking, privacy and consent, economics of cyber security.
  3. Threats to national economic security from cyber crime and attack, and to the City of London from new financial capitals such as Shanghai and Dubai.
  4. How to optimise Cyber Finance collaboration between Silicon Fen and Silicon Valley, research, entrepreneurs, VCs, the City, government and security services.

[From Rustat Conferences]

The discussions were again conducted according the Chatham House Cyber-Rule, which meant that blogging and tweeting were allowed but no comments were to be attributed to any individual speaker, so I won’t mention anything that was said there except to note that I wasn’t at all convinced by the government and industry participants that they had any real mental model of the problem nor any narrative around workable solutions. I, naturally, tend to see the whole problem as being identity-related but of course that is also too narrow a prism.

To be fair, it’s quite difficult to create and maintain risk analysis on this kind of scale and I don’t think that we (i.e., society) are anywhere nearing understanding or dealing with the risk associated with cybercrime, cyberterrorism and cybersubversion. I did read a good paper about one useful approach recently — Paul and Vignon-Davillier’s “Unifying traditional risk assessment approaches with attack trees” in Information Security and Applications19(3) (2014) — so I’m not saying that we aren’t making process, but I can’t help but feel that the kind of risk analysis that we have used for years  (in defence, finance, manufacturing and so on) must change.

Anyway, to the point. At the Fraud Advisory Panel, I mentioned a 1998 prediction by Paul Kocher, (then President of Cryptography Research), who said that breaking a crypto system is far more difficult than robbing a physical bank but potentially far more profitable. Hence, I was very interested to sit through the sessions that were about systemic attacks on the financial system, which gave me the idea for a challenge that I will share…

Thinking about systemic problems, I was trying to imagine scenarios where well-funded, motivated and expert attackers could do more damage to a bank than its own management could, but I do not know enough about the international financial system to be able to put forward a plausible candidate attack. Perhaps a correspondent might help?

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

]]>
http://tomorrowstransactions.com/2014/11/doing-something-about-cybercrime-cyberterrorism-and-cybersubversion-not/feed/ 0
Crime correlates cash http://tomorrowstransactions.com/2014/04/crime-correlates-cash/ http://tomorrowstransactions.com/2014/04/crime-correlates-cash/#respond Fri, 04 Apr 2014 16:24:53 +0000 http://tomorrowstransactions.com/?p=4359 Dgwb blog white border

Now that banks are spending more on virtual security than physical security, robbers are going to have to change their strategies.

I got into an interesting discussion about bank robbery at a recent lunch. We were talking about risk and risk analysis. It happens that Consult Hyperion has a very well-developed risk analysis methodology (it’s called “Structured Risk Analysis”, or SRA) that has been used rather successfully on a wide variety of transactional services around the globe to help clients to evolve security architectures and to direct countermeasure expenditures effectively. I was trying to make some points about why proper risk analysis like this is a more cost-effective way to proceed than (for example) panicking about newspaper stories on hacking, and that led to a train of thought around cost-benefit analysis for the robber, not the bank. Are robbers put off by thick doors and barred windows and such like? Are robbers deterred by visible, physical symbols of security?

The security of physical buildings is no longer as important for financial services.

[From CYBER SECURITY WITHIN FINANCIAL SYSTEMS NEEDS TO BE FRONT-OF-MIND | GlobalBankingAndFinance.com]

This is a fair point. So it set me thinking: if you are an amoral sociopath desperate for money, are you better off robbing a bank or working for it? As a responsible father, I want to help my teenage sons chart the best course for life. Right now, they are intent on going to University to study socially useful subjects in science and engineering, whereas I am trying to persuade them to become Somali pirates or Wolves of Wall Street. Having studied science and become a wage slave trapped in mortgage serfdom I understand that side of the equation, but am less certain of the other. So I started off by reading a paper called the “Decision-Making Practices of Armed Robbers” by Morrison and O’Donnell.

This paper is based on a study of commercial armed robbery in London, UK, involving the analysis of over 1,000 police reports and inter- views with 88 incarcerated armed robbers.

The paper, being about UK robberies, contains an interesting snippet: a great many of the armed robbers in the UK use imitation firearms even though they have ready access to real ones. I imagine that in the US the use of imitations is vastly less prevalent, since it’s presumably harder to buy an imitation gun than a real one there. But I digress.

almost all of these robbers evaluated the offence as having been financially worthwhile (aside from the fact that they were eventually caught and punished for their crime).

So robbing a bank seems like good idea, if you exclude the possibility (in fact, the likelihood) of being caught. I suppose this is standard “Wolf of Wall Street” thinking though isn’t it?

Neither does it seem practical to expect financial institutions and commercial properties to reduce counter cash much more than they already have.

I disagree, of course. This is exactly what we should expect them do, since as far as I am aware there is a direct and measurable relationship between the amount of cash (more on this later) and the amount of crime.

Even when the amount of money obtained was quite small (an element often touted in support of the irrationality of economic criminals), it must be recognised that even apparently small sums may be adequate for the offender’s immediate needs. Hence, gains may be subjectively much larger than they appear

So even thought the rewards of armed robbery seem to me, an educated middle-class professional, to be rather low, they are still sufficient to attract the robbers, because their needs are immediate and limited. They guy in the Nixon mask isn’t robbing a bank to pay his way through college or to obtain seed finance for a brilliant start up idea, he just needs to buy a car or some drugs or whatever. This article seems, then, to indicate that so long as there is some cash in the till, there will be robberies. This is not an observation confined to banking.

Our results indicate that the EBT program had a negative and significant effect on the overall crime rate as well as burglary, assault, and larceny.

[From Less Cash, Less Crime: Evidence from the Electronic Benefit Transfer Program]

What they are talking about here is the use of Electronic Benefit Transfer (EBT) programmes in the US, whereby benefit recipients are paid electronically and given cards that they can use in shops instead of being given cash. The authors found a 10% drop in crime correlated with the switch to EBT. It seems pretty overwhelming evidence, and even more so if you read the paper, which notes no impact on crimes that do not involve the acquisition of cash. If we can to stop armed robberies, that would surely be an excellent social benefit to the move to cashlessness and would help us to explain the nature of appropriate regulation to legislators.

But back to the specific point about the relationship between bank cash and robberies. What should we do about it, other than the obvious, necessary and socially-beneficial step of abolishing $50 and $100 bills (as well as £50 note and €100, €200 and the €500 “Bin Ladens” as well)? It looks as if the answer is, essentially, nothing.

But with most robbers taking a mere pittance and bank robberies being a relatively rare crime (there are more than 6,000 commercial banks in the United States and thousands more credit unions), it’s barely worth it for banks to invest in the screens, which cost a couple thousand per teller window to install… Overall, it’s probably not worth it to attempt a bank robbery, the researchers conclude. “The return on an average bank robber is, frankly, rubbish,” they write. “It’s so low that it is not worth the banks’ while to spend as little as [$7,000] per cashier position at every branch on rising screens to deter them.”

[From What You Should Know Before Robbing a Bank – US News and World Report]

The armed robbers, like everyone else, follow the money – literally – and so cash-in-transit (CIT) robberies are now the preferred option. We see the same in Europe where countries that have much higher usage of ATMs have much higher CIT robbery rates than countries that have lower ATM usage (see, for example, Sweden and Denmark).

More people seem to be taking that advice: In 2004, there were more than 7,500 bank robberies in America, 26 percent more than there were in 2010. According to the researchers, “robbing banks is no longer what you could call the crime of choice.” But they do have some other advice: “Security vans offer more attractive pickings.”

[From What You Should Know Before Robbing a Bank – US News and World Report]

Overall, then, we see another early indication of the emerging post-cash era: Spending on physical bank security is being reduced and spending on virtual bank security is being increased. We do, indeed, live in interesting times.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

]]>
http://tomorrowstransactions.com/2014/04/crime-correlates-cash/feed/ 0
Will the Target breach boost EMV in the USA? http://tomorrowstransactions.com/2014/01/will-the-target-breach-boost-emv-in-the-usa/ http://tomorrowstransactions.com/2014/01/will-the-target-breach-boost-emv-in-the-usa/#comments Wed, 15 Jan 2014 14:03:24 +0000 http://tomorrowstransactions.com/?p=2936 Dgwb blog white border

How exactly does switching to the “chip and PIN” system used everywhere else in the world (except North Korea, I’m told) stop the kind of thing that’s been going on at Target?

In our corner of the transactions treehouse there is only one topic of conversation. The Target breach and the population-scale violation of the US payment system that means that tens of millions of people have had their card details whisked away to the stripe souks of the hacking underworld where they are even now being bought and sold across the global village by global villains.

The retailer confirmed Thursday that the massive data breach, which occurred between November 27 and December 15, resulted in attackers gaining “unauthorized access” to customers’ names, credit or debit card numbers, card expiration dates, and three-digit CVV security codes. That information is all that criminals would need to make fraudulent transactions online or create working, counterfeit cards in the names of customers.

[From Target Confirms Hackers Stole 40 Million Credit Cards – InformationWeek]

I’ve seen this being reported (puzzlingly) as a failure of PCI-DSS, because under the stringent conditions that it sets out, retailers are not supposed to store (for example) CVVs. But as I understand it, this data was obtained by accessing “storage”. The malfeasants in the middle had wangled their malware into Target’s POS system so the stripe data was spirited away as it was read.

Target is assuring customers that they won’t be held liable for any fraudulent purchases made in their names as a result of the snafu. It’s also offering a year of free credit monitoring and identity theft protection to “all Target guests who shopped our U.S. stores,” which I’m guessing is, well, pretty much everyone in the U.S., except maybe like Mitt Romney.

[From Target data breach grows: 70 million customers’ personal information stolen.]

Oh, wait…

A high-end Dallas-based retailer is the latest victim of a credit card security breach.

[From Credit Card Breach At Dallas-Based Neiman Marcus « CBS Dallas / Fort Worth]

They’ve probably got Mitt’s card as well then. It’s a working assumption, as far as I can see, that to all intents and purposes, all US card details are compromised. Especially as news stories quoting credible experts — saying that more as yet unnamed retailers have been comprised — continue to circulate. Seriously. All US card details are compromised. Chip and PIN to the rescue! But wait…

But security and merchant-acquiring executives caution that EMV cards and compatible point-of-sale terminals alone would not have prevented a Target-style breach.

[From EMV Chip Cards Don’t Provide Data-Breach Immunity, Security Execs Warn]

That’s not quite right. You can read all of the data from a magnetic stripe and use it to create a counterfeit magnetic stripe card. You can read all of the data from an EMV chip but you cannot use it to create a clone EMV card. When EMV cards were first introduced, you could read all of the data from an EMV chip and use it to create a counterfeit magnetic stripe but you cannot do this (at least the UK) any more because the issuers started to use a chip ICVV that is different from the CVV on the magnetic stripe that is glued to EMV cards for legacy purposes. So if you wangle your malware into POS terminals, an EMV environment does prevent a “Target-style” breach.

The malware will harvest data, but that data cannot be used to make transactions: you cannot make a clone EMV card because you don’t have the security keys that never leave the chip, you cannot make a counterfeit magnetic stripe card because you don’t have the CVV and you cannot use the card details online at your favourite porn/guns/soda merchant because you don’t have the CVV2 from the back of the card.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

]]>
http://tomorrowstransactions.com/2014/01/will-the-target-breach-boost-emv-in-the-usa/feed/ 4
Threats, risk and attacker motivation: a real life example http://tomorrowstransactions.com/2013/12/threats-risk-attacker-motivation-real-life-example/ http://tomorrowstransactions.com/2013/12/threats-risk-attacker-motivation-real-life-example/#respond Fri, 27 Dec 2013 09:23:16 +0000 http://tomorrowstransactions.com/?p=2888 Margaret FordTravelling home from a meeting at the Payments Council on Monday afternoon, I was enjoying the peace and quiet of the train gradually emptying as it drew further out of town. At Sunningdale, a station normally notable only for the most prosperous passengers, a group of excitable teenagers joined the train obviously looking for trouble. Brandishing camera phones, they seemed more of an irritant than a threat.

Avidly reading advice on strategies to avoid arrest by over-zealous US police officers, quoted in an article from the latest edition of Cryptogram, I felt comfortably detached from my surroundings. The luxury of a half-empty train on the Reading line is a rare treat.

The author of the article advised that unlawful activity is best indulged in from the comfort of your own home. If you must commit crimes in public, avoid drawing attention to yourself. In particular, even if you become aware of an officer while performing an illegal act, it is better to continue rather than raise suspicion through a sudden change in behaviour.

At this point I became aware that I had unwittingly become the focus of the gang, who had moved on from threatening to punch random strangers to wielding newspapers and cigarette lighters while daring each other to take my phone. Suddenly alert to the situation, I put my phone away, muttered ‘excuse me’ and wandered gently up the carriage. They left the train at the next station.

I’d made the mistake of forgetting that my brand new phone which I regarded as a standard device for accessing content and keeping in touch, could also be seen as a status symbol with significant market value. On reflection, it gave me a tangible example of one of the key risk concepts being investigated by the TREsPASS project: attacker motivation. This had moved from the general to the specific, as an opportunity was spotted and the incident unfolded. It was clearly unpremeditated and yet in many ways predictable.

As my brother commented the next morning, teenage gangs in our area just aren’t what they were in our youth, when they would steam the length of trains in groups of twenty or more. He also gave me a great tip for protecting my phone in future, which in his experience deters all potential muggers.  Waterproof, costing only a few pence, with the option of additional cotton wool for extra authenticity: an attractive little black plastic bag with yellow drawstring, as commonly carried by dog walkers.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

]]>
http://tomorrowstransactions.com/2013/12/threats-risk-attacker-motivation-real-life-example/feed/ 0
Card crime and nostalgia http://tomorrowstransactions.com/2013/12/card-crime-and-nostalgia/ http://tomorrowstransactions.com/2013/12/card-crime-and-nostalgia/#respond Mon, 23 Dec 2013 13:35:31 +0000 http://tomorrowstransactions.com/?p=2895 Dgwb blog white border

In America, card fraudsters are wrapping satellite dishes in tinfoil to stop terminals from going online and then using counterfeit and stolen cards to buy gas. Amazing! I had no idea that people still used satellites for this sort of thing.

I was flabbergasted to read in the September ISO & Agent magazine that “Crooks wrap parts of satellite dishes in cooking foil to stymie data transfer and then use bogus cards to ‘purchase’ gasoline” — Heun, D., “Foiling Tin-Foil Thieves” in “ISO & Agent”, p.99 (Sep. 2013). I had absolutely no idea that people still used satellite links for this kind of thing! The story triggered a wave of nostalgia for me because the first IT project I ever worked on for banks involved satellite connections. So gather round the yule log and listen to my tale…

Cast your mind back to 1982. The interweb tubes are a distant dream. Meanwhile, in Indonesia, a group of talented young men (for they were all men) are writing computer programs to run on the world’s first regional satellite system, the Palapa-B1 service (a Hughes HS376, for the technical, with 24 C-band transponders). One of these dashing you software engineers — for it was, indeed, me — was tasked with writing initially the (and here’s one for the teenagers) X.28 code and then the X.25 code to allow (amongst other things) bank terminals and other equipment to connect via the satellite network to allow communications between bank branches on far flung islands throughout the Indonesia archipelago and bank offices in Jakarta and elsewhere. You couldn’t buy communications software for the processors we were using. You had to write it from scratch. If you tell the young people of today that, they won’t believe you.

Indo83 3 

We were working at a telecoms supplier’s site in Bandung. I know it doesn’t look much from the outside.

A Japanese team were building the baseband modems and implementing the Aloha link protocol that had originally been invented for Alohanet. This gave me the primitives to work with to implement the CCITT protocols on top. X.28 was the protocol for character input/output (using to connect terminals across a network to mainframes) and X.25 was the packet-switching protocol for interconnecting computers. I still think of terminals at DTEs (Data Terminating Equipment) and I still think of networks as DCEs (Data Circuit Terminating Equipment). All of these quaint terms vanished from the pages of history about a week after TCP/IP was invented.

Indo83 

As you can see, inside we had access to many modern facilities.

Implementing X.28 meant that staff could log on to bank mainframes using terminals in the branches. Implementing X.25 meant that remote minicomputers could interconnect. Getting the code to work, and getting it to work quickly enough, and getting it to work in the limited memory available was a fantastic education.

Indo83 2 

Here I am making a few small adjustments to the communications processors boards.

It was here I learned all my UNIX tricks and C programming stunts. Those were the days when if you didn’t like the way that the team wrote code you could quickly knock up a parser to force them into line (which one of my colleagues did, using YACC), when you had to pretend to the system administrator that you didn’t have root access (which we all did) and when the disk packs held 5Mb so you had to be very careful with the space available (wipes tear from eye).

 Indo83 1

As you can see, the team really appreciated my mad programming skills and their contribution to the great success of the project.

A few years later, I worked on a similar system using VSAT terminals in K-band (too much information, ed.) for a US telecommunications provider, one of Consult Hyperion’s first US projects. In those still pre-internet days, if you wanted to get data from a branch office back to HQ reasonably quickly you had to pay for a leased data line from the phone company, which was very expensive. Putting a satellite terminal on your roof was a cheaper alternative and as the frequencies went up from C- to Ku-based, so the dish sizes came down. The cost of installing and maintaining a six foot dish compared very favourably with the costs of leased lines.

I remember that one of the users of the system was a chain of car dealerships who had come up with a tremendously clever business case. When a customer came in to buy a car, the dealership would use the new satellite network to instantly credit check them. If they had good credit, they would be offered dealer credit. If they had bad credit, they would be referred to the local bank. Nice one. 

In the late 1980s and very early 1990s, I enjoyed working on a wide variety of projects around satellite data communications. I worked on technical architectures, system designs and even on regulation in a team with the now-infamous Vicky Pryce (who was then chief economist at KPMG, and who I remember as a very impressive and really clever, but also really nice person). Hence my nostalgia for the days of link budgets, low-noise blocks and data broadcasting.

What’s kind of weird now is that the stuff we used to send via satellite (TV, data) now comes into my house by fibre optic cable (another technology that destroyed part of my life’s work, as life as a Physics undergraduate included months spent working on a dissertation about gas lenses for lasers) and the stuff that we used to send by cable (phone calls) now comes into my house via wireless.

Ah, the good old days.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

]]>
http://tomorrowstransactions.com/2013/12/card-crime-and-nostalgia/feed/ 0
Prepaid could be, should be, great http://tomorrowstransactions.com/2011/05/prepaid-could-be-should-be-great/ http://tomorrowstransactions.com/2011/05/prepaid-could-be-should-be-great/#comments Wed, 11 May 2011 22:51:13 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2011/05/prepaid-could-be-should-be-great/ [Dave Birch] It's not clear that the use of contactless cards to date tells us anything about the future.

]]>
At the risk of turning into the Victor Meldrew of retail payments, I want to make a point about something. When I wrote about some bad experiences with contactless a couple of weeks ago, I did it because I genuinely care about this stuff, and I genuinely want the contactless experience to get better. I don’t think the blog would be useful, particularly to my colleagues in the industry who read it, if it never contained criticism, so long as that criticism is well-founded and honest. Similarly with prepaid. I really like prepaid, I really want it to succeed and I really get upset when it doesn’t work as well as it should.

Prepaid is growing. In the last five years, the volume of card transactions in Europe has grown about 9% per annum but the value has grown 7% per annum (because the average transaction size has fallen) and most of that growth has actually come from prepaid cards [F. Burelli. “Profitability dynamics of card payments” in Nordic Card Markets, Stockholm (Jan. 2010)]. Looking forward, the outlook appears to be pretty rosy. Yet I can’t help feeling that prepaid isn’t where it should be. My recent experiences with prepaid have been pretty good. I had a Visa prepaid card (which has just expired) that we were using as our “house” card at home: the kids used it when they needed to run to the supermarket or buy stuff for school. It had a simple web interface, I could see what they had been spending the money on and I could easily top it up from my debit card. Best of all, it didn’t have a name on it, so if they lost it then no-one could use it in shops (because it’s a chip and PIN card) or online (because they wouldn’t know the name or address associated with the card). Now that it’s expired, I got my eldest to go and get an Orange Cash card which annoyingly has a name on it (review to be posted shortly), so we’ll see if that can take over as house card.

But I digress. Right now, I am annoyed with prepaid. Just as I was leaving for the airport, I remembered that I had less than $100 on my Travelex US Dollar prepaid card. As I was going to be in the US for a few days, I’d need a bit more to cover meals etc so I decided to load a couple of hundred more dollars. Now, obviously I wasn’t going to bother to do that at the airport given the palaver I went through last time: I had £50 in cash in my pocket and I stopped at a Travelex booth in Heathrow to add it to my card and it took about a quarter of an hour and involved taking photocopies of my passport, the card, the receipt as well as answering security questions. The process was, presumably, designed to drive up the cost of prepaid cards to keep them beyond the reach of the poor.

Naturally, I thought that there would be some way to top up online, so I entered my 16-digit card number, my username and password and logged in to my cash passport account, only to find that there is no option for reloading (only for changing PIN and looking at transaction history). I went back to the home page and found that there’s a separate option for reloading, I clicked that, and was asked to enter the first six digits of my card number. This took me back to the account screen. I went back round again, and somehow found another link (I can’t remember what it was now) that asked my for the first six digits again and then took me to a reload screen. I entered the number of my Visa card, my address, the CVV and the amount, and was met with a screen saying tough luck.

Screen shot 2011-05-02 at 12.24.53

I wondered if it might be something to do with credit vs. debit, so I went round the loop again, this time using my Visa debit card instead. After typing in the amount, card number, address, CVV again, I got the same results. Much against my better judgement I decided to call, so I phoned the (mercifully) free phone number on the back of the card. I stupidly chose the option for speaking to an operator, and the line just went dead. So I dialled back and chose account services and then something else and then talk to an operator. I was shocked when a woman answered. After giving her my (I’m not making this up) card numbers, address, name, date of birth and a couple of other things, she put me through to another chap who said he would top up the card. I asked him if it was possible to do it via home banking and he said that it was and that he would e-mail me the details. After asking some more security questions, I started to give him my debit card number and he stopped me and said that he first had to check whether I was on the electoral roll at that address. I gave up, grabbed my BA Amex card and my John Lewis MasterCard and my Visa OnePulse and jumped in the cab.

All the way to the airport I was wondering why it was all so complicated. Why can’t I load via the ATMs at the airport, or using an app on my iPhone or by PayPal. Prepaid should be a simple, inexpensive alternative to cash, not something that has you jumping through hoops! When I got the US, I decided to get another prepaid US$ card, but this time I would register it in the US so that I could have a US BIN and billing address (some stores, such as Levenger, will let you ship internationally but will only accept payment from cards with a US billing address). Although in the end I didn’t have time, because I got sidetracked playing with my new Square, this does illustrate (once again) that there are lots of good reasons for wanting prepaid cards that are nothing to do with not being able to get a credit or debit card.

From the consumer side, prepaid allows consumers to test new opportunities and options without risking a lot of money or putting their bank accounts or credit cards on the line.

[From PaymentsJournal – When It Comes to New Payments Technology, Prepaid Will Lead the Way]

This is a good point, but I feel there’s another reason for thinking that prepaid will be developing in interesting directions, at least in Europe. You don’t need to be a bank to offer prepaid services: the combination of an Electronic Money Institution Licence (ELMI) and a Payment Institution Licence (PI) means that any company can offer a full service: an open-loop prepaid card. I suspect that many of the companies applying for these licences are doing so because they want to use new technology to deliver new services that need payment, if you see what I mean. That is, they don’t expect to earn money from the payments themselves, but from the value-added services that need the payments to take place.

I’ll be looking out for trends around value-added at this year’s Prepaid Conference in London on 13th-15th June 2011. In an act of magnificent generosity, the wonderful people at Clarion have given me a delegate pass for the conference — worth an amazing ONE THOUSAND FOUR HUNDRED AND NINETY FIVE POUNDS — to give away on this blog as a competition prize. So if you are going to be in London on those dates and you’d like to come along to meet practitioners, thought leaders and me, then all you have to do is be the first person to respond to this post telling me what the conference sponsors MasterCard were originally called when they started in 1966.

In the traditional fashion, this competition is open to all except for employees of Consult Hyperion and members of my immediate family, is void where prohibited and has been designed to be carbon neutral. The prize must be claimed within three months. Oh, and no-one can win more than one of the Digital Money Blog prizes per calendar year.

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

]]>
http://tomorrowstransactions.com/2011/05/prepaid-could-be-should-be-great/feed/ 6
Mexican standoff http://tomorrowstransactions.com/2011/04/mexican-standoff/ http://tomorrowstransactions.com/2011/04/mexican-standoff/#respond Wed, 20 Apr 2011 18:45:26 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2011/04/mexican-standoff/ [Dave Birch] While strict identity requirements may superficially aid the forces of law and order, they may also help criminals.

]]>
At last year’s conference on The Macroeconomics of Mobile Money held at Columbia University in April 2010, Carol van Cleef (a partner at Paton Boggs LLP in Washington) gave a presentation on the “Opportunities and Dangers of E-Payments”, in which she noted that the Mumbai terrorists used mobile phones and “showed themselves to be part of the mobile phone generation” (as, I imagine, they showed themselves to be part of the mass transit generation and the automatic weapons generation). She notes that the attackers were using their own phones (so the IMEIs could be tracked, making the life of law enforcement easier) and that they had purchased more than 37 SIMs in different names using false identification (so the compulsory SIM registration was shown to be pointless — although some of the SIM card sellers were arrested). She also says that the most critical tool for drug traffickers in Canada is the prepaid phone (I’m sure she’s wrong: I’ll bet it’s either cash or cars).

I remember thinking when I read this at the time that this continued law enforcement focus on the prepaid phone and the prepaid card, both of which are critical tools for financial inclusion, would end up with restrictions on both that would make no difference to criminals but would make life much harder for the financially excluded, because of the strong link between identity and money.

Why do I think that? Well it is just not clear to me that demanding strong proof of identity for prepaid products will help. In Mexico there is a national registry for prepaid phones and all purchasers are recorded and fingerprinted, the operators keep calls logs, texts and voice mail for a year (in a database only accessible with a court order — or by criminals, I’d wager). All prepaid phones not in the registry were supposed to be turned off this month, although a quick round of googling and searching couldn’t tell me whether this is actually happening or not. As I wrote a couple of weeks ago, in the context of the Mexican government’s reward scheme for people who call in reports of money laundering:

Good luck to anyone who decides to report in person, or by telephone. SIM registration is mandatory in Mexico, which means that the money launderers will find you before the police do

[From Reputation does not depend on “real” identity]

If we focus on phones, for a moment, is it reasonable to assume that demanding identity in the purchase of phones (prepaid or otherwise) will do anything to reduce crime (or will it simply shift the crime to acquiring identities and actually raise the criminal premium on those identities?).

Eight men and one woman have been arrested on suspicion of conspiracy to defraud… calling expensive premium-rate numbers owned by the fraudsters that charge up to £10 a minute… O2 had a total of £1.2m stolen through premium phone lines throughout July, with police claiming that a West African gang bought the phones from high street stores using false identities.

[From British police arrest iPhone scam gang | News | TechRadar UK]

Like many similar scams, this isn’t a mobile fraud or a payment fraud or any other kind of fraud: it’s basic identity fraud, yet again. To some extent, therefore, one has to be a tiny bit unsympathetic to O2. Clearly, if they make everyone jump through hoops to get an iPhone then they won’t sell very many of them. On the other hand, allowing people to take out contracts without really proving who they are or (and this is the commercial arrangement that is lacking) providing an identity that is underwritten by someone who will take liability for it being wrong, means accepting risk. Remember, it’s not the mobile operators, handset manufacturers or criminals who pay for the police raids, the court system, the prison time: it’s us, the taxpayer. So the distribution of risks is not aligned with the distribution of liabilities, as is so often the case in the world of identity fraud. This isn’t a UK-only problem. It is very clear that in countries without secure national identity registers (ie, almost all countries), requiring mobile operators to determine the identity of subscribers (contract or prepaid) will solve nothing. This does not, by the way, mean that it is impossible to catch criminals. Far from it.

Deputy District Attorney Mena Guirguis said that after Manunga and her former boyfriend stopped dating in 2008, she took out a pre-paid cell phone in his sister-in-law’s name, and started sending the threatening text messages to her regular cell phone… Her scheme was uncovered when the victims went to the phone store, talked with the salesman and learned that Manunga had bought the pre-paid phone under the sister-in-law’s name, Guirguis said.

They reported that information to a Costa Mesa police detective, but by then a third arrest warrant had been issued for the sister-in-law. During a follow-up investigation, the detective discovered that most of the threatening text messages were sent when the pre-paid cell phone was in close proximity to Manjunga’s home or work.

[From Woman jailed for making threats – to herself | sister, law, manunga – News – The Orange County Register]

What this story shows is that actual police work is helped by the perps using mobile phones, even if you don’t know the identity of the person using the phone, because phones mean tracking and tracing and location. We read today that iPhones keep a complete record of everywhere they’ve been…

Apple iPhone users’ movements are being tracked and stored without their knowledge in a file that could easily be accessed by a snooping employer or jealous spouse, security researchers have found.

[From Apple iPhone tracks users’ location in hidden file – Telegraph]

Surely it would be better to have criminals running around with iPhones, sending money to each other using mobile networks and generally becoming data points in the internet of things than to set rigorous, quite pointless identity barriers to keep them hidden.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

]]>
http://tomorrowstransactions.com/2011/04/mexican-standoff/feed/ 0
In all conscience http://tomorrowstransactions.com/2011/04/in-all-conscience/ http://tomorrowstransactions.com/2011/04/in-all-conscience/#comments Thu, 14 Apr 2011 12:24:55 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2011/04/in-all-conscience/ [Dave Birch] Criminals need new strategies because of changes in the payments landscape, just like banks do.

]]>
I’m giving a keynote at the Smart Card Alliance conference in Chicago in a couple of weeks. It’s going to be about EMV in the USA. I’ve just been mulling it over, and once again looked at Deborah Baxley’s neat summary of the immediate future for the US cards business:

Banks scrambling to replace lost fee revenue will likely shift focus to credit and prepaid, impose DDA and other fees, along with new account services and comprehensive pricing packages.

[From Changing the Game in Cards – pymnts.com]

It’s not just banks who have to rethink their strategies because of developments in the payment sector. I note that in the UK, according to the Centre for Economics & Business Research reported in Fraud Watch 6(18), nearly 100,000 people were victims of direct debt fraud last year, a direct consequence of the use of chip and PIN at retail POS. As card fraud has become more difficult, the criminals have shifted their focus. Direct debit fraud was one basis point of identity fraud cases a decade ago, now it is a tenth of all cases. Criminals have to adapt to chip and PIN just as banks and merchants do.

A GROUP of seven postmen intercepted letters containing credit cards, switched the microchips of the cards with fake ones and then delivered them to the applicants… the syndicate also had the help of a National Registration Department (NRD) officer who supplied them with the names of the mothers of the real credit card applicants

[From 7 M’sian postmen nabbed for credit card fraud]

It’s interesting to think like a criminal. Well, sometimes. In Chicago, two men were shot by guards while trying to rob a cash transit.

The dead suspect was identified as Jimmy Townsend, 52… a convicted felon and was sentenced to 10 years in prison for two separate armed robbery convictions.

[From 2 suspects shot, one fatally, in armored truck heist – Chicago Breaking News]

Armed robbery is a bizarre crime. I think I’m right in saying that in the UK the average sentence is longer than that for murder. In the US, Mr. Townsend spent years in jail for it, and then got killed doing it again. How dumb did he have to be go back to trying to rob armoured cars. If only he read the Digital Money Blog, he would have known that there are much easier targets.

The heavily-armed gang made off with the tournament jackpot of 242,000 euros ($327,000; £217,000) in early March. Police said a 28-year-old Lebanese man, the fourth arrested in connection with the raid, had been detained on Sunday.

[From BBC News – German police arrest poker tournament heist suspect]

OK, so not all of them got away, but casinos are not a bad idea for enterprising criminals. They do have lots of cash, and often the people in them will not report cash as stolen.

Masked men have stormed a packed casino near the Swiss border city of Basel, making off with hundreds of thousands of francs, prosecutors say.

About 10 raiders pulled up at the Grand Casino in two cars just after 0400 (0200 GMT) and smashed their way in, brandishing machine-guns and pistols. The French-speaking gang ordered the 600 guests and employees to the floor while they emptied registers.

[From BBC News – Switzerland casino is robbed by armed gang]

Criminals follow the path of least resistance. I hope Bankerstuff don’t mind me quoting from a marketing e-mail they sent me concerning a forthcoming webinar.

A Former Bank Robber Shares Security Insights During Live Webinar on April 28 from 2:00 – 3:00pm Eastern

Troy Evans pursued a career as a self-employed addict, drug dealer, gambler and thief for more than 15 years. Ultimately, his disregard of values and discipline resulted in a 13 year federal prison sentence. Facing the obstacles, pressures and violence of prison life, he was determined that his time behind bars would not be wasted… Having met and interviewed over 300 bank and credit union robbers he is able to give us a “look into the mind of the enemy”. Troy answers questions such as… What can financial institutions do to deter a desperate criminal?

I would have thought than an obvious idea would be to not have any cash since, as another bank robber famously remarked, he went “where the money is”? When it comes to card payments, the money is in getting hold of card details and (because of the switch to chip and PIN) PINs. Here, the criminals soon adapted their strategies to deal with the new instruments.

Victorian Police believe international crime syndicates are bribing shop workers in return for access to EFTPOS terminals as part of an elaborate scam. They believe criminals have stolen as much as $80 million from Australian bank accounts over the past year…

The syndicates install cameras in ceilings to film people entering their identification numbers.

[From EFTPOS scam costs Australians $80m – ABC News (Australian Broadcasting Corporation)]

They’re using these PINs (since they can’t make counterfeit chip and PIN cards) with the card details to withdraw cash from ATMs. Once all of the cards and ATMs are chip-only, this avenue will be closed to them. Thus while chip and PIN isn’t perfect, it’s good enough to push criminals into other channels. So: a thought experiment…

Suppose we improve the security of payment systems to the point where they cannot, effectively, be broken. Theft, fraud and hacking are not possible. Where would criminals go next? I think they’re spoilt for choice, so relatively small improvements in payment security would send them off to pasture news.

The poll of 533 firms shows that 55% experienced fraud in the last 12 months, with 61% of these hit more than once, a similar picture to the previous year. In total, 75% of the businesses participating in the study experienced online account takeover and/or online fraud.

[From Finextra: Account takeover fraud plaguing US small businesses]

SME account takeover seems much easier than armed robbery and much more profitable. The so-called man-in-the-middle attacks on OTP systems for remote access to baking accounts are an established attack vector.

According to BillingScore, 19.4% of the value of all transactions in the U.K. premium rate sector are fraudulent, or roughly £1 on every £5 spent. “With the premium rate sector in the U.K. mobile industry currently worth in the region of £700 million, this equates to £135.8 million per year being lost to fraud in the U.K. alone,” the company said.

[From UK mobile operators ‘hide’ £136m annual fraud loss]

A fifth? As opposed to a few bp in cards? I predict that any forward-looking criminal in this scenario will be eyeing up the telecommunications opportunities. So let’s look at what some forward-looking criminals are doing. I think criminals in eastern Europe are a useful barometer, because they tend to be well-educated and computer-savvy. And they get arrested for time to time so we can see what they get up to. Here’s the stash of Romanian hackers arrested last year. You will, of course, note that it does not include low maximum balance prepaid cards or accounts.

77,350 euros, 49,000 U.S. dollars, 64,860 pounds, 60,645 lei, a luxury watch, a rifle, three pistols and 150 grams of gold. 70 laptops, 165 mobile phones, 35 desktop computers, 15 modems, new servers, 10 blank cards, 2425 SIM cards…

[From CyberCrime & Doing Time: Nicolae Popescu, Romanian hacker, at large!]

So not only the usual euros and dollars, but also gold (clearly the hackers were diversifying) and also two-and-a-half thousand SIM cards. Two-and-a-half thousand! Here are people taking the messages of convergence, future-proofing and cloud payments quite seriously. As Eric Schmidt said when still with Google, if you don’t have a mobile strategy then you don’t have a strategy. Now, if you’re like me, you will wonder what on Earth they are going to do with these SIMs. Then I remembered something that I’d read a while ago.

Only days after almost two million Bulgarians registered their SIM cards, the Interior Ministry warns that new forms of abuse are appearing. According to the ministry, two cases had recently been uncovered in which telephone fraudsters had allegedly offered 50 leva to Romas for registered SIM cards, Bulgarian daily Standard reported… the Interior Ministry as saying that it expected a flood of SIM cards, registered to Romas and homeless people, to appear on the market in the coming weeks.

[From Interior Ministry warns of trade in registered pre-paid SIM cards – Bulgaria – The Sofia Echo]

Mystery solved. The answer to why there should be a significant value attached to SIM cards that you can buy for virtually nothing in any shop is, naturally, government policy. After pocketing their windfalls from selling their SIM cards, the homeless and Roma presumably went off to celebrate their good fortune, whereas the criminals went off to figure out how to create a mass supply instead of having to negotiate with individuals.

…only four months into 2010, and organised crime groups already have found ways of beating the system. In fact, there are unsuspecting people right now who are completely unaware that their mobile phones, or names and registration, are being used for serious criminal activities… Radio host Borislav Borissov found out that he was the “proud owner” of about 200 different SIM cards, all registered to his name and personal social security number.

[From Bulgarian criminals ‘beating the system’ of pre-paid SIM card registration – Bulgaria – The Sofia Echo]

I know where I’d invest my criminal dollars! Mobile is the future! No, of course, I’m just joking to make a point. If I really was going to invest dollars in a criminal enterprise, it would be in Somali pirates, except for one sticking point. I’m afraid my strict ethical position will not allow me to deal with these people.

The al Shabaab group, which professes loyalty to al Qaeda, said mobile money transfers (MMT) helped feed Western capitalism and were turning Somalia’s Muslims against Islamic banking practices.

[From Somalia’s al Shabaab bans mobile money transfers | Top News | Reuters]

I cannot do sufficient violence to my conscience to support a group who are against mobile payments.

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

]]>
http://tomorrowstransactions.com/2011/04/in-all-conscience/feed/ 1
The fraud trajectory http://tomorrowstransactions.com/2011/02/the-fraud-trajectory/ http://tomorrowstransactions.com/2011/02/the-fraud-trajectory/#comments Fri, 25 Feb 2011 15:33:16 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2011/02/the-fraud-trajectory/ [Dave Birch] I'm very optimistic about fighting card fraud: the force is with us

]]>
There’s no doubt that chip and PIN is one of the key planks in the industry strategy to reduce card fraud to manageable levels (which is not the same as eliminating card fraud, note). One of the reasons why it is so secure is that is uses offline PIN verification, where the chip on the card checks that the PIN input at POS is the correct one. And since the PIN is known only to the cardholder, and they never divulge it, this provides validation that… no, wait…

Despite the strict recommendations from card providers about keeping your PIN confidential, research by shopping website VoucherCodes.co.uk has revealed that over half (59pc) of Brits are flouting the rules by sharing their bank card PIN codes and are putting their personal finances in jeopardy.

[From More than half of card users share their PIN – Telegraph]

Uh oh. But come on – anyone out there in the real world will know that it’s impossible to get through life without giving your spouse your PIN. What happens when (to pick a hypothetical example) she can’t remember what the hell she’s done with her handbag and needs to get to Homebase to buy some paint? Or (to pick a hypothetical example) a husband may have stupidly left his wallet in his desk at work but needs to get cash out at an ATM on the way to a football game. Come on – we’ve all done it (except me, I should point out to the terms and conditions chaps at Barclaycard).

The poll of 3,000 people revealed that Brits are most likely to entrust their partners with this security information, but a surprising one in twenty (5pc) adults feel that it is safe to divulge this information to their children.

[From More than half of card users share their PIN – Telegraph]

What? Not in my house they don’t. We have a Visa prepaid card for “house” use, so if the kids need to get some shopping, stuff for school or other supplies, they use that one, and I top it up online when necessary. It’s a simple way to manage money, so I’m surprised more people don’t do this: and it has the added benefit that it doesn’t have a name on it, so if it gets lost or stolen it can’t be used to start identity fraud.

Incidentally: 3 per cent of the people surveyed said that they wrote their PIN on a piece of paper and kept it in their wallet, which may account for at least some of the incidence of the ATM and POS chip and PIN fraud more plausibly than complex attacks on the unencrypted messages between the card and terminal.

There are plenty of other initiatives aimed at improving the overall level of card security. 3D-Secure has taken a long time to get traction but is now widely used in e-commerce. PCI-DSS is costing a fortune, but may reduce the industrial-scale counterfeiting of the magnetic stripe cards still widely used for retail payments in less-developed parts of the world.

In raids conducted Feb. 1, agents seized $300,000 in cash, three firearms and ammunition as well as equipment to make fake credit cards from the gang… The credit card details and stolen identity information was purchased from “online data traffickers via Web-based portals, and the purchasers would store the stolen credit card information in shared e-mail accounts, allowing several defendants to begin creating counterfeit credit cards,” prosecutors said.

[From US indicts 27 in Apple product credit-card fraud ring | MP3 Players | Macworld]

Anything that stops card details like these from falling into criminal hands so easily must be worth the money, right? Actually, on the costs of PCI-DSS, there may be some relief in sight for European retailers.

Visa last week announced a new programme which means European merchants will no longer need to prove they adhere to PCI DSS regulations on an annual basis, as long as 75 percent or more of their transactions originate from EMV-enabled chip and pin terminals. The programme will be introduced on 31 March, 2011

[From Visa PCI DSS exemptions send out mixed messages to merchants | Business Computing World]

So come on, it’s not all bad. In fact the bottom line is that the fraud figures have been improving, and I expect them to improve further still over the next couple of years as we begin the integration of cards and mobiles. This is because even simple integration (eg, texting unusual transactions) delivers good returns and the impending integration of payments with handsets means that issuers will be able to go even further with 24/7 access to the “card”. I won’t rehearse the basic arguments, but I think there are many reasons for thinking that the mobile is a means to manage card fraud down, and line of thinking that we have presented frequently over the years.

So, are mobile payments safe or not? It’s not a “yes” or “no” question, as we hope this discussion has shown. Let’s ask another question instead: Can we make the risks of mobile transactions manageable? The answer to that is “yes”. In fact, in the particular case of mobile proximity payments, we happen to believe that there is more security overall in using a mobile than in using a card payment

[From TM Forum – Article: Mobile Payments – Safer than Cards?]

For one thing, as noted, we can use the mobile to provide information and as communication channel to report on and detect suspicious activity. Potentially more interesting, though, there are techniques that take advantage of the characteristics of the mobile channel, primarily location There are some practical problems to be overcome though.

ValidSoft [has] direct access to mobile networks, tables, and services around the globe and can provide mobile based location services without requiring that users opt in. Many financial institutions are interested in using these services for fraud detection but are concerned about the privacy implications and don’t want their customers thinking they are following them around.

[From Visa Europe sets trend with mobile location-based fraud detection]

Actually, I might well want my issuer to follow me around, but I might also want it to stop other people from following me around. Anyway, I’ll be talking about this kind of thing — including lessons from our practical experience advising leading payments organisations around the world and some of the things we are learning from the Ph.D in mobile handset security that Consult Hyperion is funding at the University of Surrey — at the excellent UK Card Fraud Conference on 29th/30th March 2011 in London.

The magnificent people at DT Conferences have given me a delegate pass for the event — worth an amazing ONE THOUSAND TWO HUNDRED POUNDS plus VAT — to give away on this blog as a competition prize! So if you are going to be in London on those dates and you’d like to come along to meet some of the leading thinkers in the UK’s fight against card fraud (and me) then all you have to do is be the first person to comment on this post with the name of the doomed precursor to 3D-Secure, the PKI-based online card payment security system developed in the 1990s: full name, please, not just the TLA!

In the traditional fashion, this competition is open to all except for employees of Consult Hyperion and members of my immediate family, is void where prohibited and has been gritted for your safety. The prize must be claimed within three months. Oh, and no-one can win more than one of the Digital Money Blog prizes per calendar year.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

]]>
http://tomorrowstransactions.com/2011/02/the-fraud-trajectory/feed/ 2
Why us? http://tomorrowstransactions.com/2011/02/why-us/ http://tomorrowstransactions.com/2011/02/why-us/#comments Fri, 11 Feb 2011 11:18:56 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2011/02/why-us/ [Dave Birch] Three times as many Brits are victims of card fraud as, say, Dutch. Why?

]]>
Our good friends at ACI Worldwide have just released their annual Global Card Fraud Survey, which contains some rather bad news: the UK has more card fraud than many other countries. We’re up there with the US, with three times as many people affected than in Germany and the Netherlands. So a third of us have been victims of card fraud compared to only a tenth in Netherlands. Why? Are the Dutch more honest than Brits? Are their cards more sophisticated? No. I think there are two main reasons for this discrepancy.

First of all, while chip and PIN has cut fraud on the high street, card-not-present fraud is still a big problem. In the UK, cards still account for a big portion of online payments. In the Netherlands, and some other countries, they don’t. More than two-thirds of Dutch e-commerce purchases are made with iDeal, a bank-based scheme that has no equivalent in the UK (or the US, or pretty much anywhere else for that matter).

Second, UK credit cards have high limits. In the last couple of weeks, both of my main card issuers have written to me raising credit limits (I didn’t ask for this in either case). If you’re going to steal some card details, you’d go for cards that are likely to be some way from their limit.

The survey wasn’t all bad news, by any means. I found it interesting that the proportion of people who had been victims of card fraud but were satisfied with the response of their issuer had actually increased slightly, to almost four-fifths, which isn’t bad. Personally, like the majority of people surveyed, the last time there was a strange charge on my card, the bank took off the charge then cancelled and reissued the card.

The agent informed me that new cards for me and my wife would be Fed-Ex’d, to arrive today or tomorrow. What followed were a series of texts from merchants that have my credit card on file for automatic billing, delighting me with the knowledge that I won’t be able to use such services as the Bay’s FasTrak toll lanes or uninterrupted cable service until I update my records.

[From I’m a five-time ID Fraud victim; How crazy is that? – Javelin Strategy & Research Blog]

Think how expensive this all this though: cancelling and re-issuing cards, call centre seats, letters and whatever else. So we still need to do better. Only around a third of people (fewer than before) said that they would switch financial institutions because of card fraud, which is bad news for people trying to sell anti-card fraud solutions to high street banks.

The poll of 970 UK adults, part of the bi-annual global Unisys Security Index, reveals that cyber-security is the public’s chief concern, with 85% of respondents worried, and over 50% “seriously concerned”, about bank card fraud and identity theft.

[From Finextra: Brits switching banks over security and privacy concerns – Unisys]

This is odd, I think. I couldn’t care less about bank card fraud, since it’s the banks’ problem and not mine. I never use a debit card for anything, offline or online, so I’m totally protected by the legislation around credit cards. I’m more worried about identity theft, because it’s more time consuming to put right, but that’s a different issue (being discussed at the CSFI yesterday, as it happens).

The press release also noted that 81% of people have confidence in their issuer protecting them from fraud. I think that this may be a little simplistic, for that very reason: had I been asked for the survey, I would have said that I don’t really care about Barclays’ ability to prevent fraud on my splendid OnePulse credit card because it’s their problem.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

]]>
http://tomorrowstransactions.com/2011/02/why-us/feed/ 3