Tomorrow's Transactions » fraud http://tomorrowstransactions.com Thought leadership from Consult Hyperion Fri, 18 Jul 2014 06:22:13 +0000 en-US hourly 1 http://wordpress.org/?v=3.9.1 Crime and contactless http://tomorrowstransactions.com/2014/06/crime-and-contactless/ http://tomorrowstransactions.com/2014/06/crime-and-contactless/#comments Fri, 06 Jun 2014 17:49:50 +0000 http://tomorrowstransactions.com/?p=4476 Just because there isn’t any contactless crime does not mean that we should ignore the fears of consumers (or, for that matter, the police). Time for some mass market education on cuddle cards, as I now call them. Although we don’t focus on it — by and large because it works and has become business […]

The post Crime and contactless appeared first on Tomorrow's Transactions.

]]>
Dgwb blog white border

Just because there isn’t any contactless crime does not mean that we should ignore the fears of consumers (or, for that matter, the police). Time for some mass market education on cuddle cards, as I now call them.

Although we don’t focus on it — by and large because it works and has become business as usual — I think that contactless payment technology is fun. I had an enjoyable couple of days trying out my usual panoply of cards, phones, watches and stickers when I was last in Canada and I have to report that the situation was all systems go (except for one of my UK MasterCards that was inexplicably declined) whereas in the US it remains mixed. Meanwhile, it’s going gangbusters down under, as I discovered on my last trip to Australia. I paid with cards everywhere, and almost everywhere I paid I paid with contactless. Like in this taxi, for example.

Untitled

Unfortunately, the Aussie rousers are less enthusiastic than I am about the amazing technology, the rapidly-evolving Australian retail payment environment, innovation at point of sale and quick and easy transactions for consumers. They claim, in fact, that there is wave, plague and apocalypse of crime that can be directly attributed to the new technology.

“We’re seeing many, many theft of motor cars, handbags and burglaries where people are looking for these cards, are getting hold of them and within hours of getting them, they’re going into stores and using them.

[From Tap-and-go credit cards contributing to increase in crime stats, Victoria Police says - ABC News (Australian Broadcasting Corporation)]

This is, if true, rather interesting. I say “if true”, of course, because I have been unable to uncover any statistics that back up the Victoria police claim. Nor, it seems, have any of their fellow law enforcement agencies.

Police around the country have differing views on the effect the cards are having on burglaries. The NSW Police said it had “not seen a spike in credit card related fraud since the advent of contactless payment technology”.

[From Banks stare down police over tap-and-go]

Still, this tidal wave of contactless crime must surely have shown up in the bank fraud statistics.

One of the major banks said on Thursday it had 30 per cent more ­contactless cards in the market compared with a year ago but card fraud was flat.

[From Banks stare down police over tap-and-go]

Oh well. Let’s just assume for sake of argument that there is a crime wave, plague and apocalypse but only in Victoria and only amongst issuers who do no collect or report card fraud statistics. That still sounds like a bank problem to me, since issuers will bear the losses. If a mugger demands my contactless card then I will give it to him. I couldn’t care less since it’s not my problem: the UK banks have an unequivocal guarantee to refunds unauthorised transitions. Nevertheless, the Melbourne heat seem most upset about contactless in general and especially miffed that they were not one of the stakeholders consulted in the banks’ roll-out.

he said police were not consulted before tap-and-go credit cards were introduced and that he regretted their introduction… “They are chewing up an enormous amount of police resources.

[From Tap-and-go credit cards contributing to increase in crime stats, Victoria Police says - ABC News (Australian Broadcasting Corporation)]

The crime wave, by the way, does not seem to have affected public confidence, since contactless use continues to soar. It is at very high levels in Australia already, with more than two-third of supermarket transactions already tap and go. Use amongst police chiefs, so far as the statistics presented in the article would indicate, seems particularly high.

Mr Lay did admit he used a tap-and-go card all the time.

[From Tap-and-go credit cards contributing to increase in crime stats, Victoria Police says - ABC News (Australian Broadcasting Corporation)]

Aha. I should point out, by the way, that the Victorian peelers objections to contactless go back some time. They’ve always been uncomfortable with contactless.

Police want to ban banks’ tap and go technology after vowing to take on big business over sloppy work practices. The force said it is sick of “mopping up” for “totally slack” initiatives that it states encourage crime.

[From Police want ban on tap and go technology, saying sloppy practices can promote crime | Herald Sun]

We have to address real issues, of course, but the fact is that public perception around contactless is not always rational. That Australian story was widely reported in the British press, fuelling public concerns (I have made a fascinating podcast with Karen Williams from Spectrum Insight on this topic). The British press have, it seems to me, always been rather keen on these scare stories. See this hilarious comment on a Daily Mail story about contactless.

It is well known that in America, thieves carry tablets and electronic readers in bags, walk around railway stations and shopping malls and scoop up all data automatically from these cards.

[From Customers charged twice for items because contactless cards were activated from their pockets | Mail Online]

Really? “Well-known”? If anyone can point to me a single reputable report of this ever happening, I would be grateful as I would like to link to it and continue the investigation. Far from being “well-known” I frankly doubt that it has ever happened at all. If you jammed an electronic reader up against my arse on the Tube, and kept it there undetected long enough to scan my card (I only have one in London wallet – haven’t you ever heard of card clash) then you would not get my name or the CVV for the card, so it’s not much of master crime. You can’t use the data to make a clone card and you can’t use it to buy online. Neverthess, as the analysis of contactless sentiment I discussed earlier in the week show, just because something doesn’t happen does not mean can ignore it. If consumer believe it, then we must deal with it.

I think we as an industry should probably be reacting to the “fear” area with some pretty clear messaging around how the technology works, how liabilities are distributed and the consumer protection that the combination provides.

[From Contactless sentiment - Tomorrow's Transactions]

The traditional way of educating the mass market in the UK about anything is to pester the BBC to include it as an EastEnders story line. I shall come back with some ideas soon, but since I haven’t watched EastEnders for at least a decade, it may take some research to get a viable narrative.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Crime and contactless appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2014/06/crime-and-contactless/feed/ 4
Cash hits the excluded http://tomorrowstransactions.com/2014/05/cash-hits-the-excluded/ http://tomorrowstransactions.com/2014/05/cash-hits-the-excluded/#comments Fri, 23 May 2014 18:08:25 +0000 http://tomorrowstransactions.com/?p=4447 There are good reasons for providing electronic payment systems to the less formal parts of the economy, for people who deserve better than cash. As Professor Douglas McWilliams entertainingly described in his Gresham College lecture (14th February 2014) called “Prostitutes and software developers — A short history of the Italian black economy”, Italy decided to […]

The post Cash hits the excluded appeared first on Tomorrow's Transactions.

]]>
Dgwb blog white border

There are good reasons for providing electronic payment systems to the less formal parts of the economy, for people who deserve better than cash.

As Professor Douglas McWilliams entertainingly described in his Gresham College lecture (14th February 2014) called “Prostitutes and software developers — A short history of the Italian black economy”, Italy decided to revise its GDP calculations back in 1987 in order to obtain membership of what is now the G8 by including estimates for its “black economy” in the figures. When these estimates were added, Italy’s GDP surpassed the UK’s and Italy was asked to make a greater contribution to the European Union! Oops. Anyway, to restore fair contributions, some years later, European Union statisticians revised their methodologies to treat the black economy equally in all EU countries and things like software and drug-dealing and prostitution were added to the figures in 1995.

In Diane Coyle’s excellent “GDP: A Brief but affectionate history”, she talks about this statistical revision and says that “the largely cash-based informal economy of moonlighting, avoiding taxes and regulations, but creating work and output, has been placed inside the production boundary”. So it’s measured, but the people in that economy are not contributing their fair share to the national piggy bank. We [the payments industry] don’t spend much time thinking about the black economy, but it’s an untapped market for electronic payments. Why? Well, yes, there’s a tax penalty to switching to electronic payments, but on the other hand dealing in cash is not always the optimum transactional solution. There are problems living in a cash economy.

When I went to a strip club where I could pay in Bitcoin, a dancer told me she had been tipped in Japanese and Pakistani currency in the past and had no idea what it was worth until she went to a money exchanger to cash it in. The latter wasn’t even worth changing for dollars.

[From 21 Things I Learned About Bitcoin Living On It A Second Time]

I was fascinated by this story about the weakness of cash in relation to Bitcoin and it reminded me of something I’d seen elsewhere about the relationship between cash and, and I hope readers of a gentle disposition won’t be offered by this phrase, “sex workers”. People who live on the margin get screwed by cash.

In the eastern Indian city of Calcutta, a non-governmental organisation has started a programme to help sex workers recognise fake currency given to them by clients,

[From BBC News - Teaching Indian sex workers to spot fake currency]

I can genuinely say in all of the impassioned rants against cash that I have made an industry gatherings, it had never occurred to me that one of its failings was that people would use counterfeits to defraud prostitutes. So another count is added to the prosecution charge sheet.

Prostitution is illegal in India, meaning the country’s estimated three million sex workers cannot complain to police if they are paid with fake notes. But a campaign group known as the Committee for Indomitable Women has now begun a training programme in Kolkata’s notorious Sonagachi red light zone, where an estimated 8,000 sex workers ply their trade.

[From Indian sex workers learn to spot counterfeit currency - InterAksyon.com]

Should I ever go to Calcutta, I swear I will go to meet the Committee for Indomitable Women and offer them my full support and a mobile POS. In a country where counterfeits are widespread, it is obviously the marginalised groups trapped in the cash economy who are the big losers. Fortunately, the Indian central bank has decided to help out a bit by withdrawing some of the most counterfeited notes.

Few months back, the Reserve Bank of India has clarified giving reason why pre-2005 are being removed from the system. The RBI had said, “Before 2005, the neighbouring countries had printed fake currency in large quantities”.

[From Post-2005 counterfeit notes enters Indian system before election, NIA increases surveillance : Highlights, News - India Today]

What’s my point? Well, we need to provide payment systems that deliver privacy (not anonymity) so that we can provide better alternatives to cash for people who live in the margins. They deserve better than cash.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Cash hits the excluded appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2014/05/cash-hits-the-excluded/feed/ 1
Biometrics are the answer if you ask the right question http://tomorrowstransactions.com/2014/04/biometrics-are-the-answer-if-you-ask-the-right-question/ http://tomorrowstransactions.com/2014/04/biometrics-are-the-answer-if-you-ask-the-right-question/#respond Wed, 02 Apr 2014 08:23:53 +0000 http://tomorrowstransactions.com/?p=4351 Many people think, correctly, that biometrics can help to improve security for mass-market payment systems. But you have to use them the right way. How would did you pay for your last car? Or your last cup of coffee? Did you use different payment products or technologies for these different purposes? I didn’t: I used […]

The post Biometrics are the answer if you ask the right question appeared first on Tomorrow's Transactions.

]]>
Dgwb blog white border

Many people think, correctly, that biometrics can help to improve security for mass-market payment systems. But you have to use them the right way.

How would did you pay for your last car? Or your last cup of coffee? Did you use different payment products or technologies for these different purposes? I didn’t: I used my debit card for both. In order to buy the car, I just had to know the PIN. In order to buy the cup of coffee, I didn’t have to know my PIN (or signature or anything else) but I did have to provide photo ID. As a consequence, it took longer to buy the coffee and was less convenient. Welcome to the world of payment authentication.

I don’t think buying car using a chip and PIN card is remarkable or even interesting, by the way. I’m sure people do it all them time. Here’s a chap in Canada who did it, for example.

Monaco, the founder and managing partner of a Toronto investment relations firm, alleges in his lawsuit that he discovered the charge of $81,276 “during a routine check of his Visa account balance” in June 2010.

[From Bank customer's lawsuit raises questions about fraud liability - Canada - CBC News]

So the guy bought a car with a chip and PIN card. As I said, we’ve done the same. When my wife bought her new car, we paid using chip and PIN. Having test driven the car, a used Peugot, and decided that she wanted it, we arranged to go and complete the sale. I called the dealer and asked if he wanted me send him the money over the interweb tubes (in the UK, we have the immediate settlement Faster Payment Service, FPS, so I could have sent him the money by PingIt or mobile banking with no trouble at all) and he said that no, a debit card would be fine (*). We drove down to dealership, signed the papers, I put by bank debit card into the terminal and entered by PIN. Transaction accepted. I thought I might get a phone call from my bank just to double check that I was buying a $12,000 used car with my debit card, but I never did.

Compare and contrast this pleasant and quick purchasing experience with my most recent card purchasing experience in America where, as I mentioned before, I was required to produce photo ID to buy a $3 cup of coffee on my Simple card. As was Jim Bruene, who was similarly surprised by the state of payments in the US in 2014!

it was more of a waste of time that you might imagine, since the photo ID I showed was an expired building pass for our New York office. Anyway, back to my point. If had a card with an $80,000+ credit limit and I used it to buy a car, even with a PIN, I would expect another authentication factor. Maybe an SMS to my phone, a message to my Amex app, something. I might even, for charges in excess of, let’s say, $75,000, expect to have my picture taken or be required to use my iPhone fingerprint reader as an additional factor to confirm the transaction.

This is not because the iPhone fingerprint reader delivers James Bond-style nuclear-launch level identification. It doesn’t, because it’s about convenience. In fact it does not guarantee identification at all, but using it as an additional and convenient authentication factor with the range of factors present in the mobile makes complete sense in risk management terms. And I think the public would be happy with it.

One in two people surveyed (49%) stated they would like to have biometric payments, such as fingerprint, palm or iris scanners, far outweighing the popularity of emerging mobile technology options.

[From Biometric payments are top option for security-concious shoppers, survey finds | Retail News]

What this means, other than customers have seen biometrics in Hollywood movies but not NFC, is unclear, but I do think that using biometrics as a convenience technology in authentication for retail payments makes complete sense.

“We expect to see biometrics becoming increasingly prevalent over the course of the next 3-4 years, driven by a desire among vendors and consumers alike to be better protected when accessing mobile services,” summarised [Jean-Noel Georges].

[From Investorideas.com - Biometrics Can Revolutionise Mobile Payment Security, says Frost & Sullivan]

As our old chum Julian Ashbourn (you can listen to Julian in our podcast series here) points out in this excellent new book “Biometrics in the New World–The Cloud, Mobile Technology and Pervasive Identity“, there is a world of difference between using biometrics for identification and using them for authentication to establish entitlement. It is this latter mode, in combination with the mobile phone, that offers us a practical and cost-effective way forward.

* Actually, I know that I always say that I never buy anything with a debit card, but the dealership surcharged on credit cards. Since I figured I had ample warranty and associated legal protections, and that I was buying from a reputable dealership, and that the Avios or cashback that I would get weren’t worth a fraction of the surcharge amount, I decided to use the debit card.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Biometrics are the answer if you ask the right question appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2014/04/biometrics-are-the-answer-if-you-ask-the-right-question/feed/ 0
Loyalty points are money http://tomorrowstransactions.com/2014/03/loyalty-points-are-money/ http://tomorrowstransactions.com/2014/03/loyalty-points-are-money/#comments Tue, 11 Mar 2014 19:03:54 +0000 http://tomorrowstransactions.com/?p=4001 Surely the ultimate proof that loyalty points are in fact a form of money is that people steal them. It is not unusual to hear people at conferences about payments (e.g., me) talk about loyalty points and say that they are already a form of money, which is sort of true. The concrete proof that […]

The post Loyalty points are money appeared first on Tomorrow's Transactions.

]]>
Dgwb blog white border

Surely the ultimate proof that loyalty points are in fact a form of money is that people steal them.

It is not unusual to hear people at conferences about payments (e.g., me) talk about loyalty points and say that they are already a form of money, which is sort of true. The concrete proof that they are form of money is that people steal them. Remember the proliferation of recent stories about Tesco loyalty points being the subject of widespread attack.

Tesco customers have complained that vouchers worth hundreds of pounds have disappeared from their online rewards accounts, raising the possibility that thieves hacked into the company’s system.

[From Tesco calls in police after dozens of customers complain that their Clubcard accounts have been emptied online | Mail Online]

In case you were wondering where these stolen loyalty points are going to, well…

Screengrabs taken from Silk Road 2, the successor to the original site, reveal that its most popular items for sale until recently were Tesco Clubcard vouchers. Vouchers worth £100 each, offered by a vendor using the handle Revivalry, were selling for $61 (£43).

[From Silk Road website did roaring trade in Tesco Clubcard vouchers | Society | The Observer]

Seriously: last weekend, the most popular items for sale on the darkest of dark webs, the spawn of Bitcoin and Satan, Silk Road, were Tesco vouchers. Not terrorist training manuals, ketamine samplers or child porn DVDs, but Tesco vouchers. In other words, money. Sold at a discount. And a pretty big discount (not that I know what money launderers generally charge for this sort of thing). Pound notes selling for 43p.

Yes, these vouchers are money. As I’ve written before, a John Lewis voucher, a Clubcard voucher, a Marks & Spencer’s voucher, are all means of exchange that trade at par. I have personal experience of this and will state unequivocally that I will accept John Lewis vouchers as de facto legal tender for the discharge of debits incurred. I spend a fortune at Amazon, so Amazon e-vouchers are money. Anywhere I spend money, there is the potential for a money substitute. Surely this is where e-money is taking us.

When I was originally mulling over the threats to supermarkets throughout the land, I heard a report on BBC Radio about the Metropolitan Police calling for something to be done about ticket fraud for pop concerts and sporting events, running at about £40m per annum in London, if I heard correctly.

The Metropolitan Police’s specialist ticket fraud unit has called on the government to introduce legislation around the resale of tickets to gigs and sports events.

[From BBC - Newsbeat - Police call for ticket resale legal regulation]

This is ludicrous. It is absurd that ticketing reselling is illegal at all, If you bought a ticket, you should be entitled to do what you like with it. But that’s by the by. The source of these problems are the same as the source of the loyalty points problems and most other fraud problems: As you might expect, the lack of an identity infrastructure. Identity is the money, but it’s also the new loyalty card, the pop concert ticket and the sporting event ticket.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Loyalty points are money appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2014/03/loyalty-points-are-money/feed/ 1
Bitcoin exchange failures don’t mean anything in the long run http://tomorrowstransactions.com/2014/03/bitcoin-exchange-failures-dont-mean-anything-in-the-long-run/ http://tomorrowstransactions.com/2014/03/bitcoin-exchange-failures-dont-mean-anything-in-the-long-run/#respond Wed, 05 Mar 2014 12:38:34 +0000 http://tomorrowstransactions.com/?p=3959 It’s a great set of stories for the media and an illustration of the need to employ boring old-fashioned secure electronic transaction consultants when designing new systems, but the Bitcoin exchange failures don’t really mean anything. The media fascination with Bitcoin continues. The Sunday Times magazine led with a “who is Satoshi” this weekend (they […]

The post Bitcoin exchange failures don’t mean anything in the long run appeared first on Tomorrow's Transactions.

]]>
Dgwb blog white border

It’s a great set of stories for the media and an illustration of the need to employ boring old-fashioned secure electronic transaction consultants when designing new systems, but the Bitcoin exchange failures don’t really mean anything.

The media fascination with Bitcoin continues. The Sunday Times magazine led with a “who is Satoshi” this weekend (they don’t know) and the BBC’s Business Editor, Robert Peston, said last week that

What excites is the development, by Bitcoin enthusiasts, known as miners, of a super-efficient money transmission network on the internet,

[From BBC News - Bitcoin's life-or-death moment]

I would put it slightly differently: it’s a digital asset transmission network, and electronic cash is only one of the kinds of digital asset that might be transferred and quite probably not the most interesting one (if you can transfer digital assets efficiently then you have no need to use cash as an intermediary). But some people are using it for cash, and having handed over that cash to people they had never met before and had no reason to trust, they are predictably upset that it has vanished.

Citing an unnamed company lawyer who also spoke at the press conference, The Wall Street Journal reported that MtGox had lost 750,000 bitcoins (around $412.5 million) belonging to customers, and over 100,000 bitcoins (around $55 million) of its own money.

[From Having lost $468 million in bitcoins, MtGox files for bankruptcy protection | Ars Technica]

On twitter, I couldn’t help remarking on the coincidence of the amount, which rather neatly matches the amount that seems to have gone missing from Citi at the same time.

as much as $400m was misappropriated throughout the course of the fraud

[From BBC News - Citigroup profit hit by Mexican fraud]

Imagine trying to get $400m out of Citi by robbing branches with a shotgun! It is inconceivable. As the old saying goes, if you want to rob a bank, work for it. Which, in the absence of any verified facts whatsoever, leads observers to the natural speculation that Mt. Gox’s money may have walked out of the back door rather than the front.

But I digress. Oh wait, another Bitcoin exchange has just been robbed and shut down. The question I am being asked repeatedly is what the Bitcoin exchange shenanigans mean for the long run. As I said when interviewed for the BBC Today programme, I strongly suspect that it means nothing. And the reason I say this is because as I have long and boringly maintained (starting back in 2011), I don’t think XBT makes sense as a currency and I think the activity around the currency is a speculative bubble (as does Nobel Laureate economist Robert Shiller). I do drink the cryptocurrency kool-aid, but I see the advent of cryptocurrencies that embed values that make sense to wider communities. XBT is different. It isn’t about values, it is about belief.

Bitcoin can’t survive without manufacturing consent for its ideology.

[From The Bitcoin personality cult lives on | FT Alphaville]

That may be true of the currency, but I don’t think it is true of the technology, a genuine breakthrough. Right. I promise not post anything about Bitcoin for at least a week.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Bitcoin exchange failures don’t mean anything in the long run appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2014/03/bitcoin-exchange-failures-dont-mean-anything-in-the-long-run/feed/ 0
Target breach may have consequences beyond EMV http://tomorrowstransactions.com/2014/01/target-breach-may-have-consequences-beyond-emv/ http://tomorrowstransactions.com/2014/01/target-breach-may-have-consequences-beyond-emv/#respond Fri, 03 Jan 2014 15:02:29 +0000 http://tomorrowstransactions.com/?p=2905 The Target breach will encourage the US to adopt EMV, but it’s not a magic bullet. However, the breach may have wider implications for the future of retail transactions than EMV adoption. The fun end-of-year card fraud story was, of course, the infamous Target breach, an epic-scale hack that obtained millions of card details. Nov. […]

The post Target breach may have consequences beyond EMV appeared first on Tomorrow's Transactions.

]]>
Dgwb blog white border

The Target breach will encourage the US to adopt EMV, but it’s not a magic bullet. However, the breach may have wider implications for the future of retail transactions than EMV adoption.

The fun end-of-year card fraud story was, of course, the infamous Target breach, an epic-scale hack that obtained millions of card details.

Nov. 27-Dec. 15: A data hack at U.S. Target stores exposes as many as 40 million credit- and debit-card customers to potential fraud.

[From Target’s Data-Breach Timeline - Corporate Intelligence - WSJ]

The scale of the hack is unusual, but it also noteworthy because of the mechanism employed. If media reports are accurate, then it appear that the retailer’s systems were thoroughly penetrated.

The thieves breached the point-of-sale system (POS) and stole customer magstripe data, including names, credit or debit card numbers, expiration dates and everything else needed to make counterfeit cards.

[From Target Admits Massive Credit Card Breach; 40 Million Affected | Threat Level | Wired.com]

Everything else needed to make counterfeit magnetic stripe cards, to be more specific. But we’ll come back to this later on. One notable feature of the breach was that the POS system was compromised so thoroughly that all of the data that the POS handles, including the PINs, were stolen. In the case of the PINs, however, this is unlikely to help the thieves terribly much.

While we previously shared that encrypted data was obtained, this morning through additional forensics work we were able to confirm that strongly encrypted PIN data was removed. We remain confident that PIN numbers are safe and secure. The PIN information was fully encrypted at the keypad, remained encrypted within our system, and remained encrypted when it was removed from our systems.

[From Target Data Security Media Update #4 | Target Corporate]

In an odd way, I found the reports of what had happened to the card details after they had been stolen as fascinating as the attack itself, because these reports tell us a lot about the shape and nature of the underground market for card details. Brian Krebs has a series of wonderful stories about the breach over at his “Krebs on Security” blog, which I urge you to read, and which has astonishingly interesting observations on that market. Why, for example, is there a discrepancy in the cost of domestic and international cards? 

Hundreds of thousands of cards issued by non-U.S. banks that were used at Target across the United States during the retailer’s 19-day data breach. It’s not clear how quickly the non-U.S. cards are selling, but they seem to be fetching a much higher price than those issued by U.S. banks.

[From Krebs on Security]

I guess it might be that international cards have chips on them but that fraud systems have been told to allow stripe transactions but only in the US. Personally, I would prefer my issuers to disallow stipe (and online) transactions for all of my cards unless I specifically tell them others. My Barclays debit card, to give an obvious example, has a stripe on it and is embossed 1950s style. I would prefer it to have neither. But back to the story. Issuing banks have responded in different ways. Some have placed limits on compromised card activity, some have invited customers to ask for new cards if they are worried and so and so forth.

Many banks are taking more of a wait-and-see approach, asking customers to monitor their accounts, and using the banks’ fraud analytics software to monitor transactions for signs of foul play, but not rushing to close accounts and reissue cards.

[From Target Breach Raises Questions About Security, Account Limits and EMV - American Banker Article]

Sales at Target stores are supposedly down slightly but I don’t know enough about the figures to know whether this is due to the breach or not. What our clients are more interested in, I’m sure, is looking at what will be the longer term impact of the Target breach. Gartner analyst Avivah Litan, who I always pay attention to, puts it simply:

it’s time for the U.S. card industry to move to chip/smart cards and stop expecting retailers to patch an insecure payment card system.

[From What can we learn from the Target Breach]

I’m sure everyone agrees that this is the way forward. When Avivah says “smart cards” she means payment cards that use the EMV (“Europay-MasterCard-Visa”) standard  that it used almost everywhere else in the entire world. So let’s look at how exactly EMV might have helped. In an EMV scheme, it doesn’t matter if you capture all of the card details that are sent unencrypted from the card to the terminal. That is because you cannot use these details to create either a counterfeit magnetic stripe card (because the ICVV given up by the card chip is not the same as the CVV on the magnetic stripe) or a clone chip card (because you do not have access to the security keys inside the chip – these are used to create the digital signatures passed in the transaction). What’s more, you shouldn’t be able to use those details in a CNP transaction either, because they do not include the CVV2 on the back of the card. However, some retailers — and it is up to them because it is at their own risk — do accept cards for online payments without checking the CVV2 (or even, in some cases, the AVS). If you were able to capture the unencrypted PIN (PIN encryption is not mandatory in EMV) it sill wouldn’t help you unless you could steal the physical card as well.

So what does this all mean?

Well, the Target hack has given us the opportunity to look again at how EMV might help and, just as importantly, how it might not help. Since it looks as if the US Senate might be discussing the subject in the future, I thought it might be friendly and helpful for CHYP USA to provide some background for US lawmakers…

Three US senators have proposed to the Senate Banking Committee that they hold hearings on the issue of customer data security following the Target data breach. They specifically seek to address the adoption of EMV in the hearings.

[From US Senators seeking to publicise the EMV debate in US following Target breach | The Bankwatch]

The most important point is that EMV isn’t a magic bullet to fix card fraud and it would be a mistake to try and formulate an industry business case based on that alone. However, if you look at the costs across all of the stakeholders, it seems to me that on balance it still makes sense that the US to proceed with its EMV migration even though everything that has been said about alternative payment technologies is simultaneously true.

Yes, EMV was designed for the offline world of 1994 even though mobile phones and the Internet already existed.

Yes, it is entirely possible to start designing a second-generation “son of EMV” that comes off the drawing board in a world of ubiquitous, pervasive interconnection and industry-wide initiatives in identity and authentication.

Yes, I don’t doubt for a moment that it is possible to make such a son-of-EMV even more secure than EMV is today and, what’s more, make it work in online environments.

Having said all that, we are where we are. Most non-cash payments at retail point of sale are card, and will stay card across the next post replacement cycle. Since all of the bits and pieces that banks need to buy, retailers need to buy, processors need to buy etc are all readily available, along with the expertise needed to make them work cost-effectively, it’s the easiest choice. US cards will them work fine overseas, overseas cards will then work fine in the US and without the pantomime of signing for transactions.

Signed and Sealed

If we want to look at how EMV will change the fraud situation in the US, then the obvious place to look is in France. France has had chip cards longer than any other country and it resembles the US in an important way: it has inefficient payment system that still uses checks. So now that we have had many years to observe the dynamics around the transition to smart cards in retail purchases, what have we learned? Well, here are the basic facts (“French card fraud continues upward trend .

  • Card present fraud at retail point-of-sale is about two basis points (2bp).
  • Card not present fraud on the Internet is about 299bp (ie, two orders of magnitude worse).
  • Mail-order/telephone order fraud is about 338bp.

Here in the UK the criminals have responded to the adoption of EMV in two ways: by inventing ever-more elaborate scams to get hold of cards and PINs and by stepping up their efforts on the internet. Right now, they are doing rather well, as fraud is up again this year. This is why I stress that EMV is not a magic bullet and it will not eliminate fraud.

So what we see in the UK and France is exactly what we would expect to see given what we know about EMV. It leads to a major reduction in card-present (CP) fraud, partly because you cannot counterfeit the chips used in the smart cards and partly because of the off-line PIN verification. It does nothing to help with card-not-present (CNP) fraud and it does nothing to help with mail-order/telephone order (MOTO) fraud. It could, but it doesn’t.

Most banks in Europe decided not to use EMV is the basis for their 3-D Secure (3DS) authentication, so although there are ways to use EMV cards to combat both both CNP and MOTO fraud, they are not used. I can give you a UK example. My bank is Barclays and they sent me a little calculator like device called a “PIN sentry” several years ago. This implements a standard for using offline PIN to provide one-off numbers for authentication (using the MasterCard CAP and Visa DPA protocols). In fact, since both of my sons bank at Barclays as well we have more than one of these devices lying around the house. When I want to log into online banking, I take my debit card and pick up any one of the PIN sentries, insert the card and punch in my PIN. The device displays a one-off number and I type this in to the Barclays web site to log in. It’s easy and I like it.

PIN Sentry

But if I were to use my debit card to buy something online (which is hypothetical, since I would never do this) then I have to remember a 3DS password. It would be much easier to use the PIN Sentry again. The PIN Sentry is a simple and cheap device because all of the cryptography is inside the EMV chip. I did suggest doing this inside a standardised identity framework a few years ago (we called this “4D Secure”, but it never took off!). So, for various reasons, EMV cards were not used to attack online fraud and now, given the trajectory of mobile transactions, will never be. I say this because it seems obvious that the mobile phone will become the authentication device for transactions across all channels. In the future will be using my mobile to pay in Waitrose and at John Lewis’ web site, and as a consumer i won’t know or care that the protocols used a mundane and virtual POS are different.

One more point.

I see that there has been a traditional American response to the breach.

Just days after acknowledging a massive hack of customer credit card data, Target is facing at least two dozen lawsuits. And more could be on the way.

[From Lawsuits piling up on Target over hack - Dec. 23, 2013]

I suspect that there may well be another consequence of the Target breach, once the costs reach a few billion or so. Since class action lawyers are more effective agents of change than consultants or, indeed, the US Senators are, this might be the tipping point for a major change in the use of new retail transaction technologies in the US. Yes, it will provide a kick to implement EMV and transfer liability back to the card issuers, but it may also provide a kick to reduce the dependence on “traditional” card products entirely. Note that the Target hack included the theft of Target’s own Red decoupled debit card details. These are of no use to the criminals because they can only be used in Target. They are, to use the jargon, “tokens”. They point the way forward: the major international payments schemes are involved in a huge effort to move to tokenisation for mobile and online transactions. But the payment schemes will not be the only organisations to have noticed this dynamic as the consequences of the breach unfold. Indeed, observers are already (correctly, in my opinion) noting that retailers will be exploring other possibilities too.

Retailers have a unique opportunity to lower payment liability by shifting consumers to card and mobile ach decoupled debit.

[From The Target Breach: what it means to card and mobile ACH payment: | The Competitor's Code]

I wonder if this may be the long-term legacy of the breach? If the issuers don’t get their act together and accelerate EMV deployment, then the retailers will be tempted to move away from the traditional card schemes altogether and use their own tokens, either via their decoupled debit cards or via their own apps (using HCE/BLE so that standard terminal estate can be used) to both reduce that payment liability and reduce costs.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Target breach may have consequences beyond EMV appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2014/01/target-breach-may-have-consequences-beyond-emv/feed/ 0
Are gift cards a present to fraudsters? http://tomorrowstransactions.com/2013/12/are-gift-cards-a-present-to-fraudsters/ http://tomorrowstransactions.com/2013/12/are-gift-cards-a-present-to-fraudsters/#respond Tue, 10 Dec 2013 17:14:37 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/?p=115 The BBC asked me to comment on the security of gift cards in connection with a story they were running on “You and Yours” (it’s about 35 minutes in if you are interested). The story was about a woman who had bought a gift card at Debenhams and given it to a relative. When the […]

The post Are gift cards a present to fraudsters? appeared first on Tomorrow's Transactions.

]]>
dgwb_blog_white_border.jpgThe BBC asked me to comment on the security of gift cards in connection with a story they were running on “You and Yours” (it’s about 35 minutes in if you are interested). The story was about a woman who had bought a gift card at Debenhams and given it to a relative. When the relative went to use the card, it was empty because it had already been used (in a series of transactions)

Obviously, I couldn’t comment on the Debenham’s example that triggered the story since I don’t know anything about it, but by way of comment, here’s a similar kind of fraud running in the US right now, discovered at Wal-mart.

They re-seal the Visa card into the seemingly new unopened box, sneak it back into Wal-mart and put it back on the shelves. Next, they just wait until somebody buys the card. Once the fake card has been scanned, the real card (in the hands of the thief) becomes active, funded and ready to use before the unsuspecting customer has any clue.

[From ▶ Wal-Mart "VISA" Gift Card Scam 2013 - YouTube]

This is actually a well-known problem…

In another traditional scheme, a thief will apply a bar-code sticker over the genuine bar code of a gift card in a shop. When the sticker is scanned, it activates a blank card that the crook has stolen instead of the card the consumer is purchasing.

[From Gift Card Scammers Skirt Security with New Tricks | Fox Business]

Again, speaking generally and not referring to either of these cases, gift card fraud is often collusive.

Many retailers are finding out that their biggest gift card fraudsters are their employees.

[From Preventing Gift Card Fraud]

In some cases, an insider is either copying the card details by skimming or simply writing down the numbers and passing them to conspirators. This works because the details are copyable, which is why the payment card industry decided to move to chips. But chips are too expensive for gift cards, so they will remain magnetic stripe, and remain vulnerable.

So is they sky falling in? Well, no. The UK gift card and voucher market is already £5 billion and still growing. The gift card providers are developing a variety of countermeasures around activation and usage and I suspect they have a few more idea (based, largely, on mobile) up their sleeves. I was under the impression that gift card fraud in the UK was fairly low, so I asked Tony Craddock of Gx, who knows all about this kind of thing, and he confirmed this. In fact, he said that gift card fraud in the UK was “surprisingly” low, albeit growing.

In the US, where gift cards are a $100 billion+ market segment, the arms race between gift cards and fraudsters is far more active and accelerating. Since the gift card providers there have been implementing a variety of security countermeasures, so the fraudsters have been displaying energy and ingenuity in circumventing them.

In a classic gift card scam, a thief checks gift cards displayed in a store and writes down identifying information or lifts it from the card’s magnetic stripe using a scanner. The crook then goes home and repeatedly checks online to see when the card is activated (usually this is done when the cashier rings up the purchase of the card). Once activated, the thief spends the card balance online.

[From Gift Card Scammers Skirt Security with New Tricks | Fox Business]

One the bigger problems in the US, though, where there is no chip and PIN at POS, is that counterfeit and stolen payment cards are used to buy gift cards. There’s even a problem with people using gift cards to encode the counterfeit magnetic stripe data!

A group of people used stolen credit card information to produce fraudulent cards and re-encode gift cards, then used the faked cards to buy large numbers of high-end items for later resale, police said.

[From Gift cards used for taking from Target, police say - Chicago Tribune]

Now, I must confess, a few years ago, we did this. Go and get a blank gift card, or any old magnetic stripe card, and then re-encode it with your ATM card details. Then, when out about in foreign lands or dangerous parts of Woking, carry the apparently worthless card instead of your real ATM card. If you get mugged, it looks like a gift card (but of course it won’t work in the store terminals). If you don’t get mugged, and you need some cash, you can use it at the ATM. Chip and PIN put paid to this useful decentralised nerd-friendly crime prevention technique!

Anyway, for the Radio 4 show I said, essentially, that the security of the cards themselves was unlikely to improve. I said this because I’d been to a useful Money 2020 session on EMV migration in the US where it was one of the topics discussed. I hope I’m paraphrasing correctly from my scant notes, but broadly speaking I think the overall message was that gift cards will either remain stripe or vanish into mobile apps because the cost of chips doesn’t make sense in the gift card world. Mobile and e-gifting are growing rapidly so we may even see the stripe cards disappear as well. As Nate from City National Bank said at the Tomorrow’s Transactions Unconference in Palo Alto, mobile apps are going to get rid of plastic before they get rid of cash, and I suspect this true for gift cards as much as for other kinds of cards.

These are personal opinions and should not be misunderstood as representing the opinions of Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Are gift cards a present to fraudsters? appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2013/12/are-gift-cards-a-present-to-fraudsters/feed/ 0
Defending cash http://tomorrowstransactions.com/2008/12/defending-cash/ http://tomorrowstransactions.com/2008/12/defending-cash/#comments Mon, 29 Dec 2008 23:33:04 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2008/12/defending-cash/ Summary

The post Defending cash appeared first on Tomorrow's Transactions.

]]>
[Dave Birch] I was listening to a recent episode of Skepticality, about the TV show “Numb3rs”. The presenters were interviewing one of the writers about the making the show and they made a comment that caught my money-obsessed ear. The writers said that they had been researching a show about counterfeiting and during the course of this research they had copied a $20 bill on a photocopier to see how well it came out. Shortly thereafter they got a phone call from the US Treasury! The photocopier was online, and phones home when someone tries to copy money! (Incidentally, the Treasury guys weren’t very happy to hear the proposed plotline about the FBI investigating some counterfeiters because it’s the Secret Service — until 2002 part of the Treasury — who take care of that.) I thought they might be exaggerating, but it turns out that not only do some photocopiers have this feature built in to them, there are many printer drivers that won’t print scanned bills!!. Ever-vigilant for the cause of monetary trivia, I tried it out myself. I scanned a fiver and tried to print it, and I got this error message.

It turns out that this functionality is much more widespread that you would have thought (if, like me, you hadn’t really thought about it).

Adobe and other makers of image-manipulation programs have, at the behest of a little-known group of national banks, inserted secret technology into their programs to foil counterfeiting, the companies acknowledged this week.

[From Adobe, others slip anticounterfeiting code into apps - CNET News]

Hardly secret, but it’s certainly unpublicised. And I shouldn’t think it helps much, since it only took me two minutes to find a crack to download to turn off the functionality in Photoshop. Anyway, that’s not the point. Being a nerd, I immediately started to wonder how do they do it and it turns out that there’s a bankers’ organisation that provides the relevant data.

Photoshop and other programs will no longer be able to open files containing images of several nations’ currencies, said Kevin Connor, director of product management for Adobe. The code to detect such images came from the Central Bank Counterfeit Deterrence Group, a low-profile association representing the national banks from Belgium, Canada, France, Germany, Italy, Japan, the Netherlands, Sweden, Switzerland, the United Kingdom and the United States.

[From Adobe, others slip anticounterfeiting code into apps - CNET News]

There are many companies involved, not just Adobe, and I’m not saying anything bad about any of them. I’m just genuinely interested that one particular type of old technology (cash) should get this kind of protection afforded to it. It must cost the companies money to implement the anti-counterfeiting technology in their products, but I suppose it might generate other useful skills or spin-offs.

That’s why researchers at HP Labs and experts from the company’s printing and imaging business got together at the request of U.S. and international officials to help clamp down on counterfeiting.

[From HP Labs : News : HP Helps U.S. Clamp Down on Counterfeiting]

I would have thought that a better way to lessen the impact counterfeiting would be to reduce the use of cash, but I always think that about everything.

These opinions are my own (I think) and presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Defending cash appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2008/12/defending-cash/feed/ 1
It’s always, always the same http://tomorrowstransactions.com/2008/12/its-always-always-the-same/ http://tomorrowstransactions.com/2008/12/its-always-always-the-same/#respond Mon, 22 Dec 2008 19:13:47 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2008/12/its-always-always-the-same/ [Dave Birch] One of the reasons why a digital identity infrastructure ought to be more than just building a big database of everyone and then letting everyone have access to it is that the infrastructure will inevitably be abused by those on the inside, no matter how much effort goes into keeping out the bad […]

The post It’s always, always the same appeared first on Tomorrow's Transactions.

]]>
[Dave Birch] One of the reasons why a digital identity infrastructure ought to be more than just building a big database of everyone and then letting everyone have access to it is that the infrastructure will inevitably be abused by those on the inside, no matter how much effort goes into keeping out the bad guys on the outside.

Missouri Citibank employee Brandon Wyatt… accused of tapping Citibank's computers for customer information, then using it to set up checking accounts online with competing banks, including Bank of America, Washington Mutual and AmTrust. Wyatt allegedly wire transferred customer funds from Citibank to the new accounts, then cashed them out with additional transfers, checks, debit card purchases and ATM withdrawals. His take, according to federal prosecutors in St. Louis, was at least $380,000.

[From Fed Blotter: Citibank Worker Allegedly Plunders Customer Accounts | Threat Level from Wired.com]

It's hard to see how you can stop this from happening completely in an economic way, but what you can do is make sure that there is an audit trail so that someone how decides to have a go at this kind of fraud has a reasonable expectation of being caught. Although I have to say that armed bank robbers have a reasonable expectation of being caught (and a reasonable expectation of a long sentence if they are caught) but they still do it. Anyway, my point is that if you take people personal data and put it in a honeypot, there is only one outcome. A database is not an infrastructure.

As I am sure that we all understand, the problem of insiders obtaining personal data (stealing or, more accurately, copying identites) in financial systems is the least of anyone's worries because at the end of the day all that is stolen is money. There are far more important systems, where there are much greater ramifications to identity crime.

A hacker in Chile calling himself the 'Anonymous Coward' published confidential data belonging to six million people on the internet. Authorities are investigating the theft of the leaked data, which includes identity card numbers, addresses, telephone numbers, emails and academic records.

[From Emergent Chaos: 6/16ths of Chileans personal information leaked by hacker]

As I asked the Home Secretary at her update on the ID card, what is the "break the glass" plan when this happens? When people do this kind of thing for political purposes they don't care about the personal consquences. If a disgruntled civil servant decides to publish the entire contents of the national identity database on the web as a protest against government policy on something or other, they know they are going to get caught. But they don't care. Political conscience aside, sometimes, people do this kind of thing just because they are, well, people.

This brings up another problem that ties into this, or what is known as medical identity theft. While medical identity theft hardly ties into Britney Spears getting her information "peeked at," it has become a huge problem. The tie would be the ease in which naughty employees, with no business looking at it, were able to do so.

[From Fraud, Phishing and Financial Misdeeds: Naughty UCLA employees peek at Britney's medical information]

If you could look up the medical records of neighbours, employers, celebrities or "love rivals" on the web, then you would, not because you are evil but because you are human. We need to be realistic about human behaviour in the systems we build. If we don't want people to snacking on personal tidbits in a the data fridge, a sternly-worded magnet on the door isn't going to help: we shouldn't leaving them in there at all.

These opinions are my own (I think) and are presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post It’s always, always the same appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2008/12/its-always-always-the-same/feed/ 0