iTnews
  • Home
  • News
  • Technology
  • Security

Industry lays into 3-D Secure

By Phil Muncaster
Apr 14 2008 11:22AM
Follow google news

Payments experts have rounded on the 3-D Secure identity verification scheme, which was set up to secure online transactions. The system is vulnerable to fraud and non-intuitive, they argue.

Industry lays into 3-D Secure
At a recent roundtable event hosted by fraud detection firm CyberSource, experts from banking, e-commerce and academia argued that 3-D Secure – which comprises Verified by Visa and Mastercard SecureCode – is fundamentally insecure.

Criminals can potentially set up fake 3-D Secure enrolment screens to harvest customer details, warned Mike Levi of Cardiff University. "How can you tell if it is genuine 3-D Secure?" he added.

And merchants, including Lastminute.com, are already reporting difficulties. Mick Scott of lastminute.com said the firm had found one case of fraudulent activity on a UK card which was nevertheless authorised using Verified by Visa.

Security firm Sophos this week confirmed that phishers are undermining the integrity of the system. It discovered emails claiming to be from MasterCard that are being mass-mailed out to entice consumers to click on a link in order to sign up to SecureCode. The link then takes them to a false registration page where card and other details are harvested for future use by the phishers.

"The thing I can see being more confusing than anything else is that you can go to a number of places to sign up for [the genuine SecureCode] – even local banks," argued Sophos' Carole Theriault. "There should be only one official site."

Lastminute's Scott also expressed concern that the complexity of the system was off-putting for customers. "We turned on Verified by Visa in Spain and it was horrific," said Scott. "There was a 30 percent drop off in completed purchases."

Further problems included the difficulties of training customers to use the system. The amount of user training necessary was unexpectedly high, suggested Ken Muir, British Airways' global payments manager. The problem was compounded by the risk that users would wrongly perceive training material to be a phishing attack. "There were a whole load of things we'd like to do but we couldn't because it would look like phishing," he added.

"There's nowhere we can send the customer to for information they can trust… because fraudsters will do the same."

Muir argued that even if it were successful, the 3D Secure scheme would only push fraudsters into different ways of defrauding customers. "We invested all that money and there was a slow shift [to other methods] rather than a prevention of fraud."

The only secure method of safeguarding transactions is to provide two-factor authentications tools which rely on dynamic encryption keys, said Phil Curtis, managing director of First Data, which provides data processing for Bank of Scotland. He cited the one-time passcode card readers distributed by Barclays to its customers as a prime example of good practice.

"Apacs is trying to force the banks to get together but it has no teeth – we need a mechanism to bang their heads together and you can only do this if you are the government," he added.

Users should be the ultimate arbiter of authentication methods argued Mike Davies of secure authentication firm VeriSign. "Organisations have to take a pragmatic view and not mandate [card readers] like Barclays, but offer it to those who want it and understand there are those who won't and take that as part of their business model."

Visa and MasterCard declined to comment on 3-D Secure.

Add iTnews as your trusted source

Add iTnews As Your Trusted Source Add iTnews As Your Trusted Source
Got a news tip for our journalists? Share it with us anonymously here.
itweek.co.uk @ 2010 Incisive Media
Tags:
industryintolayssecuresecurity

Related Articles

  • Apple bumps up security in fresh operating system releases Apple bumps up security in fresh operating system releases
  • Meta accuses NSO Group of violating court order by WhatsApp spear phishing Meta accuses NSO Group of violating court order by WhatsApp spear phishing
  • Researchers build self-replicating AI worm with BYO LLM Researchers build self-replicating AI worm with BYO LLM
  • Anthropic opens Claude Mythos Preview AI program to Australia Anthropic opens Claude Mythos Preview AI program to Australia
Join our WhatsApp Channel

Partner Content

Onel Consulting Strengthens Its White-Glove Services With Strategic COO Appointment
Promoted Content Onel Consulting Strengthens Its White-Glove Services With Strategic COO Appointment
Why resilient communications are becoming critical infrastructure for modern enterprise IT
Promoted Content Why resilient communications are becoming critical infrastructure for modern enterprise IT
Scalable AI solutions: secure delivery
Scalable AI solutions: secure delivery
AI is delivering business value today
Partner Content AI is delivering business value today

Sponsored Whitepapers

Agile in the AI Era: why projects still fail
Agile in the AI Era: why projects still fail
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
High-volume data sources for AI-driven security analytics
High-volume data sources for AI-driven security analytics
How healthcare organisations can get more value from cloud
How healthcare organisations can get more value from cloud
1 in 3 companies lose SaaS data. Here’s how to prevent it
1 in 3 companies lose SaaS data. Here’s how to prevent it

Events

  • iTnews State of Security Breakfast iTnews State of Security Breakfast
  • iTnews State of Data & AI Breakfast iTnews State of Data & AI Breakfast
  • The 2026 iAwards The 2026 iAwards
  • Integrate 2026 Integrate 2026
  • Security Exhibition & Conference Security Exhibition & Conference
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Anthropic opens Claude Mythos Preview AI program to Australia

Anthropic opens Claude Mythos Preview AI program to Australia

Defence says Palantir is "sandboxed" in its environment

Defence says Palantir is "sandboxed" in its environment

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Microsoft backs down on legal threats against 0day disclosing researchers

Microsoft backs down on legal threats against 0day disclosing researchers

techpartner.news logo
Sydney-based AI-cloud waste startup raises $3m
Sydney-based AI-cloud waste startup raises $3m
Brennan uses NiCE to modernise its contact centre
Brennan uses NiCE to modernise its contact centre
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Interactive introduces private cloud platform
Interactive introduces private cloud platform
Digital61 expands cybersecurity portfolio
Digital61 expands cybersecurity portfolio
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.