iTnews
  • Home
  • News
  • Technology
  • Security

Researchers slam 3-D Secure as insecure

By Phil Muncaster
Jan 28 2010 2:39AM
Follow google news

Verified by Visa and SecureCode 'fatally flawed'.

University of Cambridge researchers have launched a withering attack on the 3-D Secure protocol used by Visa and MasterCard to authenticate online customers, branding it "a textbook example of how not to design an authentication protocol".

In a new piece of research entitled Verified by Visa and MasterCard SecureCode: or, How Not to Design Authentication (PDF), Steven Murdoch and Ross Anderson argue that 3-D Secure has become popular because it "got the economics right", rather than being intrinsically more secure than less popular rivals such as OpenID, InfoCard and Liberty.

The research maintains that the protocol often confuses users by running counter to traditional advice about entering credentials only into sites secured by Transport Layer Security, which browsers such as Internet Explorer 8 now recognise by displaying a green address bar.

"Because the 3-D Secure form is an iframe or pop-up without an address bar, there is no easy way for a customer to verify who is asking for their password. This not only makes attacks against 3-D Secure easier, but undermines other anti-phishing initiatives by contradicting previous advice," the report advised.

Customer confidence may be further undermined by the registration process, which is often completed during a shopping transaction and involves the user being asked for personal details such as date of birth.

"From the customer's perspective, an online shopping web site is asking for personal details. This further undermines customers' security usability and trust experience. And it is being exploited by criminals as phishing web sites impersonating the ADS form to ask for banking details," the report noted.

Some banks have also used the 3-D Secure system to shift liability for fraud losses unfairly onto the consumer, according to the report.

Murdoch and Anderson further warn that the system is likely to be undermined in time by man-in-the-middle attacks and the continuing growth in sophisticated malware, and that attention needs to be focused not on a single sign-on system such as this but on "transaction authentication".

"In the long term we need to move to a trustworthy payment device," the report concluded.

"This is not rocket science; rather than spending US$10 [$11] per customer to issue chip authentication program calculators, banks should spend US$20 to issue a similar device but with a USB interface and a trustworthy display."

Researchers slam 3-D Secure as insecure

Add iTnews as your trusted source

Add iTnews As Your Trusted Source Add iTnews As Your Trusted Source
Got a news tip for our journalists? Share it with us anonymously here.
Copyright ©v3.co.uk
Tags:
securesecuritysuch

Related Articles

  • US charges suspected Russian hacker with facilitating cyber campaign US charges suspected Russian hacker with facilitating cyber campaign
  • Gov looks for upstream threat blocking by telcos, cloud operators Gov looks for upstream threat blocking by telcos, cloud operators
  • Federal Parliamentary Computer Network set for its "most significant" upgrade Federal Parliamentary Computer Network set for its "most significant" upgrade
  • Marathon OAIC investigation finds Optus breached 51,000 customers' privacy Marathon OAIC investigation finds Optus breached 51,000 customers' privacy
Join our WhatsApp Channel

Partner Content

From test case to control tower: How DXC and ServiceNow are governing enterprise AI at scale
Promoted Content From test case to control tower: How DXC and ServiceNow are governing enterprise AI at scale
Agile isn’t the problem: why projects still fail, and what’s missing
Partner Content Agile isn’t the problem: why projects still fail, and what’s missing
CommBank creates opportunities for technologists to upskill  with frontier AI companies
Partner Content CommBank creates opportunities for technologists to upskill with frontier AI companies
Thomas Peer Solutions unveils data cloud platform and executive leadership forum for 2026
Partner Content Thomas Peer Solutions unveils data cloud platform and executive leadership forum for 2026

Sponsored Whitepapers

When cyber risk has no clear owner: A practical guide for senior Australian business leaders
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
Agile in the AI Era: why projects still fail
Agile in the AI Era: why projects still fail
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
High-volume data sources for AI-driven security analytics
High-volume data sources for AI-driven security analytics
How healthcare organisations can get more value from cloud
How healthcare organisations can get more value from cloud

Events

  • iTnews State of Security Breakfast iTnews State of Security Breakfast
  • iTnews State of Data & AI Breakfast iTnews State of Data & AI Breakfast
  • Forrester's AI Forum Sydney Forrester's AI Forum Sydney
  • The 2026 iAwards The 2026 iAwards
  • Integrate 2026 Integrate 2026
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Anthropic opens Claude Mythos Preview AI program to Australia

Anthropic opens Claude Mythos Preview AI program to Australia

Defence says Palantir is "sandboxed" in its environment

Defence says Palantir is "sandboxed" in its environment

Researchers build self-replicating AI worm with BYO LLM

Researchers build self-replicating AI worm with BYO LLM

techpartner.news logo
Sydney-based AI-cloud waste startup raises $3m
Sydney-based AI-cloud waste startup raises $3m
Brennan uses NiCE to modernise its contact centre
Brennan uses NiCE to modernise its contact centre
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Interactive introduces private cloud platform
Interactive introduces private cloud platform
Digital61 expands cybersecurity portfolio
Digital61 expands cybersecurity portfolio
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.