Putting all security and functionality on a single card makes it unsafe
Putting all security and functionality on a single card makes it unsafe
R E L A T E D   C O N T E N T
ADVERTISEMENT

Credit card flaws fuel online fraud bonanza

Fundamental design errors helping criminals, claims analyst

Robert Jaques, vnunet.com 10 Mar 2005
ADVERTISEMENT

Today's credit cards are vulnerable to online fraud because of fundamental design flaws, industry experts warned today.

According to Forrester Research, the provision of all security and other functionality on a single physical card makes it intrinsically unsafe.

Ivan Remsik, senior analyst for financial services at Forrester, warned that, as long as multiple technologies use or reside on the same physical plastic entity, fraud is set to rise.

"The criminals will always look for the weakest combination. For instance, they would copy data from the magnetic strip on a chip card and acquire the cardholder's Pin through a fake terminal," he said.

"It is then child's play to encode this data on a plastic hotel room key and use it to withdraw money from a cash machine."

The analyst firm also warned that card fraud is increasingly moving online. Remsik argued that "something clearly needs to be done" to reduce the ease with which card-not-present fraud can be perpetrated, in particular online.

But he added that the current fraud prevention mechanisms on offer from Visa and Mastercard have their own problems.

Forrester indicated that various types of online scam targeting the consumer are on the increase, both technical, such as Trojans, and non-technical, such as phishing.

The analyst firm believes that fighting this threat effectively must combine technical and non-technical responses from financial services institutions, and potentially others such as ISPs.

Forrester's warning comes after the Association for Payment Clearing Services released figures this week indicating that UK card fraud increased by 20 per cent in 2004 compared to the previous year.

According to APACS, losses are reported to total £504.8m. The rise is attributed to fraudsters increasing their activity before the security benefits of chip and Pin are fully realised, in addition to targeting other areas such as card-not-present and identity fraud.

See also:

New payment system developed to fight card-not-present (CNP) fraud  13 Jun 2005
SecurityThe latest wave of cyber-crimes and acts of vandalism have demonstrated once again that many systems are still vulnerable to attack.  15 Apr 2004

All Hacking

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Shinfield Park, Reading, United Kingdom | Foster Wheeler
Analyst Programmer - HP Service Center - Competitive Salary - Reading Foster Wheeler is a leading international project management, engineering and construction organisation with global construction capabilities working on major projects within upstream oil & ... more >
Solihull, United Kingdom | Enzen Global Limited
 Business Consultant - £35,000 - £40,000 - Solihull We are in need of a Business Consultant with strong analytical skills and a penchant for learning the domain knowledge of the Utilities sector (Gas industry in ... more >
Durham, United Kingdom | Durham University
Durham University Shaped by the past, creating the future Ocean-Bottom Instrumentation Consortium Software Developer £25,888 - £33,780 per annum Applications are invited for a software developer to join the Ocean-Bottom Instrumentation Consortium (http://www.obs.ac.uk/), who provide ... more >
United Kingdom | MI5 Security Services
UNIX and Database Technology Team Manager - Competitive + excellent benefits - Central London Getting the best out of technology is critical to helping us protect the UK. Join MI5 and use your skills and ... more >
More job opportunities