All Top Banking

Showing posts with label PIN. Show all posts
Showing posts with label PIN. Show all posts

And the Password Is...(Information Card)

Posted by John B. Frank Monday, August 11, 2008 0 comments

Information Cards (protected by a PIN) look to be a logical replacement to passwords.  Microsoft, Google and Oracle are among the founding members.  So what exactly is an information card?  Here's a brief overview from the Information Card Foundation: (ICF)

Information Cards are the digital, online equivalents of your physical identification credentials such as a drivers license, passport, credit card, club card, business card or a social greeting card. Users control the distribution of their personal information through each Information Card. Information Cards are stored in a user’s own online wallet (called a “selector”) and “handed out” with a mouse click just like a physical ID card.

Information Cards can be issued to users by organizations for general or specific use. Users can also create their own Information Cards as a shortcut to avoid the endless process of filling out web forms. But more importantly, the infastructure behind the cards allows for trusted sources (a bank, a credit union, a government office, etc.) to verify specific information (“claims”) made by a user. In other words, Information Cards give users the ability to make claims about themselves, verified by qualified 3rd parties, while using the Internet.

Here's an excerpt from an article from yesterday's NY Times "Goodbye Passwords You Aren't a Good Defense" talking more about Information Cards:

Password-based log-ons are susceptible to being compromised in any number of ways. Consider a single threat, that posed by phishers who trick us into clicking to a site designed to mimic a legitimate one in order to harvest our log-on information. Once we’ve been suckered at one site and our password purloined, it can be tried at other sites.

The solution urged by the experts is to abandon passwords — and to move to a fundamentally different model, one in which humans play little or no part in logging on. Instead, machines have a cryptographically encoded conversation to establish both parties’ authenticity, using digital keys that we, as users, have no need to see.  In short, we need a log-on system that relies on cryptography, not mnemonics.

As users, we would replace passwords with so-called information cards, icons on our screen that we select with a click to log on to a Web site. The click starts a handshake between machines that relies on hard-to-crack cryptographic code. The necessary software for creating information cards is on only about 20 percent of PCs, though that’s up from 10 percent a year ago. Windows Vista machines are equipped by default, but Windows XP, Mac and Linux machines require downloads.  And that’s only half the battle: Web site hosts must also be persuaded to adopt information-card technology for sign-ons.

It is the author of the NY Times article that we won’t make much progress on information cards in the near future because of what he calls "wasted energy and attention devoted to a large distraction, the OpenID initiative". OpenID promotes “Single Sign-On”: with it, logging on to one OpenID Web site with one password will grant entrance during that session to all Web sites that accept OpenID credentials.

Support for OpenID is conspicuously limited, however. Each of the big powers supposedly backing OpenID is glad to create an OpenID identity for visitors, which can be used at its site, but it isn’t willing to rely upon the OpenID credentials issued by others. You can’t use Microsoft-issued OpenID at Yahoo, nor Yahoo’s at Microsoft.

Why not? Because the companies see the many ways that the password-based log-on process, handled elsewhere, could be compromised. They do not want to take on the liability for mischief originating at someone else’s site.

Kim Cameron, Microsoft’s chief architect of identity, is an enthusiastic advocate of information cards, which are not only vastly more secure than a password-based security system, but are also customizable, permitting users to limit what information is released to particular sites. “I don’t like Single Sign-On,” Mr. Cameron said. “I don’t believe in Single Sign-On.”

Microsoft and Google are among the six founding companies of the Information Card Foundation, formed to promote adoption of the card technology. The presence of PayPal, which is owned by eBay, in the group is the most significant: PayPal, with its direct access to our checking accounts, will naturally be inclined to be conservative. If it becomes convinced that these cards are more secure than passwords, we should listen.

BUT perhaps information cards in certain situations are convenient to a fault, permitting anyone who happens by a PC that is momentarily unattended in an office setting to click quickly through a sign-on at a Web site holding sensitive information. This need not pose a problem, however.

“Users on shared systems can easily set up a simple PIN code to protect any card from use by other users,” Mr. Cameron said.  The PIN doesn’t return us to the Web password mess: it never leaves our machine and can’t be seen by phishers.

Logging on to a site should entail a cryptographic conversation between machines, saving us from inadvertently giving away the keys.

Canada Gets Ready for Chip and PIN Adoption

Posted by John B. Frank Tuesday, July 29, 2008 0 comments



The rapidly evolving payment industry is undergoing a new chip and PIN revolution in Canada and merchants will need to stay on their toes to keep up. Industry observers, including a newly appointed Canadian INSIDE Contactless executive weigh in on the issue and Rafael Ruffolo writes about it for ComputerWorld Canada:



By: Rafael Ruffolo, ComputerWorld Canada (29 Jul 2008)


With chip and PIN contactless technology set to hit widespread adoption by 2010, industry watchers are advising merchants to look at how the new payment method can benefit them in fraud reduction and value-added services, rather than worrying about the initial implementation costs.



“This is a little like the early 1980s with PCs,” Catherine Johnston, president and CEO at Advanced Card Technologies (ACT) Canada, said. “We’re beginning to understand the capabilities and the things we will be able to do with chip cards and I think merchants will need to look at the positive gains.”



Whether the positives of chip and PIN – which refers to a movement which will equip all credit cards with a chip and PIN number–will outweigh the implementation costs for Canadian merchants remains to be seen. Members of the payment card industry, including Interac Association, MasterCard Canada Inc. and Visa Canada, are in the midst of a chip and PIN trial in Ontario’s Kitchener-Waterloo area.



France-based payment chip maker INSIDE Contactless creates chip sets that are used for access control, ID, transit and other applications. Kim Madore, the recently appointed vice-president of sales and business development for the company’s Canadian operations, said the results of the Southern Ontario rollout has been promising and mass migration to the contactless payment technology should get underway this fall.



“For merchants, it will be fraud reduction that gives them the business model to move forward with this,” Madore said. “Plus, Canada has had PIN since 1992 when Interac was introduced, so consumers will be very accustomed to the technology and recognize the security benefits.”

But while the hype around fraud reduction might be enough to get consumers onside, some merchants might have a difficult time making a business case on that fact alone. Lise Dellazizzo, senior vice-president of technology research at Harris/Decima said that even though widespread rollout will occur within the next two years, many merchants haven’t had a chance to work with the technology yet..


A significant problem for some merchants, Dellazizzo said, is the expensive hardware and software costs involved in the migration. She said while businesses in the food services industry – which often rent their payment machines – may get off relatively easy, it will be a far different story for merchants in other fields.



“For the folks in the oil and gas sector, retrofitting the pumps will be a costly job,” Dellazizzo told ComputerWorld Canada earlier this year. “It’s been very difficult for the card associations and the players to convince these merchants that there is an ROI in making the move. And when it costs you $15,000 to replace each pump and you’ve got thousands of them across the country, it can be a tough pill to swallow.”



But according to Madore, merchants in many industries – including the oil and gas sector – are already taking steps to plan for the technology. “With respect to Canada and the gas industry, many of the pumps are already retrofitted,” she said. “You take a Petro Canada and they’ve even gone to the extreme of retrofitting for contactless technology as well.”



Johnston agreed with Madore, saying that most service companies have experienced similar changes over the last few decades and should be able to handle the changes that come with contactless payment technology. She added that as early as ten years ago, credit and debit card readers were missing from gas pumps.



“We’re now looking at technology like mobile payment, near field communication (NFC), and dual-interface cards that have both contact and contactless technology embedded,” Johnston said.



Her advice to merchants was to accept the fact that the payment industry is constantly evolving and take advantage of the advancements the technology can offer.



“For instance, if you look at a smaller merchant, they really don’t have a strong business case for issuing their own loyalty program cards,” she said. “But because chips can have multiple applications on the same card, merchants can band together and each put their own applications on consumer credit cards.”



Besides cutting down on the amount of credit cards in your customers’ wallet, Madore said the technology can also make transactions more personal.



“What if you went to a checkout at Tim Horton’s and the terminal actually greeted you with personalized information?” she asked. That aside, the bottom line for merchants is that it won’t be a matter of “if” they upgrade, but rather “when” they upgrade.



Visa Canada has already said Canadian businesses will need to get onboard with the new technology by October 2010 or the liability for payment fraud claims falls to the merchant themselves.



The ongoing Kitchener-Waterloo payment industry trial is scheduled to be completed this fall.



Copyright © 2008
ITworldcanada.com





Zemanta Pixie

More on Australia's PEN or PIN Program

Posted by John B. Frank Friday, June 6, 2008 0 comments

Credit card users will be given the option of entering a PIN as an alternative to signing their name to authenticate a transaction under a banking industry initiative scheduled to start today. (June 4th)

Simon Greig, principle for Phoenix IT&T Consulting — contracted by the industry to manage the transition to the 'Pen or Pin' project for credit card transactions — says all of the banks are ready for the move. The main impetus for the initiative, led by Mastercard and Visa, is convenience and not necessarily security, he said. "The objective here is to provide a choice for cardholders," he said. "Australian consumers have been using PIN numbers for decades on their EFTPOS cards, and now they will have that option on their credit cards." "This is not a fraud-related activity," he said. "'It's simply about an option of convenience for cardholders that would like to use a PIN.

And for the retailer, they don't have to use their discretion to judge a signature." The initiative is unrelated, Greig said, to chip and PIN technology being pitched by some banks to reduce credit card fraud. Most Australian banks — including Westpac and the Commonwealth Bank, are trialing chip and PIN technology — which replaces the magnetic strip of a credit card with a microchip — and requires customers to enter a PIN number. It is deemed to be a far more secure approach to today's credit card transactions.

A spokesperson for the Commonwealth Bank told ZDNet.com.au that the bank does expect 'Pin or Pen' to "afford the customer additional [security] protection", but believes the real gains in security terms are more likely to be addressed by chip and PIN. "[Commonwealth] Bank takes card security very seriously and is currently working on its chip card solution," the spokesperson said.

Upon introduction in the UK, chip and PIN security faced its share of teething problems. However, the UK experience, says Greig, involved consumers that had rarely used PIN numbers engaging in a "massive leap" into chip and PIN. He doesn't expect such issues to arise in Australia, where consumers "have been using PIN numbers since the seventies. He also doesn't see 'Pen or Pin' being used as an excuse by banks to transfer liability for fraudulent transactions onto merchants and users, as UK banks have aimed to with chip and PIN. Greig said that under the new 'Pen or Pin' option, cardholders and merchants will be bound by the same rules and regulations using a PIN number as they would if a signature option was used."I have not heard of anybody changing their terms of use," he said.

Zemanta Pixie

Powered by Blogger.

Search This Blog

Our Manufacturing Facility

Learn More About Us

Find out how our patented technology can empower your financial institution.

Our secure two-factor online banking authentication eliminates dangerous passwords and usernames and replicates the same trusted process used to access cash at ATM's. (Insert Bank Issued Card, Enter Bank Issued PIN)

There is an R.O.I. as FI's also earn recurring revenue from each transaction conducted using our PCI 2.0 Certified PIN Entry Device. Our technology also provides a unique real-time P2P "Instant-Transfer" which allows your online banking customer to transfer cash from ANY of their bankcards to ANY other bankcard...with the Swipe of a card.

Help your bank eliminate phishing and your customers avoid identity theft by providing them with the ability to stop typing and start swiping. There is no safer way to conduct financial transactions online than by 3DES DUKPT encrypting the cardholder details, which we do at the mag-head "inside the box/outside the browser."

Total Pageviews

SLIM for PC or SmartPhone

SLIM for PC or SmartPhone
Click to Inquire

Chip and PIN eCommerce and Mobile

Chip and PIN eCommerce and Mobile
Click to Inquire

Kapersky Calls for Mass Adoption of Card Readers

Kapersky Calls for Mass Adoption of Card Readers

Translate This Blog

BobCaps

Search ePayment News (example: NFC)

About Me

My photo
Named one of the best Payment Industry News Blogs 4 Years Running

Feedjit

My Zimbio