Picture of a wireless pinpad
Wireless pinpads are widely judged to have been a success

Taking chip-and-PIN further

Contactless payments and near-field communications are the next steps for card technology

Written by Angelica Mari

This month marks the two-year anniversary of chip-and-PIN credit and debit cards in the UK.

The technology is widely seen as a success, and face-to-face card fraud levels are down 47 per cent since 2005.

But further developments are needed to keep up with increasingly sophisticated scam techniques. For example, card-not-present crime is still on the rise: up 16 per cent in 2006 and now valued at £213m annually.

“Chip-and-PIN has given a lot of confidence to customers and it has been very successful in reducing face-to-face fraud,” said a spokesman for Apacs, the banking industry group.

“But the level of counterfeit transactions made online and abroad is still increasing.

“And as chip-and-PIN becomes more available in Europe, UK-issued magnetic stripe cards have been used by fraudsters in countries such as the US.”

Fraud using the magnetic stripe is one of the biggest problems, and card issuers are struggling to find a solution, according to Deloitte security and privacy services director Nick Seaver.

“Banks could totally eliminate both the stripe and the number printed on the front of the cards ­ which are two valuable pieces of data for fraudsters,” he said.

“But then customers would have to have another magnetic stripe, to use in countries that do not have chip-and-PIN, so it is security versus convenience.”

Two-factor authentication schemes ­ where a user needs both something they have and something they know ­ are a key element of some of the big banks’ attempts to address online card-not-present fraud.

Barclays, Lloyds TSB and Royal Bank of Scotland (RBS) all have two-factor systems that give customers automatically-generated one-time passcodes, to use in conjunction with the password they already know. And Nationwide is due to start a three-month trial covering one million customers next month.

“The readers provide an additional layer of security to protect our members from fraud by authenticating the customer as genuine,” said a Nationwide spokeswoman.

“The initiative will not strengthen the use of chip-and-PIN, but uses the technology in another way,” she said.

The problem with two-factor schemes is their impracticality, said EA Consulting Group director Robin Bearne.

“The fact that each issuer of cards will use a different authentication device means that a customer with three cards could end up with three different devices in their pockets,” he said.

Alongside banks’ anti-fraud schemes, there are two main developments for the next generation of payment cards.

Contactless systems enable users to hold their card up to a reader to take money out of a cash machine or make low-value payments.

In July, Barclaycard started issuing a multi-function card including standard chip-and-PIN, Oyster travel card and Visa “wave and pay” contactless payment.

RBS is also rolling out the technology to customers in the London trial area. And Lloyds TSB started a multimillion-pound pilot in January, ahead of plans to create a cash-free environment for the 2012 Olympics.

The chief benefit of contactless payments is efficiency, said Mastercard head of strategy Oliver Steeley. “Contactless is a way to balance risk, with speed and convenience,” he said.

The other main development is near-field communications (NFC) ­ a wireless technology based on a storage “tag” inside a device, such as a mobile phone, that can be used as a car key, electronic wallet, ticket or travelcard.

The big mobile companies are developing a global standard for the technology. In the UK, O2 is working with two banks - First Direct and Lloyds TSB ­ to provide cashless payments and mobile banking services.

“Customers are demanding alternative ways of communicating, and a richer mobile experience is an integral part of the strategy of our clients in the banking sector,” said O2 channel business manager Mark Coby.

Chip-and-PIN: the numbers

  • Online fraud cost £34m in 2006.
  • 36 million consumers have been issued with chip-and-PIN cards since 2005.
  • The EU estimates chip-and-PIN will save banks and retailers £412m annually.
  • Card fraud costs the UK £1m every day.
  • Face-to-face fraud cost £70m in 2007, a 47 per cent drop from 2005 levels.
  • It takes 20 seconds for a counterfeit transaction to take place.
  • The financial sector spent £1bn migrating to chip-and-PIN.

reader comments

related articles

Olympic runners

Contactless cards trial begins

Lloyds TSB scheme is first step to cash-free 2012 Olympics 14 Feb 2008

 

Barclays claims zero online fraud

The bank credits the absence of online crime to the introduction of two-factor authentication devices 16 Jul 2008

HSBC strengthens online fraud defences

Combination of web and phone expected to improve security 07 Jan 2009

Barclays rolls out contactless payment for debit cards

Three million customers to receive cards embedded with the new technology by year end 03 Mar 2009

related whitepapers

today's top stories

What does Windows 7 mean for Microsoft?

With the sting of Vista still fresh, Redmond has to make next Windows work 10 Jul 2009

A smarter way to use BI

Getting the most from business intelligence systems requires not only careful management on the part of IT leaders, but also the committed involvement of decision-makers across the organisation 08 Jul 2009

The truth behind the Google/Microsoft/NHS rumours

Before Monday July 6th, did you know that Google and Microsoft had services for storing health records? Thanks to an article in... 10 Jul 2009

Quenching a thirst for IT modernisation

A substantial restructure at soft drink supplier Nichols -­ purveyor of Vimto - ­led the company to update its software to Sage 1000 to replace its in-house application. This resulted in the streamlining of the IT department and an opportunity to customise the system 08 Jul 2009

How Satyam cleaned up its act

Chief executive CP Gurnani tells Angelica Mari why Tech Mahindra opted to keep the Satyam brand after it bought the scandal-hit services firm, and explains what the deal means for existing and prospective customers 09 Jul 2009

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Will Google Chrome OS be a genuine alternative to Windows?

Will Google Chrome OS be a genuine alternative to Windows?

Tell us your views on the new operating system rivalry

View poll results

Latest audio and video articles

network cablesVideo

How to maximise the value of your IT networking investment

A panel of experts discuss networking strategies that deliver real value to business 03 Jul 2009

green footprintsVideo

How to manage enterprise energy use - and the role IT can play

A panel of experts explore how firms can get to grips with their carbon footprint and make smarter use of energy 01 Jul 2009

Latest in-depth articles

Google ChromeAnalysis

Lack of enterprise appeal takes shine off Chrome OS

Enterprise buyers unlikely to ditch Windows for Chrome OS in the near term, say experts 09 Jul 2009

Satyam CEO CP GurnaniNews

How Satyam cleaned up its act

Chief executive CP Gurnani tells Angelica Mari why Tech Mahindra opted to keep the Satyam brand after it bought the scandal-hit services firm, and explains what the deal means for existing and prospective customers 09 Jul 2009

Advertisement

Primary Navigation