Picture of michael barrett

PayPal acts to stamp out phishing attacks

Online payment site will fight fraud with two-factor system

Written by Tom Young

PayPal’s decision to introduce an optional two-factor authentication system highlights the increasing concern of banks and online payment organisations over phishing.

The amount of money lost to online banking fraud in the UK increased 55 per cent to £22.5m in the first half of 2006, according to figures from banking industry body Apacs – and all the signs indicate this amount will continue to rise.

Most phishing emails now target PayPal and eBay customers, largely because they are such a huge demographic – 123 million customers at the end of 2006 – but also because PayPal is designed to make it easy to move money around, predisposing it to being phished.

Surprisingly, however, phishing is not a large financial problem for PayPal or its customers.

Michael Barrett, chief information security officer at PayPal, says the problem with phishing has more to do with perception than reality.

‘Financially, phishing is not even in the top five of categories that we suffer from fraud–wise. But when you say you work for PayPal, people say: ‘Oh I get all these emails from you. What are you doing about that?’ People perceive that there is an issue, so there is an issue,’ he said.

Customers receiving phishing emails lose confidence, so PayPal’s two-factor efforts should help with some of these worries.

‘Security is, of course, about relatives and risk assessment, and not absolutes. What we are seeing at the moment is a period of experimentation where different companies are trying different solutions,’ said Barrett.

Recent research by security vendor RSA shows that 91 per cent of bank account holders are willing to use stronger authentication methods, while more than half (52 per cent) are ‘less likely’ to sign up for or use online banking than they were.

As well as introducing two-factor, PayPal is responding to this drop in public confidence by introducing a new green light system where users of Internet Explorer 7 will see the browser flash green if the site is safe.

‘One of the other things we are doing is heavily pushing digital signature and email signing technologies so that all PayPal and eBay outbound email is digitally signed,’ said Barrett.

‘It is incumbent on us to set an example and say these technologies will help once they reach a critical mass,’ he said.

Peter Cassidy, secretary general of the Anti-Phishing Working Group, says nothing is absolute.

‘None of these solutions will stop online payment systems being attacked; criminals will just up their game. But two-factor systems will also get attention because consumers are experiencing something novel,’ he said.

What do you think? Email us at feedback@computing.co.uk

Further Reading:

Fraudsters use phishing tactics

Bank victiom of record phishing strike

International phishing gang arrested

reader comments

related articles

 

Latest tactics for fighting e-crime could backfire

Experts warn sting operations may make fraudsters harder to catch in future 28 Oct 2008

PayPal signs up for stronger authentication

Payment firm becomes first UK customer of VeriSign two-factor service 26 Jan 2009

Fraud-as-a-service looms over firms

Criminals are offering fraud services via chat rooms and forums 28 Oct 2008

related whitepapers

today's top stories

What does Windows 7 mean for Microsoft?

With the sting of Vista still fresh, Redmond has to make next Windows work 10 Jul 2009

A smarter way to use BI

Getting the most from business intelligence systems requires not only careful management on the part of IT leaders, but also the committed involvement of decision-makers across the organisation 08 Jul 2009

The truth behind the Google/Microsoft/NHS rumours

Before Monday 6 July, did you know that Google and Microsoft had services for storing health records? Thanks to an article in... 10 Jul 2009

Quenching a thirst for IT modernisation

A substantial restructure at soft drink supplier Nichols -­ purveyor of Vimto - ­led the company to update its software to Sage 1000 to replace its in-house application. This resulted in the streamlining of the IT department and an opportunity to customise the system 08 Jul 2009

How Satyam cleaned up its act

Chief executive CP Gurnani tells Angelica Mari why Tech Mahindra opted to keep the Satyam brand after it bought the scandal-hit services firm, and explains what the deal means for existing and prospective customers 09 Jul 2009

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Will Google Chrome OS be a genuine alternative to Windows?

Will Google Chrome OS be a genuine alternative to Windows?

Tell us your views on the new operating system rivalry

View poll results

Latest audio and video articles

network cablesVideo

How to maximise the value of your IT networking investment

A panel of experts discuss networking strategies that deliver real value to business 03 Jul 2009

green footprintsVideo

How to manage enterprise energy use - and the role IT can play

A panel of experts explore how firms can get to grips with their carbon footprint and make smarter use of energy 01 Jul 2009

Latest in-depth articles

Google ChromeAnalysis

Lack of enterprise appeal takes shine off Chrome OS

Enterprise buyers unlikely to ditch Windows for Chrome OS in the near term, say experts 09 Jul 2009

Satyam CEO CP GurnaniNews

How Satyam cleaned up its act

Chief executive CP Gurnani tells Angelica Mari why Tech Mahindra opted to keep the Satyam brand after it bought the scandal-hit services firm, and explains what the deal means for existing and prospective customers 09 Jul 2009

Advertisement

Primary Navigation