Neil Barrett
Neil Barrett

Who's who for online buyers?

Using chip-and-PIN-style authentication systems online might not be a good idea

Written by Neil Barrett

You can buy everything on eBay, from the sublime to the ridiculous. Cuckolded husbands sell their wives' underwear; pranksters sell paper aeroplanes; you can even bid for a paper cup thrown at an American basketball star. But of course it also has its problems, most obviously the potential for imaginative crime.

Recently I heard of a hacker who had managed to fool a bidder into paying for an item being sold by someone else. Caveat emptor, of course: let the buyer beware. In other cases, the items sold have been the proceeds of robberies; the thieves used eBay as a high-tech way to turn the items into cash as anonymously as possible. But it's hard for any buyer to beware - or indeed, for any internet bank truly to "know their customer" - in an environment where "nobody knows you're a dog"; and where high degrees of anonymity are possible.

The issue, of course, is identification and authorisation - the identification of living human beings with some form of process block, and the authorisation of that process block to gain access to information.

There are three levels of authentication which are commonly recognised. Type 1, something that you know; a password, for example. Type 2, something that you have; a token or a smartcard. And type 3, something that you are; a biometric measure. And then, there are two common "factors" of authentication: one factor uses only one of these types; two factor uses two of them, preferably of different types. Unfortunately, almost all authentication that takes place on the internet, or indeed, in all but the most security conscious of environments, is one factor (a password) or at most a weak version of two factors (two passwords; a password and something such as your mother's maiden name).

In any security plan these would be considered weak, but they are the commonplace elements of most internet financial transactions.

There have long been better ways of achieving this authentication. Chip and PIN cards, for example, support true two-factor authentication: something you have, the card itself; and something you know, the PIN. Why can't we have those systems in place routinely on the internet, even if just for internet banking?

There are two reasons. First, the expense would cut into the banks' profits. Well, given the huge difference in cost between high street transactions and internet transactions - something like 20 times - this profit element seems less important. But there is another reason, and that is that users would be, in fact, less well protected.

An internet transaction on a credit card is a "cardholder not present" transaction, meaning that the burden of proof for the transaction lies with the merchant and the customer can expect to be refunded if anything goes wrong.

If you move to a stronger authentication - or even some form of digital signature - then this protection is removed; it becomes a "cardholder present" transaction and the burden shifts.

So, intriguingly, customers might be better protected with the weaker security versions. Worth thinking about next time you buy something online from eBay?

Tags:

reader comments

related articles

Doubts cast over efficacy of two-factor authentication

Hackers can beat security tokens

Two-factor authentication 'doesn't solve anything', claims security expert 15 Mar 2005

 

Microsoft to abandon passwords

Two-factor authentication vital to future of e-commerce, claims Redmond 14 Mar 2005

related whitepapers

today's top stories

CIOs must embrace collaboration tools

Author Don Tapscott gives Angelica Mari his reasons for promoting social networking tools and says transparency is the key to security 04 Dec 2008

On a quest to build a connected society

BT Design’s JP Rangaswami talks to Gareth Morgan about his pivotal role in the telecoms giant’s efforts to deliver universal broadband and his plans to tap into the creativity of the open source community 04 Dec 2008

IT leaders must stand by India

A sense of perspective is the most important response from IT leaders to the attacks in Mumbai 04 Dec 2008

Case study: Clifford Chance

Law firm implements Sun platform and reduces datacentres to gain efficiency and cost synergies 03 Dec 2008

Should CRM be more sociable?

As vendors rush to add more social networking bells and whistles to their CRM products, some experts warn that users must tread carefully when venturing into online communities 03 Dec 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Will the terrorist attacks in Mumbai affect your offshoring plans?

Will the terrorist attacks in Mumbai affect your offshoring plans?

Is India becoming a risky destination?

Previous poll results

Latest audio and video articles

Padlocked CDVideo

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

Podcast imageAudio

Computing podcast - Standard Life's offshoring plans; and the prospects for government IT

The insurance giant outlines its new outsourcing strategy; and we ask if the government's economic bailout will affect its IT plans 28 Nov 2008

Latest in-depth articles

Doctors looking at a computerAnalysis

Watchdog wants IT to cure privacy woes

Information Commissioner Richard Thomas is urging organisations to put privacy protection at the top of their procurement and development criteria 04 Dec 2008

Colin McDonaldComment

Web 2.0 has potential to transform staff training

Employees can sharpen their IT skills through using the latest interactive training tools, writes Colin McDonald 04 Dec 2008

Advertisement

Primary Navigation