Putting all security and functionality on a single card makes it unsafe
Putting all security and functionality on a single card makes it unsafe

Credit card flaws fuel online fraud bonanza

Fundamental design errors helping criminals, claims analyst

Written by Robert Jaques

Today's credit cards are vulnerable to online fraud because of fundamental design flaws, industry experts warned today.

According to Forrester Research, the provision of all security and other functionality on a single physical card makes it intrinsically unsafe.

Ivan Remsik, senior analyst for financial services at Forrester, warned that, as long as multiple technologies use or reside on the same physical plastic entity, fraud is set to rise.

"The criminals will always look for the weakest combination. For instance, they would copy data from the magnetic strip on a chip card and acquire the cardholder's Pin through a fake terminal," he said.

"It is then child's play to encode this data on a plastic hotel room key and use it to withdraw money from a cash machine."

The analyst firm also warned that card fraud is increasingly moving online. Remsik argued that "something clearly needs to be done" to reduce the ease with which card-not-present fraud can be perpetrated, in particular online.

But he added that the current fraud prevention mechanisms on offer from Visa and Mastercard have their own problems.

Forrester indicated that various types of online scam targeting the consumer are on the increase, both technical, such as Trojans, and non-technical, such as phishing.

The analyst firm believes that fighting this threat effectively must combine technical and non-technical responses from financial services institutions, and potentially others such as ISPs.

Forrester's warning comes after the Association for Payment Clearing Services released figures this week indicating that UK card fraud increased by 20 per cent in 2004 compared to the previous year.

According to APACS, losses are reported to total £504.8m. The rise is attributed to fraudsters increasing their activity before the security benefits of chip and Pin are fully realised, in addition to targeting other areas such as card-not-present and identity fraud.

Tags:

Further reading

Vendors fight card cheats

New payment system developed to fight card-not-present (CNP) fraud   More...

Chip-and-PIN makes mark on UK card fraud

Criminals increased efforts in advance of tighter card security measures   More...

Online fraud hits record levels

Total amount stolen in the US last year estimated at $1.2bn   More...

Worms turn as Trojans take over

Rise of the botnet   More...

Related articles

Researchers warn of chip and Pin flaws

Popular retail machines vulnerable to attack   More...

Online banking fraud on the decline

But credit card fraud abroad pushing up overall losses   More...

Fraudsters exploit card protection system

Warning issued over flaw in Address Verification System   More...

London is UK's online fraud hotspot

Manchester and Kilmarnock close behind   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

04 Jul 2008

5.51 MBPodcast Special: Views from the Valley More...

03 Jul 2008

3.46 MBGreen grid computing, Trojans stop play and location-based services More...

02 Jul 2008

3.2 MBOnline TV, SME security and flexible laptops More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Online pornography

US rebate cheques spent on porn

Economic stimulus package works wonders   More...

Louis Vuitton

UK online fake goods market worth £800m

Legal experts warn of dramatic rise in 'e-fencing'   More...

Advertisement

Fibre-optics

New fibre-optic connections overtake cable

Broadband first-timers choosing fibre where possible   More...

Stars and Stripes

Cyber-crooks celebrate Independence Day

Security firms warn users to take extra care   More...

Advertisement