Most Popular Stories
- Google targets Exchange users with migration tool
- IT execs lease data centers instead of building them
- Will posting Fed contracts expose sensitive data?
- eZ Systems brings former IBM exec on board as CEO
- Microsoft offers sneak peek at Internet Explorer 9
- HP settles ink cartridge patent case with importers
Events
- AIIM Expo + Conference
April 20-22, 2010 — Philadelphia, PA - TM Forum Management World 2010
18-20, May — Nice, France - A&D Cybersecurity Forum
March 31-April 1 — Washington, DC - Sensors Expo & Conference
June 7-9, 2010 — Rosemont, IL
Sponsored Links
HOT TOPICS >> Solid State Drives | IT Security | Open Source | ARM Processors | Google Chrome 4
INDUSTRY >> Healthcare | Government | Financial Services | Biotech | Compliance
Free Newsletter
Latest News
Popular Topics
Whitepapers
- Email Encryption- Protecting Data in Transit
- White paper: Managing your company's wireless expense is not enough. Be BudgetCorrectâ„¢
- Tracking File Access for Auditing and Compliance
- How to Improve Business Results through Secure Single Sign-On to SAP?
- How Secure is a Password?
- Whitepaper: Integrated Analytics and WCM Can Improve Performance & ROI
Credit card verification system not secure, says researcher
Researchers from the University of Cambridge are questioning a security system that credit card companies say gives additional security to credit card transactions. Called 3-D Secure (3DS), the system is implemented--and paid for--by online vendors. In a nutshell, the system requires the use of a password for verification on top of the standard credit card information.
For their troubles, merchants will find it easier to shift liability away from themselves in the event of fraudulent usage. Unfortunately, the general way of implementing 3DS involves the use of iframes in HTML, which effectively prevents users from ascertaining the validity of the site. This is detrimental as it exposes users to possibility of man-in-the-middle attacks. In addition, the use of static passwords is also prone to phishing methods by scammers.
Don't expect the situation to change anytime soon, though. As noted by one of the researchers, Steven J. Murdoch, "Most banks have chosen to go for passwords than anything better...Passwords are really cheap."
For more on this story:
- check out this article at Ars Technica
- check out this article at PCWorld
Related Articles:
Symantec: Call center worker in India may have sold credit card data
Biggest hacking case ever sends security warning
Heartland settles with American Express
Related Stories
- Cyberthieves target SMB bank accounts
- Another stolen laptop, another breach
- The dangers of online file sharing
- Bad account management leads to breaches
- Bank sues cybertheft victim
- Portable flash drives often misplaced, lost
- Hacking is top cause of data breaches
- Financial firm warns 1.2 million files exposed
- What we can expect from cloud computing in 2010
- A plea in the massive Heartland breach case
Comments
Post new comment
Home
| Subscribe | Advertise | RSS |
Privacy
| Site MapTHE FIERCEMARKETS NETWORKFierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceVoIP | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe | FierceCable© 2010 FierceMarkets. All rights reserved. |
![]() |






