Most Popular Stories
- Nearly half of U.S. businesses to have mobile apps this year
- Apple's iPad 3 will be unveiled first week of March, says report
- Why people don't really plan website migrations
- Chrome 17's new features enhance speed, security
- Microsoft: How will Windows 8 on ARM be different
- Microsoft's Patch Tuesday for February has 9 security bulletins
Events
- CIO Healthcare Summit
March 11-14 — Scottsdale, AZ - The AIIM Conference 2012
March 20-22, 2012 — San Francisco, CA - Customer Engagement Technology World
March 28-29, 2012 — San Francisco - Ready to meet the next-generation of business?
March 4-6 2012 — San Francisco, CA
Sponsored Links
Free Newsletter
HOT TOPICS >> The tech world's top flops and fiascos of 2011 | Top 8 features in Windows 8 | Paul's Q&As
INDUSTRY >> Healthcare IT | Government IT | Financial Services IT | Biotech IT | Compliance IT
Free Newsletter
Latest News
Popular Topics
Whitepapers
- Whitepaper: Integrated Analytics and WCM Can Improve Performance & ROI
- Innovative Solutions for Database and DBA Management
- Whitepaper: Mobile Device Management Buyer's Guide: An Insider's View of the Market
- IMPROVING THE MANAGEMENT OF FEDERAL GOVERNMENT IT ASSETS THROUGH BETTER COMMUNICATION WITH THE IT INDUSTRY
- Green Doesn't Have to be Hard
- Business Intelligence: It's All in the Data
Credit card verification system not secure, says researcher
Researchers from the University of Cambridge are questioning a security system that credit card companies say gives additional security to credit card transactions. Called 3-D Secure (3DS), the system is implemented--and paid for--by online vendors. In a nutshell, the system requires the use of a password for verification on top of the standard credit card information.
For their troubles, merchants will find it easier to shift liability away from themselves in the event of fraudulent usage. Unfortunately, the general way of implementing 3DS involves the use of iframes in HTML, which effectively prevents users from ascertaining the validity of the site. This is detrimental as it exposes users to possibility of man-in-the-middle attacks. In addition, the use of static passwords is also prone to phishing methods by scammers.
Don't expect the situation to change anytime soon, though. As noted by one of the researchers, Steven J. Murdoch, "Most banks have chosen to go for passwords than anything better...Passwords are really cheap."
For more on this story:
- check out this article at Ars Technica
- check out this article at PCWorld
Related Articles:
Symantec: Call center worker in India may have sold credit card data
Biggest hacking case ever sends security warning
Heartland settles with American Express
Related Stories
- Hungarian hacker steals Marriott's data, tries to blackmail company into hiring him for IT job
- Citigroup reports another data breach
- Man admits to infecting college PCs with malware for profit
- Citigroup breached by simply altering URL; now admits 360k accounts hacked
- Hacker breaks into Barracuda Networks database using SQL Injection
- RSA tells more about SecurID breach
- Midsized businesses increasingly targeted by hackers, says McAfee
- Grocery chain issues warning about tampered payment terminals
- Email remains a major vector of enterprise data loss
- New study says cybercrime costs enterprises $3.8 million a year
Home
| Subscribe | Advertise | RSS |
Privacy
| Site Map
| EditorsTHE FIERCEMARKETS NETWORKFierceEnergy | FierceSmartGrid | FierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceHealthPayer | FiercePracticeManagement | FierceEMR | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceGovernment | FierceHomelandSecurity | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceMedicalDevices | FierceDrugDelivery | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceEnterpriseCommunications | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe | FierceCable© 2011 FierceMarkets. All rights reserved. |
![]() |




