SlideShare ist ein Scribd-Unternehmen logo
1 von 1
Downloaden Sie, um offline zu lesen
SUPPLEMENT: CYBER CRIME 2010




        3-D Secure™ Enrolment Activation
        Andrea Wilson, CEO First Atlantic Commerce asks whether this is the new breeding ground for Issuer merchant fraud reporting.
        Verified by Visa (VbV) has been hailed by the banks       Full service website                                    staff have never heard of Securesuite.co.uk. Chances
        and the Card Associations as an important step in        Cardholders register using a full-function, Issuer-     are the consumer thinks they are being phished or
        the fight against online card fraud. However, it has      branded Verified by Visa website maintained by           scammed or it’s the merchant who is trying to obtain
        been criticized by cardholders who have complained       Visa. The site allows cardholders to enroll, create     personal and security information from you. Either
        about being forced to input card numbers and             a password, and change a pass-word. It also             way it’s not good for business, or the reputation of
        other security details at a website that pops up the     provides cardholders with customer service contact      the merchant who remains powerless to prevent the
        Issuer enrolment activation window when they are         information.                                            VbV activation via their website.
        making purchases. Understandably, many people                                                                       More of a burgeoning problem is enrolment in
        shun the Verified by Visa ‘activation during checkout’    Activation during shopping                              VbV by fraudsters who have compromised card
        procedure for fear that it’s a phishing scam.            Cardholders are prompted to enroll during check-        numbers either through counterfeiting or card
           3-D Secure™ is an XML-based protocol used as          out while shopping at participating Verified by          generation software. Online activation has made it
        consumer authentication security for online credit       Visa merchant websites. A Verified by Visa pop-up        simple for fraudsters to register a consumer’s credit
        and debit card transactions. It was developed by         window prompts them to enroll in the service and        card in VbV and then start using it. This is a form of
        Visa to improve the security of Internet payments.       create a password.                                      identity theft which is difficult to quantify. I recently
                                                                                                                         heard of a case in Europe where a consumer’s VbV
        “What started out to be a universally good idea to reduce                                                        enrolment had been compromised and the Issuer
                                                                                                                         reported the merchant for fraud with the Card
        online credit card fraud has become a security nightmare                                                         Associations in order to circumvent the chargeback
        for consumers, acquiring banks and merchants.”                                                                   liability shift rights under chargeback rules. The
                                                                                                                         Issuer reported the merchant as fraud but didn’t
        The challenge for large card issuing banks was           Mass enrollment                                         process a chargeback so the acquiring bank was left
        (and still is) consumer education and rationale          Cardholders are enrolled automatically in the           dealing with a fraud report impacting the acquirer’s
        for enrolment. How would the banks get 500,000           Verified by Visa service and assigned pre-defined         portfolio ratios and the merchant’s credibility… but
        or more card numbers registered in Verified by            passwords delivered via a secure mailer.                not a chargeback loss.
        Visa in order to protect the bank and consumers              Activation and enrolment online, however, is           What started out to be a universally good idea
        against online fraudulent use? How can that many         plagued with problems, including phishing, hijacked     to reduce online credit card fraud has become a
        cardholders be educated on the value of the service      merchant websites and counterfeit or stolen card        security nightmare for consumers, acquiring banks
        for a reasonable cost to the Issuer? The answer          enrolment fraud. Issuers who mass activate are not      and merchants. Merchants who register with good
        became ‘Activation Online’ – a push enrolment            adequately informing their cardholders (if at all)      intention to reduce fraud transactions at their
        process that solved the Issuer’s mass enrolment and      that the enrolment will take place online and the       website are being reported by Issuers to Visa for
        cost concerns, but left cardholders frustrated and       cardholder believes the merchant is trying to obtain    fraud, when in fact the liability resides squarely with
        suspicious… and merchants taking the blame for           their personal information so they exit the site and    the Issuing banks… and their lack of foresight or
        it all. There are four methods for mass enrolment        cancel the purchase.                                    planning on how to mass register their
        by Issuers all of which take place online, and               Another problem with mass activation is that        consumers in Verified by Visa. ■
        are triggered at a website where the merchant is         Issuers typically revert to third-party providers
        enrolled in 3D-Secure™ authentication by their           to support the enrolment process so when the
                                                                                                                           Andrea Wilson
        acquiring bank:                                          consumer is presented with the pop-up box, the            CEO, First Atlantic Commerce
                                                                 consumer has no idea who the Issuer’s provider
        Activation anytime                                       is. Take for example, Securesuite.co.uk, a large
                                                                                                                             Andrea Wilson is Chief Executive
        Cardholders visit Error! Hyperlink reference not         third-party provider of Verified by Visa Issuer ACS          Officer and co-founder of First
        valid and enter their card number. If they are not       solutions for AIB, Royal Bank of Scotland and               Atlantic Commerce Ltd. Andrea has extensive
        enrolled in the service, they are asked to complete an   MBNA. You cannot Google http://www.securesuite.             experience in international, offshore and
        activation page. After entering the required identity    co.uk and find any information about this provider.          domestic card payment systems as well as
                                                                                                                             with Visa and MasterCard regional compliance
        information, the cardholder creates a password and       You perform a WHOIS query, and you will find out
                                                                                                                             regulations, ecommerce risk management and
        is congratulated for successfully registering for the    that Securesuite.co.uk is registered by Cyota in New        acquirer consulting.
        service.                                                 York City. You call the bank and the customer service


        52 iGamingBusiness Issue 60 January/February 2010
             ■             ■        ■




52.indd 52                                                                                                                                                                  11/1/10 17:08:09

Weitere ähnliche Inhalte

Was ist angesagt?

What is electronic_banking_mini
What is electronic_banking_miniWhat is electronic_banking_mini
What is electronic_banking_mini
lekshmipriyahari
 
Economic offenses through Credit Card Frauds Dissected
Economic offenses through Credit Card Frauds DissectedEconomic offenses through Credit Card Frauds Dissected
Economic offenses through Credit Card Frauds Dissected
amiable_indian
 

Was ist angesagt? (20)

debit cards
debit cardsdebit cards
debit cards
 
Creditworld debit cards-guide
Creditworld debit cards-guideCreditworld debit cards-guide
Creditworld debit cards-guide
 
Replace The Current Antiquated Credit Card System
Replace The Current Antiquated Credit Card SystemReplace The Current Antiquated Credit Card System
Replace The Current Antiquated Credit Card System
 
PCI FAQs and Myths
PCI FAQs and MythsPCI FAQs and Myths
PCI FAQs and Myths
 
Leveraging Analytics to Combat Digital Fraud in Financial Organizations
Leveraging Analytics to Combat Digital Fraud in Financial OrganizationsLeveraging Analytics to Combat Digital Fraud in Financial Organizations
Leveraging Analytics to Combat Digital Fraud in Financial Organizations
 
E business paper bba
E business paper bbaE business paper bba
E business paper bba
 
Reducing Fraud with the Right SSL Certificate in E-Commerce
Reducing Fraud with the Right SSL Certificate in E-CommerceReducing Fraud with the Right SSL Certificate in E-Commerce
Reducing Fraud with the Right SSL Certificate in E-Commerce
 
EMV Liability Shift: Why Financial Institutions Should Get Their ATMs in Line...
EMV Liability Shift: Why Financial Institutions Should Get Their ATMs in Line...EMV Liability Shift: Why Financial Institutions Should Get Their ATMs in Line...
EMV Liability Shift: Why Financial Institutions Should Get Their ATMs in Line...
 
The iWallet’s Effects on Small Business and What It Means to You
The iWallet’s Effects on Small Business and What It Means to YouThe iWallet’s Effects on Small Business and What It Means to You
The iWallet’s Effects on Small Business and What It Means to You
 
Plastic money
Plastic moneyPlastic money
Plastic money
 
Everything You Need to Know About Taking Plastic
Everything You Need to Know About Taking PlasticEverything You Need to Know About Taking Plastic
Everything You Need to Know About Taking Plastic
 
The end of passwords: Two-factor-authentication and biometrics are coming 2019
The end of passwords: Two-factor-authentication and biometrics are coming 2019The end of passwords: Two-factor-authentication and biometrics are coming 2019
The end of passwords: Two-factor-authentication and biometrics are coming 2019
 
What is electronic_banking_mini
What is electronic_banking_miniWhat is electronic_banking_mini
What is electronic_banking_mini
 
Economic offenses through Credit Card Frauds Dissected
Economic offenses through Credit Card Frauds DissectedEconomic offenses through Credit Card Frauds Dissected
Economic offenses through Credit Card Frauds Dissected
 
Making Seamless E-Payments a Reality
Making Seamless E-Payments a RealityMaking Seamless E-Payments a Reality
Making Seamless E-Payments a Reality
 
Plastic money sign of modernizing economy
Plastic money sign of modernizing economyPlastic money sign of modernizing economy
Plastic money sign of modernizing economy
 
Age Verificationn in the Alcohol industry
Age Verificationn in the Alcohol industry Age Verificationn in the Alcohol industry
Age Verificationn in the Alcohol industry
 
AlertPay Sellers Guide
AlertPay Sellers GuideAlertPay Sellers Guide
AlertPay Sellers Guide
 
Money Laundering in the Art, Collectibles, and Luxury Goods Industry
Money Laundering in the Art, Collectibles, and Luxury Goods IndustryMoney Laundering in the Art, Collectibles, and Luxury Goods Industry
Money Laundering in the Art, Collectibles, and Luxury Goods Industry
 
Factors to Consider While Choosing a Payment Gateway Provider
Factors to Consider While Choosing a Payment Gateway ProviderFactors to Consider While Choosing a Payment Gateway Provider
Factors to Consider While Choosing a Payment Gateway Provider
 

Ähnlich wie 3-D Secure Enrolment Activation

Ähnlich wie 3-D Secure Enrolment Activation (20)

Card & Payments Industry Overview
Card & Payments Industry OverviewCard & Payments Industry Overview
Card & Payments Industry Overview
 
Payer Authentication Solutions For Verified by VISA
Payer Authentication Solutions For Verified by VISAPayer Authentication Solutions For Verified by VISA
Payer Authentication Solutions For Verified by VISA
 
Credit card processing highrisk gateways
Credit card processing   highrisk gatewaysCredit card processing   highrisk gateways
Credit card processing highrisk gateways
 
How Credit Card Processing Works
How Credit Card Processing WorksHow Credit Card Processing Works
How Credit Card Processing Works
 
VISA Report - Revised
VISA Report - RevisedVISA Report - Revised
VISA Report - Revised
 
The Payments Glossary
The Payments GlossaryThe Payments Glossary
The Payments Glossary
 
Instant Virtual Debit Card Online A Convenient Financial Solution.pdf
Instant Virtual Debit Card Online A Convenient Financial Solution.pdfInstant Virtual Debit Card Online A Convenient Financial Solution.pdf
Instant Virtual Debit Card Online A Convenient Financial Solution.pdf
 
How to be a credit card processing ninja
How to be a credit card processing ninjaHow to be a credit card processing ninja
How to be a credit card processing ninja
 
Virtual Credit Cards
Virtual Credit Cards Virtual Credit Cards
Virtual Credit Cards
 
Cyber cash
Cyber cashCyber cash
Cyber cash
 
Active capital reinsurance
Active capital reinsuranceActive capital reinsurance
Active capital reinsurance
 
The 3-D Secure Protocol
The 3-D Secure ProtocolThe 3-D Secure Protocol
The 3-D Secure Protocol
 
Electronic payment
Electronic paymentElectronic payment
Electronic payment
 
Online Payment Gateway System
Online Payment Gateway SystemOnline Payment Gateway System
Online Payment Gateway System
 
Online payments and Security Gateways
Online payments and Security Gateways Online payments and Security Gateways
Online payments and Security Gateways
 
21 Simple Steps to Reduce Your Risk of Chargebacks
21 Simple Steps to Reduce Your Risk of Chargebacks21 Simple Steps to Reduce Your Risk of Chargebacks
21 Simple Steps to Reduce Your Risk of Chargebacks
 
How fraud and chargeback prevention works
How fraud and chargeback prevention worksHow fraud and chargeback prevention works
How fraud and chargeback prevention works
 
VISA.ppt
VISA.pptVISA.ppt
VISA.ppt
 
How an online payment gateway works
How an online payment gateway worksHow an online payment gateway works
How an online payment gateway works
 
OI_MerchProd
OI_MerchProdOI_MerchProd
OI_MerchProd
 

Kürzlich hochgeladen

Tales from a Passkey Provider Progress from Awareness to Implementation.pptx
Tales from a Passkey Provider  Progress from Awareness to Implementation.pptxTales from a Passkey Provider  Progress from Awareness to Implementation.pptx
Tales from a Passkey Provider Progress from Awareness to Implementation.pptx
FIDO Alliance
 
Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...
Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...
Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...
panagenda
 
Hyatt driving innovation and exceptional customer experiences with FIDO passw...
Hyatt driving innovation and exceptional customer experiences with FIDO passw...Hyatt driving innovation and exceptional customer experiences with FIDO passw...
Hyatt driving innovation and exceptional customer experiences with FIDO passw...
FIDO Alliance
 

Kürzlich hochgeladen (20)

The Metaverse: Are We There Yet?
The  Metaverse:    Are   We  There  Yet?The  Metaverse:    Are   We  There  Yet?
The Metaverse: Are We There Yet?
 
Working together SRE & Platform Engineering
Working together SRE & Platform EngineeringWorking together SRE & Platform Engineering
Working together SRE & Platform Engineering
 
Oauth 2.0 Introduction and Flows with MuleSoft
Oauth 2.0 Introduction and Flows with MuleSoftOauth 2.0 Introduction and Flows with MuleSoft
Oauth 2.0 Introduction and Flows with MuleSoft
 
(Explainable) Data-Centric AI: what are you explaininhg, and to whom?
(Explainable) Data-Centric AI: what are you explaininhg, and to whom?(Explainable) Data-Centric AI: what are you explaininhg, and to whom?
(Explainable) Data-Centric AI: what are you explaininhg, and to whom?
 
Easier, Faster, and More Powerful – Notes Document Properties Reimagined
Easier, Faster, and More Powerful – Notes Document Properties ReimaginedEasier, Faster, and More Powerful – Notes Document Properties Reimagined
Easier, Faster, and More Powerful – Notes Document Properties Reimagined
 
Tales from a Passkey Provider Progress from Awareness to Implementation.pptx
Tales from a Passkey Provider  Progress from Awareness to Implementation.pptxTales from a Passkey Provider  Progress from Awareness to Implementation.pptx
Tales from a Passkey Provider Progress from Awareness to Implementation.pptx
 
Collecting & Temporal Analysis of Behavioral Web Data - Tales From The Inside
Collecting & Temporal Analysis of Behavioral Web Data - Tales From The InsideCollecting & Temporal Analysis of Behavioral Web Data - Tales From The Inside
Collecting & Temporal Analysis of Behavioral Web Data - Tales From The Inside
 
Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...
Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...
Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...
 
Linux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdf
Linux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdfLinux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdf
Linux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdf
 
How we scaled to 80K users by doing nothing!.pdf
How we scaled to 80K users by doing nothing!.pdfHow we scaled to 80K users by doing nothing!.pdf
How we scaled to 80K users by doing nothing!.pdf
 
Extensible Python: Robustness through Addition - PyCon 2024
Extensible Python: Robustness through Addition - PyCon 2024Extensible Python: Robustness through Addition - PyCon 2024
Extensible Python: Robustness through Addition - PyCon 2024
 
Event-Driven Architecture Masterclass: Engineering a Robust, High-performance...
Event-Driven Architecture Masterclass: Engineering a Robust, High-performance...Event-Driven Architecture Masterclass: Engineering a Robust, High-performance...
Event-Driven Architecture Masterclass: Engineering a Robust, High-performance...
 
Where to Learn More About FDO _ Richard at FIDO Alliance.pdf
Where to Learn More About FDO _ Richard at FIDO Alliance.pdfWhere to Learn More About FDO _ Richard at FIDO Alliance.pdf
Where to Learn More About FDO _ Richard at FIDO Alliance.pdf
 
Your enemies use GenAI too - staying ahead of fraud with Neo4j
Your enemies use GenAI too - staying ahead of fraud with Neo4jYour enemies use GenAI too - staying ahead of fraud with Neo4j
Your enemies use GenAI too - staying ahead of fraud with Neo4j
 
TopCryptoSupers 12thReport OrionX May2024
TopCryptoSupers 12thReport OrionX May2024TopCryptoSupers 12thReport OrionX May2024
TopCryptoSupers 12thReport OrionX May2024
 
ERP Contender Series: Acumatica vs. Sage Intacct
ERP Contender Series: Acumatica vs. Sage IntacctERP Contender Series: Acumatica vs. Sage Intacct
ERP Contender Series: Acumatica vs. Sage Intacct
 
Choosing the Right FDO Deployment Model for Your Application _ Geoffrey at In...
Choosing the Right FDO Deployment Model for Your Application _ Geoffrey at In...Choosing the Right FDO Deployment Model for Your Application _ Geoffrey at In...
Choosing the Right FDO Deployment Model for Your Application _ Geoffrey at In...
 
Introduction to FDO and How It works Applications _ Richard at FIDO Alliance.pdf
Introduction to FDO and How It works Applications _ Richard at FIDO Alliance.pdfIntroduction to FDO and How It works Applications _ Richard at FIDO Alliance.pdf
Introduction to FDO and How It works Applications _ Richard at FIDO Alliance.pdf
 
How Red Hat Uses FDO in Device Lifecycle _ Costin and Vitaliy at Red Hat.pdf
How Red Hat Uses FDO in Device Lifecycle _ Costin and Vitaliy at Red Hat.pdfHow Red Hat Uses FDO in Device Lifecycle _ Costin and Vitaliy at Red Hat.pdf
How Red Hat Uses FDO in Device Lifecycle _ Costin and Vitaliy at Red Hat.pdf
 
Hyatt driving innovation and exceptional customer experiences with FIDO passw...
Hyatt driving innovation and exceptional customer experiences with FIDO passw...Hyatt driving innovation and exceptional customer experiences with FIDO passw...
Hyatt driving innovation and exceptional customer experiences with FIDO passw...
 

3-D Secure Enrolment Activation

  • 1. SUPPLEMENT: CYBER CRIME 2010 3-D Secure™ Enrolment Activation Andrea Wilson, CEO First Atlantic Commerce asks whether this is the new breeding ground for Issuer merchant fraud reporting. Verified by Visa (VbV) has been hailed by the banks Full service website staff have never heard of Securesuite.co.uk. Chances and the Card Associations as an important step in Cardholders register using a full-function, Issuer- are the consumer thinks they are being phished or the fight against online card fraud. However, it has branded Verified by Visa website maintained by scammed or it’s the merchant who is trying to obtain been criticized by cardholders who have complained Visa. The site allows cardholders to enroll, create personal and security information from you. Either about being forced to input card numbers and a password, and change a pass-word. It also way it’s not good for business, or the reputation of other security details at a website that pops up the provides cardholders with customer service contact the merchant who remains powerless to prevent the Issuer enrolment activation window when they are information. VbV activation via their website. making purchases. Understandably, many people More of a burgeoning problem is enrolment in shun the Verified by Visa ‘activation during checkout’ Activation during shopping VbV by fraudsters who have compromised card procedure for fear that it’s a phishing scam. Cardholders are prompted to enroll during check- numbers either through counterfeiting or card 3-D Secure™ is an XML-based protocol used as out while shopping at participating Verified by generation software. Online activation has made it consumer authentication security for online credit Visa merchant websites. A Verified by Visa pop-up simple for fraudsters to register a consumer’s credit and debit card transactions. It was developed by window prompts them to enroll in the service and card in VbV and then start using it. This is a form of Visa to improve the security of Internet payments. create a password. identity theft which is difficult to quantify. I recently heard of a case in Europe where a consumer’s VbV “What started out to be a universally good idea to reduce enrolment had been compromised and the Issuer reported the merchant for fraud with the Card online credit card fraud has become a security nightmare Associations in order to circumvent the chargeback for consumers, acquiring banks and merchants.” liability shift rights under chargeback rules. The Issuer reported the merchant as fraud but didn’t The challenge for large card issuing banks was Mass enrollment process a chargeback so the acquiring bank was left (and still is) consumer education and rationale Cardholders are enrolled automatically in the dealing with a fraud report impacting the acquirer’s for enrolment. How would the banks get 500,000 Verified by Visa service and assigned pre-defined portfolio ratios and the merchant’s credibility… but or more card numbers registered in Verified by passwords delivered via a secure mailer. not a chargeback loss. Visa in order to protect the bank and consumers Activation and enrolment online, however, is What started out to be a universally good idea against online fraudulent use? How can that many plagued with problems, including phishing, hijacked to reduce online credit card fraud has become a cardholders be educated on the value of the service merchant websites and counterfeit or stolen card security nightmare for consumers, acquiring banks for a reasonable cost to the Issuer? The answer enrolment fraud. Issuers who mass activate are not and merchants. Merchants who register with good became ‘Activation Online’ – a push enrolment adequately informing their cardholders (if at all) intention to reduce fraud transactions at their process that solved the Issuer’s mass enrolment and that the enrolment will take place online and the website are being reported by Issuers to Visa for cost concerns, but left cardholders frustrated and cardholder believes the merchant is trying to obtain fraud, when in fact the liability resides squarely with suspicious… and merchants taking the blame for their personal information so they exit the site and the Issuing banks… and their lack of foresight or it all. There are four methods for mass enrolment cancel the purchase. planning on how to mass register their by Issuers all of which take place online, and Another problem with mass activation is that consumers in Verified by Visa. ■ are triggered at a website where the merchant is Issuers typically revert to third-party providers enrolled in 3D-Secure™ authentication by their to support the enrolment process so when the Andrea Wilson acquiring bank: consumer is presented with the pop-up box, the CEO, First Atlantic Commerce consumer has no idea who the Issuer’s provider Activation anytime is. Take for example, Securesuite.co.uk, a large Andrea Wilson is Chief Executive Cardholders visit Error! Hyperlink reference not third-party provider of Verified by Visa Issuer ACS Officer and co-founder of First valid and enter their card number. If they are not solutions for AIB, Royal Bank of Scotland and Atlantic Commerce Ltd. Andrea has extensive enrolled in the service, they are asked to complete an MBNA. You cannot Google http://www.securesuite. experience in international, offshore and activation page. After entering the required identity co.uk and find any information about this provider. domestic card payment systems as well as with Visa and MasterCard regional compliance information, the cardholder creates a password and You perform a WHOIS query, and you will find out regulations, ecommerce risk management and is congratulated for successfully registering for the that Securesuite.co.uk is registered by Cyota in New acquirer consulting. service. York City. You call the bank and the customer service 52 iGamingBusiness Issue 60 January/February 2010 ■ ■ ■ 52.indd 52 11/1/10 17:08:09