Credit card of tomorrow: software, not plastic

[email protected] (News Network)
April 3, 2014

Apr 3: Since the 1970s, paying with plastic has been pretty standard everywhere: customers swiped their cards, signed receipts and took home their purchases.

Credit_cardBut after security breaches at Target late last year led to the loss of personal data from as many as 110 million customers, the financial industry is racing to adopt technologies that will alter that decades-old ritual. Driven largely by security concerns, credit card companies and issuers say they are working to make the system as consumers know it obsolete through smart chips and advanced computer programming.

To many, it is about time. The roots of the magnetic strip on credit cards extend back to World War II, ample time for thieves to learn to hack and steal those black lines of prized account information. Credit card fraud totalled nearly $5.3 billion in the United States alone in 2012, giving the industry plenty of incentive to devise a better system. The amount lost to fraud continues to grow by 30 to 50 per cent a year, according to estimates from the Aite Group, a research company.

Efforts to bolster card security were underway well before hackers broke into the systems of Target, Neiman Marcus, Michaels and other store chains. But the recent data breaches injected new urgency into adopting newer technology. “I think this will become a defining moment about how we in the industry think about security,” said Eileen Serra, the chief executive of Chase Card Services.

The credit card industry, especially in the United States, has long relied on increasingly sophisticated analytical programmes to weed out potentially fraudulent transactions. But it has also focussed on a handful of technologies it contends will better protect customers in stores and online. One is placing microprocessors onto cards, a standard known as EMV for its initial backers: Europay, MasterCard and Visa. Another is known as tokenisation, a way of masking consumers" card information over the Internet. “It"s about taking vulnerable data out of the merchant environment,” said Ellen Richey, Visa"s chief legal officer.

EMV is the best-known technology. Such cards are embedded with smart chips authenticating that their bearers are their rightful users. The chip is also extraordinarily difficult for thieves to counterfeit. Cardholders verify the transaction with a PIN or a signature. Though the latter is less secure, it will likely be more prevalent in the United States at first, though Chase and others expect to offer chip-and-PIN cards this year.

Europe and parts of Asia have already used the system for the better part of a decade, while American merchants and issuers have balked, largely because of cost. Chip-equipped cards cost an estimated $1.30 each to make, while a standard plastic card with a magnetic stripe on the back costs roughly 10 cents. Retailers, too, have been loath to update their systems to accept chip technology because of the added cost.

“EMV is going to cost billions of dollars to implement in this country,” said Shirley W Inscoe, an analyst at the Aite Group. But research suggests that the system works. In 2005, when Britain fully phased in the EMV technology, credit counterfeit card fraud was 25 per cent; such fraud plummeted to 11 per cent seven years later, according to the Aite Group.

Visa, MasterCard and American Express all announced road maps for adopting smart chips more than a year and a half ago, with the aim of forcing most retailers and issuers to put EMV in place by October 2015 in the United States. By then, the liability for any counterfeit fraud will fall on whoever has not adopted the chip technology (gas stations and ATMs will have until 2017 to meet the new requirements.)

From 17 million to 20 million chip cards have been issued in the United States, according to the Smart Card Alliance, an industry group. But that represents just 2 per cent of the one billion cards in use. In many ways, the chip technology is already decades old. It has been around since the 1990s, born in an era before the Internet and widespread e-commerce.

Industry officials concede that such technology would not have prevented the data breach at Target, or any sort of online fraud in which thieves obtained lists of customers" credit card numbers. Markets where EMV has been adopted have shown a significant increase in Internet fraud. That is a gap that tokenisation is meant to fill.

The technology works behind the scenes of a digital transaction: customers still put in their card number, but software then transforms that information into a one-time token — a randomly generated code — that is sent through the payment-processing chain. Thieves who intercept the code can do little with it without the means to unscramble the token.

To many in the industry, part of the technology"s appeal is that it requires less upheaval than EMV customers still put in card information as they always have. And the digital tokens are largely in the same format as traditional card numbers, but mask identifying information.

“Now you don"t have personal information around the world,” Serra said. “With tokenisation, we can keep that data much more secure.” The hope of digital tokens is that they will not be confined to any one way of paying. Websites, digital wallets and mobile devices could all use the technology, broadening its utility. “Every device should have the same foundation,” Ed McLaughlin, MasterCard"s chief emerging payments officer, said.

Token technology

Still, for years token technology lacked the sort of universal standard that underpins chip cards. But in recent months, a joint venture of Visa, MasterCard, American Express and others announced a proposed framework to ensure that everyone was on the same page. At least two of the five biggest card issuers in the United States are adopting some form of tokens, Inscoe said.

A framework for token systems is still being built, and meaningful adoption is years away, said Randy Vanderhoof, the executive director of the Smart Card Alliance. For now, chip cards will help eliminate the most obvious and pressing kinds of fraud. “If your boat is leaking in multiple places, and you can"t plug them all up at the same time, you plug the biggest one first,” Vanderhoof said.

Ultimately, while physical cards will remain in use for some time, many in the industry predict plastic as the primary way to pay will give way to digital wallets embedded in smart phones, tablets and other devices. MasterCard is already testing a way for Australian consumers with Samsung Galaxy S4 phones to pay using their phones.

Smart chips and tokens eventually will be embedded in an array of computers, providing multiple layers of security, Mr McLaughlin of MasterCard said. A consumer"s smartphone will not only have a unique ID, it will also generate one-of-a-kind tokens for every transaction — ones that can easily be disabled if the phone is lost or stolen. “The mag stripe will become functionally obsolete,” Richey of Visa said. “Mobile will take over.”

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
March 25,2020

In an unprecedented crisis despite Prime Minister Narendra Modi assuring the continuation of essential services like food and groceries, online marketplaces like Flipkart and Amazon along with delivery platforms like Bigbasket, Grofers and FreshToHomes hit a major blockade on Wednesday as local authorities shut warehouses and sent delivery boys back, even harassed them.

Millions of people across cities were left helpless at homes as essential items like fruits and vegetables, dairy and milk, meat and fish etc did not reach their doors despite placing orders well in advance. Later, the orders went dry.

While Grofers' warehouse in Faridabad was closed by the local law enforcement agencies, Bigbasket complained that the police stopped its delivery partners and "some of them were even beaten up by for no fault of theirs".

"We are not operational due to restrictions imposed by local authorities on movement of goods in spite of clear guidelines provided by central authorities to enable essential services. We are working with the authorities to be back soon,' Bigbasket tweeted.

In a statement to IANS, Bigbasket said that it will help to have better coordination between the Centre and state, and between the state and local police to "ensure that our delivery vans and bikes don't get stopped by the police. Bigbasket and bb daily are not taking new orders".

Furious people stormed the social media platforms, writing their plight to NITI Aayog CEO Amitabh Kant on Twitter.

"Sir, all e-commerce are down. Believe me I tried everything (Grofers, Bigbasket, Flipkart, Amazon, Big Bazaar), no delivery till 31st March or Server Down or No Service. Need to think how we can enable them through digital India," tweeted one user.

Kant tweeted back to Bigbasket: "They should give me specifics - State & location. I will act on it by getting in touch with concerned authorities & sorting it out. Govt guidelines exempt them. We will ensure that citizens are not impacted".

Kant also responded to Grofers: "Cold storages & Warehouses as well as delivery of all essentials goods including food, pharma thru E-Commerce are exempted under MHA order. I have spoken to CS & DGP, Haryana . They have taken immediate action to ensure that supply chains efficiently function for the citizens".

The subscription-based hyperlocal delivery startup FreshToHome sent messages to its customers, saying that despite the government declaring food delivery as essential, "we are facing hardships in continuing our operations".

"Please bear with us as we are working hard to unblock local authority hurdles," said the FreshToHome team.

Reports later surfaced that the Department for Promotion of Industry and Internal Trade (DPIIT) has initiated talks with the state Chief Secretaries asking them not to restrict movement of people engaged in home delivery of essential items, mentioned in the list of exempted items circulated by the Home Ministry.

Meanwhile, Flipkart said it has temporarily suspended its operations and services - including grocery items. The marketplace has decided to halt all orders from March 25 for all three supply chains -- groceries, non-large goods and large items.

"Flipkart has temporarily suspended orders as we assess the possibilities of operating in the lockdown. We are prioritising the safety of our delivery executives and seeking the support of the local governments and police authorities to meet the needs of our customers as they stay home during this lockdown," Rajneesh Kumar, Chief Corporate Affairs Officer, Flipkart, said in a statement.

E-commerce giant Amazon said the company has to "temporarily stop taking orders and disable shipments for lower-priority products.

"For all pending customer orders on lower-priority products, we are reaching out to customers and giving them a choice to cancel their orders, and receive a refund for prepaid items," said the company.

Witnessing a surge in demand, supermarket chain Biz Bazaar entered the fray, with launching doorstep delivery services in major cities like Delhi, Mumbai, Bengaluru and Gurugram.

However, within no time, Big Bazaar was flooded with calls, forcing the company to issue a statement, saying that "In light of the recent announcement, we are receiving an unprecedented number of requests for doorstep delivery. There could be a delay due to the restrictions on movements".

Already battling massive surge in demand, the online delivery platforms faced other issues too, including zero access to several high-rises across the country which have gone under complete lockdown with all entry and exit gates locked.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
January 25,2020

New Delhi, Jan 25: The Patiala House court on Saturday started hearing a plea filed by the Nirbhaya convicts that alleged that the Tihar Jail administration have "not presented the papers on time".

The Public Prosecutor informed the court that Tihar Jail authorities have already supplied the relevant documents. He further informed that these are mere delaying tactics adopted by the convicts.

Advocate A.P. Singh, lawyer for three of the four death row convicts in the Nirbhaya gang-rape case had moved an application before the court seeking directions to the Tihar Jail authorities to supply him the relevant documents in order to exercise the remaining legal remedies available with the death row convicts -- Vinay Pawan and Akshay.

The Public Prosecutor also told the court that he spoke to the jail authorities over the phone and a report in this regard will be filed shortly as the jail officials were on their way to the court.

The judge demanded from the convicts lawyer to show what he has filed.

The convicts lawyer, A.P. Singh, said that he received some documents, but has still not been supplied with the personal diary of one of the convict -- Vinay Kumar Sharma and also the medical documents.

Judge then asked the lawyer to wait for until the report arrives form the Tihar Jail.

On this, the convicts lawyer said he was not questioning the intention of the jail. "I know the jail has been changed. It isn't there fault, too," he said.

The Public Prosecutor refuted the allegation saying that the defence counsel was trying to defeat the speed of law.

"We have supplied all the documents to the counsel. We have supplied all the documents except the painting and some other documents. We have nothing apart from that," public prosecutor said.

Singh, in his plea filed before the Patiala House Court sought urgent orders of the court in order to file a mercy petition of Vinay Sharma and in relation to requests for documents for convicts Vinay Sharma, Pawan Kumar Gupta and Akshay Kumar Singh.

He further said that the convicts undertook several steps to obtain relevant information necessary for filing the mercy petitions. In regular interval, the convicts requested the concerned authority to supply documents pertaining to their medical records from 2012 to 2015 and 2019-2020, records of cellular confinement, records of the amount earned in prison through labour, records of educational and reformative activities like Tihar Olympics and Painting, etc.

The Supreme court had recently dismissed the curative petition for the other two convicts -- Vinay Kumar Sharma (26) and Mukesh Singh (32).

The court had recently issued death warrant against the convicts and fixed 6 a.m. on February 1 as the date and time of execution of the death penalty.

The 23-year-old victim in the case was brutally gang raped and tortured on December 16, 2012, which later led to her death. All the six accused were arrested and charged with sexual assault and murder. One of the accused was a minor and appeared before a juvenile justice court, while another accused committed suicide in Tihar Jail.

Four of the convicts were sentenced to death by a trial court in September 2013, and the verdict was confirmed by the Delhi High Court in March 2014 and subsequently upheld by the Supreme Court in May 2017, which also dismissed their review petitions.

A Juvenile involved in the crime was convicted by a juvenile justice board and released from a reformation home after serving a three-year term.

Hearing in a different case, Chief Justice of India S.A. Bobde on Thursday said a condemned person cannot fight the death penalty endlessly and it was important for the capital punishment to reach its finality.

The death penalty, he noted, cannot be questioned at every turn by the convict.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
March 8,2020

Consumer watchdog Which? has claimed that more than one billion Android phones and tablets are vulnerable to hackers as they no longer supported by security updates.

According to the research report, the most at-risk phones are any that run Android 4 or older and those smartphones running Android 7.0 which can not be updated are also at risk.

Based on data from Google analysed by Which?, two in five android device users around the world are no longer receiving the important updates. Currently, those devices are unlikely to have issues, but the lack of security leaves them open to attack.

"It is very concerning that expensive Android devices have such a short shelf life before they lose security support, leaving millions of users at risk of serious consequences if they fall victim to hackers," Kate Bevan editor Which? said in a statement.

"Google and phone manufacturers need to be upfront about security updates with clear information about how long they will last and what customers should do when they run out. The government must also push ahead with planned legislation to ensure manufacturers are far more transparent about security updates for smart devices and their impact on consumers," Kate added.

Android phone released around 2012 or earlier, including popular models like the Samsung Galaxy S3 and Sony Xperia S, are particularly at risk to hackers.

Which? has made suggestions to Android users on what to consider if they have an older phone that may be at risk.

Any Android device which is more than two years old, check whether it can be updated to a newer version of the operating system. If it is on an earlier version than Android 7.0 Nougat, try to update via Settings> System>Advanced System update.

In case a user is not able tto update the phone, the device could be at risk of being hacked if it is running a version of Android 4 or lower.

A user also need to be careful about downloading apps outside the Google Play store and should also install a mobile anti-virus via an app.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.