<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Tales from the Crypto : Credit Cards</title><link>http://msmvps.com/blogs/alunj/archive/tags/Credit+Cards/default.aspx</link><description>Tags: Credit Cards</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>How broken is the banking system?</title><link>http://msmvps.com/blogs/alunj/archive/2008/01/07/1445985.aspx</link><pubDate>Tue, 08 Jan 2008 05:22:01 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1445985</guid><dc:creator>Alun Jones</dc:creator><slash:comments>3</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/alunj/rsscomments.aspx?PostID=1445985</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/alunj/commentapi.aspx?PostID=1445985</wfw:comment><comments>http://msmvps.com/blogs/alunj/archive/2008/01/07/1445985.aspx#comments</comments><description>&lt;p&gt;&lt;img style="margin:0px 10px 0px 0px;" height="152" alt="Jeremy Clarkson - we should all have his simple naivete and faith in the system" hspace="0" src="http://newsimg.bbc.co.uk/media/images/44339000/jpg/_44339792_clarkson_bodypa203.jpg" width="203" align="left" border="0" /&gt;My kid and I love watching &lt;a title="Top Gear - hosted by William Woolard, Angela Rippon and Noel Edmonds" href="http://www.bbc.co.uk/topgear/"&gt;Top Gear&lt;/a&gt; - me, because it&amp;#39;s nice to see him interested in a very traditional British TV programme (in the US, you can find it on BBC America), and him, because he just loves cars - particularly high-performance ones.&lt;/p&gt; &lt;p&gt;So I have to admit to having a little chuckle as I find what&amp;#39;s been going on in the life of its host, Jeremy Clarkson.&lt;/p&gt; &lt;p&gt;Well, in the wake of the recent loss of 25 million child benefit case records by the UK Government&amp;#39;s HMRC (tax and customs) department... what, you didn&amp;#39;t hear about it?&lt;/p&gt; &lt;blockquote&gt; &lt;p&gt;Okay, I&amp;#39;ll admit, I didn&amp;#39;t report on it, because I figured the world and his wife had already heard all there was to hear on the story. Cut to the chase - someone at the HMRC received a call from someone at the NAO (National Audit Office), asking for some records. Rather than asking if they were supposed to be handing those records over, or if the NAO actually had any rights to receive the records, the &amp;quot;junior official&amp;quot; involved sent a couple of disks ... in internal mail (which turned out not to be so internal, having been contracted out to a courier) to the NAO.&lt;/p&gt; &lt;p&gt;The NAO called back after a few days, asking where their data was.&lt;/p&gt; &lt;p&gt;The junior official sent another copy!&lt;/p&gt; &lt;p&gt;At this point, somebody told someone, and a big stink got raised that there was all this data out there - 25 million records, 7.5 million families, containing names, addresses, bank account numbers, national insurance numbers (NI numbers - that&amp;#39;s our equivalent of Social Security Numbers or SSNs).&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;Okay, so in the wake of all this, lad Jeremy decides he&amp;#39;s fed up of all the press coverage of the waste of time investigation into the whole loss of two miserable little CDs.&lt;/p&gt; &lt;p&gt;He declares, in one of the UK national newspapers (the one with semi-naked women on one of its inside pages), that it&amp;#39;s all a load of fuss over nothing - even goes so far as to call it a &amp;quot;palaver&amp;quot; (which is not, apparently, a knitted garment - that would be either a pullover, or a balaclava).&lt;/p&gt; &lt;p&gt;Mr C even goes so far as to publish his own bank account number. With sort code (aka bank routing number, to those of us in the USA).&lt;/p&gt; &lt;blockquote&gt; &lt;p&gt;&amp;quot;All you&amp;#39;ll be able to do with them is put money into my account. Not take it out. Honestly, I&amp;#39;ve never known such a palaver about nothing,&amp;quot;&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;See - I told you he called it a palaver.&lt;/p&gt; &lt;p&gt;Sadly, as the BBC (don&amp;#39;t they broadcast Top Gear, or something?) reports, &amp;quot;&lt;a title="Clarkson stung after bank prank - BBC News" href="http://news.bbc.co.uk/2/hi/entertainment/7174760.stm"&gt;Clarkson stung after bank prank&lt;/a&gt;&amp;quot;. I guess we couldn&amp;#39;t predict that.&lt;/p&gt; &lt;blockquote&gt; &lt;p&gt;&amp;quot;I opened my bank statement this morning to find out that someone has set up a direct debit which automatically takes £500 from my account,&amp;quot;&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;After explaining to some disbelieving friends how this could have happened, I realised that not everyone has had the chance to run their own business, and see what a mess the banking system is. We all assume that the banks have our best interests at heart, and operate securely in ways that ensure we can&amp;#39;t lose a penny.&lt;/p&gt; &lt;p&gt;Not really, no. They work (mostly) on the basis that it&amp;#39;s cheaper to refund your money if you notice a problem and complain, than it would be to fix the problem in the first place.&lt;/p&gt; &lt;p&gt;Here&amp;#39;s a &lt;a title="APACS - the UK payments association - direct debit FAQ" href="http://www.apacs.org.uk/resources_publications/faqs/bacs_9.html"&gt;simple explanation of how &amp;quot;direct debit&amp;quot;&lt;/a&gt; (in the US, &amp;quot;automated payment&amp;quot;) works:&lt;/p&gt; &lt;blockquote&gt; &lt;p&gt;Most commonly you would complete a written Direct Debit Instruction, obtained from the organisation you wish to pay and return it to them for onward transmission to your bank. Some direct debits may be set up over the phone or via the Internet. In these cases the organisation must subsequently write to you confirming what has been agreed.&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;So, the receiving organisation claims to the bank that someone claiming to be the account holder requested them to withdraw money from the account.&lt;/p&gt; &lt;p&gt;Note &amp;quot;claims&amp;quot;, because there&amp;#39;s no proof at that stage.&lt;/p&gt; &lt;p&gt;It&amp;#39;s not even as workable as &amp;quot;you write to the bank requesting they allow a direct debit from your account&amp;quot; - the bank has no opportunity to interact with the customer except by sending them their next bank statement!&lt;/p&gt; &lt;p&gt;That&amp;#39;s broken - but then again, I&amp;#39;ve written before about how broken the credit card system for web purchases is. Again, the actual issuing bank, the one with whom you have a relationship, and who could validate your identity, is kept out of the transaction until it&amp;#39;s already finished.&lt;/p&gt; &lt;p&gt;What would be super is if a celerity like Jerembly Clarkson would start a campaign to have the banks be required to all team up and do a properly secure set of protocols for credit card and payment authorisations. Then merchants like me wouldn&amp;#39;t whine about repeated charge-backs that we can&amp;#39;t actually refute, and people like him, ignorant about the truth of the banking industry&amp;#39;s inability to secure the very money they are entrusted with, wouldn&amp;#39;t go handing out money willy-nilly to random charities just to prove that his trust is woefully misplaced.&lt;/p&gt; &lt;p&gt;I just don&amp;#39;t think it&amp;#39;ll happen.&lt;/p&gt; &lt;p&gt;I hope there was only £500 in the account, and that Mr Clarkson has already closed that account, and opened one whose number he will keep secret, sharing only with the bank, the company that prints his cheques, everyone he ever pays by cheque... now there&amp;#39;s another broken system.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1445985" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/alunj/archive/tags/General+Security/default.aspx">General Security</category><category domain="http://msmvps.com/blogs/alunj/archive/tags/Credit+Cards/default.aspx">Credit Cards</category><category domain="http://msmvps.com/blogs/alunj/archive/tags/What+my+wife+knows/default.aspx">What my wife knows</category></item><item><title>Finally, credit cards done right... maybe</title><link>http://msmvps.com/blogs/alunj/archive/2006/12/29/finally-credit-cards-done-right-maybe.aspx</link><pubDate>Fri, 29 Dec 2006 16:19:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:458385</guid><dc:creator>Alun Jones</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/alunj/rsscomments.aspx?PostID=458385</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/alunj/commentapi.aspx?PostID=458385</wfw:comment><comments>http://msmvps.com/blogs/alunj/archive/2006/12/29/finally-credit-cards-done-right-maybe.aspx#comments</comments><description>&lt;P&gt;For the longest time, I've been mystified at the way in which we as an information-based society conduct online transactions.&lt;/P&gt;
&lt;P&gt;Here's how it goes right now:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Customer sends secret information (card number and maybe CVV2) to vendor.&lt;/LI&gt;
&lt;LI&gt;Vendor promises not to disclose information to anyone but the bank.&lt;/LI&gt;
&lt;LI&gt;Vendor accidentally or deliberately discloses secret information to thieves.&lt;/LI&gt;
&lt;LI&gt;Thieves run up huge credit card bills with other vendors (call them "suckers").&lt;/LI&gt;
&lt;LI&gt;Customer reports unapproved use of credit card.&lt;/LI&gt;
&lt;LI&gt;Bank takes money out of sucker vendors' accounts in the amount of the theft plus a fine. Oh, and charges a percentage of the transaction cost in both directions.&lt;/LI&gt;
&lt;LI&gt;Rinse, lather, repeat.&lt;/LI&gt;&lt;/OL&gt;
&lt;P&gt;Obviously, those vendors that are accepting credit cards are complete suckers, because they get fined for accepting credit card numbers from the thieves, when of course the bank has provided them with no means of confirming the identity of the person placing the order.&lt;/P&gt;
&lt;P&gt;It's really obvious that the way this should proceed in an Internet-connected society is as follows:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Customer identifies herself to the bank (through secret information or public key infrastructure, doesn't much matter, because there are only two parties concerned&amp;nbsp;- bank and customer)&lt;/LI&gt;
&lt;LI&gt;Customer tells bank what vendor they want to pay, and how much.&lt;/LI&gt;
&lt;LI&gt;Bank provides customer with a difficult-to-forge, non-repeatable, time-sensitive code tied to this one purchase.&lt;/LI&gt;
&lt;LI&gt;Customer sends code to vendor.&lt;/LI&gt;
&lt;LI&gt;Vendor can post code on billboards, for all anyone cares, because that code is only usable by that vendor, for this transaction, for this amount, over the next couple of days (hey, vendors are slow to cash credit card transactions).&lt;/LI&gt;
&lt;LI&gt;Vendor sends code to bank.&lt;/LI&gt;
&lt;LI&gt;Bank pays vendor from customer's account.&lt;/LI&gt;
&lt;LI&gt;Vendor can post code on billboards, for all anyone cares, because that code is now not usable by any vendor, for any transaction.&lt;/LI&gt;&lt;/OL&gt;
&lt;P&gt;Obviously, there's still opportunity for fraud - if the customer or the bank share their shared secret with someone else. But then, that's two parties who have engaged in a contract to trust one another for monetary exchange, and who have adequate reason to keep that information secret - plus, if the secret is exposed, there's already an approved method to re-assign new secrets.&lt;/P&gt;
&lt;P&gt;Sadly, there's no incentive for the system to change this way - neither the customer nor the banks have any incentive to change, because they don't lost money when credit cards are used fraudulently - it's only the sucker vendor who loses money, and the sucker vendor has to accept credit cards, because there's no other way to take money over the Internet.&lt;/P&gt;
&lt;P&gt;All that is about to change, I hope.&lt;/P&gt;
&lt;P&gt;PayPal, a division of eBay, is one of the biggest sucker vendors there can be. Clearly, they've gotten tired of having to pay the fees, fines, and cost of lost goods, when credit cards are fraudulently used. Because they've finally come up with &lt;A class="" title="PayPal 'Virtual Debit Card' Beta Seeks to Eliminate ID Theft" href="http://www.betanews.com/article/PayPal_Virtual_Debit_Card_Beta_Seeks_to_Eliminate_ID_Theft/1167345809"&gt;the right way to do things&lt;/A&gt;!&lt;/P&gt;
&lt;P&gt;Okay, so it's not quite as I outlined, because of course PayPal decided to do it in such a way that a vendor doesn't even have to know that they're dealing with PayPal's new scheme - the secret code is exactly a MasterCard number.&lt;/P&gt;
&lt;P&gt;Apart from this significant problem - that vendors still have no way to ensure that they are dealing with a more secure payment means, and therefore can't offer faster service, less chance of fraud checking triggering an alert, etc - this is a good scheme, and I want to see it proceed to fruition.&lt;/P&gt;
&lt;P&gt;It'll be even better if someone at PayPal wises up to the idea of providing a simple means to check that the MasterCard number provided is from the secured payment program (PayPal calls it "Virtual Debit Card" or "VDC" for the present).&lt;/P&gt;
&lt;P&gt;This scheme, or something similar, has been operated previously by other banks and in other countries, but the fact that PayPal, a large provider,&amp;nbsp;is going to adopt it means that we should be on the road to a more secure future, where vendors aren't dunned by banks and thieves alike for credit card fraud that is beyond the vendors' control.&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=458385" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/alunj/archive/tags/General+Security/default.aspx">General Security</category><category domain="http://msmvps.com/blogs/alunj/archive/tags/Credit+Cards/default.aspx">Credit Cards</category></item></channel></rss>