Neil Barrett
Neil Barrett

Who's who for online buyers?

Using chip-and-PIN-style authentication systems online might not be a good idea

Neil Barrett

You can buy everything on eBay, from the sublime to the ridiculous. Cuckolded husbands sell their wives' underwear; pranksters sell paper aeroplanes; you can even bid for a paper cup thrown at an American basketball star. But of course it also has its problems, most obviously the potential for imaginative crime.

Recently I heard of a hacker who had managed to fool a bidder into paying for an item being sold by someone else. Caveat emptor, of course: let the buyer beware. In other cases, the items sold have been the proceeds of robberies; the thieves used eBay as a high-tech way to turn the items into cash as anonymously as possible. But it's hard for any buyer to beware - or indeed, for any internet bank truly to "know their customer" - in an environment where "nobody knows you're a dog"; and where high degrees of anonymity are possible.

Advertisement

The issue, of course, is identification and authorisation - the identification of living human beings with some form of process block, and the authorisation of that process block to gain access to information.

There are three levels of authentication which are commonly recognised. Type 1, something that you know; a password, for example. Type 2, something that you have; a token or a smartcard. And type 3, something that you are; a biometric measure. And then, there are two common "factors" of authentication: one factor uses only one of these types; two factor uses two of them, preferably of different types. Unfortunately, almost all authentication that takes place on the internet, or indeed, in all but the most security conscious of environments, is one factor (a password) or at most a weak version of two factors (two passwords; a password and something such as your mother's maiden name).

In any security plan these would be considered weak, but they are the commonplace elements of most internet financial transactions.

There have long been better ways of achieving this authentication. Chip and PIN cards, for example, support true two-factor authentication: something you have, the card itself; and something you know, the PIN. Why can't we have those systems in place routinely on the internet, even if just for internet banking?

There are two reasons. First, the expense would cut into the banks' profits. Well, given the huge difference in cost between high street transactions and internet transactions - something like 20 times - this profit element seems less important. But there is another reason, and that is that users would be, in fact, less well protected.

An internet transaction on a credit card is a "cardholder not present" transaction, meaning that the burden of proof for the transaction lies with the merchant and the customer can expect to be refunded if anything goes wrong.

If you move to a stronger authentication - or even some form of digital signature - then this protection is removed; it becomes a "cardholder present" transaction and the burden shifts.

So, intriguingly, customers might be better protected with the weaker security versions. Worth thinking about next time you buy something online from eBay?

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

Doubts cast over efficacy of two-factor authentication

Hackers can beat security tokens

Two-factor authentication 'doesn't solve anything', claims security expert

CeBIT 2005

Microsoft to abandon passwords

Two-factor authentication vital to future of e-commerce, claims Redmond

Related whitepapers

Related jobs

Most watched

Xperia X1

Video Review: Sony Ericsson Xperia X1

First Looks Editor Ian Williams gets hands on with the Sony Ericsson Xperia X1

iPhone

Video Review: iPhone 3GS

We put Apple's latest iPhone through its paces

IT white papers

Search white papers

Top categories

Poll

Poll: Summer smartphones

Poll: Summer smartphones

Which smartphone will you be taking to the beach this summer?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

a padlock

Microsoft to plug security holes

Microsoft has given advance warning of a number of security...

Nokia handset

Top 10 articles, 10 July 09

No Nokia Android phone, ActiveX attacks and Google enters into...

Can Google beat Microsoft at its own game?

Google's announcement this week that it plans to step into...

iPhone

Video Review: iPhone 3GS

We put Apple's latest iPhone through its paces

Primary Navigation