Credit card
3-D Secure can confuse online shoppers by running counter to traditional advice

Researchers slam 3-D Secure as insecure

Verified by Visa and SecureCode 'fatally flawed', say Cambridge University experts

Phil Muncaster

University of Cambridge researchers have launched a withering attack on the 3-D Secure protocol used by Visa and MasterCard to authenticate online customers, branding it "a textbook example of how not to design an authentication protocol".

In a new piece of research entitled Verified by Visa and MasterCard SecureCode: or, How Not to Design Authentication (PDF), Steven Murdoch and Ross Anderson argue that 3-D Secure has become popular because it "got the economics right", rather than being intrinsically more secure than less popular rivals such as OpenID, InfoCard and Liberty.

The research maintains that the protocol often confuses users by running counter to traditional advice about entering credentials only into sites secured by Transport Layer Security, which browsers such as Internet Explorer 8 now recognise by displaying a green address bar.

"Because the 3-D Secure form is an iframe or pop-up without an address bar, there is no easy way for a customer to verify who is asking for their password. This not only makes attacks against 3-D Secure easier, but undermines other anti-phishing initiatives by contradicting previous advice," the report advised.

Customer confidence may be further undermined by the registration process, which is often completed during a shopping transaction and involves the user being asked for personal details such as date of birth.

"From the customer's perspective, an online shopping web site is asking for personal details. This further undermines customers' security usability and trust experience. And it is being exploited by criminals as phishing web sites impersonating the ADS form to ask for banking details," the report noted.

Some banks have also used the 3-D Secure system to shift liability for fraud losses unfairly onto the consumer, according to the report.

Murdoch and Anderson further warn that the system is likely to be undermined in time by man-in-the-middle attacks and the continuing growth in sophisticated malware, and that attention needs to be focused not on a single sign-on system such as this but on "transaction authentication".

"In the long term we need to move to a trustworthy payment device," the report concluded.

"This is not rocket science; rather than spending $10 [£6.15] per customer to issue chip authentication program calculators [like Barclays' PinSentry devices], banks should spend $20 [£12.30] to issue a similar device but with a USB interface and a trustworthy display."

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Do you agree?

Further reading

Online shopping

UK e-tailers losing £400,000 a year in fraud

Latest Cybersource fraud report finds merchants losing 1.8 per cent of online revenue

handcuffs

419 scammers go for underpants bomber

Beware of emails promising gifts

SentryBay boosts fraud prevention service

Partnership with Lucid Intelligence will add extra fraud monitoring capabilities for customers

Phishing app sneaks on to Android Market

Attack highlights risk of open app stores

Related white papers

Related jobs

Most watched

Nokia N8

Nokia N8 video demo

Handset maker gives an early look at its first Symbian^3 smartphone

Motorola Milestone 2

Motorola Milestone 2 video demo

Android 2.2 comes to Milestone line

Analysis and Reports

Best practices to secure and protect backup data
Exploding the myths about data security and backup encryption

Using data integration to drive down costs and increase profits
This paper outlines why data integration is an important weapon in an enterprise’s competitive arsenal

Poll

VMworld 2010 poll

VMworld 2010 poll

How advanced is your firm's cloud computing strategy?

View poll results

White paper library

Attachmate

Smartstream

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you thousands of white papers, case studies and analyst reports.

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Chip

GlobalFoundries maps out 28nm future

Company unveils first ARM A9 design and 90nm Flash plans

Jigsaw

Salesforce pieces together Jigsaw for CRM

New tool designed to manage and analyse contact information

Motorola Defy

Motorola Defy hands on video

Rugged Android-based smartphone

Apple iPod Nano

Apple overhauls iPod Shuffle, Nano and Touch

New models come with iTunes update and social networking tool

Primary Navigation