Skip to main content

Why Apple Pay Is Our Best Hope To Stop Online Fraud


To make matters worse, the past year has been a perfect storm for online criminals, which will sharply escalate the rate of e-commerce fraud in the coming years. Hacks of T-Mobile/Experian, Ashley Madison, Chase, Anthem Blue Cross, OPM and many more released huge amounts of sensitive personal data like names, addresses, email addresses, phone numbers and social security numbers onto the dark web.
These PII (personally identifiable information) leaks were compounded by payment data leaks: millions of credit card numbers released in the Target and Home Depot hacks, plus other data raids. Together, fraudsters have more than enough material to paint a full picture of an individual’s financial identity, enabling them to apply for loans, lines of credits and other financial products, as well as order goods online, fraudulently, in someone else’s name.
With all these hacks, it makes sense that financial institutions are bolstering security. The EMV deadline is just that — now that the deadline has passed, brick-and-mortar retailers must have chip-enabled point-of-sale terminals, or be held liable for any fraudulent transactions that happen in their stores. The U.S. EMV liability shift is being hailed as a firewall against fraud; in reality, it’s nothing more than a half-measure taken by credit card companies and banks to protect themselves while leaving retailers holding the bag.
First, most point-of-sale terminals will require chip-and-signature, which is far less secure than chip-and-pin — a security shortcut chosen by the financial industry. And second, EMV will not fix the big growth area in fraud: the Internet. Past switches to EMV in countries like Australia and the U.K. show that fraud will simply migrate online as criminals look to exploit the next weakest target — sending a tidal wave of criminals straight toward unprepared online merchants.
When taken together, the situation for businesses looks bleak. To mitigate losses due to fraud over the long term, merchants and consumers alike need to move en masse to next-generation tokenized payment systems — which, like two-factor authentication to protect passwords, adds an extra barrier to the payment process, keeping sensitive data out of merchants’ fragile systems and safe from hackers.
And these payment systems haven’t been doing too well. Despite big promotion, use of Apple Payis very low — a recent survey from the Aite Group found that it accounts for just 1 percent of all U.S. retail transactions. That’s still far above Android Pay (the product formerly known as “Google Wallet,” and now on its umpteenth rebranding) and Samsung Pay, which only launched recently.
This begs the question: What will it take to bring Apple Pay (or a similarly secure solution) mainstream, and save online merchants and banks from huge losses due to fraud?

Comments

Popular posts from this blog

Five budget-friendly open source storage servers

Storage is essential for the enterprise: Data must be stored. Data must be retrieved. Data must be shared. Data must be secured. At the same time, storage must not consume the entirety of your IT budget. Fortunately, you can find effective solutions in the world of open source. Outside of cost effectiveness, one of the biggest benefits of these solutions is the ability to modify them to perfectly fit your needs. You can make minor changes or even roll your own storage solution based on one of these tools. If you want enterprise support and a "solution in a can" that will meet just about any enterprise storage need, you should turn to Red Hat or SUSE. Both Linux-based companies offer some of the most powerful enterprise-ready tools on the market. But if you'd rather get your hands dirty and craft something of your own—something that won't demolish your budget—these five open source tools are a great place to start. 1: ownCloud ownCloud ( Figure ...

Facebook Now Supports PGP To Send You Encrypted Emails

You can now instruct Facebook to encrypt every email it sends to you so nobody — not even the NSA — is likely to be able to read your messages anytime soon. All you have to do is import your public PGP key into your Facebook settings and you’re good to go. The problem here, of course, is that most people have no idea how public/private key email encryption works and how to even get started with it. In the wake of Edward Snowden’s leaks, a number of organizations, including Google, promised to completely hide the complexities of end-to-end email encryption from regular users. Very few of these products have materialized so far, however — not for lack of trying, but because this is actually a very complex problem, both from a technical and user experience perspective. Facebook uses the well-established PGP scheme (the GNU Privacy Guard implementation of  OpenPGP, to be precise) to encrypt messages and tools lik...

Visa confirms Coinbase wasn’t at fault for overcharging users

Yesterday, we wrote that Coinbase customers were being charged multiple times for past transactions. While some speculated that the erroneous withdraws were down to a Coinbase engineering issue, Coinbase issued a statement saying it wasn’t liable for the duplicate charges. The blame, instead, rested with Visa for the way it handled a migration of merchant categories for cryptocurrencies, Coinbase said. While you can read my post yesterday for an in-depth description of what happened, the basic gist is that Visa refunded and recharged (under a different merchant category) a month of old transactions. Many users saw the recharge come through before the refund processed, making it look like they were double charged. Honestly, the issue was likely exacerbated by existing payment rails — it’s normal for refunds to take multiple days to show up on credit and debit statements. But here’s where it gets weird — this morning Visa issued a statement to some publications shifting the blam...

Microsoft allays privacy concerns of Windows 10 users

Microsoft attempts to put all rumours related to Windows 10 privacy concern to rest GettyImages Allaying concerns of Windows 10 users over privacy, Microsoft has said information is collected only to offer a better OS experience. Besides, it provides users the ability to have control over the information collected. Microsoft asserts that Windows 10 is based on these two major principles. Besides, the data collected from every system is encrypted to the company's servers and remains in secure facilities. The company says information such as device ID, device type and application crash data is collected in order to help the user obtain an even more secure OS experience. Microsoft clarifies that the data does not include the user's personal files or content. Another reason that Microsoft collects data is to offer a better personalised windows experience. This includes updates on game scores, app recommendations and the common words one types in messaging. If users are ...