Skip the navigation
)
News

As smartcards loom, magnetic cards made safer

Smartcards may be the future, but legacy payment cards still need support

May 24, 2010 06:00 AM ET

Computerworld - As news of Wal-Mart Stores Inc.'s plan to convert its U.S. payment terminals to smartcard-compatible systems surfaced, there was also news of efforts to make existing magnetic stripe cards more secure.

One effort that appears to have made considerable progress involves a card authentication technology that uses information from the magnetic stripe on the back of each card to create a unique digital fingerprint of the card.

Each time the card is used, information from its magnetic stripe is matched with its fingerprint. The technology is designed to use data about stolen cards to detect and stop the use of counterfeit cards at the payment terminal.

A major U.S. retailer will be announcing its support for the technology within the next one month or so, said Tom Patterson, chief security officer at MagTek Inc., a Seal Beach, Calif.-based vendor of card readers, check scanners, PIN pads and other electronic payment and identification products.

Patterson said the unnamed retailer is equipping about 30,000 of its outlets with payment terminals featuring a MagTek technology that captures specific magnetic stripe information and compares it to a baseline "fingerprint," stored by the card issuer, for that card. Fifth Third Bank piloted similar technology with Visa last year.

In the Fifth Third pilot, called Digital ID, the bank installed upgraded payment readers at several merchant locations and tested the fingerprinting method.

The fingerprint approach offers a viable and relatively low-cost means of securing magnetic stripe card transactions, Patterson said. "We view this as a risk-management tool that can be used by merchants" to mitigate the threat of fraud, he said.

"We are not against smartcards. We know they are being used around the world," Patterson said.

But technologies such as magnetic stripe fingerprinting systems give merchants a way to continue supporting existing cards in a more secure manner for several years, he said. "The mag stripe is going to be a legacy for more than a decade at least" and possibly considerably longer, said Patterson.

He said that several other companies have expressed interest in the fingerprint technology.

Other initiatives are testing other ways of making magnetic stripe card transactions more secure.

For example, retailer OfficeMax Inc. last year tested a challenge-response security system at point-of-sale terminals in several hundred of its stores.

Another approach that is being tested is card tokenization technology, which takes the information in the magnetic strip on the back of a card and replaces it with randomly generated numbers, or tokens, before transmitting it for authorization.

Such efforts come even as card issuers and the major credit card companies are coming under slowly mounting pressure to move to chip-and-PIN technologies. Chip-and-PIN systems use smartcards that store cardholder data on embedded microprocessors (or chips) rather than magnetic stripes. To complete a transaction with such cards, cardholders usually have to enter personal identification numbers (or PINs). Smartcards equipped with chips are thought to be significantly safer than magnetic stripe cards, and payment systems that use them have been adopted widely around the world.

The U.S. has been one of the few holdouts in the migration to chip-and-PIN systems, largely because of concerns about the cost of moving to the technology.

This week, Wal-Mart disclosed plans to make all payment terminals in its domestic stores chip-and-PIN-capable. And the United Nations Federal Credit Union (UNFCU) announced this week that it will soon be issuing smart credit cards.

A number of other retailers and card issuers are said to be exploring the technology, but few have gone public about the plans yet.

"The issue for U.S. retailers is where they should be investing their money," said Avivah Litan, an analyst at Gartner Inc.

Because of recent changes to the credit card industry's Payment Card Industry (PCI) data security standards, many retailers will soon need to upgrade to new payment terminals that are capable of supporting encryption, she said.

The question retailers will need to deal with is whether they should upgrade to new chip-and-PIN-compatible systems or to systems that are designed to make magnetic stripe transactions safer, she said.

"They don't want to invest their money twice," said Litan. "Chip-and-PIN is where the rest of the world is. It is not perfect, but it's stronger than shoring up magnetic stripe."

Jaikumar Vijayan covers data security and privacy issues, financial services security and e-voting for Computerworld. Follow Jaikumar on Twitter at Twitter @jaivijayan, or subscribe to Jaikumar's RSS feed Vijayan RSS. His e-mail address is jvijayan@computerworld.com.

Read more about Security Hardware and Software in Computerworld's Security Hardware and Software Topic Center.



What is Tech Briefcase?
TechBriefcase is a new, free service where IT Professionals can Search, Store and Share IT white papers and content like this. Learn more
Bookmark content
Speed up your research efforts with content across the web.
Search and Store
Find the white papers you need. Create folders for any topic.
View Anywhere
Open your briefcase on your iPhone, tablet or desktop. Share with colleagues.
Don't have an account yet?
Additional Resources
Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Security Hardware and Software White Papers
Database Activity Monitoring Is Evolving
Read the analyst report and learn how you can leverage the core capabilities of a DAP solution for better database security.
Practice Management: Double Billing Rate and Improve Patient Services
Would you like to double your billing rate and achieve faster payment for services?

Download this customer success story to see how One Health...
Mission Critical Data Explosion and Customer Case Study
Would you like to double your tier 1 storage capacity while simultaneously reducing your storage footprint?

Download this customer success story to see how...
Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios
Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.
Establishing a Strategy for Database Security is No Longer Optional
The options for securing increasingly valuable databases are very broad and deep, and can be confusing. This research provides an overview of three...
All Security Hardware and Software White Papers
Security Hardware and Software Webcasts
Close a Dangerous Vulnerability: Automated Methods for Managing Admin Rights
In this exclusive webcast from Viewfinity, you'll hear how to leverage Group Policy Object settings to close this vulnerability by elevating privileges for...
Case Study: Kimberly-Clark Implements Workday for Global Human Resources
See how Kimberly-Clark evaluated and deployed SaaS when it upgraded its human capital management system, gaining software security and peace of mind across...
Distributed Database Security with Real-time Monitoring
View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with...
InfoSphere Warehouse Packs Demo
These flash modules make warehousing more tangible and relevant to business users through detailed explanations of the InfoSphere Warehouse Packs.
Delivery Management -- Extending Lifecycle Management
Date: Wednesday, June 20, 2012, 1:00 PM EDT

Siloed organizations continue doing the wrong things and doing things wrong, leading to increased costs,...
All Security Hardware and Software Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs