Visa launches one-time passcode cards in Europe
IDG News Service - Visa has launched a payment card in Europe that contains a keypad and an eight-character display for showing a one-time passcode, an additional defense against potentially fraudulent Internet transactions.
Visa's CodeSure also acts as a chip-and-PIN (personal identification number) card, where people enter into a terminal a four-digit pin that is confirmed by a microchip within the card during a face-to-face or cash machine transaction.
Online transactions, however, are more susceptible to fraud as they do not use the PIN, often relying only on the details printed on the card. A hacker who has obtained details such as the card's number, expiration date and three-digit security code, may be able to make a purchase online.
Visa and MasterCard have been pushing online merchants to implement the more stringent 3D Secure (3DS) system, also known as Verified by Visa or MasterCard SecureCode. The system requires a person to enter a password or portions of a password in a browser frame displayed during a transaction in order to complete an on-line purchase.
But 3D Secure still uses a static password selected by a consumer and is vulnerable if someone mistakenly reveals their password through a phishing attack.
The alphanumeric display and a keypad on Visa's CodeSure card overcome that vulnerability. During an e-commerce transaction, the customer would press the "Verified by Visa" button on the card and enter their PIN. If the PIN is correct, the card will generate an electronic one-time passcode that can be entered into the Verified by Visa frame.
This one-time passcode is only valid for a very short period of time. If it were to be intercepted by a hacker, it would have to be used quickly before it expired.
The card also has other modes that can be used for other authentication purposes such as online banking, according to Visa. The bank would show a number, called a dynamic numerical challenge code, which the customer would enter onto the card's keypad. If that number is verified by the card, it confirms that the request is from the customer's bank. The customer would then enter their PIN on the card to generate a one-time passcode for the transaction. The process is known as mutual authentication. The same steps could be used during a phone transaction with a bank using a CodeSure card.
It also can be used to sign online banking transactions using elements such as an account reference number or transaction amount. Another mode can provide authentication for access to third-party services such as VPNs, frequent flyer programs or other online services. CodeSure cards have an estimated three-year battery life.
In the U.K., fraudulent card-not-present payments amounted to £266.4 million ($389 million) in 2009, down 19% from 2008, where the total reached £328.4 million. The decline was attributed to increased use of 3DS, according to the U.K. Cards Association and Financial Fraud Action U.K.
Send news tips and comments to jeremy_kirk@idg.com.


- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Obtaining Fortune 500 Security without Busting your Budget
- Network Security and Compliance on a Budget Made Simple
- Controlling the Cost of File Transfers
- This solution brief explains why something as seemingly simple and straightforward as a file transfer task turns into such a costly operation. It...
- Practice Management: Double Billing Rate and Improve Patient Services
- Would you like to double your billing rate and achieve faster payment for services?
Download this customer success story to see how One Health... - Mission Critical Data Explosion and Customer Case Study
- Would you like to double your tier 1 storage capacity while simultaneously reducing your storage footprint?
Download this customer success story to see how... - Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios
- Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats. All Network Security White Papers
- Distributed Database Security with Real-time Monitoring
- View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with...
- InfoSphere Warehouse Packs Demo
- These flash modules make warehousing more tangible and relevant to business users through detailed explanations of the InfoSphere Warehouse Packs.
- Delivery Management -- Extending Lifecycle Management
- Date: Wednesday, June 20, 2012, 1:00 PM EDT
Siloed organizations continue doing the wrong things and doing things wrong, leading to increased costs,... - Leverage automation today to reduce IT complexity
- Date: Tuesday, June 5, 2012, 2:00 PM EDT
Whether your B2B complexity is caused by multiple technologies due to M&A, business or application specific... - Redefine Expectations in the Data Center
- Need to do more with less? Watch this video to learn how HP ProLiant Gen8 servers can help your business deploy servers three... All Network Security Webcasts