Skip the navigation
)
News

Visa launches one-time passcode cards in Europe

By Jeremy Kirk
June 4, 2010 07:10 AM ET

IDG News Service - Visa has launched a payment card in Europe that contains a keypad and an eight-character display for showing a one-time passcode, an additional defense against potentially fraudulent Internet transactions.

Visa's CodeSure also acts as a chip-and-PIN (personal identification number) card, where people enter into a terminal a four-digit pin that is confirmed by a microchip within the card during a face-to-face or cash machine transaction.

Online transactions, however, are more susceptible to fraud as they do not use the PIN, often relying only on the details printed on the card. A hacker who has obtained details such as the card's number, expiration date and three-digit security code, may be able to make a purchase online.

Visa and MasterCard have been pushing online merchants to implement the more stringent 3D Secure (3DS) system, also known as Verified by Visa or MasterCard SecureCode. The system requires a person to enter a password or portions of a password in a browser frame displayed during a transaction in order to complete an on-line purchase.

But 3D Secure still uses a static password selected by a consumer and is vulnerable if someone mistakenly reveals their password through a phishing attack.

The alphanumeric display and a keypad on Visa's CodeSure card overcome that vulnerability. During an e-commerce transaction, the customer would press the "Verified by Visa" button on the card and enter their PIN. If the PIN is correct, the card will generate an electronic one-time passcode that can be entered into the Verified by Visa frame.

This one-time passcode is only valid for a very short period of time. If it were to be intercepted by a hacker, it would have to be used quickly before it expired.

The card also has other modes that can be used for other authentication purposes such as online banking, according to Visa. The bank would show a number, called a dynamic numerical challenge code, which the customer would enter onto the card's keypad. If that number is verified by the card, it confirms that the request is from the customer's bank. The customer would then enter their PIN on the card to generate a one-time passcode for the transaction. The process is known as mutual authentication. The same steps could be used during a phone transaction with a bank using a CodeSure card.

It also can be used to sign online banking transactions using elements such as an account reference number or transaction amount. Another mode can provide authentication for access to third-party services such as VPNs, frequent flyer programs or other online services. CodeSure cards have an estimated three-year battery life.

In the U.K., fraudulent card-not-present payments amounted to £266.4 million ($389 million) in 2009, down 19% from 2008, where the total reached £328.4 million. The decline was attributed to increased use of 3DS, according to the U.K. Cards Association and Financial Fraud Action U.K.

Send news tips and comments to jeremy_kirk@idg.com.

Reprinted with permission from IDG.net. Story copyright 2012 International Data Group. All rights reserved.
What is Tech Briefcase?
TechBriefcase is a new, free service where IT Professionals can Search, Store and Share IT white papers and content like this. Learn more
Bookmark content
Speed up your research efforts with content across the web.
Search and Store
Find the white papers you need. Create folders for any topic.
View Anywhere
Open your briefcase on your iPhone, tablet or desktop. Share with colleagues.
Don't have an account yet?
Additional Resources
Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Network Security White Papers
Obtaining Fortune 500 Security without Busting your Budget
Network Security and Compliance on a Budget Made Simple
Controlling the Cost of File Transfers
This solution brief explains why something as seemingly simple and straightforward as a file transfer task turns into such a costly operation. It...
Practice Management: Double Billing Rate and Improve Patient Services
Would you like to double your billing rate and achieve faster payment for services?

Download this customer success story to see how One Health...
Mission Critical Data Explosion and Customer Case Study
Would you like to double your tier 1 storage capacity while simultaneously reducing your storage footprint?

Download this customer success story to see how...
Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios
Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.
All Network Security White Papers
Network Security Webcasts
Distributed Database Security with Real-time Monitoring
View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with...
InfoSphere Warehouse Packs Demo
These flash modules make warehousing more tangible and relevant to business users through detailed explanations of the InfoSphere Warehouse Packs.
Delivery Management -- Extending Lifecycle Management
Date: Wednesday, June 20, 2012, 1:00 PM EDT

Siloed organizations continue doing the wrong things and doing things wrong, leading to increased costs,...
Leverage automation today to reduce IT complexity
Date: Tuesday, June 5, 2012, 2:00 PM EDT

Whether your B2B complexity is caused by multiple technologies due to M&A, business or application specific...
Redefine Expectations in the Data Center
Need to do more with less? Watch this video to learn how HP ProLiant Gen8 servers can help your business deploy servers three...
All Network Security Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs