S'pore looking to improve online security

 

Summary

Monetary Authority of Singapore exploring new guidelines to enhance security for online transactions and credit card payments, says Visa exec.

Events

IBM Technology Conference & Expo 2012
May 23, 2012

Convention Centre B2 Room at 22nd Floor, Centara Grand @ Central World, 999/99 Rama I Road, Pathumwan, Bangkok 10330

Echelon 2012
June 11 and 12, 2012

University Cultural Centre, National University of Singapore

Startup Asia Jakarta 2012
June 7 and 8, 2012

12th Floor, Annex Building, Wisma Nusantara Complex, Jl. M.H. Thamrin No. 59 Jakarta 10350, Indonesia

MMA Forum Singapore
April 23-25, 2012

Grand Hyatt Singapore

SINGAPORE--The Monetary Authority of Singapore (MAS) is exploring ways to enhance security for online purchases, according to an industry player, who adds that dynamic authentication will be a good step toward that direction.

Ingo Noka, Visa's Asia-Pacific head of data security and enterprise risk management, explained that dynamic authentication uses passwords that are generated every 10 seconds. This helps ensure passwords, even when stolen, will no longer be valid for use in online transactions after a time limit, Noka said in an interview with ZDNet Asia.

These passwords can be generated by a token or sent via SMS to the consumer, he added. The payment structure is similar to Internet banking transactions in Singapore, where local banks support dynamic passwords as part of the two-factor authentication process.

He said Visa is prepared to support this implementation, having spent efforts building an infrastructure it calls 3-D Secure (three domain secure), also known as Verified by Visa. Noka explained that this system will enable card-issuing banks to implement their own dynamic authentication without affecting the merchant's bank authorization process.

For the merchant, supporting the infrastructure would involve installing a plugin, he said. According to Visa, the plugin facilitates the delivery of authentication requests to an access control server, which then carries out the authentication policy as defined by the issuer bank.

Chipping at card security
The MAS is also exploring ways to beef up security for credit card payments and is closely looking at moving Singapore to chip-based cards, Noka said, adding that these offer better security than magnetic strips as data on chips is more difficult to clone.

He acknowledged that the deployment of chip cards have been touted for several years, but noted that it takes time for the necessary infrastructure to be rolled out, locally and globally, so payments can be supported regardless of where the consumers use the cards.

Asked what components are essential to safeguard against credit card fraud, he replied that it would take a combination of dynamic authentication for online transactions, chip cards to combat offline fraud and the deployment of Payment Card Industry (PCI) Data Security Standard (DSS).

Governed by the PCI Security Standards Council, the PCI DSS comprises a set of guidelines aimed at enhancing data security, combating fraud and eliminating security vulnerabilities for payments made by credit and debit cards.

Noka added that merchants also play an important role in keeping credit card payments secured. "There is no point in giving customers a chip card when no merchants are installing the terminals [to support such payments]," he said.

He noted that credit card fraud related to lost or stolen cards is currently "kept very well under control" via various security policies, including what Visa calls advanced authorization. This system checks a transaction against a set of parameters, gives a score to indicate the risk of the transaction and sends that data to the card issuer.

"The issuer can take this into account. They might let that one transaction go through depending on the amount, for example, or they can call the cardholder immediately to ensure it is a legal transaction. If the cardholder says, 'That's not me', the issuer can block every subsequent transaction," said Noka.

Asked if hand-written signatures should be replaced as a form of authorization for credit card payments, Noka said some customers remain "psychologically" attached to the signature. "They want to have the feeling [of assurance] that the transaction will only be charged to their card after they have signed on it," he said, adding that as such, signatures will likely remain a component of the authorization process.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

ZDNet Asia Live

Sudden departure of Pacnet CEO, no explanation - ZDNet Asia: Sudden departure of Pacnet CEO, no explanationZDNet... http://t.co/UVG3OKCG

@ChemarieMonica : Malaysia organizations don't realize severity of cyberattacks - ZDN... http://t.co/iO8wdbz8 http://t.co/1QrdIsaV #tech

Malaysia organizations don't realize severity of cyberattacks. http://t.co/QK7PKdaP

RT @daryllau: Malaysia offers some manufacturing benefits over China http://t.co/mH23Uumr

Malaysia organizations don't realize severity of cyberattacks - ZDNet Asia http://t.co/HniF8J72 #news

#InfoSec Malaysia organizations don't realize severity of cyberattacks - ZDNet Asia http://t.co/vFzACdwm #CyberSecurity

http://t.co/bTDnDh7J Malaysia organizations don't realize severity of cyberattacks - ZDNet Asi... http://t.co/CzsMF2zn #infosec #security

Malaysia organizations don't realize severity of cyberattacks - ZDNet Asia: Malaysia organizat... http://t.co/iUpDhbeU #cloud #fail #TCN

Pacnet CEO departs; acquisition rumors gain steam. http://t.co/Nu2Mdcj0

Malaysia organizations don't realize severity of cyberattacks http://t.co/zeaxHbYa http://t.co/erFSwAUB #arcavir

http://t.co/VNaUVSe1 Malaysia organizations don't realize severity of cyberattacks: Cyberatt... http://t.co/TA5zWvUI http://t.co/wiqTBKkj

Malaysia organizations don't realize severity of cyberattacks - ZDNet Asia: Malaysia organizations don't realize... http://t.co/x1BJ0qSK

Malaysia organizations don't realize severity of cyberattacks - ZDNet Asia: Malaysia organizations don't realize... http://t.co/3Yaa40JE

Malaysia organizations don't realize severity of cyberattacks, country's minister of sci, tech, innovation says http://t.co/KGEHLi18 #in

Malaysia offers some manufacturing benefits over China http://t.co/mH23Uumr

So much as we know , MTK6575 extremely integrated frequency1GHz ARM Cortex-A9 processor, the superiority of 3G / HSPA Modem, and help the...

1 day ago by y15822137359 on 5 SaaS adoption speed bumps to avoid

I reckon your view: "CRM is strategy, not software", if a company replicating the approach uses in ERP implementation into CRM, what they...

2 days ago by wykoong on Gartner: Mobile CRM gives better ROI than social

This video will teach you about the Excel fill handle but also provide you with a workook to download... http://www.youtube.com/watch?v=...

2 days ago by TradeBrother on A quick fill handle trick for Microsoft Excel

waiting...

4 days ago by eapete on What should count in a company's market value?

Boy, you've opened a can of worms now.

Wait for the rants & raves.

4 days ago by eapete on What should count in a company's market value?

I was puzzling before this whether to replicate the success formula we executed for a financial institute, and come out with a standard s...

5 days ago by wykoong on Drop the egos, copy ideas, then innovate