New For Your Wallet, Secure Credit Cards With Displays and a Button
May 3, 2007Two security firms have crafted a fully-functional credit card with a tiny monitor and button that will issue one-time passwords. But whether any banks will offer the expensive formfactor is another question.
The firms -- Verisign and Innovative Card Technologies (ICT) -- announced Tuesday that they are jointly trying to sell this concept to various credit-card (and debit card) issuers, with per-card prices ranging from $10 to $30, depending on volume purchased. That compares with a traditional card that costs less than a dollar and sometimes far less than a dollar. Verisign VP Fran Rosch guessed that major banks would likely pay "in the teens" for the new formfactor, given the volumes they would likely be using.
The concept of the card is powerful and timely, as retailers are desperately trying to improve POS security, especially for E-Commerce transactions. With thefts of credit-card identifying data growing rampant, the idea of an authentication code that in theory couldn't possibly be stolen from some retailer's database is quite compelling.
"Personally, I think this form factor makes tremendous sense," said Gartner security analyst Avivah Litan. "It's much more convenient for users and it can be used in multiple channels -- point-of-sale, ATM, voice and web. Most of the data stolen from breaches would be rendered useless unless the thief stole the actual card."
Litan said it looked quite likely that banks will end up supporting this approach. "I am fairly certain they'll get one or two top-ten banks to pilot it. And let's be real: considering all the charges consumers get on their credit card or debit card bills, the banks could easily slip in another $10 'security fee' if they believed in the solution. This would be a lot less offensive than their late fees and financing charges."
She also made the case that technology advances along with more standardization before such a rollout could be completed. "Work has to be done to upgrade the payment/ATM/VRU and Web systems to accept this form factor and one-time-passwords but those costs are less than the costs of security upgrades today," Litan said. "The banks need to spend more on the cards though so we haven't seen that much momentum from financial institutions and card issuers but it could help solve a lot of security problems out there in the market today."
But that's not necessarily going to happen. Even assuming the extreme lower-end of that price range, the price could easily be far too expensive for the typical large card issuer, said David Robertson, publisher of The Nilson Report , a well-respected research site tracking the payments space.
"The cost is way too high for mass market distribution in the U.S., even at $10," Robertson said. "There are cheaper fraud solutions for online purchases."
The typical card today costs 27 cents to make, compared with the $10-$30 range for the one-time-password-issuing version. Although an oft-quoted figure for credit card cost is $1/card, that includes 73 cents for the customization of the embossed name, the magstripe programming, packaging and distribution, among other things. All of those other charges would still have to happen with the higher-priced secure card, making the true comparison price 27 cents, Robertson said.
With more than 1.2 billion cards in the market today, this could only be "a niche card for people who are doing a lot of online purchasing," he said. But he doesn't see how one could make a business case for it.
"That's a lot of money of money to spend to push someone who might be a fence-sitter, who might be hesitant to make purchases online. The differential between 27 cents and $10 and you're going to take a reluctant customer and try and push them beyond their insecurity?" Robertson asked. "You're not going to find any major financial issuer in the United States adopting this kind of technology."
Given the fact that consumers have not pulled back from online purchasing even in the wake of TJX and other recent well-publicized large data breaches, Robertson can't see the ROI argument here. "Online sales are increasing and the good guys are able to stay one step ahead of the bad guys at this time," he said. "Fraud is part of the cost of doing business. It's a manageable cost at this time."
Even if the market changes enough to make the price acceptable, there are still technological hurdles that would have to be overcome. "Work has to be done to upgrade the payment/ATM/VRU and Web systems to accept this form factor and one-time-passwords but those costs are less than the costs of security upgrades today," Gartner's Litan said. "The banks need to spend more on the cards though so we haven't seen that much momentum from financial institutions and card issuers but it could help solve a lot of security problems out there in the market today."
Banks would theoretically have several payment options, including passing all of the charges along to the consumer, some of the charges to consumers or absorbing the whole cost and turning it into a marketing advantage for nervous consumers.
Verisign and ICT's statement said that would "integrate the security of a one-time password token into a card the size of a standard credit or debit card. At the push of a button on the back of the card, an integrated display shows a password that changes with every transaction. During an online transaction, this number is entered into a user interface with other information (such as the user's static PIN and login name) for multifactor authentication."
The credit-card formfactor is the most interesting part of the announcement, but the two companies are also trying to sell their one-time-password-issuing device in other formfactors, primarily pocket-sized standalone security devices. The one-time-password device being tested by EBay's PayPal is one such application from Verisign and ICT.
Verisign's Rosch said many banks are conservative and hesitant about new formfactors. "When they start changing, they're very cautious," which is why the pair are offering a standalone security device in addition to the credit card version.
When asked, Rosch said "we think we'll have 1.5 million out by the end of the year" but then clarified that "a relatively small percentage will be credit cards."
Copyright 2007 by Ziff Davis Media, Distributed by United Press International
-
Bogus training offer opens hacker doors to bank accounts
Feb 05, 2012 |
5 / 5 (5) |
3
-
'Saudi hacker' publishes Israeli credit card details
Jan 03, 2012 |
3.5 / 5 (2) |
0
-
'Anonymous' hackers target US security think tank
Dec 25, 2011 |
5 / 5 (11) |
96
-
Mobile money transfers gaining currency with consumers
Dec 15, 2011 |
not rated yet |
0
-
'Tis the season to be wary of elder financial abuse
Dec 14, 2011 |
not rated yet |
0
-
Engineers build first sub-10-nm carbon nanotube transistor
Feb 01, 2012 |
4.9 / 5 (31) |
30
-
Something old, something new: Evolution and the structural divergence of duplicate genes
Jan 31, 2012 |
4.6 / 5 (7) |
1
-
The hidden nanoworld of ice crystals: Revealing the dynamic behavior of quasi-liquid layers
Jan 30, 2012 |
5 / 5 (3) |
1
-
Stock market network reveals investor clustering
Jan 27, 2012 |
3.9 / 5 (23) |
8
-
Of microchemistry and molecules: Electronic microfluidic device synthesizes biocompatible probes
Jan 26, 2012 |
5 / 5 (1) |
0
-
Need help reading 3-D
5 hours ago
-
A way to send and receive wireless data
11 hours ago
-
Tabletop Cold Fusion Reactor
13 hours ago
-
Calling function with no input argument
Feb 10, 2012
-
Force free body diagram problem on gym equipment
Feb 10, 2012
-
Empirical data regarding shower heads and water
Feb 10, 2012
- More from Physics Forums - General Engineering
More news stories
Japan scientist makes 'Avatar' robot
A Japanese-developed robot that mimics the movements of its human controller is bringing the Hollywood blockbuster "Avatar" one step closer to reality.
Feb 10, 2012 |
5 / 5 (7) |
13
Intel packs performance and reliability into its latest SSD 520 series
Intel Corporation announced today its fastest, most robust client/consumer solid-state drive (SSD) to date, the Intel Solid-State Drive 520 Series (Intel SSD 520), a 6 gigabit-per-second (gbps) SATA III SSD ...
Feb 07, 2012 |
5 / 5 (1) |
4
Google rumored to have built Heads-Up-Display glasses prototype
(PhysOrg.com) -- 9to5Google is reporting that they have received a tip from someone they believe to be a reliable source saying that Google is working on a Heads-Up-Display (HUD) pair of eye-glasses. The per ...
New Kindle Touch is an impressive e-reader
When it comes to reading digital books, tablets are all the rage. But there's a lot to like about simple e-readers, which over the past year have become both a lot cheaper and a lot less clunky.
Electronics / Consumer & Gadgets
Feb 09, 2012 |
5 / 5 (4) |
1
Apple to debut 'iPad 3' in March: report
Apple will unveil a new version of its market-ruling iPad table computer in March, according to a report in Dow Jones-owned technology blog All Things D.
Electronics / Consumer & Gadgets
Feb 09, 2012 |
1.9 / 5 (21) |
0
Walney offshore wind farm is world's biggest (for now)
(PhysOrg.com) -- The Walney wind farm on the Irish Sea--characterized by high tides, waves and windy weather--officially opened this week. The farm is treated in the press as a very big deal as the Walney ...
GPS court ruling leaves US phone tracking unclear
A US Supreme Court decision requiring a warrant to place a GPS device on the car of a criminal suspect leaves unresolved the bigger issue of police tracking using mobile phones, legal experts say.
Europeans protest controversial Internet pact
Tens of thousands of people marched in protests in more than a dozen European cities Saturday against a controversial anti-online piracy pact that critics say could curtail Internet freedom.
Europe stakes billion-dollar bet on new rocket
A pencil-slim rocket is scheduled to lift into space from South America on Monday, carrying a billion-dollar bet that Europe can grab a juicy slice of the market to place satellites in low orbit.
Study finds that anti-diabetic medication can prevent the long-term effects of maternal obesity
In a study to be presented today at the Society for Maternal-Fetal Medicine's annual meeting, The Pregnancy Meeting, in Dallas, Texas, researchers will report findings that show that short therapy with the anti-diabetic medication ...
Netflix settlement trims 14 pct off 4Q earnings
(AP) -- Netflix pressed the rewind button on its fourth-quarter earnings after settling allegations that the video subscription service violated a consumer-privacy law.