Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

December 2nd, 2011, 16:08 GMT · By Eduard Kovacs

‘Verified by Visa’ Presents Major Security Flaw

SHARE:

Adjust text size:


Verified by Visa doesn't mean it's completely secure
Enlarge picture
Trend Micro researchers discovered that the technology behind the Verified by Visa trademark is much more unsecure than anyone would believe and not a coding error is to blame, instead it’s a design flaw that could be taken advantage of by cyber and non-cyber criminals.

The 3 Domain Secure (3DS) security protocol introduced by Visa in 2001 was developed to prevent credit card fraud and while its purpose is highly noble, in practice it’s not so efficient.

The way the protocol works is pretty simple. When we make an online transaction that’s protected by Visa, we are redirected to a verification page that requires confirmation of some details and a password. Since the merchant doesn’t come in contact with our details at any point in the process, theoretically, the transaction should be secure.

In theory it sounds good, but the problem emerges due to the password reset feature that’s offered by Visa.

When the customer accesses the reset password function, he is presented with a form that requires some details of the cardholder to prevent fraud, but the problem is that all the data can be found on the physical credit card.

Signature panel code, expiry date, cardholder name and birth date is requested from the customer in order to complete the reset process. All the details except for the birth date are printed on the card, but also, these are the details first obtained by any cybercriminal in operations that target credit cards.

Researchers propose that this verification method should be at least updated to encapsulate a secret question, a one-time password reset URL should be sent to the user’s email, and the entire procedure should result in a notification

Worryingly, the 3DS security protocol is not only used by Visa. Websites that display MasterCard Secure Code, J/Secure (JCB International) and SafeKey (American Express) basically implement the same technology.

Also, this reminds me of what a hacker from Operation Robin Hood said yesterday about knowing foreigners who can bypass the Verified by Visa certification for a mere $5 (3.5 EUR).

TELL US WHAT YOU THINK:

2,420 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Hospitality and Educational Institutions Attacked with Credit-Card-Stealing Trojan

PayPal Email Address Modification Alerts Hide Phishing

Tanki Online Enhances Payment Security with Gate2Shop

2,000 Nike and Ugg Selling Sites Taken Down by Metropolitan Police

Skype TopUp Payment Leads to PayPal Phishing

READER COMMENTS:


Comment #1 by: eric on 02 Dec 2011, 21:29 UTC reply to this comment

Incorrect. If you lose your card, you report it lost and if you were smart your provider provides fraud protection/recovery. The idea is that only the person with the card can make the purchase which is insured by the trademark. What a joke of an article.

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM