Showing posts with label Identity management. Show all posts
Showing posts with label Identity management. Show all posts

Tuesday, November 27, 2007

Thwarting fraudsters

I have purposely avoided writing anything about the HM Revenue & Customs'(HMRC) data breach of millions of UK consumers personal and banking details, but I felt compelled to say something when I started seeing information security vendors leaping on the bandwagon.

While it may be true to say that "fraud is already firmly on the banking industry agenda," when information security vendors say that consumers should not lose sleep over the HM Revenue & Customs' debacle because banks have risk management systems in place, it does not really provide me with much comfort.

The fact remains that despite these systems, fraud and identity theft still occur on an ever increasing scale, and it is arguable whether banks' systems are adequate. Even if thieves cannot access a person's bank account directly, they could still use their name and address details to apply for a credit card or other forms of financing.

What is the most alarming thing about the HM Revenue & Customs data leak is that it reflects well entrenched practices within government departments of posting customer data on unencrypted CDs.

It strikes me as rather odd that on the one hand you have a government wanting ISP providers and banks to take more responsibility for protecting consumers' identity and personal details, but yet government departments which hold reams of information on millions of people, are not subject to the same levels of scrutiny or compliance.

According to Jeremy Smith, managing director of Jardine Lloyd Thompson’s Financial & Professional Risks division, the HMRC incident has prompted security experts to renew their request for the current law to be urgently reviewed for, unlike our American counterparts, the Data Protection Act does not currently compel companies to notify those affected by the loss of data.

Smith points to the almost £1 million fine levied by the FSA on the Nationwide Building Society for a laptop theft from an employee’s house. Yet, no such fines will be levied on government departments which do not face the same regulatory scrutiny as banks. Arguably however, as the government steps up its "Big Brother" campaign to collate as much information as possible on individuals, one has to seriously question the lack of government department accountability.

On the technology side, there has been so much focus on authenticating a customer's identity at the point of sale using chip or pin, but very little focus on securing the storage and transmission of customer data between government departments and banks that share this data and training employees to abide by the strictest codes when it comes to managing that data.

At this point, information security experts are going to proffer some kind of comment about the latest and greatest solutions that can help banks identify fraud before it occurs. One such comment in the wake of the HM Revenue & Customs' debacle was:

"By understanding customer behaviour across multiple payment channels in real time, banks will be able to identify irregular account activity that could potentially thwart fraudsters before they have even committed a crime.”


Sounds great in theory, but show me a bank that has the systems and business processes in place that they can accurately monitor and understand customer behaviour across multiple channels and product silos in real time. Even if such a bank exists I don't think they would be game to put their hand up for fear that they will be proven wrong.

The banking industry and government cannot afford to rest its laurels on the fact that banks have implemented a nice piece of software kit with bells and whistles, which is going to make everything alright. With banks, government departments and web sites collating unprecedented levels of personal information on consumers, is it any wonder that identity theft is on the rise. And no amount of banking software is going to change that.

Wednesday, August 15, 2007

Politicians up the ante about online fraud

UK politicians it seems are getting all hot and bothered about online fraud, particularly in the banking sector, with the release this week of a UK parliamentary report entitled, "Personal Internet Security", which describes the internet as a “playground for criminals”.

No new revelations there, then. The internet has been used by criminals pretty much since its inception, so why are the politicians suddenly getting hot under the collar about it? Well it seems that the report's authors, the House of Lords Science and Technology Committee, has gone and given themselves a major dose of the 'spooks' by compiling damning statistics and evidence that suggest online fraud is an epidemic.

Not only is online fraud being perpetrated by organized crime gangs (nothing new there either) instead of the teenage-hacker-in-his-bedroom with nothing better to do, the report states, but they have also succeeded in remaining largely "invisible".

The report reels off a damning array of statistics including VeriSign's predictions that the level of “bad traffic” (Denial of Service attacks, email spam, phishing) was peaking at 170 times the basic level of Internet traffic; by 2010 it is predicted to be 500 times the basic level.

The report highlighted the vulnerability of online banking to fraudulent activity, citing figures published by the UK bank payments association, APACS, which recorded more than 1,500 “unique” phishing attacks directed at UK banks in September 2006, up from just 18 in January 2005. US banks are the most targeted by phishing, with their losses totalling approximately $2 billion.

The UK parliamentary report recommends the establishment of a framework for collecting and classifying data on e-crime, and “more rigorous and co-ordinated analysis” of the incidence and costs of such crime. It also talked about deployment of security software at ISP level (not that old chestnut), the need for a dedicated regulator for the online world (Hmmm!) and for Government to increase banks' fraud liability.

It did not take long for the security software industry to leap on the parliamentary band wagon, coming out and touting the latest and greatest authentication technologies including two factor authentication (which uses two different methods for authenticating someone's identity), and the most amazing suggestion I have heard so far, a "pattern-based" approach based on peoples' ability to remember patterns to offer a more secure, yet more simple (surely not?) means of authentication, other than the much maligned Chip and PIN.

No one is disputing the need for stronger more robust means of authenticating someone's identity. However, some of the newer technologies being touted are expensive to deploy and complex to implement. Furthermore, a lot of these technologies only provide authentication up to a point. With pin and password for example, it may authenticate a user to an online site or banking application, but it does not provide an iron-clad guarantee that person is who they say they are.

What is even more alarming is that multinational corporations sending high volume payments via their banking partners, have desk drawers full of security tokens and fobs which only provide authentication at the corporate level, but do not identify the individual sending a payment and whether they are authorized to do so.



It seems the banks have been caught napping and have been too busy trying to push their proprietary identity management and information security technologies on customers in an effort to lock them in.

Well no one wants to be locked in, they want to be able to bank online or send payments electronically without the risk of someone intervening in that transaction and altering payment details for fraudulent purposes.

What is even more surprising is that banks have been sitting on a solution for the last eight years. It is called IdenTrust, which uses PKI encrypted digital certificates to verify someone is who they say they are.

The advantage of IdenTrust is that the banks behind it have already invested $170 million in ensuring IdenTrust digital certificates are binding in more than 175 countries and interoperable cross-border between banks.

So with a solution to stronger means of authentication staring them in the face and the chance to deliver a single identity management solution instead of a multitude of different ones, why on earth does the industry continue to perpetuate their own proprietary versions of digital certificates and other security technologies that do not actually vouch for someone's identity?

Mind you if we have entrusted banks with our money, can we entrust them with our identities? The argument in banks favour is that they already hold a lot of theinformation necessary to authenticate someone is who they say they are, although admittedly some of this documentation may be fraudulent.

The security software services industry also has to ask itself does it want to continue to perpetuate solutions that sound like a prop from a James Bond film but are difficult and expensive to implement for widespread use.

Wednesday, August 08, 2007

IdenTrust adoption at inflection point

A couple of years ago in financial-i magazine we did an article aptly titled,'Whatever Happened To', which alluded to the spate of bank-led initiatives, Identrus (now IdenTrust), Bolero, SWIFT's ePaymentsPlus, CFOWeb.com, that emerged at the height of the dot.com boom only to find that user adoption was not forthcoming.

Some of these solutions, particularly CFOWeb.com and ePaymentsPlus have since gone to the technological graveyard in the sky, and even those that have survived have had to re-invent themselves to establish a more compelling business case for user adoption.

One of those companies of course is IdenTrust, which with a new name, a new focus and a new CEO,Karen Wendel, formerly of Gemini Consulting, has gone from being a bank-centric organisation to one that is now focused on helping banks deliver more robust identity management solutions to their corporate customers.

Formed in 1999 by leading global cash management banks such as Citi, Bank of America and Deutsche, IdenTrust (then known as Identrus) positioned banks as trusted third parties in B2B e-commerce by establishing policies, rules and guidelines for banks to issue PKI-encrypted digital certificates for authenticating an individual's identity.

IdenTrust's founding bank's invested $170 million in developing a policies, legal framework, trusted operations and technology (P.L.O.T.) to create a comprehensive environment for issuing trusted identities based on customer agreements which are enforceable in more than 175 countries.

IdenTrust is the only bank-developed identity authentication platform and unlike other digital ID solutions, it emphasizes the interoperability of its digital certificates and their ability to function cross-border. However, since its formation in 1999 it has suffered from an image problem. Wendel says at the time of its inception, PKI was largely driven by 'techies' more focused on encryption than business applications of PKI.

Early implementations of PKI were also costly and cumbersome to implement, and by the onset of the millennium it had been superseded by cheaper means of authentication such as pin and password. But as the incidence of identity fraud has increased in recent years, with attacks becoming more sophisticated, Wendel says PKI and IdenTrust are back in favour.

According to Wendel, IdenTrust's digital certificate volume is doubling every year and instead of having to spend $7 million to $10 million just to get started, banks can deploy PKI digital certificates for less than $500,000.

But the real inflection point when it comes to adoption of IdenTrust's identity credentials has to be pressure from major multinationals such as Shell and Merck, weighed down with hundreds of different security tokens and signature cards for logging onto proprietary banking applications.

These companies are asking banks to implement a single ID management solution that is interoperable across multiple banks. As part of a multi-year overhaul of its treasury management operations, Merck is implementing an innovative identity management solution using IdenTrust digital ID credentials and the concept of an "e-vault," to provide an extra layer of security.

Wendel says Shell will also be one of the first corporates to implement a bank account mandate application which has IdenTrust credentials embedded in it. The challenge now for IdenTrust is to encourage banks and software vendors to develop more applications with its digital credentials embedded in it and to get banks to abandon their proprietary PKI technologies.

As more and more corporates communicate with their banking providers via SWIFT, IdenTrust believes it also well positioned to provide authentication at the individual level for bulk payment transfers via the SWIFT network. Currently SWIFT’s PKI security protocol only provides authentication at the corporate level, so the bank knows for example, that Company A is sending a payment file, but not the individual within that company that has authorized the payment.