Feeds

Visa trials RF credit cards

Security implications unclear

  • alert
  • submit to reddit

Providing a secure and efficient Helpdesk

Consumers in Malaysia will soon be able to pay for their shopping with contactless, EMV standard smart cards, as Visa does away with the need for a signature with the launch of its new system, Visa Wave.

The company is running a four-month trial with 2000 Visa customers and over 150 merchants. The idea behind it (apart from selling lots of card readers) is to speed up the payment process. This, Visa hopes, will encourage people to use their cards more often in place of cash. Cardholders just need to wave their card near (within 4cm) the reader and the transaction goes through.

The move contrasts sharply with the added layers of secure authentication in Europe and the UK. To pay in person in Europe, and soon in the UK, we have chip-and-PIN-and-signture, while Asia Pacific does away with the authentication step altogether.

The implications for security and fraud are not altogether clear, particularly with respect to skimming the card details, and the possibility of card cloning. These are the issues that chip and PIN is being introduced to tackle: a cloned card is useless if it is not accompanied by the correct PIN.

The Visa Wave system seems similar, in terms of risk, to using your card in a ticket machine at the train station, for example. In this case, you insert your card, the details are read and the cost of the ticket is debited from your account without any further authentication.

However, what is not clear from the announcement is the interaction between the card and the reader. The important question is whether it would be possible to skim card details without a person's knowledge, for example, by scanning handbags and pockets with a duplicate reader on a busy train.

One would hope that a company like Visa would make sure that the data on the card is properly encrypted, but so far we have not been able to confirm those details with them. ®

Related stories

UK credit card fraud down 8%
Boffins test voice-activated secure credit card
Brits are crap at password security
Open and helpful community - of credit card thieves
Chip and PIN: not enough to beat card fraud

Choosing a cloud hosting partner with confidence

More from The Register

next story
SMASH the Bash bug! Apple and Red Hat scramble for patch batches
'Applying multiple security updates is extremely difficult'
Apple's new iPhone 6 vulnerable to last year's TouchID fingerprint hack
But unsophisticated thieves need not attempt this trick
Hackers thrash Bash Shellshock bug: World races to cover hole
Update your gear now to avoid early attacks hitting the web
Oracle SHELLSHOCKER - data titan lists unpatchables
Database kingpin lists 32 products that can't be patched (yet) as GNU fixes second vuln
Who.is does the Harlem Shake
Blame it on LOLing XSS terroristas
Researchers tell black hats: 'YOU'RE SOOO PREDICTABLE'
Want to register that domain? We're way ahead of you.
Stunned by Shellshock Bash bug? Patch all you can – or be punished
UK data watchdog rolls up its sleeves, polishes truncheon
Ello? ello? ello?: Facebook challenger in DDoS KNOCKOUT
Gets back up again after half an hour though
prev story

Whitepapers

A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.