Showing posts with label PIN. Show all posts
Showing posts with label PIN. Show all posts

Wednesday, 24 June 2015

How to fight Credit card fraud?

Regulatory policy wonks in India are engaged in intense combat — this time, over whether the Reserve Bank of India (RBI) has gone overboard with seeking to secure online and offline credit card payments. The RBI has made it mandatory to validate offline credit card payments in India with a 'PIN' (personal identification number) and online Indian payments with an 'OTP' (one-time password) to be generated by SMS on the mobile phone.
Thanks to these measures, India has one of the most secure credit card and online payment systems in the world. Some have attacked the security measures as being retrograde. The main charge is that the two-stage validation process wastes time. The argument is that the benefits gained from the security measure do not out-weigh the cost of the additional time spent. Moreover, since the RBI does not regulate foreign payment gateways, it has exempted them from the security requirement — so, payments made even from India, through foreign payment gateways, do not have to comply with this security measure.
What this means for the consumer is that purchase of a book on Amazon.com would not require an OTP while purchase of the same book on Amazon.in would require it. Both sites enable storing your credit card information (if you are willing to trust their servers with your data). On Amazon.in, you need to enter your CVV/CSC number ("card verification value" or "card security code") — a number physically pre-printed on your card. Once your transaction is authenticated, you also have to get your OTP by sending a text message to your credit card issuer. An OTP gets sent to your phone within seconds of the SMS request and is valid for a single use, to be made within 30 minutes.

On Amazon.com, since the security feature is not mandatory, if your credit card data is stored on its server, you can complete your purchase with a single click (popularly branded as "1-Click Ordering"). Therefore, does it take longer to shop on an Indian site? Yes. Is that an unbearable time burden? No. And, does it make India a more secure place for electronic payments? Indeed.
According to The Nilson Report, a payments industry trade journal, the United States, accounts for nearly 47 per cent of the global credit card fraud even while contributing to just 23 per cent of the volume of global credit card payments. On the other hand, media reports quote Visa International as stating that India has the lowest online card fraud incidence. Yet, the size of credit card frauds is growing worldwide, and does pose a threat to confidence in the electronic payments system.
As India brings more of her people into the banking and electronic payment system, the scope for fraud too would increase. There is also the culture of general laxity with security that needs to be contended with. For example, after the RBI introduced the mandatory requirement to enter your PIN into the card reader in the store to effect an offline credit card payment, many restaurants did not deploy wireless card readers. Waiters would simply ask the guest for the PIN and many, lazy to get up from their tables, would gladly oblige. This is pretty much how most passwords are compromised — simply by asking.
Against this backdrop, the benefit of better security in online and offline credit card payments can outweigh the cost of spending a few more seconds getting an OTP on sms, or entering the PIN into a card reader. In a nation that has poor banking penetration and a propensity to stack currency notes under the mattress for safe-keeping, one blaring slanging match in a prime-time television debate can be enough to destroy confidence in the banking system.
On the other hand, India, home to 16 per cent of the global population, would do well to innovate and lead the change in how payments are made secure worldwide. After all, one should remember that even while shares of Chinese online retailer Alibaba.com got a fancy valuation for listing shares in the United States, Indian online retail companies such as Flipkart and Snapdeal snapped up spectacular valuations and attracted serious investments despite the payment security measures.

To know more about Identity Theft visit: www.cibilconsultants.com

Source: Secondary

Monday, 22 June 2015

Punching card PIN at shops may prove to be risky

As per the guidelines of the Reserve Bank of India (RBI), effective from December 1. The debit card holders will have to punch in their personal identification number (PIN) every time at Point-of-Sales (PoS) at merchant outlets to minimize frauds.
But many bankers as well as merchants in the city pointed out that this is far from fool-proof and the system has an alleged drawback of lack of privacy.
First, the debit card holders will have to enter the PIN of their ATM cards in the swipe machine and then sign on the transaction slip, for any purchase at any shop.
This may prove to be risky, as thieves may misuse the system by keeping an eye during the swipe, memorize the PIN, clone the card to easily withdraw large sums of cash from any nearby ATM .

But it has been found that none of the merchant outlets in the city have made arrangement for privacy of the customers while punching the ATM PIN while purchasing goods.
Glenn Serrao, the son of a hotel owner in sector 17, Vashi, said, "Debit and credit cards are accepted only on the first floor of our restaurant premises. Around 80% of our regular customers do not mind revealing their PIN to the waiters, who in turn, swipe the cards to pay the bill and issue the payment slip for the customer's signature. If any customer demands privacy to punch their PIN, then we will surely provide that service."
Pradeep Kumar, the manager of IDBI bank, Vashi branch said, "Logically, due to lack of privacy at shops, there is a possibility of misuse of the system. Now, to resolve this alleged lacunae in the customer service, our bank will suggest to our product team that the shops need to provide a secluded place for the ATM card swipe machine which should offer adequate privacy for the customer while punching his/her PIN." The product team will then forward the suggestion to the RBI authorities for corrective measures in the guidelines.
"Anyone who thinks that this system can be misused by miscreants, should come forward with their suggestions on the RBI's website, as well," added Kumar.
Susaant Patnaaik (41), an LIC consultant said, "The need for privacy to use one's debit or even credit card is a must. The swipe machine should be kept separately near the establishment manager's counter and be hidden by a partition to prevent onlookers from reading the secret digits being punched by the customer. "
Patnaaik also said that the banks have warned their ATM debit card holders not to read out or enter their PIN when someone is standing behind them.
"One must never swipe in front of any onlookers to ensure the safety of their card," he added.

Learn more about identity theft at www.cibilconsultants.com

Source: Secondary

How to keep your credit card safe online

RAIPUR: With hacking of Facebook, Gmail and other networking websites on rise, threat of credit card/debit card bank accounts also being hacked looms large in state. Online shopping has further increased this threat.

Monendra Sahu, an ethical hacker said, "For hackers, carding, which refers to credit card/debit card fraud is the new duplicity that has made significant rise in state. Hackers have been using credit card/debit card numbers of people to carry out financial transactions for their personal benefits".

Online shopping/banking by users provides the easiest way for hackers to swindle money. "Whenever a user buys anything from the website, he enters his card details to make payment. This becomes an easy gateway for the hacker to trace card details and he gets access to all users who have used that website, by hacking it." Monendra said.


"It has also been observed that the hacker traces around 1000 or even more credit card/debit card numbers and carries out his transaction withdrawing around Rs 4000-5000 from each account. However, this risk is a bit lesser in an online bank account as in this; the user directly enters the bank website."

In fact, with new techniques coming in, hackers have even evolved a technique of scheming, in which they implant a device in the ATM machine or the POS portal and get card details. "A device which can be stuck with Fevikwik, is used by the hackers. It becomes difficult to differentiate between the device and ATM machine."

"Majorly, in the old ATM machines, which can be easily opened from back-side, hackers can easily process it by a pen-drive. It's easier to open the machine and inject a processed pen-drive which will take the card details of users who have carried out their transaction throughout the day. However the newly developed machines aren't much vulnerable," he added.

"Hackers try to use cyber cafes, where they can get in touch with a large number of users and with an open wi-fi connection which it make things easier for them," he added.

Users guide

* Change the pin of ATM card after getting the pin. Try to have a locked Wi-fi network however LAN cable would be even more secure.

* Stop using free anti-virus.

* Always use updated system for your laptop/computer.


* Use websites with HTTPS communication protocol which give encrypted password.

Protect yourself from Identity Theft. Visit www.cibilconsultants.com

Source: Secondary

Tuesday, 16 June 2015

ATM Thefts

It's any time money not just for depositors but also for thieves.
If India puts not just a man on the moon but also the first ATM, the next day's headlines could announce that the money withdrawn by the country's first lunar bank customer was swiped seconds later by an anonymous compatriot who had managed to get there on his own steam.
ATM thefts are one area where India is not lagging behind the developed world. It's not just in Japan that there are reports of the yakuza (gangsters) using trucks with sophisticated construction equipment to uproot ATMs. India's Silicon Valley of Bangalore has also witnessed amateurish attempts to carry away ATMs, lock, stock and barrel.
And so what if, according to some media reports, India holds the record for the world's highest installed ATM some 4,000 metres above sea level and around the Nathu La Pass in Sikkim. There are also reports that the Agricultural Bank of China has installed the world's highest ATM at around 4,500 m in Tibet. There are no reports however of the highest ATM theft. Whether the record is jointly held by Chindia is not known.


ATMs are hitting the headlines for all the wrong reasons. It is not just the customer who no longer has to go to the bank to withdraw money but can swipe a smart card (with an embedded chip containing a unique number) at an ATM. Likewise, instead of holding up a bank like the gangster John Dillinger used to do in the days of the Great Depression in America, the 21st-century thief can source his daily requirements by swiping someone else's money at the nearest friendly neighborhood ATM which is open 24x7.
The ATM has not just enabled the individual customer to have transactions with his own account without accessing the bank's entire database. It has also decentralized bank thefts since the individual thief can operate at a micro level and swipe someone else's hard-earned money by circumventing the customer-identity integrity systems by attaching fake keypads or card-readers on ATMs, to record confidential data like the depositor's PIN. Technological devices have been developed to detect foreign objects on ATMs.

Learn about identity theft at www.cibilconsultants.com

Source: Secondary