Showing posts with label Debit card. Show all posts
Showing posts with label Debit card. Show all posts

Wednesday, December 14, 2016

Qualcomm follows many others in pointing out vulnerabilities of electronic financial transactions in India

Qualcomm follows many others in pointing out vulnerabilities of electronic financial transactions in India

How an ATM attack works. Infographic from Symantec's blog.
By 
Qualcomm has pointed out that most banking apps and mobile digital wallets in India do not use hardware-level security measures to ensure that the financial transactions are not compromised. Qualcomm is in the process of approaching the makers of such apps to integrate hardware level security features of Qualcomm chipsets into the applications. The sandboxing approach prevents any malware from affecting financial transactions.
There has been an increased focus on the security of electronic financial transactions, ever since a malware got into the systems of Hitachi Payment Services, which provides back end services to ATM machines and Point of Sale nodes across India. 32 lakh debit cards were compromised including those issued by SBI, HDFC, YES, AXIS, BOB and ICICI.
Security experts and consultants have pointed out various holes in the electronic transaction systems in place in India. ATMs need to implement state of the art encryption. The magnetic stripe cards need to be replaced with newer EMV chip cards, a global standard created by Europay, MasterCard, and Visa. ATM transactions are vulnerable to skimming and cloning attacks because of the continued use of the magnetic stripe cards. The databases of the banks themselves have to be adequately secured.
Intel has also warned that ATM machines in India are vulnerable to malicious attacks. Intel points out that countries in the Asia Pacific region are developing and are particularly vulnerable because of old systems and machines being used. The ATM machines tend to use outdated operating systems such as Windows XP, which makes them a easier target to execute malicious attacks against. Intel has also called for securing ATM machines with multiple levels of authentication and industry standard encryption.
The humans are the weakest link in the security chain, and there is a need for banks to educate users about phishing web sites, frauds, and scam emails. This is particularly important to users who are only starting to use digital wallets and banking apps after the demonetisation. The critical login credentials of users can be compromised by someone merely glancing at the screen and the app being used in a public place, a method of low-tech hacking known as shoulder surfing.
Antivirus solutions installed by users on their devices to protect financial transactions, actually end up making online banking less secure, according to researchers from the  Concordia University in Montreal, Canada. The anti virus software intervene in the regular operations of the browser and operating system, and can be used to fool the system with fake credentials. Commonly used security services were tested, and the researchers found that they lowered the levels of security normally provided by the browsers.
The hacking collective known as Legion has warned of weaknesses in the Indian Banking System. The group has said that it has the capability of hacking into financial systems, but has chosen not to do so. Legion has also said that there have been significant breaches in the past, but Banks have not alerted their consumers about it. There is no requirement by law to disclose data breaches to customers, the onus is on the Banks to do so.
However, it is not just amateur hackers who are a threat. There are serious cybercriminals and even the largest financial networks are susceptible to attacks. Swift has confirmed that hackers trying to get into the system have succeeded multiple times, and are continuously using newer and more sophisticated techniques. Swift has warned of consistent efforts by the group that pulled of the Banladesh Bank Heist to compromise the systems.
The laws in place are outdated, and need to be tweaked taking into accounts new developments. Digital wallets in India currently have no prescribed security standards, and are free to implement their own measures. There are no laws to hold the digital wallets responsible if something goes wrong during financial transactions.
Qualcomm senior director product management Sy Choudhury lauded the efforts by Aadhaar. The India Stack, which is a collection of APIs, which are ready to be integrated with applications and services. One of the aims of the India Stack is to ensure smooth and secure financial transactions. Unified Payment Interface (UPI), Aadhaar linked biometric identification, Unique Identification Authority of India (UIDAI), e-KYC, Aadhaar Enabled Payments System (AEPS) are all elements of the stack, that can improve security of transactions.

Saturday, December 3, 2016

Hackers can hack any Visa credit card or debit card in six seconds

Visa credit hacked
Visa credit hacked

02 Dec 2016 , 14:50


It can take hackers just six seconds, a laptop and an internet connection to hack any Visa credit or debit card, new research has revealed. The research, published in the journal “IEEE Security and Privacy”, said that the “distributed guessing attack” circumvents all the security features put in place to protect online payments from fraud. Neither the network, nor the banks are able to detect attackers making multiple, invalid attempts to get payment card data.
The current online payment system does not detect multiple invalid payment requests from different websites. This allows unlimited guesses on each card data field, using up to the allowed number of attempts – typically 10 or 20 guesses – on each website, explained Mohammed Ali, a PhD student in Newcastle University.
“Different websites ask for different variations in the card data fields to validate an online purchase. “This means it’s quite easy to build up the information and piece it together like a jigsaw,” Ali added. The combination of these two factors — unlimited guesses and variation in the payment data fields — makes it easy for attackers to hack all the card details.
Each generated card field can be used in succession to generate the next field and so on. “If the hits are spread across enough websites then a positive response to each question can be received within two seconds – just like any online payment,” Ali warned.
The researchers explained that even starting with no details at all other than the first six digits — which tell you the bank and card type — a hacker can obtain essential pieces of information. These are — card number, expiry date and security code — to make an online purchase within as little as six seconds. Researchers believe this ‘guessing attack’ method could have been used in the recent Tesco cyber attack where the hackers defrauded customers of 2.5 million pounds.
The risk is higher at this time of the year as many people are making online purchases ahead of Christmas. However, researchers found that unlike Visa cards, MasterCard’s centralised network was able to detect the guessing attack after less than 10 attempts – even when those payments were distributed across multiple networks.
The researchers suggested that to minimise the chances of hacking, card-holders should use just one card for online payments and keep the spending limit on that account as low as possible. “If it’s a bank card then keep ready funds to a minimum and transfer over money as you need it,” said Martin Emms, co-author of the research.
IANS

Thursday, October 27, 2016

Banks need to switch to fully-encrypted security solutions to avoid security breaches

Banks need to switch to fully-encrypted security solutions to avoid security breaches

While some of the country’s premier banks are busy blocking debit cards that have been compromised (the numbers run into millions) in one of the financial sector’s biggest data breaches, it’s time for banks to adopt state-of-the-art, fully encrypted ATM security solutions to safeguard consumers, the country’s top cyber experts have suggested. The State Bank of India (SBI), HDFC Bank, ICICI Bank, Axis Bank and YES Bank are among banks which reported several of their customers’ debit cards being compromised following a malware-related security breach in an ATM network. The SBI has blocked nearly 600,000 debit cards so far.
“This incident is a wake-up call for the Indian banking ecosystem to pause and realise that adopting extra-layered, state-of-the-art encryption security to minimise consumer financial data breach has become essential. The breach is attributable to malware which was introduced in ATM systems. The said malware has resulted in unauthorised access to data,” Pavan Duggal, one of the nation’s top cyber law experts, told IANS.
Malware attacks and cyber threats have affected countries like Japan and Bangladesh in the recent past and banks in India will have to make efforts to ensure that data is protected with multiple levels of authentication and industry-standard encryption, ensuring data security at all points of a transaction.
“It is time that magnetic-stripe cards issued by banks for ATM transactions are replaced at the earliest. While the affected banks are blocking debit cards to minimise the impact, the already ongoing replacement of mag-stripe cards with EMV chip cards will help the banks and consumers,” explained Atul Singh, Regional Director-Banking and Transport (India Subcontinent) at the digital security giant Gemalto.
Gemalto works with some of the world’s leading enterprises, banks and telcos to help them deploy consumer-friendly technology solutions for payment, banking and other financial services on the mobile and securing confidential information. EMV — which stands for Europay, MasterCard and Visa — is a global standard for credit cards that uses computer chips to authenticate (and secure) chip-card transactions.
“This is in line with the RBI directive to issue EMV chip- and PIN-enabled cards. According to industry estimates, around 400 million mag-stripe cards have to be migrated to EMV standard in the next two years while nearly 120 million cards would have been migrated this year,” Singh told IANS. Further, banks need to work towards gradually enabling EMV chip and PIN-enabled card acceptance and processing at ATMs to enhance the safety and security of transactions.
While the point of sale (POS) terminal infrastructure in the country has been enabled to accept and process EMV Chip and PIN cards, the ATM infrastructure, on the whole, continues to process the card transactions based on data from the magnetic stripe.
“As a result, ATM card transactions remain vulnerable to skimming and cloning, etc., even though the cards are EMV Chip and PIN-based. Therefore, in line with RBI’s directive of May 26, 2016, to all banks to upgrade ATMs to accept chip and PIN by September 2017, banks must take immediate steps to implement this in a fast-track mode,” Singh added. Worryingly, Indian cyber laws do not talk specifically about banking frauds.
“The Information Technology Act, 2000, being the sector-specific legislation, was amended in 2008. By virtue of the 2008 amendments, certain cosmetic amendments concerning cyber security were made under the Information Technology Act, 2000. The said amendments are not sufficient and adequate in today’s scenario,” Duggal informed. “Further, the ground realities for cyber security breach are distinctly different in 2016 as compared to 2008. As such, there is a distinct need for India to beef up its legal frameworks on cyber security when it comes to banking frauds,” he told IANS.
According to Rakshit Tandon, a consultant at the Internet and Mobile Association of India (IAMAI) and a cyber security expert, ATM cards are vulnerable; ATMs are weak, and banks’ own servers are at hacking risk. “Banks must introduce biometrics like retina scan, voice scan or fingerprint as double verification at ATMs. PIN numbers must be changed periodically. But the option is only in four-digit and so making strong PINs is out of the question as of now,” Tandon told IANS.
Watch bank statements closely and contact the bank in the event of any signs of unexpected charges or transfers. Consumers also need to be aware of phishing scams where cybercriminals hijack banking systems and send bogus emails that lure people into sharing personal information or clicking malicious URLS with malware. “Make all new PIN and account passwords different and difficult to guess. Include upper and lower case letters, numbers and symbols to make passwords harder to crack online,” suggested Sunil Sharma, Vice President-Sales and Operations (India & SAARC), Sophos, a global leader in network and endpoint security.
Further, “the Information Technology Act, 2000, needs to be amended to come up with stringent provisions pertaining to a variety of cybercrimes, including banking frauds,” Duggal noted. In the meantime, banks must take a serious note of this incident to concentrate on cyber security and help protect the interest of users and consumers, the experts advised.
IANS

Related Posts Plugin for WordPress, Blogger...