A simple solution to credit card fraud, and why you won't see it any time soon
blog.rongarret.info
blog.rongarret.info
Overreacting:
- the most up-to-date technologies for anti-credit card fraud, namely variants of smart card/EMV, are already available and widely used by all the large credit card providers and banks in the EU and Asia (excluding domestic transactions in China and Japan). There are even US providers who use it in some situations.
- in addition, most merchants in those regions have upgraded their PoS terminals for smart cards and in some cases refuse to accept non-smart credit cards.
- he made no case for how HSBC money laundering and subprime crisis have anything whatsoever to do with anti-fraud credit card technologies. Just randomly put it out there...
Shallow:
- Not even a minor reference to the specific technology being discussed is made, only a vague mention of "public-key cryptography".
Misleading:
- the credit card industry HAS and IS deploying the most up-to-date technology. In some regions, e.g. US, there are legal or infrastructure barriers that take time to overcome.
- the key moment at which the new infrastructure is rapidly rolled out and fully enters the public consciousness is associated with the "liability shift" when credit card infastructure providers push liability for fraud to merchants, therefore forcing merchants to upgrade their equipment and processes:
-- Mastercard is implementing a liability shift for point of sale terminals in October, 2015. For pay at the pump, at gas stations, the liability shift is October, 2017. For ATMs, the liability shift date is in October 2016.
-- Visa is implementing a liability shift for point of sale terminals on October 1, 2015. For pay at the pump, at gas stations, the liability shift is October 1, 2017. For ATMs, the liability shift date is October 1, 2017. [1]
Bait-link:
- a solution is already out there. It is based on "public key cryptography". Whether it is "simple" or not is a matter of opinion at this point, without any further clarification by the author. Nothing he has proposed has improved on the solution.
The only solutions I've seen to using EMV itself for online/phone transactions involve having a more advanced card (i.e. with LCD token readout) or a standalone card reader to interact with the chip.
E.g.: ftp://ftp10.us.freebsd.org/users/azhang/disc/springer/0558/papers/2455/24550388.pdf
What is needed is a better system.
Banks make money on transactions regardless of whether they are fraudulent, criminal, or not. I think the argument is that as long as banks profit from illegal activity (identity theft) they have no incentive to take steps to reduce that profit. They lose money if the security is too strong or too weak. Apparently the security we get is just right (for the banks).
And why is that, you think? People are somewhat surprised that a magstripe is still even considered valid here and have been for years. I've seen zero chip readers in the US. It's been more than five years since I've heard of a merchant using magstrips in the EU.
The industry in the US isn't toothless. Nor is the government. They seemed perfectly capable of banning betting and sales of illegal goods or donations to causes they disapprove of. Yes, they are now starting to roll out stuff. I have no idea how they're going to do it seeing as they're apparently still living in the remote past. Can they roll out all this by 2017? Perhaps. Meanwhile, in the EU Square Up is distributing free chip readers for android or iphone, same as the US side does for magstripes. Which they can then transmit over the nice 100 Mbit fiber. Apparently, it wasn't that damn hard, except in the US.
I was in the US last summer for two weeks, and I saw several. Perhaps because I'm used to chip and pin?
> in the EU Square Up is distributing free chip readers for android or iphone
No they aren't, I think they said they were going to but there's no way to get one from them right now.
On the small business angle, chip and pin in the UK has been a nightmare for small retailers. It's been in for several years now and things like Square are much more recent. A chip and pin device is not cheap - far more than many small businesses can afford.
By 2015 (which is the liability date for point of sale terminals and you bet your boots they will change those machines quickly once it's costing them money) Square and things like it will be mature and ready, so hopefully you guys will make the transition much more easily than we are!
Not only should future payment systems be based on cryptography, but they should also require an affirmative step on the part of the payer to initiate a given transaction of a given amount. In other words, it shouldn't be a matter of handing over your card number, or even a one-use cryptographic token, and letting the merchant fill in the details. You should have to explicitly send an amount of money that you specify. Then, of course, a smart merchant would verify that the amount is correct before fulfilling her end of the bargain.
In other words, the process should be that the payer gives money to the payee, not that the payee takes money from the payer.
Unfortunately, as the author points out, progress on this front has been almost nonexistent with respect to the established credit card networks. We may have to hope/work for a totally new system to replace it. (Perhaps Bitcoin, or something inspired by it.)
I don't know whether those transactions tend to be larger or smaller than average. I'd assume the detection systems are quite good, and crooks start with small charges (gas stations and shoes are what I hear are test spots they use). So they may be pretty close to average sized transactions.
The kind of work that would require would be on the order of hundreds of millions of dollars of work, an entirely new infrastructure, and massive retraining. The return on investment is a very long term issue.
I currently work in the sector, so can't say too much about it, but the problem is that it's a hard problem at scale.
Anecdotally, I know that I'm much more hesitant to whip out my card for that burrito when they added a $.45 convenience charge. I still use the card sometimes, but that one charge is enough to make me keep cash on hand. I wonder whether people would pay for the convenience if the true cost of it were more visible.
Merchant - (RFF) -> Bank - (prompts for auth) -> Consumer - (grants auth) -> Bank - (RFF granted) -> Merchant
Of course, smartphones are still potentially insecure, another more cumbersome model could revolve around challenge-response codes - where the customer has an offline digital code card:
[Merchant - (RFF) -> Bank - ($challenge) -> Merchant -($challenge) -> Consumer(punches in challenge code) - ($response) -> Merchant - ($challenge$response) -> Bank - (auth) -> Merchant
IIRC the card signs the merchant's request for funds once the PIN has been validated by the chip on the card, then sends it to the bank. I don't think there's anything in the standard that would preclude having one time PIN codes(the PIN validation is done by the chip, so you could just have a different app that does more than check a single PIN code), but the chip in the card itself doesn't have network access.
If you really wanted to have online authorization through the cell network, you could hold the processing of the AQRC message until it is verified through SMS (which can take several minutes for delivery and is best effort). However, that would hold the card reader unusable until the authorization is granted, as the card needs to stay in the terminal until the transaction is complete.
This obviously disregards offline processing (ie. card terminals that are not always connected to the network) and CNP transactions. For those, verification through another channel would be much more realistic.
When you’re on a website and want to make a payment, the site makes a request to the bank, which then presents you with whatever method of authentication your bank uses. Generally this is some two-factor system. After giving the OK, you’re redirect back to the merchant.
Actually, it would seem to me that PayPal is very similar.
The word you're looking for is "capability", not permission. Permission requires consent, which is something you give separately from the actual card number.
A minor point, but I think it changes the tone of that statement.
> possession of credit card data amounts to the capability to charge any arbitrary amount to it
I'm not sure anyone is ignorant of this fact though, and yet everyone seems OK with it.
> Not only should future payment systems be based on cryptography, but they should also require an affirmative step on the part of the payer to initiate a given transaction of a given amount. In other words, it shouldn't be a matter of handing over your card number, or even a one-use cryptographic token, and letting the merchant fill in the details. You should have to explicitly send an amount of money that you specify. Then, of course, a smart merchant would verify that the amount is correct before fulfilling her end of the bargain.
Ugh, no thanks. The system you describe is more like cash. I have to actively dole out the necessary amount, and then receive change that is counted at each transition. I abhor these types of transactions.
Convenience is a significant motivator in the adoption of credit cards. Any competing system will have to compete on simplicity. The fact that consumers and merchants haven't fled from credit card use as fraud rates (and costs) have increased is evidence that the market is willing to bear them.
The legislative changes that allow merchants to charge a CC-use surcharge will resolve the significant matter of ignorance. I do agree that consumers are largely ignorant of the hidden costs of fraud associated with the current CC model. The question is whether they'll pay these costs once they're brought to light. I believe they will continue to pay them in exchange for convenience.
Not in this case. There's no reason the merchant can't send a request for a specific amount, encrypted using your credit account's public key and signed by their private key. Your credit authorizing device (smartphone, desktop app, phone call, whatever) then asks you to confirm the amount, and that amount is sent back to the merchant. I'm sure there's some way of cryptographically tying the request for funds to the transmission of funds so that it's clear what transaction the funds are for, that the amount sent matches the amount requested, etc.
Ugh, no thanks. The system you describe is more like cash. I have to actively dole out the necessary amount, and then receive change that is counted at each transition. I abhor these types of transactions.
Not as I imagine it. I think the merchant would be able to set up a transaction, and the consumer would have to take a minimal step to approve it.
Also, if this system would annoy you, I'd be fine with allowing individual consumers to opt out of it. Personally, I would absolutely opt in.
The fact that consumers and merchants haven't fled from credit card use as fraud rates (and costs) have increased is evidence that the market is willing to bear them.
Partially. But this fact can also be attributed in large part to the major barriers to entry.
So you do this for a handful of companies (the electric company, the gas company, etc), and for everything else, you use the push model.
Fortunately the anti-fraud solutions out there are pretty effective, which helps control the damage a stolen card can do.
In my experience, not reliably. For example, I've known people who gave their credit card info to a seemingly legit company, which then proceeded to make monthly debits without authorization, and this went on indefinitely. The credit card company was unwilling to intervene, and said it had to be worked out with the merchant.
That may sound surprising to you, because you're aware of chargebacks and other checks and balances. However, for some reason or another, none of that helped the victims in these cases. It's little consolation to them to say that "in theory, there are mechanisms in place to prevent this kind of abuse."
The logistics of drop safes and daily deposits plus losses due to counterfeiting, robberies and pilfering can cost a similar amount to the 3-4% credit card fees.
That's why merchants aren't grumbling too much.
In other words, cash buyers are subsidizing the interchange fees, your Rewards Points, Cash Back deals, etc.
This is evident especially at gas stations. Many have "cash only" prices that are lower than credit prices; Arco generally has the lowest gas prices but accepts only cash or ATM (with an additional ATM fee).
It's been policy for a while now that you simply can't charge more for (just) credit card transactions (you could however discount cash purchases). That landscape is changing recently [1][2], but we haven't seen its full effects yet.
[1] http://www.dailyfinance.com/2012/07/19/3-reasons-why-credit-... [2] http://www.dailyfinance.com/2013/01/24/new-credit-card-check...
I'm not sure how/if this was recently changed in the US, my knowledge is 5+ years out of date now and I'm not in the US either.
That said, I agree with the author. Signature based debit should have long since been replaced by something more secure (e.g., Chip and PIN), yet its much higher fee structure creates a perverse incentive to maintain its use.
But I don't think anyone wants to give customers this wallet-like capability..
Then one day one of those slimy Brooklyn camera stores overcharged me by $10, even though I specifically put in a limit equal to the purchase price. I called the bank and asked what happened, and they said that they always add a pad on top of the limit because people often forget about shipping charges, etc.
Sigh.
This sort of thing reared its ugly head last decade in the UK with phantom ATM withdrawals. The banks claimed the consumers must have made the transactions as PINs are required and banks are perfectly secure. It turned out that the banks weren't as secure as claimed. (Search for [ross anderson phantom withdrawals] for more details as well as attacks on chip and pin systems.)
The reason we don't deal with credit card fraud is that there are no consequences for being a victim, for any definition of victim. If the victims had consequences, then there would be demand for action. But there is none. Further, because there are no consequences, the cost to solve credit card fraud isn't worth it.
Edit: This is a true statement. I feel capable to comment on this topic and have spent time working with this industry. I've dealt with abuse and fraud for years on many sides of the transaction (there are more than two). If you think you have a retort, please think carefully if you really understand what I just wrote above. There are no consequences for the victims. No matter how you define victim.
Edit 2: You deserve better explanations. I'll work on a blog post. But one case of a financially tight victim having to call the bank, etc. isn't enough. In the aggregate, nobody is inconvenienced. There are no consequences. If merchants had consequences, they'd stop accepting credit cards, but in the aggregate, that's a non-starter. Issuers similarly have no consequences. There's no arbitrage for improvement either.
If you have a viewpoint that is polar opposite to how everybody else understands something, maybe it's your obligation to explain it better. And saying that you're in some form of authority to speak about the subject isn't an explanation.
Incorrect. There are no serious consequences for the victims of credit card fraud (unless you consider the victims to be the merchants).
When fraud takes place, the credit card company removes the bill from your statement. Then they take the money back that they sent to the merchant. The merchant is left holding the bag. Whatever they sold is now gone, and they have no money to cover the cost of that good. The merchants bear the entire risk of credit card fraud.
This is why it makes no sense that credit card companies even threaten to charge merchants higher rates if they have more fraud. Merchants with high chargebacks get beaten down in multiple ways. First there's a chargeback fee. Then they raise your processing rates. AND you still lose out on your goods that were stolen.
(Technically I suppose if the fraud is big enough, the merchant could be insolvent in which case the credit card companies bear the burden, but this is certainly an exception).
On the consumer side, I had to waste time ringing the bank, going through the chargeback process, getting a new card, not be able to use the card for a little while, etc.
On the merchant side, you waste time fighting the chargeback, and then if the chargeback goes through, you lose both the money and the goods.
So when you say there are no consequences for victims, it doesn't make sense to me... Could you elaborate?
I believe that anything you suggest worth addressing costs more than the fraud itself. The only way to eliminate fraud is to show that doing so increases transaction volume. Since there has yet to be a proposed solution that does that, people focus instead on trying to "save money" lost to fraud, which doesn't work because there are no consequences to credit card fraud. (this is not a circular argument, though I see how it might read that way)
In reality, the costs of fraud are shared widely, and there are definitely victims in aggregate. First, the merchants are clearly victims. In a counterfactual universe that contains no credit card fraud, merchants pay lower fees to accept credit cards, and make more money for selling the same amount of goods at the same prices. Second, consumers are definitely victims. In the same counterfactual universe, consumers pay less for goods by a tiny margin, and thus are able to consume more and achieve higher levels of utility. Additionally, in this counterfactual universe, nobody has to deal with credit card fraud, which is an inconvenience which has both a direct dollar cost, in cases where people aren't satisfied with their legal protection or incur legal costs in exercising their protection, and in non-dollar costs like having to call their bank, stress, broken relationships etc. Note that these are real costs and lower standards of living and utility even if they aren't dollar costs.
From a macro perspective, it's obvious that fraud has a negative impact on the economy. All of the effort that is spent by every fraud researcher, fraud company, credit card company fraud agent etc. is fundamentally unproductive effort which is nonetheless included in GDP. If these people didn't have to deal with credit card fraud, because it simply didn't exist, they could be gainfully employed in other productive fields that work to meet the hedonic goals of other humans.
I just want you to be aware of the tough row you have to hoe if you are really planning on going down this path, and if you ignore the above arguments, well, you aren't making a very compelling case.
To your point that all the effort to combat fraud implies there is a problem, you've created a fallacious point.
To your point on unproductive exercise, I believe it is wasted effort and loss. Perhaps the real victims of fraud are fraud fighters!
To inconvenience as a form of consequence, you clearly already understand the difference there.
Maybe it 'isn't enough,' but that's not the same as no consequences.
I don't worry about credit card fraud because my credit card company does not hold me responsible for fraud as long as I bring it to their attention in a timely manner (30 to 60 days). So I just make sure to review my statements every month.
Yes, in a general sense I pay the cost of this insurance because all businesses are imaginary pass-through entities. By that standard, let's not tax businesses either since we ultimately all pay those taxes too.
But, complex technical solutions ALSO have a cost--not only to implement and maintain, but in the friction they introduce into the commerce of everyday people's lives. And since businesses exist to minimize costs, we can assume that they have not implemented complex technical solutions because they cost more than the insurance.
In summary: not every optimal solution exists in the space of engineering. Social and legal structures can help solve problems too.
The solution is hardly "complex".
Your CC number never leaves your card unencrypted. Your card details are encrypted on a server somewhere. A transaction consists of a record of sale that is signed by the merchant's private key, sent to your card, which then signs it with your private key.
Said package of data is delivered up to Visa's servers. Your digital signature is validated with your public key, merchant's key is validated, the order goes through. Yes this requires an internet connection, yes it breaks offline processing. It also cuts fraud to 0.
Online purchases get more complicated, sure. Lazy way is to have something running on client machine that can sign data downloaded from merchant, make it a browser plugin or even better a standard all browsers implement, so long as the private key is stored somewhere and can be applied to a message. This is not exactly a hard problem. Doing it right is tricky, thankfully a good number of correct implementations already exist. Use one of those.
A more secure solution, especially for PCs, is to have a dongle, everything is processed on card. Then even if the PC is rooted 50 ways to Sunday all orders are still secure.
This is no more convoluted (and many would argue less) than the current way by which credit card orders are processed.
Credit Card companies currently place the entire burden of fraud onto merchants. They don't really have a reason to care about fraud, other than that it is bad customer service to have your customer's identity stolen.
The real problem here is how to deal with crap like reoccurring payments. Too many organizations are used to a workflow where in they store your credit card number. That is obviously insecure (see: news stories that come out all the time). I am not sure how to solve that particular problem though. Obviously it is a big blocker to getting a more secure system implemented!
Getting stores to adopt these services is a lot easier than getting Visa to change how their product fundamentally works.
In this hypothetical rational world, you would go to the government office when you needed to open a new payment account to make or receive payments. You would show proof of identity, and receive a duly signed certificate bound to a a hardware token of a standard type that you could then use to make transactions both on and offline. Since everybody would use the same systems there would be no questions about if someone could pay you.
But in this world, government securing the currency is regarded as an outmoded and dangerous idea, unless it's a bailout...
Already exists. It's called cash.
http://www.irongeek.com/i.php?page=videos/derbycon2/3-1-1-da...
As the above shows, crypto is useful, but it's far from perfect due to its reliance on insecure stuff (i.e. web browsers, operating systems, ...). When the foundation is flawed, it's turtles all the way up.
Also, don't let HN or the web in general get you down. Writing for those with a short attention span makes for short stories, not long ones. Being wedged could be an indication that you have a lot to say, too much to get it going properly. I've got a hunch you have a nice long story to tell, and it will be worth reading even if it comes out in a round about fashion. I ain't a crypto or security person, nor do I play one on TV, but if you want a proof reader contact me privately.
Why is this so shocking to the author?
One thing that is now changing is that responsibility for charge-backs is going to be moving from the merchants and card issuers (who do bear risk in ATM transactions, for example) to the acquiring point of sale network, operator or ATM. In order to prevent that from happening, the operators are being required to support EMV in X% of devices by Y date. MasterCard has a write-up of this here: http://www.mastercardadvisors.com/_assets/pdf/emv_us_aquirer...
You can Google "EMV acquirer risk" to find more on this issue.
As someone who was part of a lawsuit involving public key cryptography I can assure you that the barrier to deploying it in the US rested squarely on RSA Data Security (patent holder) until the patents expired.
To understand how to deploy better security look at Stripe. Stripe is displacing (with pre-existing card technology) the connection between card companies and merchants with a better experience. With an established customer base they will be in a position to drive the replacement of cards.
No system with as many moving parts as the credit card system has, can be "quickly" changed (and by quick here I'm talking demi-decades) however it can be disrupted and replaced.
- What exactly are these barriers the industry has set up?
- What kind of savings be obtained through his solution?
- What exactly is this solution without going into the crypto part (which I assume is what he wants to sell)?
- Any solution involving crypto means at the least both client and server side changes are needed, which means every merchant needs to upgrade. What is he proposing that has a better value proposition inspite of the costs involved?
I am not even questioning his crypto protocol, assuming its good.
Unfortunately the risk isn't as high as the author intended. There are still many credit card launder groups that take advantage of in-person fake card transactions. The margin is so high that they would often purchase over a few thousand worth of items at Wal-mart or such (mostly gift cards) at a single time and the lack of care from cashiers just doesn't help with the deterrent factor.
Aside from the big boss, even the busboys would try to snatch up items for themselves from the store aside from the gift cards to give back to the big boss. This creates a healthy enough ecosystem that each part of the chain will have enough motivation to not cause the group to fall apart, because the margin is just too high.
The credit card itself builds too much on trust and is fundamentally broken. Trust is a rare quality in human and it is just not present in a criminal's eyes. Of course, the trust allows a credit card to be used simply without much additional overhead. If one day we collectively deem credit cards to be insecure enough maybe we'll consider trading off the easy usability for a more secure measure such as presenting your id when using credit card. Or perhaps we should all just wait for the future where we each have biometric chips embedded in us to scan at a credit card machine.
The industry is actually doing a lot of work to minimize the fraud and keep it under control. But there is absolutely correct understanding that it will never go down to 0. Even if you deploy super-modern PKI solution, you still have to deal with fraud like "didn't get an item", etc. Thus the benefits of not having a credit card number are not that significant in the big picture. While inconvenience and complexities are pretty high.
I think it is much more likely bitcoin takes off as a real currency for exchange and people just start using banks that facilitates transparent conversion between the two when buying stuff online. It doesn't help with using a credit card online from a CC company, but it does skip them entirely.
I've heard from my Canadian friend who owns a Shoppers Drug Mart, that it has cut down chargebacks to almost 0.
Why they haven't implemented this in the US I'm not sure. The only problem is that if they figure out your PIN, it makes it very hard to fight chargebacks from the point of the consumer. But we all know that the CC companies don't care.
The one thing to note is that it's very hard for the CC companies to lose money with fraud. Usually the merchant or the consumer is on the hook. Then the issuing bank, etc. They're last in line, so their incentive to make drastic change is nil.
There's a strong relationship between card fraud and DDA fraud which very directly hits the bottom line. Typically credit card fraud is monetized by making a balance transfer to a DDA.
Chip and pin is on the way. A lot of new cards have it. See below...
http://www.federalreserve.gov/newsevents/bank_of_america_201...
Never explain with conspiracy what can be explained by incompetence.
Some finnish banks introduced a "verified by Visa" scheme where you need to verify online transactions with one time password (those are normally used to log into online bank account). At least for me the result was that now I choose PayPal whenever possible, since PayPal allows me to pay with just username and normal password.
Indeed.
I'd like to elaborate on my agreement but...I can't figure out how to write about without coming across like a paranoid loon. Methinks it has to do with approaching the half-century mark. "I've seen things you people wouldn't believe..."
Simply, the reason given is that credit card fraud costs them about $3 billion annually. That's not enough to get them to move.
You should be able to the account URI (based on IBAN) and the total, issue the payment order to your bank with your phone. The recipient gets notified by his bank in real-time that the payment has been made. Thank you, have a good day.
"Fraud isn't costing them money, it is costing you money. [they] pass the cost on to you, the consumer."
That's true of any business really. Increased costs get passed onto the consumer. But that doesn't stop other businesses from trying to reduce costs.
It's clear to me that the advent of push liability opens the lots wider for no-fraud payment systems, I.e. bitcoins. Evidentially, that situation is only two to five years away. Which is plenty of time for mobile wallet startups to help me get rid of my annoying leather wallet!
https://encrypted-tbn3.gstatic.com/images?q=tbn:ANd9GcSP3PxS...