On TechRepublic: Beware of crazy recruiter tricks
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 34 of 34:
« Previous
Biometrics?
The problem is securely associating a person with a link to the system. The real question is "Is this person the account holder?" which decomposes into two questions, "prove yourself" and "what account?". Currently the first is done by PIN, which has been shown to be compromised. Any other password system suffers from the same fundamental weakness, so ultimately we need some unique ID on the Card to test against something unique on the user: biometrics. At that point, the proving status becomes "The user matches the card": the second question then comes into play, "does this card match the account?" Here, I'd prefer a moving target: the client card should carry a code changed by the server each time it's used, so there's no possibility of cloning it. If the two get out of step, then the card's temporarily invalidated until the user can prove his identity at his bank again.
The alternative is that users will end up distrusting all electronic payment systems: they were brought in for the safety of the retail arm, but the risk has been passed to the user, which is unfair. Each time one of my banks starts suggesting it doesn't trust its password systems, I personally already revert to manual rather than upgrading to their key-generators etc whch are functionally no more secure at a systemic level.
Posted by: JelMin   Posted on: 08/26/09 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

I've never seen an upside to debit cards.  enduser_z | 03/16/06
Depends if you can get a credit card  voska | 03/16/06
Two ideas.  enduser_z | 03/16/06
That's just ridiculous  rushnrockt | 03/17/06
Upside to Debit Cards  SarcasticB | 03/16/06
Oh, &...  SarcasticB | 03/16/06
Best reason I've ever heard for a debit card.  enduser_z | 03/16/06
True, but...  SarcasticB | 03/17/06
credit vs debit cards  ernwes@... | 03/20/06
Cash back at the grocery store...  BitTwiddler | 03/16/06
I love mine  Patrick Jones | 03/16/06
Upside? Shop around - there's an upside.  horusfalcon | 03/16/06
Great points.  enduser_z | 03/16/06
There are more reasons why Credit is better  rushnrockt | 03/17/06
Merchants LOVE them  Roger Ramjet | 03/16/06
debit card plus  jlzimm | 03/16/06
that's why Wal-Mart defaults to the PIN screen  fireman949 | 03/17/06
Two Prices For Gas  godhner | 08/24/09
Making systems so good, that people are not required to be good any more..!  atulkherde@... | 03/16/06
It's Technology  SarcasticB | 03/17/06
Debit cards  legentry | 03/16/06
Old fashioned PIN  Pazooza | 03/17/06
Speedpass Idea  yabadaba | 03/17/06
Update to message 19  yabadaba | 03/17/06
What prevents snooping with speedpasses?  enduser_z | 03/17/06
Snooping with speedpasses - not so easy  rick1947 | 03/17/06
What prevents snooping with speedpasses?  yabadaba | 03/17/06
Physics book or two?  rushnrockt | 03/17/06
Physics book or two?  yabadaba | 03/17/06
Word of the moment: encryption  rushnrockt | 03/18/06
RFID is not so easy to track  rushnrockt | 03/17/06
Have you been RFIDed?  yabadaba | 03/18/06
What about PIN #  KrazyGuy | 03/20/06
Biometrics?  JelMin | 08/26/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
advertisement

Meet Doc