Site Sponsor:

mcafee_logo.gif
line

Now Available:

Featured Resource:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Dan or post a comment to the blog.

« Simplify Vista and Office Deployments - Or Try a Better Option | Main | Google Ruling Raises Questions for Web 2.0 Mashups »

Improving Security of Online Transactions

The steady stream of security breaches is taking its toll on consumer confidence. Andrea Klein at E-Commerce Times points out:

[T]he Ponemon Institute, a research and education organization focusing on information and privacy practices, revealed in its "2006 Privacy Trust Study for Retail Banking" that banks are only one or two security breaches away from losing customers -- with 34 percent of respondents indicating that they would transfer their funds after a single security breach.

Banks and other financial institutions are taking notice.

PayPal is offering a hardware security key which generates a new random number every 30 seconds for authentication.

Andrew Rolfe of E-Commerce Times makes a good argument for out-of-band communications. The basic idea is that an on-line transaction must be authenticated using some other channel (i.e. not the Internet); the phone is the obvious choice. The financial institution would place a call to an phone of record to verify a transaction. The possibility of an attacker hacking the phone number database is there but this method significantly raises the level of difficulty over today's attacks.

Cryptography is also improving. According to Vipul Gupta of Sun Microsystems:

Something that is here today will not be good enough for tomorrow. About five years ago, DES was ruled inadequate. Now we are moving from RSA to a new deployment of ECC. We are also working on new hashing and key algorithms to AES (advanced encryption standard). All these various components are vital to full security.

These options are promising but there are still challenges.

Klein argues for a comprehensive identity strucuture that poses real hurdles, both technical and legal. One of the reasons PKI is not more widely used is the difficulty in setting it up and administering it. Federated identity management is getting better but it is also difficult to manage, especially when there are fine-grained policy details to worry about.

Finally, Gupta hits on the biggest challenge:


Attackers go after the weakest chain in the link, and that is the end user. Security education is falling behind. We have to strengthen our efforts in educating users about security

TrackBack

TrackBack URL for this entry:
http://www.realtime-websecurity.com/type/mt-tb.cgi/219

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Dan Sullivan's Bio:

Dan Sullivan is a systems architect with 20 years of IT experience that includes engagements in enterprise security, application design, and systems architecture. His experience includes a broad range of industries, including financial services, manufacturing, government, retail, gas and oil production, power generation, and education. Dan’s security-related project work has ranged from requirements analysis for enterprise information security to designing and implementing security for database applications and enterprise portals. Dan has written about information security and other enterprise information management topics for Business Security Advisor, DM Review, Intelligent Enterprise, and E-Business Advisor. You can contact Dan at: dan_sullivan@realtimepublishers.net