Finextra Research
Sign in
Sign up
  • News
    • Latest news
    • Company updates
    • Long reads
  • TV
  • Research
  • Events
    • All
    • Conferences
    • Webinars
    • Popular
  • Community
    • Community latest
    • Latest expert opinions
    • Groups
    • Search members
  • Jobs
  • APIs
Sign in
Sign up
  • News
    • Back
    • News
    • Latest news
    • Company updates
    • Long reads
  • TV
  • Research
  • Events
    • Back
    • Events
    • All
    • Conferences
    • Webinars
    • Popular
  • Community
    • Back
    • Community
    • Community latest
    • Latest expert opinions
    • Groups
    • Search members
  • Jobs
  • APIs
  • payments
  • markets
  • retail
  • wholesale
  • wealth
  • regulation
  • crime
  • crypto
  • sustainable
  • startups
  • devops
  • identity
  • security
  • cloud
  • ai

Community

  • Your feed
  • Latest expert opinions
  • Groups

Join the Community

23,448
Expert opinions
42,335
Total members
302
New members (last 30 days)
176
New opinions (last 30 days)
29,126
Total comments
Join Sign in
Follow Unfollow

Stephen Wilson

Managing Director
Lockstep Consulting
Member since
24 Apr 2008
Location
Sydney
Followers
6
Following
2
Opinions
34
Long reads
0
Followed by John Sims, Martha Boyle and 5 others you follow
View Stephen Wilson's full profile

Stephen's comments

clear
Smartcard readers from your local corner store

The appearance of connected smartcard readers on the UK market is very interesting. Are they being aimed at Chip and PIN usage online? 

To date, AFAIK the only online Chip and PIN applications have used un-connected smartcard readers, to generate OTPs for Internet banking. But the connected reader is hugely more powerful, for it allows digital signatures. 

To date I reckon thinking about digital signatures has tended to be a bit wooden, being overly preoccupied with "non repudiation".  But that's not the be all and end all. A digital signature is actually more complex than a handwritten 'legal' autograph; it allows all sorts of digital attributes to be baked into online transactions -- like credit card numbers, scheme membership, account numbers, qualifications, government IDs, whatever is relevant to a transaction, even personal properties like age or nationality as might be notarised by a trusted third party.

And thanks to PKI, digital signatures plus attributes can be processed in 'open' settings (and even offline!). In contrast, OTPs and all conventional two factor authenticators only work in closed 'hub and spoke' environments. 

So, for instance, an OTP generated by a Chip and PIN card and an un-connected reader is good for accessing my Internet bank account, but it cannot be recognised by anyone else, notably web merchants. However, my smartcard in a connected reader can allow me to send a notarised (digitally signed) copy of my credit card details to any merchant, to stop CNP fraud. 

In effect, a connected smartcard reader together with PKI could help make Card Not Present transactions over the Internet look much more like Card Present. 

Cheers,

Stephen Wilson.

 

01 May 2008 07:51 Read comment

Regulators chasing their tail over data security lapses
Dean Procter asked: "The question is, do you sell it to a bank or banks, buy a bank, become a bank or do it for all banks?"

I do believe the best hope for a solution to ID theft (including CNP fraud) is through safeguarding personal details in chips, be they EMV cards, SIMs, other smartcards, perhaps TPM chips [There are huge latent benefits to be had in applying government ID cards to secreting and notarising personal identifiers, protecting citizens from cyber crime, which would go a long way to redress community angst that ID cards don't really deliver much good to the individual.] 

But the most practical way forward, short term, would be for EMV card issuers to use their chips to secrete and notarise customer details for use online. Compared with using cards in unconnected readers to generate OTPs, this is a far more powerful and scalable way to leverage EMV cards into the online world. It could shore up 3D Secure (by hardening the personal details) or offer an alternative to 3D Secure, by sending notarised cardholder details direct from chip to merchant server. 

How to "sell it"?  EMV cards could be "Specially Personalised" [marketing speak!] for secure online payments, perhaps for a small fee levied annually against the cardholder.  Merchant sites could accept smartcard-notarised payments with very simple updates to their commerce servers.  For a bank to go ahead on its own with this, it might have to work with select merchants, through the acquiring side of its business, to have them preferentially accept such specially personalised cards (as opposed to regular CNP) for web transactions. Payment gateways could be important players; in many jurisdictions they act as systems integrators for merchant commerce servers, so they could make the necessary web site updates. 

Merchants, issuer and customers alike would all enjoy reduced exposure to fraud. Ideally that sort of proposition should 'sell itself' ;-)

Cheers,

Stephen Wilson.

 

01 May 2008 01:55 Read comment

  • 1
  • 14
  • 15
  • 16
  • 17
  • 18

Stephen writes about

  • security
  • payments
  • regulation & compliance

Stephen's opinion archive

  • 2012 (3)
  • 2011 (6)
  • 2010 (6)
  • 2009 (9)
  • 2008 (10)

Latest groups joined by Stephen

  • Online Banking

  • Transaction Fraud Systems and Analysis

See all groups joined

Stephen reads

  • Lockstep Technologies
  • Constellation Research
ShowHide similar members

Similar members

Stuart Adams

Stuart Adams
Managing Director at Adams Business Consulting

Follow Unfollow
Mike McCormack

Mike McCormack
Managing Director at PALMA ADVISORS LLC

Follow Unfollow
David Baxter

David Baxter
Managing Director at T-Scape

Follow Unfollow
Jonathan Duffy

Jonathan Duffy
Managing Director at Netclearance Europe

Follow Unfollow
Pierre Legrand

Pierre Legrand
Managing Director at Alvarez and Marsal

Follow Unfollow

Welcome to Finextra. We use cookies to help us to deliver our services. You may change your preferences at our Cookie Centre.

Please read our Privacy Policy.

Accept
Finextra

Finextra

  • About

Community

  • Rules
  • Contact the community team

News

  • Guidance
  • Contact the news desk

Sales

  • Media pack
  • Contact the sales team

Get involved

  • Finextra Live@
  • Webinars
  • Finextra TV
  • Research
  • Finextra.jobs

Events

  • Sustainable Finance Live
  • NextGen Nordics
  • EBAday
  • NextGen:AI
Join the community Register for news alerts
Apple App Store Google App Store

© Finextra Research 2025

Terms of usePrivacy PolicyCookie Centre