According to Abrazhevic, one of the most crucial and well-researched issues in payment systems is security. Since the Internet is an open network with no centralized control, the infrastructure supporting electronic commerce and payment systems in particular, must be resistant to attacks in the Internet environment[1].
Payment Card Fraud: Examples from Recent Cases
Managing payment card fraud can be challenging for financial institutions. Chip based or EMV[2]payments were a big step forward from magnetic stripe card payments. Magnetic stripes can easily be copied but it is impossible to clone the chip, therefore chips based cards increase security and reduce fraud resulting from counterfeit, lost and stolen cards. While almost all terminals in Europe are chip-enabled, the US is one of the last countries to migrate to EMV chip technology[3]. However chip cards will not end fraud. As seen in Europe, where chip cards already are standard, fraudsters shift focus to card-not-present[4]transactions instead.[5]
In the middle of July 2015, parallel with launching Apple Pay in the UK, some UK papers reported that contactless payment cards in our pocket might not be as secure as we assumed[6]. According to the article, agroup of guys was able to use an “easily and cheaply” acquired card reader to successfully retrieve the 12-digit card numbers and expiry dates from 10 cards. Despite this, they weren’t able to obtain the three-digit verification code on the back of the cards. Surprisingly with these data and with the help of a fake name, they were able to put in an order on Amazon for a $4,000 TV.
Figure 1 below shows the credentials required when purchasing via Amazon.
Figure 1.
Cardholders will realize missing cards in a relatively short time, but it is almost impossible to detect if card data are compromised i.e if someone got unauthorized access to card data especially if the card is in our pocket. If the card is used for small amount illegal purchases and the card holder is a regular user of Amazon the card holder will not notice that money is siphoned out of his account.
Contactless payment cards cannot be switched off, it will give full customer details unencrypted if a point of sale (POS) terminal or a smartphone initiates a question without any validation or authorization. Someone with malicious intent could easily rake a small fortune each day by brushing past people on a bus and skim lots of cards while they are in the pockets and wallets. Many fraudulent transactions do not get noticed until things have spiraled way out of control.
Two important liability issues should be mentioned regarding contactless payment cards. Firstly, if the CVC2/CVV2 authentication procedure exists, why isn’t it obligatory for all merchants? Secondly, if card issuers and banks regard bank account numbers and expiration dates as a public data not requiring protection, then why not use a secret password that would serve as a second factor to protect users’ money? Actually there is the PIN, however this is not required during online transactions.
Strong Customer Authentication in PSD2 and in the EBA Guidelines
EBA gained importance in the surveillance of PSD2 requirements and is entitled in - close cooperation with the ECB - to develop technical standards on the requirements of strong customer authentication[7].
EBA published its final guidelines on the security of internet payments on 19thDecember 2014[8]. These guidelines are based on the recommendations of the European Forum on the Security of Retail Payments (SecuRe Pay) a voluntary cooperative initiative set up by the ECB and comprising relevant authorities from the EEA. Interestingly, these guidelines touched sensitive points including strong customer authentication also covered by PSD2. Furthermore, EBA required that these guidelines should be applicable as of 1st of August 2015, before the acceptance of PSD2. This raised some concerns between different stakeholders including MasterCard and small firms in the UK. FCA even made public its views on its website: \"We do not have the power without legislative change to make binding rules requiring all payment service providers (credit institutions, payment institutions and e-money institutions) to comply with the EBA Guidelines”. MasterCard complied a FAQs on its website informing its customers on the applicability of the EBA guidelines and their relation to PSD2 not yet in force[9].
EBA is a regulatory agency of the Commission it does not possess legislative power. The technical standards drafted by EBA (based on the empowerment in PSD2) only have binding effect and direct applicability for Member States once endorsed by the Commission. The EBA’s guidelines however are “binding” for those competent authorities to whom the guidelines apply and they should comply by incorporating them into their supervisory practices as appropriate[10]. This procedure is often called “implement or explain” meaning that it is possible for competent authorities to decide not to comply with the guidelines. For example the UK opted out explaining that “it does not have the power without legislative change to make binding rules requiring all payment service providers (credit institutions, payment institutions and e-money institutions) to comply with the EBA Guidelines”[11]. The Swedish Financial Supervisory Authority reported that it will comply with all guidelines, except the strong customer authentication requirements for card payment schemes and providers of wallet solutions[12].
In terms of PSD 2 and the EBA Guidelines strong customer authentication means an authentication based on the use of two or more elements categorized as
1. knowledge (something only the user knows e.g. PIN),
2. possession (something only the user possesses e.g. token) and
3. inherence (something the user is e.g. fingerprint or retina)
that are independent, in that the breach of one does not compromise the reliability of the others and is designed in such a way as to protect the confidentiality of the authentication data[13]
A sophisticated technology may fail if the customer is not able to handle it with ease[14]. In 2014 during the EBA consultation period, MasterCard raised its concerns about the strong customer authentication requirement in the draft EBA guidelines[15]. MasterCard highlighted that the EBA guidelines do not observe customer convenience in other words “the guidelines impose additional heavy and awkward authentication procedures for customers which may end up discouraging them from using internet payments”[16].
In MasterCard’s opinion strong customer authentication should be optional for payments whose risk is not high. The reason for this is very simple. Generally it is the card issuer PSP which is liable in case of fraud. When a PSP is prepared to bear liability in case of fraud that PSP should be permitted to decide which level of authentication to apply (strong or risk based) provided that the card issuer respects some minimal authentication guidelines. Therefore there is no need to mandate upon card issuing PSPs a strong authentication requirement on every transaction when they bear the risk of fraud[17]
Ecommerce Europe confirmed the above: “the new authentication rules could stifle innovation in the area of digital payments. Multifactor authentication has a huge impact on conversion for merchants, as many consumers will leave the check-out process when payment becomes too complicated.”[18]
It seems that not only customer convenience but also liability and its financial consequence was the real reason for MasterCard to vote for less stringent authentication requirements. According to Article 66 1c of PSD2:
“Where the payer\'s payment service provider does not require strong customer authentication, the payer shall only bear any financial consequences where having acted fraudulently. Should the payee or the payment service provider of the payee fail to accept strong customer authentication, they shall refund the financial damage caused to the payer’s payment service provider.”
If PSPs fail to apply strong customer authentication they shall bear full liability except if the payer acted fraudulently. According to Ecommerce Europe “if PSPs do not perform strong authentication they are liable and liability does not shift to the merchant when he chooses not to authenticate while the PSP is offering it. This is a change from today where the merchant is liable when no authentication is used. However, failing to do so might eventually lead to the merchant losing its contract with the PSP”[19].
Nevertheless it seems that EBA followed the above advice of stakeholders, because the final guidelines were incorporated in such a way that it made possible the consideration of alternative authentication measures for pre-identified categories of low-risk transactions e.g. based on transaction risk analysis or involving low value payments[20].
Source of picture: socialcustomer
[1] Dennis Abrazhevich, Electronic Payment Systems: a User centered perspectiveand Interaction Design (Technische Universiteit Eisndhoven, 2004) p.36
[2] EMV is an abbreviation for Europay, Mastercard and Visa. The EMV specifications were developed to define a set of requirements to ensure interoperability between chip-based payment cards and terminals. EMV chip cards contain embedded microprocessors that provide strong transaction security features and other application capabilities not possible with traditional magnetic stripe cards. http://www.emvco.com/
[4] A card not present transaction is a payment card transaction where the holder cannot physically show the card for visual examination when payment is effected (e.g transactions over the phone, the internet or by mail.)
[5] ECB (July 2015) „Fourth Report on Card Fraud”
[6] http://gizmodo.com/contactless-payment-cards-are-perhaps-not-as-secure-as-1719690656
[7] Article 87a1.a of PSD2
[8] http://www.eba.europa.eu/regulation-and-policy/consumer-protection-and-financial-innovation/guidelines-on-the-security-of-internet-payments
[9] http://newsroom.mastercard.com/wp-content/uploads/2015/07/FAQ-EBA-guidelines.pdf
[10] EBA, Final guidelines on the securty of internet payments p 8.
[11] EBA,Compliance Table - Guidelines - Based on information supplied by them, the following competent authorities comply or intend to comply with: EBA Guidelines EBA/GL/2014/12 on the security of internet payments, published on 19th December 2014.
[12] Ibidem.
[13] Article 4 22. Of PSD2
[14] Wen-Chen HU,Chung-wei Lee & Weidong Kou, Advances in Security and Payment Methods for Mobile Commerce (Idea Group Publishing, 2005) p. 210
[15] Mastercard (2014) „Mastercard’s comments on the EBA Consultation Paper on the implementation of draft EBA guidelines on the security of internet payments prior to the transposition of the revised Payment Services Directive (PSD2)”
[16] Ibidem.
[17] Ibidem.
[18]Ecommerce Europe (2015) “Stronger consumer authentication for online payments needed as of 1 August 2015”
[19] Ibidem.
[20] EBA, Final guidelines on the securty of internet payments, Section 7.5




