Sunday | 7 September, 2008
Computerworld
New PayPal key to help thwart phishers
To fight phishing, PayPal plans to introduce a new two-factor authentication system called the PayPal Security Key
Computerworld Buyer's Guide - Vendors Matched to this Article
Related Features
  • +

    Your World. . . Hacked 02/10/2007 10:51:23

    As your business becomes more collaborative and global, the risks to your company’s trade secrets rise proportionally. Fortunately, there are new strategies to protect the data that allows you to compete
    The call to Bob Bailey, an IT executive with a major US government contractor, came on an otherwise ordinary day in October 2003. "Why are you attacking us?" demanded the caller, an IT leader with a Silicon Valley manufacturer. He wanted to know why Bailey's company had launched a denial-of-service attack against his network
  • +

    Strategies for Dealing With IT Complexity 24/12/2007 10:30:47

    Every innovation, every business process improvement, comes with an IT complexity tax that must be paid by CIOs in time, money and sweat. Here are strategies to mitigate the increasing complexity of IT as it enables new business.
    Every innovation, every business process improvement, comes with an IT complexity tax that must be paid by CIOs in time, money and sweat. Here are strategies to mitigate the increasing complexity of IT as it enables new business.
Additional Resources
Executive Guides
Whitepapers
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.

Newsletter Subscription

Sign up for our Computerworld newsletters!
Computerworld's twice-daily news service keeps you in touch with the latest, most important headlines from Australia and around the world.
Keep up with the latest virtualisation technologies, products, news and features.
RSS Feeds

Over the next few months, Ebay will be offering its PayPal users a new tool in the fight against phishers: a US$5 security key.

The PayPal Security Key is actually a small electronic device, designed to clip on to a keychain, that calculates a new numeric password every 30 seconds. PayPal users who sign up to use the device will need to enter their regular passwords as well as the number displayed on the key whenever they log in to the online payment service.

"The key is really going to give users one more layer of security for their accounts," said Sara Bettencourt, a PayPal spokeswoman.

Because the numeric password changes so frequently, even successful phishers will end up with obsolete numeric passwords and will be unable to empty PayPal accounts.

"If you fall for a phishing scam and give away your user name and password ... if you used the PayPal Security Key, a third party couldn't get to your account because they wouldn't have this dynamic digit," Bettencourt said.

The Security Key could be an important tool for PayPal, whose Web site is frequently spoofed by phishers looking to steal user account information.

The PayPal Security Key is being tested by PayPal employees right now, and the test will be opened up to beta users in the U.S., Germany, and Australia "in the next month or so," Bettencourt said. Later this year, the company plans to begin promoting the devices to all PayPal users. News of the new PayPal system was first reported on AuctionBytes.com

PayPal users who want this extra level of security will be able to buy the devices for US$5, but this fee will be waived for PayPal business accounts.

PayPal's device is based on VeriSign's One-Time Password Token product, which is also being tested by Charles Schwab & Co. and U.S. Bancorp.

ETrade Financial also uses a similar system, based on RSA Security's SecurID tokens.

Over the past year, online financial companies have paid more attention to authentication technologies such as the VeriSign tokens, which add a second layer of authentication to online transactions. Adoption of these "two-factor" authentication techniques has been further boosted by new federal guidelines, which require stronger authentication for online transactions.

Still, phishing attacks are becoming increasingly lucrative for criminals.

Research company Gartner estimates that phishers cost U.S. financial institutions about US$2.8 billion last year. The average loss per phishing attack was US$1,244, up from US$256 in 2005.

Computerworld Buyer's Guide - Vendors Matched to this Article
Market Place

Computerworld Member Login


 

Prioritizing Services with IT Service Management (ITSM)

Computerworld Live Webinar
Wednesday 20th, August 2008
11:00am EST (Sydney, Australia)

To be repeated on:

Thursday 4th, September 2008
11:00am EST (Sydney Australia)

Sign up and receive a free copy of The Forrester WaveTM Service Desk Management Tools, Q2 2008 at the conclusion of the Webinar.

Attend and discover:

  • How to deliver value to your business through ITSM
  • Best practice ITSM implementation
  • Why emphasis is changing from optimizing IT management processes to better servicing customers and demonstrating real dollar value
  • If service-oriented ITSM is best for your business
Whitepaper

Best Practice in Building an Integrated Information Management Strategy

Discover the business value that creating an integrated information platform can bring. Learn how to provide consistent, accurate information to all stakeholders within your business network. Integrate vital data from disparate sources and deliver a trusted information foundation. Read on to uncover the stepping-stones to your new information management strategy.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links