Sunday, July 29, 2012

Unverified by Visa

It's been a long while since I last wrote scathing reviews about security nightmares (or, worse than that, misunderstood security "precautions"), and of all possible companies that could have annoyed me enough to take up the blogging again, it's Visa that made me return. Yes, Visa, the credit card company. Visa, the company that holds some of my most sensitive information.

What happened?

"Verified by Visa" happened.

In particular, the "personal security message" that they use.

Visa is kindly explaining to you how it is supposed to work:
http://www.visaeurope.com/en/cardholders/verified_by_visa.aspx

My favourite line:
"First you’ll see the personal message that you provided when you signed up for Verified by Visa and that only you and your bank know about. This lets you know that the security screen you’re seeing is genuine."

What an excellent idea!

Here is how I think it is supposed work:
  • You put stuff into your cart at, say, Amazon, and proceed to order it.
  • You enter your credit card number, expiration date and the security code on the back of the card. (That's the amount of security you get without the special "Verified by Visa" treatment, meaning that pretty much anyone who steals your card can immediately use it for shopping online.)
  • You are forwarded to the "Verified by Visa" page, shown your personal message (that only you and your bank know about), can deduct from the message that the input screen is genuine, and enter your password.
  • The transaction is complete.

Let me go off on a tangent and explain why it's so important to know that the screen is genuine if, after all, this does not prevent the shop you are giving money to from being fraudulent.

Let's say you are not shopping at Amazon.com, but at Shady.org. They have the best offers you can imagine, and perfect user reviews. Except that they will never actually send you anything you order, nor are any of their user reviews genuine. In fact, Shady.org only does two things:

One, it has a lot of fake offers. You order a new flat screen TV for only 300€ from them, pay them their money, the TV never arrives, and by the time you notice, the company does not exist any more.

And two, they steal credit card information. You order some cheap items from them, enter your credit card number, expiration date and security code to pay for them, and indeed you receive your items shortly after. However, Shady.org now knows all they need about your credit card in order to go shopping with it themselves now.

"Verified by Visa" can't do anything to protect you from the former.

"Verified by Visa" can do a lot to protect you from the latter. That's because only you and Visa know your password. After entering the other three pieces of data (card number, expiration date, security code), you are forwarded to a security input screen that is owned, hosted and resolved by Visa themselves. The only way for Shady.org to use your credit card information would be if they managed to steal the password as well.

And that is where the whole wonderful system is falling apart. Because there is no way for you to know whether the password entry field is genuine or a phishing version.

"But the personal security message!" you might yelp. "Only Visa and I know it!"

Riiight, let's have a look at that. What exactly did you need in order to get to a screen that shows you your security message? Credit card number, expiration date and security code? What did you just give Shady.org?

Someone clearly has not thought that one through to the end.

Without using any form of cryptographic protocols, there is no way, I repeat: no way to prove, using only plain text messages, that what you see is genuine. (Yes, they could simply use proper security certificates like everyone else instead of these "security messages", but Visa is already in a lot of hot water for not implementing those properly either[1].)

"Well, okay, so it's completely useless" you might say, "but it does not do any harm either, does it?"

Yes, yes it does. Because the only thing that is worse than no security is wrong security. Riddle me this: What will you tell your child on the first day of school? "Never go with any strangers"? Or "Never go with any strangers unless they know your name"?

And still, all of that would not yet have sent me seething. What triggered this little rant was that on www.cardcomplete.com/umsatzabfrage, you can enter any credit card number and immediately get the corresponding "top secret" security message that "only you and your bank know about". Way to go, Visa. Way to go.

[1]http://en.wikipedia.org/wiki/3-D_Secure#Verifiability_of_site_identity

Sunday, May 1, 2011

On chains and dumbest links

And yet another picture that's worth a thousand words:


-- Birgit

Wednesday, April 20, 2011

On chains and weakest links

A picture is worth a thousand words:

white trash repairs - Flawless


-- Birgit

Saturday, March 19, 2011

Cisco Security Training

For the greater good of humankind (and to demonstrate the effectiveness of their security training), Cisco chose to publish a rather comprehensive article about security education:

http://www.cisco.com/web/about/security/cspo/awareness/index.html


-- Birgit

Sunday, February 27, 2011

Fast forward to failure

Not so long ago, I moved to a new flat. Since I still needed to receive postal mail sent to my old address, I chose to use the mail forwarding service of the German post company.

Requesting your mail to be forwarded can be done easily via the homepage of the German post company: You need to give your old address, the address that the mail should be forwarded to, as well as your bank account number from which the service fee will be withdrawn automatically.

Simple enough. Even for someone who isn't you.

There have been quite a few cases of fraudulent use of this service in the past, most often committed by angry ex-partners or particularly creepy stalkers. But there have also been a few cases already where a fraudster had someone's mail rerouted just in time to receive new debit cards, credit cards, the corresponding PINs, and all kinds of other stuff to cause major financial damage with.

Having realized that this forwarding service might therefore constitute a minor security issue, the German post company decided to prevent this kind of fraud by sending an information letter to the original address whenever a mail forwarding request is received, saying something along the lines: "In order to prevent fraud, we are hereby informing you that a mail forwarding service has been requested for your address, and that from now on all your postal mail will be forwarded to the new address given below. If you did not initiate this yourself, please contact us immediately." This ensures that in case of an illegitimate request, the victim is at least aware of the situation and can take steps to cancel the forwarding service and possibly prosecute the offender.

Guess what?

That information letter was forwarded to my new address.

-- Birgit

Monday, February 21, 2011

Half security is no security

Let's start with an example:

For various goods there are those special anti-theft-tags used in shops to prevent people from shoplifting. Most frequently they are used for CDs and clothing.

Now, often these tags themselves cost quite a bit of money. After all, they usually contain some kind of sender as well as an intricate system that allows easy removal with the correct tools, but at the same time has to make removal without those tools as hard as possible.

Not to mention that they frequently get lost, damaged, or [ironically] stolen.

In short, anti-theft-tags are an important cost factor in any anti-theft system.

A fact to which some managers have rather peculiar solutions. I wish I could explain their reasoning, but I'm at a loss for even remotely comprehensible explanations. I'll therefore stick with the observable facts: Once in a while, I walk into a shop and notice that roughly every second or every third item in a shelf is tagged with an anti-theft-tag, while the rest is not. And I don't mean that pricey items are tagged and cheap ones aren't -- no, of exactly identical items, only every second is tagged.

What are they thinking?

That they could at least get half the possible security out of it?

That there would be a 50% chance that a thief would pick one of the tagged items?

That this [alleged] risk would prevent thieves from even trying?

Dear shop managers, I shall enlighten you, free of charge, with one of the most basic principles of ... well, common sense: If there are two identical items, and one has a huge anti-theft-tag on it and the other hasn't -- guess which one a thief will take? (Take three guesses if you have to.)

The moral of the story: There is no such thing as half security. It's like locking the left car door and leaving the right one wide open. Or hiding top secret documents in a safe and leaving a copy on the copy machine. Or using half a condom. Or guarding a prison exit door only in the afternoon. Or ... Well, you get the idea.

If there are two ways, there's simply no point in securing only one of them.

-- Birgit

P.S.: More examples of this are sure to follow. I wasn't surprised that it happens at all, but I'm surprised time and again about how frequently it happens.

Thursday, February 17, 2011

Terrorists, this way please!

Somewhere on the Zürich Airport...


... in the baggage claim area ...


... you will find the following sign on one baggage conveyor belt:


Roughly translated:

"To all employees in the customs hall / local unloading point:

Crossing from the customs hall to the local unloading point via this conveyor belt for bulky baggage is strictly prohibited for all persons!!!

A violation of this regulation is considered a circumvention of the security check and will be punished with 8 points and a 14 days revocation of your employee ID!!!
"


Well, why not directly put up a sign saying:

Dear Terrorists!

If you wish to secretly gain access to the most security critical parts of this airport, please feel free to use this huge gaping hole in our security concept to circumvent security checks."

Best regards,
Airport Security

On the upside, at least they don't seem to indulge in security by obscurity.

-- Birgit




(First picture courtesy of the Wikimedia Foundation: http://commons.wikimedia.org/wiki/File:LSZH_UniqueAirportCity_001.png)