Close
  • Latest News
  • Artificial Intelligence
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity

    PayPal Security Chief: User Education Remains Greatest Hurdle

    By
    Matt Hines
    -
    February 9, 2007
    Share
    Facebook
    Twitter
    Linkedin

      SAN FRANCISCO—A sleek, silver, nearly weightless gizmo that fits in your hand represents the next generation of security for customers of eBays PayPal division.

      The diminutive machine is a wireless password-generation device that the company plans to begin distributing to its users beginning on Feb. 12 to help its customers further validate the authenticity of the online payment system— a product of necessity to help fight the litany of phishing attacks and fraud schemes that seek to rip-off PayPals more than 130 million registered members.

      Depressing the single button on the oval handheld, which is roughly the size of a pack of gum, produces a one-time password that PayPal users will be able to enter into its Web pages to ensure they are not instead logging onto one of the legions of fake URLs created by fraudsters to steal the San Jose, Calif.-based companys customers screen names, passwords and money.

      Yet, despite the pending launch of the next generation of PayPal security, Michael Barrett, the companys chief information security officer, admits the online payment leader will still be troubled by phishing and other attacks.

      In addition to the fact that use of the password devices, manufactured by Mountain View, Calif.-based VeriSign, wont be mandatory, and Barrett has no expectation that all of PayPals customers will want to employ the extra step for protecting their accounts, the CISO knows that no matter how hard the company works to arm its users with such tools and educate people about the dangers of online fraud, there will still be plenty of individuals who fall for the schemes.

      The biggest challenge faced by the company in the realm of security remains the very process of teaching its customers what not to do when conducting business online, Barrett said, and he knows that among the massive user base there will likely always be those who dont get the picture.

      /zimages/1/28571.gifPayPal and eBay remain top phising targets. Click here to read more.

      “There are so many people that reaching everyone is very difficult, and that alone may always remain the hardest part of protecting the customer,” said Barrett. “The trick is that there is no silver bullet for this process, and we will need to offer a range of solutions and programs to help get the word out; its really less about firing one bullet into the air than filling it up with a lot of buckshot.”

      /zimages/1/164826.jpg

      Despite his concession that there will likely always be new security challenges, especially as malware writers and online criminals continue to devise new methods for defrauding his customers, Barrett claims he is encouraged about the state of PayPals defenses, even though there is much work he still wants to get done.

      Beyond arming users with the password fobs, which will be offered for no charge to PayPals business customers and at a price of $5 apiece to consumers, the security chief said that his company will seek out new ways to help stop the e-mail campaigns that phishers use to lure people to their sites. The effort will include partnering with major Webmail providers such as AOL, Google and Yahoo to help those companies filter out spam messages before they ever reach users in-boxes.

      Next Page: Other security strategies.

      2

      Using anti-spam tools that include features that specifically seek out fake eBay and PayPal messages could provide a significant improvement by choking off the primary marketing tool of its adversaries, and the executive said his company can drastically reduce the number of unhappy customers calling to report that theyve been duped into handing over their credentials.

      All of PayPals legitimate e-mail is already identified with unique digital signatures.

      “If customers never see the phishing e-mails in the first place, its a lot harder for them to be victimized,” Barrett said. “Were working with all the major e-mail vendors to help raise the status of the security problem. If they see anything with our name on it that doesnt have a signature, were telling them to drop it.”

      PayPal is also pursuing a wide range of other security strategies in the name of creating a defense-in-depth approach for protecting its customers. These include the use of new EV SSL (Extended Validation Secure Sockets Layer) digital certificates, which will provide users with visual cues in browsers such as Microsofts new Internet Explorer 7 to let them know when theyre on a fake site.

      To fight attacks such as cross-site scripting, which have corrupted PayPals legitimate URLs in the past, Barrett said the company is working hard to make sure that its software developers avoid any vulnerabilities in writing and reviewing the millions of lines of code that make up its site.

      Behind the scenes, the company is deploying real-time fraud-monitoring tools that watch out for suspicious behavior on its pages and using data-matching techniques to help identify transactions that might indicate the use of hijacked accounts.

      Outside the world of technology, PayPal is working more closely than ever before with law enforcement officials, particularly in the United States, although the process remains hard because local, state and federal authorities have so much work on their plates—and thieves have deduced they are less likely to be caught if they pull off larger numbers of smaller heists that make it harder for PayPal and the police to discover them and bring charges.

      While he remains somewhat frustrated by the lack of government resources dedicated to fighting online fraud, Barrett said hes hopeful that politicians and regulators will ramp up their efforts, and PayPal is working actively to advocate stronger penalties for cyber-criminals.

      “Working with law enforcement has improved, but it could be better, in particular in the sense that they look at relatively high fraud loss limits before taking interest in prosecution,” he said. “But this isnt a problem thats just about the U.S.; its hard to get very far into fighting things internationally before you find yourself getting into deep legal conversations over jurisdiction.”

      PayPal is also trying to exert pressure with legislators on Capitol Hill, where he believes progress may be in the making, despite recent setbacks.

      “We thought the laptop theft at the Department of Veterans Affairs might have helped more to that end, but then they got it back, and its been sort of quiet,” Barrett said. “One of the interesting things were waiting to see is if the new Congress takes up ID theft legislation; weve been waiting for that for a long time.”

      Check out eWEEK.coms Security Center for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEKs Security Watch blog.

      Matt Hines
      Get the Free Newsletter!
      Subscribe to Daily Tech Insider for top news, trends & analysis
      This email address is invalid.
      Get the Free Newsletter!
      Subscribe to Daily Tech Insider for top news, trends & analysis
      This email address is invalid.

      MOST POPULAR ARTICLES

      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Applications

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Applications

      Kyndryl’s Nicolas Sekkaki on Handling AI and...

      James Maguire - November 9, 2022 0
      I spoke with Nicolas Sekkaki, Group Practice Leader for Applications, Data and AI at Kyndryl, about how companies can boost both their AI and...
      Read more
      Cloud

      IGEL CEO Jed Ayres on Edge and...

      James Maguire - June 14, 2022 0
      I spoke with Jed Ayres, CEO of IGEL, about the endpoint sector, and an open source OS for the cloud; we also spoke about...
      Read more
      IT Management

      Intuit’s Nhung Ho on AI for the...

      James Maguire - May 13, 2022 0
      I spoke with Nhung Ho, Vice President of AI at Intuit, about adoption of AI in the small and medium-sized business market, and how...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2022 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×