<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: What&#8217;s in a 100 Million?</title>
	<atom:link href="http://eternallyoptimistic.com/2009/01/21/whats-in-a-100-million/feed/" rel="self" type="application/rss+xml" />
	<link>http://eternallyoptimistic.com/2009/01/21/whats-in-a-100-million/</link>
	<description></description>
	<lastBuildDate>Wed, 21 Apr 2010 14:34:25 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Bob Pinheiro</title>
		<link>http://eternallyoptimistic.com/2009/01/21/whats-in-a-100-million/comment-page-1/#comment-493</link>
		<dc:creator>Bob Pinheiro</dc:creator>
		<pubDate>Thu, 22 Jan 2009 17:25:14 +0000</pubDate>
		<guid isPermaLink="false">http://eternaloptimist.wordpress.com/?p=796#comment-493</guid>
		<description>Presumably at least some of these stolen credit card numbers were originally used in online credit card transactions.  While it may be difficult to ensure that merchants and credit card processors are taking adequate measures to secure this information, the ultimate goal is to prevent bogus payment transactions using the stolen information.

One solution to online credit card fraud has been around for a while, but isn&#039;t much used.  Single-use credit card numbers are offered by only a small number of banks, and aren&#039;t widely promoted.  One reason is that these single-use numbers are cumbersome to use:  you have to either download a piece of software and login to generate the numbers, or you have to login to the bank&#039;s website.  Then you must copy or drag the cc information to the merchant&#039;s payment page.  Most people won&#039;t bother, especially since consumers are generally not held responsible for fraudulent use of their credit cards.

Despite these disadvantages, there are at least two big advantages: since single-use cc numbers are good only once, it won&#039;t matter if they are stolen. Secondly, since authentication is required to generate them, there is less chance of unauthorized charges being made.  So merchants have some protection against financial loss due to chargebacks from the credit card company.

The use of managed Information Cards as a way to generate and deliver a single-use credit card number to a merchant during an online payment transaction might be a better way to get single-use cc numbers more widely used.  Provided of course that (a): the Information Card community can make Information Cards easy for consumers to obtain and use, (b) vendors of online shopping carts can be persuaded to incorporate the necessary processing for acceptance of the security tokens carrying the credit card information, and (c) credit card companies / banks support the use of managed Information cards for online cc payments, publicize their availability, and encourage their use by consumers.

Not a small set of challenges, but I think the ever-increasing number of data breaches presents some real opportunities for Information Cards to help prevent online identity and payment fraud.</description>
		<content:encoded><![CDATA[<p>Presumably at least some of these stolen credit card numbers were originally used in online credit card transactions.  While it may be difficult to ensure that merchants and credit card processors are taking adequate measures to secure this information, the ultimate goal is to prevent bogus payment transactions using the stolen information.</p>
<p>One solution to online credit card fraud has been around for a while, but isn&#8217;t much used.  Single-use credit card numbers are offered by only a small number of banks, and aren&#8217;t widely promoted.  One reason is that these single-use numbers are cumbersome to use:  you have to either download a piece of software and login to generate the numbers, or you have to login to the bank&#8217;s website.  Then you must copy or drag the cc information to the merchant&#8217;s payment page.  Most people won&#8217;t bother, especially since consumers are generally not held responsible for fraudulent use of their credit cards.</p>
<p>Despite these disadvantages, there are at least two big advantages: since single-use cc numbers are good only once, it won&#8217;t matter if they are stolen. Secondly, since authentication is required to generate them, there is less chance of unauthorized charges being made.  So merchants have some protection against financial loss due to chargebacks from the credit card company.</p>
<p>The use of managed Information Cards as a way to generate and deliver a single-use credit card number to a merchant during an online payment transaction might be a better way to get single-use cc numbers more widely used.  Provided of course that (a): the Information Card community can make Information Cards easy for consumers to obtain and use, (b) vendors of online shopping carts can be persuaded to incorporate the necessary processing for acceptance of the security tokens carrying the credit card information, and (c) credit card companies / banks support the use of managed Information cards for online cc payments, publicize their availability, and encourage their use by consumers.</p>
<p>Not a small set of challenges, but I think the ever-increasing number of data breaches presents some real opportunities for Information Cards to help prevent online identity and payment fraud.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bob Blakley</title>
		<link>http://eternallyoptimistic.com/2009/01/21/whats-in-a-100-million/comment-page-1/#comment-494</link>
		<dc:creator>Bob Blakley</dc:creator>
		<pubDate>Thu, 22 Jan 2009 00:28:28 +0000</pubDate>
		<guid isPermaLink="false">http://eternaloptimist.wordpress.com/?p=796#comment-494</guid>
		<description>The real costs are even higher than those associated with reissuing cards; when merchants are presented with counterfeit cards produced with the aid of information obtained fraudulently as in this case, they often have literally no way of detecting that the cards are bogus - but they are still held responsible for the cost of the stolen merchandise under their credit card agreements.  So this sort of incident can be very damaging to businesses who rely on credit cards.</description>
		<content:encoded><![CDATA[<p>The real costs are even higher than those associated with reissuing cards; when merchants are presented with counterfeit cards produced with the aid of information obtained fraudulently as in this case, they often have literally no way of detecting that the cards are bogus &#8211; but they are still held responsible for the cost of the stolen merchandise under their credit card agreements.  So this sort of incident can be very damaging to businesses who rely on credit cards.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
