Does the Online Card Payment Landscape Unwittingly Facilitate Fraud?
- Submitting institution
-
The University of Kent
- Unit of assessment
- 11 - Computer Science and Informatics
- Output identifier
- 9710
- Type
- D - Journal article
- DOI
-
10.1109/MSP.2017.27
- Title of journal
- IEEE Security & Privacy
- Article number
- -
- First page
- 78
- Volume
- 15
- Issue
- 2
- ISSN
- 1540-7993
- Open access status
- Compliant
- Month of publication
- April
- Year of publication
- 2017
- URL
-
https://kar.kent.ac.uk/58364/
- Supplementary information
-
-
- Request cross-referral to
- -
- Output has been delayed by COVID-19
- No
- COVID-19 affected output statement
- -
- Forensic science
- No
- Criminology
- No
- Interdisciplinary
- No
- Number of additional authors
-
3
- Research group(s)
-
-
- Citation count
- 7
- Proposed double-weighted
- No
- Reserve for an output with double weighting
- No
- Additional information
- This paper demonstrates how a previously unknown systemic vulnerability in online payment can be exploited to mount a distributed guessing attack, allowing attackers to obtain all of a payment cards’ security data fields. This is significant because, after responsible disclosure, we notified 36 payment sites, and eight changed their procedures as a result.
- Author contribution statement
- -
- Non-English
- No
- English abstract
- -