‘Stronger’ Strong Customer Authentication Boosts Fraud Prevention (Infographic)
PSD2, also known as the Payment Service Providers Directive (PSPD), has been implemented in European countries. There are several issues merchants and issuers will need to address to make this work. Due to long cycles and high implementation costs, e-commerce has high abandonment rates, and fraud can still happen even with strong customer authentication methods.
PSD2 Requirements for Strong Customer Authentication
There are two types of requirements for strong customer identification solutions under the PSD2 provisions. Articles 6, 7, and 8 describe the need for multi-factor authentication and passwordless authentication ux that should include a minimum of two of the following elements.
- Something known – PIN or a password
- Something owned – mobile phone, laptop, security key
- Something you are – a biometric like a fingerprint or face ID
Article 9.3 describes the second category that explains the requirement of authentication devices to maintain an independent relationship between various authentication methods. It includes the provision that two authentication elements are not interacting.
Vulnerabilities of Strong Customer Authentication
Even with strong customer authentication, hackers and fraudsters can still get to your information.
- Phishing is also known as social engineering. It’s a method that attempts to get people to give out personal information, such as usernames or passwords, by sending them emails or SMS to their bank accounts.
- SIM Swapping refers to the act of pretending to have a mobile phone and calling the company. The fraudster then lies to the phone company, claiming a new SIM to activate the account. The fraudster then uses this fake SIM to intercept OTP (one-time passwords) via SMS.
- Malicious accessibility, also known as the zero-day exploit, is when hackers exploit known and unknown vulnerabilities. This primary means of bypassing strong customer authentication allows hackers to exploit the vulnerability before fraud prevention actions or measures can be taken.
For more information on strong customer authentication and how it boosts fraud prevention, you can head over to Login ID.