<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Silver Tail Blog &#187; Cost of fraud</title>
	<atom:link href="http://silvertailsystems.wordpress.com/tag/cost-of-fraud/feed/" rel="self" type="application/rss+xml" />
	<link>http://silvertailsystems.wordpress.com</link>
	<description>Fighting against business logic abuse.</description>
	<lastBuildDate>Fri, 18 Dec 2009 12:11:53 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='silvertailsystems.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/577fb613fda4531b5f1cbba10427b2bb?s=96&#038;d=http://s.wordpress.com/i/buttonw-com.png</url>
		<title>Silver Tail Blog &#187; Cost of fraud</title>
		<link>http://silvertailsystems.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://silvertailsystems.wordpress.com/osd.xml" title="Silver Tail Blog" />
		<item>
		<title>The ROI of prevention vs. policy</title>
		<link>http://silvertailsystems.wordpress.com/2009/01/15/the-roi-of-prevention-vs-policy/</link>
		<comments>http://silvertailsystems.wordpress.com/2009/01/15/the-roi-of-prevention-vs-policy/#comments</comments>
		<pubDate>Thu, 15 Jan 2009 23:05:11 +0000</pubDate>
		<dc:creator>Laura Mather</dc:creator>
				<category><![CDATA[Cost of fraud]]></category>
		<category><![CDATA[Fraud]]></category>
		<category><![CDATA[Online Fraud]]></category>
		<category><![CDATA[Prevention]]></category>
		<category><![CDATA[policy]]></category>
		<category><![CDATA[ROI]]></category>

		<guid isPermaLink="false">http://silvertailsystems.wordpress.com/?p=143</guid>
		<description><![CDATA[Most websites and e-commerce businesses understand that there is an element to their transactions that involves professional fraud.  I&#8217;m not talking about the people who forget that they signed up for an online service and therefore do a chargeback on their credit card for their subscription.  Instead I&#8217;m talking about the criminal element that understands [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=silvertailsystems.wordpress.com&blog=5811723&post=143&subd=silvertailsystems&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Most websites and e-commerce businesses understand that there is an element to their transactions that involves professional fraud.  I&#8217;m not talking about the people who forget that they signed up for an online service and therefore do a chargeback on their credit card for their subscription.  Instead I&#8217;m talking about the criminal element that understands how to take advantage of a website for financial gain.</p>
<p>There are several ways to <a title="Internet Fraud" href="http://en.wikipedia.org/wiki/Internet_fraud" target="_blank">make money on websites</a>.  For example, if the website represents a financial institution, you could steal the password for someone&#8217;s account and try to move the money to your own account (or the account of a trusted partner).  If the website sells goods you could steal someone&#8217;s password and send yourself &#8220;gifts&#8221; (which you would likely later sell).  Or you could buy a stolen credit card, open a new account and send things to yourself, knowing that it is unlikely that the site would detect that they will not be paid for the goods until after they have arrived at your door.</p>
<p>By accepting that some part of their business is going to be fraudulent, many of these websites create policies of how to handle the fraud once it is reported and clean up the incidents after they occur.  That&#8217;s a simple enough formula.</p>
<p><img class="alignleft size-thumbnail wp-image-152" title="sherlock-holmes" src="http://silvertailsystems.files.wordpress.com/2009/01/sherlock-holmes.jpg?w=88&#038;h=96" alt="sherlock-holmes" width="88" height="96" />What if you could change the game, though?  What if you could detect the fraud as it is occurring and either prevent it from happening or take action quickly enough that your incurred losses are significantly reduced?  It seems like that is a no brainer.  Most websites would say &#8220;Of course I&#8217;d want to change my model such that I could prevent the fraudulent event from happening.&#8221;  Moving from this ideal to the reality can be tricky though.</p>
<p>The major complication comes from the fact that it can be difficult to justify the cost of implementing a new system.  In a hypothetical case, say there is already a system in place that costs $20k/month to deal with the fraud and absorb the fraud losses, and a prevention system will cost $200k to install and $4k/mo to use.  Given that the prevention system is so expensive, it can be difficult to justify spending money on the prevention system.  This is mis-leading for 2 reasons. First, as the bad guys are essentially &#8220;allowed&#8221; to perpetuate fraud (because the website does not try to prevent fraud but only tries to find it after the fact), the fraud will continue to grow and the website will become known as an easy target. Second, it&#8217;s important to consider the long term implications to the company.  A prevention system will significantly decrease the fraud losses experienced by the website and, given that customers will have many fewer negative experiences that they associate with the website&#8217;s site and brand, it is likely that the website will have improved customer loyalty and trust which often equates to more active customers and, therefore, a higher bottom line.  In the end, all of this can add up to a much higher return than focusing on cleaning up the damage after it has been done.</p>
 Tagged: Cost of fraud, Fraud, policy, Prevention, ROI <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/silvertailsystems.wordpress.com/143/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/silvertailsystems.wordpress.com/143/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/silvertailsystems.wordpress.com/143/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/silvertailsystems.wordpress.com/143/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/silvertailsystems.wordpress.com/143/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/silvertailsystems.wordpress.com/143/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/silvertailsystems.wordpress.com/143/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/silvertailsystems.wordpress.com/143/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/silvertailsystems.wordpress.com/143/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/silvertailsystems.wordpress.com/143/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=silvertailsystems.wordpress.com&blog=5811723&post=143&subd=silvertailsystems&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://silvertailsystems.wordpress.com/2009/01/15/the-roi-of-prevention-vs-policy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/ea92b086d3a5647be783f387715694ee?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Laura Mather</media:title>
		</media:content>

		<media:content url="http://silvertailsystems.files.wordpress.com/2009/01/sherlock-holmes.jpg?w=88" medium="image">
			<media:title type="html">sherlock-holmes</media:title>
		</media:content>
	</item>
		<item>
		<title>To lock or not to lock, that is the question</title>
		<link>http://silvertailsystems.wordpress.com/2009/01/13/to-lock-or-not-to-lock-that-is-the-question/</link>
		<comments>http://silvertailsystems.wordpress.com/2009/01/13/to-lock-or-not-to-lock-that-is-the-question/#comments</comments>
		<pubDate>Tue, 13 Jan 2009 19:52:22 +0000</pubDate>
		<dc:creator>Sherrick Murdoff</dc:creator>
				<category><![CDATA[Cost of fraud]]></category>
		<category><![CDATA[Fraud]]></category>
		<category><![CDATA[Online Fraud]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[password guessing]]></category>
		<category><![CDATA[Prevention]]></category>

		<guid isPermaLink="false">http://silvertailsystems.wordpress.com/?p=135</guid>
		<description><![CDATA[Many websites believe they have the problem of password guessing solved.  They do what is called &#8220;account locking&#8221;: if the customer enters an incorrect password X number of times &#8211; sequentially &#8211; the website locks them out.  The lockout can be for a specified amount of time or until they contact customer support to get [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=silvertailsystems.wordpress.com&blog=5811723&post=135&subd=silvertailsystems&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><img class="alignleft size-thumbnail wp-image-136" title="lock" src="http://silvertailsystems.files.wordpress.com/2009/01/lock.jpg?w=96&#038;h=96" alt="lock" width="96" height="96" />Many websites believe they have the problem of password guessing solved.  They do what is called &#8220;account locking&#8221;: if the customer enters an incorrect password X number of times &#8211; sequentially &#8211; the website locks them out.  The lockout can be for a specified amount of time or until they contact customer support to get their account unlocked.</p>
<p>I don&#8217;t have quantitative data on the number or percent of websites that use this approach, but I am encouraged to see that researchers and others are beginning to understand the <a href="http://www.pinkas.net/PAPERS/pwdweb.pdf" target="_blank">deficiencies of using this as a security mechanism</a>.  There are two main reasons why account locking doesn&#8217;t help with password guessing: negative customer experience and horizontal password guessing attacks.</p>
<p>The customer experience of account locking is important to consider.  Because security experts have encouraged people to have different passwords for all of their online accounts, consumers now must remember dozens of passwords.  When logging in to a particular website, it would not be uncommon for the average person to have to try several different passwords before they remember the one that is correct for that site.  In the case of account locking, it is likely that the consumer will get locked out of their account when they are trying their various passwords and this results in a negative customer experience.</p>
<p>The responses consumers have to getting locked out can vary.  On one extreme, the customer waits until the lockout period has ended (sometimes you know how long you are locked out, but a lot of times you don&#8217;t).  In the middle of the extremes, the customer either calls customer support or, in the case of a bank, goes to a brick and mortar branch of the bank to perform their transaction.  On the far end of the extreme, the customer decides to take their business somewhere else.</p>
<p>Although I have not seen hard data on the cost of account locking to websites and especially financial institutions, I&#8217;m guessing that the cost of the customer support calls, branch visits, and customer attrition are not negligible.</p>
<p>One bank tried a unique approach to avoid using password lockout. This was a bank implemented a <a title="CAPTCHA" href="http://en.wikipedia.org/wiki/Captcha" target="_blank">CAPTCHA</a> (the fuzzy numbers in the box you must type in to prove you are human and not a computer) for every login. They implemented the feature without any user testing thinking this would eliminate password guessing. They ended up with so much negative push back from their customers, they had to take the feature off. This was a clear case where the true cost of the solution (extreme negative customer experience, in this case) ended costing more than the problem (password guessing).</p>
<p>The second problem with account locking is that it doesn&#8217;t protect against horizontal password guessing attacks.  It&#8217;s true that if I decide I want to access Joe Smith&#8217;s account and I know Joe Smith&#8217;s userID, I can try lots of passwords on his account &#8211; and probably get locked out.  But what if I just want to get access to as many accounts as possible?  For example, say the limit for password tries before lockout is 5, I could try 4 passwords on lots of accounts.  If I did this for one day and then waited until the next day to try 4 new passwords on the same accounts, I might have a decent success rate.  And if I&#8217;m a smart bad guy and I know the most popular passwords on the Internet (see our <a title="What's your password?" href="http://silvertailsystems.wordpress.com/2009/01/08/whats-your-password/" target="_blank">earlier blog post</a> on how most bad guys already know this), then I will probably be even more successful.</p>
<p>In security, it&#8217;s always important to balance a negative customer experience with the amount of protection  gained.  In the case of account locks, I would say that there is more inconvenience being foisted onto consumers than the security increase warrants.  That doesn&#8217;t mean that websites shouldn&#8217;t protect against password guessing &#8211; they should.  But it would be better to do so in such a way that the system detects actual password guessing and responds to that.  This way the consumer is not inconvenienced and the bad guy is not able to take advantage of the system.</p>
 Tagged: Cost of fraud, password, password guessing, Prevention <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/silvertailsystems.wordpress.com/135/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/silvertailsystems.wordpress.com/135/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/silvertailsystems.wordpress.com/135/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/silvertailsystems.wordpress.com/135/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/silvertailsystems.wordpress.com/135/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/silvertailsystems.wordpress.com/135/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/silvertailsystems.wordpress.com/135/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/silvertailsystems.wordpress.com/135/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/silvertailsystems.wordpress.com/135/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/silvertailsystems.wordpress.com/135/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=silvertailsystems.wordpress.com&blog=5811723&post=135&subd=silvertailsystems&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://silvertailsystems.wordpress.com/2009/01/13/to-lock-or-not-to-lock-that-is-the-question/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9a4f40f1e603ec693ab9ec817a4ada9d?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">silvertail</media:title>
		</media:content>

		<media:content url="http://silvertailsystems.files.wordpress.com/2009/01/lock.jpg?w=96" medium="image">
			<media:title type="html">lock</media:title>
		</media:content>
	</item>
	</channel>
</rss>