Will Target Credit Card Disaster be the Tipping Point for Mobile Banking?

By

Target has managed to become the poster child for security ire, having lost around 40 million credit and debit cards. It's the latest documented breech of credit card security. Financial institutions have to be thinking how to migrate away from the increasingly exploited system of numbers, plastic and mag stripes, especially as lawsuits start arriving.

Credit card authentication has been lame for years, as my numerous credit card replacements over the past 24 months can attest.  A card is swiped or entered in on line, sometimes accompanied with a three (yes, 3 whole digits) security authorization number on the back.  The card number is run against a database to confirm the security authorization number along with the purchase amount -- mostly to see if you are up against your credit limit, and a cursory geographic check if it is an in-person purchase.   On-line purchases get scrubbed a bit more carefully with looks at with IP addresses and purchasing websites due to the anonymous nature of the Internet, but that's about the extent of additional verification.

For years, telecom carriers have dreamed about holding the mobile wallet, and fumbled through various iterations of offering financial services. The latest variation on the theme has been using NFC (near-field communications) to enable touch-payments with (presumably) better security.  On a larger scale, the phone can provide multiple physical bits to authenticate with including Wireless MAC address, IP address on a network, and phone number. 

The trick to more secure payments is combining the existing financial credit card verification system with the mobile world while keeping both sides separated as much as possible.  The credit/debit card industry would hold one authentication "keys" and the mobile phone network would hold the other one or ones.  Making a purchase would require the phone and credit card information.  In theory, the credit card numbers could/would reside on the phone, with separate processes validating the two pieces at the point of sale. A phone could be stolen, but only one phone or two phones would be uniquely mapped to a small set of accounts.

Further security could be encouraged by keeping credit card numbers separate from the phone, using a mag card swipe and a NFC tap or some other mechanism  (WiFi MAC query) to provide two-factor authentication with card and phone.  Additional protection is provided by keeping cards and phone separate; if one is lost, the other one can provide some funds while limiting bigger purchases and/or subject to increased scrutiny.

The final step in the process may be in providing multi-factor biometric authentication at point of sale.  Voice and finger prints may be possibilities, but a simple photograph of the card holder might be better and harder to defeat.  Rolling in face detection could provide a better -- but a bit more costly -- solution for kiosk sales, self-checkout and busy lines. 




Edited by Cassandra Tucker
Get stories like this delivered straight to your inbox. [Free eNews Subscription]

Contributing Editor

SHARE THIS ARTICLE
Related Articles

Why More Leads Won't Fix a Broken Lead Management Process

By: Contributing Writer    6/23/2026

When sales results start to stall, many organizations immediately look to the top of the funnel for answers. The assumption is simple: if revenue i…

Read More

Your Post-Quantum Readiness Starts at Y2Q Summit

By: TMCnet News    5/27/2026

Y2Q Summit is an executive conference focused on helping enterprises prepare for the coming era of quantum computing disruption, cybersecurity transfo…

Read More

Why Award Marketing Should Be Part of Every B2B Tech Company's Growth Strategy

By: Erik Linask    5/20/2026

Award marketing matters for B2B tech companies because industry recognition can strengthen trust, support sales and partner relationships, improve con…

Read More

Why Email Is Still the Most Underrated Layer of Modern Software Infrastructure

By: Contributing Writer    5/15/2026

Take, for example, the following scenario. A user requests a password reset, waits a few seconds, refreshes their inbox and nothing arrives. They try …

Read More

Jitterbit's Visionary Status Signals a Shift in the iPaaS Market

By: Contributing Writer    4/7/2026

As enterprise ecosystems grow more complex, integration has become less of a backend IT function and more of a strategic driver of business performanc…

Read More