Sunday | 21 March, 2010
CSO
PayPal CISO outlines antifraud strategy
What PayPal is doing to combat online fraud
Ellen Messmer (Network World) 15/02/2007 12:43:18

PayPal has 133 million customers that use its Internet-based money-transfer service, which handled US$37 billion in transactions last year. Michael Barrett, who is CISO at the eBay subsidiary, recently spoke with Network World senior editor Ellen Messmer about new approaches PayPal is taking to combat online fraud.

Almost every day I get a fake PayPal e-mail that's obviously a phishing scam. How do you deal with this phishing fraud or even use e-mail to communicate with PayPal customers?

There's a lot of spoofing of eBay.com and PayPal.com. We get e-mail from customers asking questions about this and other topics and we respond within 15 minutes. We use our own Web-based e-mail to communicate. The problem with phishing and spoofing generally is there's no magic bullet. So it's classic defense in depth.

How much fraud hits PayPal each year?

As a class of operational loss, it's 0.41 percent. In the industry, that's known as 41 basis points, which is pretty low. When our customers are victimized, their user ID and password are compromised, we compensate them.

What are some of your defensive strategies?

If the consumer actually never actually saw the phish e-mail, it's hard for the criminal to victimize you. We're working with people who make e-mail clients and the ISPs, such as Yahoo, MSN and AOL, on a technical strategy that says if the e-mail is not signed by us, drop it. We're having good discussions, but we have nothing to announce now.

What specifically do you do today?

We believe in consumer training, and we have a "Think before you click on a link" program. We've also begun supporting the Extended Validation SSL certificate for safe browsing, which gives consumers the green glow in the Internet Explorer 7 browser. The Internet Explorer 7.0 antiphishing filter works very well with black lists of sites updated regularly. If there's a big red URL bar, you're attempting to browse a URL site it would recommend you not.

This week we're also launching the PayPal Security Key in the United States, Australia and Germany. You log on with your PayPal ID and password and then also use a dynamic password generated by a keyfob made by VeriSign. Use of this is voluntary and we're supplying the keyfob on request for a nominal $5 charge, which doesn't even cover the cost. It will even be free for certain business customers, and we may decide it's mandatory for specific business segments.

Are there changes in general you think would help combat online fraud, which is global in nature?

There's a lot of fraud here, a lot in Eastern Europe and elsewhere. We have a large team of fraud investigators at both eBay and PayPal. It would help if there were harmonization of laws internationally in sentencing guidelines. There is simply a patchwork of laws everywhere.

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

More information about formatting options

Enter the fully qualified URL, eg. http://www.example.com/
Users posting comments agree to the CSO Online comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
PayPal CISO, Michael Barrett
PayPal CISO, Michael Barrett
Additional Resources
Newsletter Subscription
Sign up for our CSO Online newsletters!
RSS Feeds
Syndicate content
 
Whitepaper

Making the move to Ethernet | A DECISION GUIDE

While enterprises today need higher bandwidth, there is increasing demand for solutions that can provide scalability, performance, simplicity and control at lower costs. Get the best of both worlds - read about Ethernet adoption today.

Sponsored Links