Research on Security and Problems in Credit Card Online

Research on Security and Problems in Credit Card Online Transaction
Research on Security and
Problems in Credit Card Online
Transaction
Author: Tan Kong Han
Session: 2002/2003
The candidate confirms that the work submitted is their own and the appropriate credit
has been given where reference has been made to the work of others.
I understand that failure to attribute material which is obtained from another source may
be considered as plagiarism.
(Signature of student):______________________________
Prepared by Tan Kong Han
-1-
School of Computing
Research on Security and Problems in Credit Card Online Transaction
Table of Content
Summary---------------------------------------------------------------------------------------------------i
Chapter 1: History and evolution of credit card and how it work
What is credit card online transaction? ----------------------------------------------------------------1
History and evolution of credit card--------------------------------------------------------------------2
How it works? --------------------------------------------------------------------------------------------2
Chapter 2: Public perception and awareness of credit card in online transaction
Background and update information of credit card in e-commerce--------------------------------3
Issues of credit card online transaction----------------------------------------------------------------3
Questionnaire----------------------------------------------------------------------------------------------4-10
Chapter 3: Problems encountered in credit card online transaction
Merchant frauds-------------------------------------------------------------------------------------------11
Individual frauds------------------------------------------------------------------------------------------12-13
Chapter 4: Project management
Gantt chart-------------------------------------------------------------------------------------------------14
Evaluation-------------------------------------------------------------------------------------------------14-16
Chapter 5: Solutions and security measurements for the problems encountered
Improvements on security of credit card online transaction----------------------------------------17
Credit Cards Offer Consumers Protection against Fraud-------------------------------------------18
Adding consumers trust and confidence--------------------------------------------------------------18
Appendix A: Reflect upon project experience---------------------------------------------------- 19-20
Bibliography----------------------------------------------------------------------------------------------21
Appendix
Appendix A: Gantt Chart--------------------------------------------------------------------------------22-23
Appendix B: Mid-term Report-------------------------------------------------------------------------24
Prepared by Tan Kong Han
-2-
School of Computing
Research on Security and Problems in Credit Card Online Transaction
Summary
This report is mainly concerned about credit card online transactions. In this report, we look first
at the general view of credit card online transactions. Here, we look at the history and evolution
of credit card online transaction and how it works. In addition, several issues such as “Is credit
card system failing E-Commerce” and “Is it safer to use credit card electronically or those
conducted face-to-face, by email or by phone.” Public perception against credit card online
transaction will be conducted by using questionnaire. Next, problems encountered in the credit
card online transactions will be identified and various solutions to combat the credit card fraud
will be suggested in the chapter of solutions to the credit card online transactions. A chapter
called project management is included in this report in purpose to response to the assessor’s
comments. Lastly, appendix called reflects upon my experience and bibliography is located at the
end of this report.
There are many issues of using credit card electronically. Security and safety are the main issues
being questioned by the public. For example, “Credit card frauds bedevils web! Millions lost to
Internet fraud!” They’re common headlines, and guaranteed to grab attention as consumers
consider how best to take advantage of expanding Internet. However, do these headlines really
telling the truth story or are they more often than not used as an easy way to sell a few extra
newspapers. ‘According to Australian Research Company , the security of credit card transactions
remains the number one concern both for Internet users who have yet to make an online purchase,
and for those who have performed an online transaction. An interesting issue is pointed out by
Hally Wolhandler, VP of Research at US-based ActivMedia Research and is supported both by
the MasterCard International and Visa International: “Web-based transactions are, in many cases,
safer than those that take place over the phone and even with bricks-and-mortar retailers.”
Prepared by Tan Kong Han
-3-
School of Computing
Research on Security and Problems in Credit Card Online Transaction
Chapter 1: History and evolution of Credit Card Online Transactions
What is Credit Card Online Transaction?
Credit card online transaction is a type of payment that you can get use of the Internet. In other
word, you can use your credit card electronically either to pay a bill, purchase products or
services. Using credit card electronically does provide many convenience and benefits to
consumers, but at the same time, consumers may suffer credit card fraud in the online transaction.
History and Evolution of credit card
According to Encyclopedia Britannica, the use of credit card is originated in the United States in
1920s. In the same year, a "buy now, pay later" system was introduced in the USA. It could only
be used in the shops which issued it. In 1950, various standard restaurants in United State wished
to promote a better or convenience way for the loyal customers to pay for the meal. They then
created the first credit card to make the payment.
In 1950, Diners Club and American Express launched their charge cards in the USA-the first
"plastic money" in credit card history. In 1951, Diners Club issued the first credit card to 200
customers who could use it at 27 restaurants in New York. But it was only until the establishment
of standards for the magnetic strip in 1970 that the credit card became part of the information age.
How the online credit card transaction work
This is the process of being able to actually take credit cards and have transactions moved into
your checking account. This involves signing up with a bank credit application for Visa or
MasterCard. Once you have a merchant account, this can usually be accomplished with a phone
call.
Once you have a merchant account, you need a mechanism to process transactions. Traditionally
you used either swipe the credit card in the store or you used payment processing software like
ICVerify for physical or mail order processing. Internet payment processing involves transaction
processing over an open Internet connection, so the transaction can be performed online,
Prepared by Tan Kong Han
-4-
School of Computing
Research on Security and Problems in Credit Card Online Transaction
potentially even on the web server itself. ‘Internet transaction services typically provide an API,
and HTML type input terminal for manual entry and full online reports of transactions.’
Transaction processors are separate from the banks that provide a merchant account, although
some providers provide a single transaction statement seemingly providing a single service.
Once the logistics are set up and you can actually take credit cards and process them over the
Web, but you first need to integrate the software into your application. Most providers have an
API that allows code access to processing functions. Most of these APIs are in C and require
writing a wrapper DLL. API architecture also varies from client server pieces and pure server
pieces. Client servers’ pieces are more difficult to set up as the client side needs to be configured
with secure keys and require the server to be configured to match. Pure server side APIs typically
require no client setup and are more flexible as you can use HTTP tools of your choice. Here is
the simple illustration of how an online credit card transaction works. First of all, the purchaser
places an order in the web. The merchant securely transfer order information and send to the
payment gateway. The transaction is then routed to the issuing bank to request authorization. The
transaction is either authorized or declined by the issuing bank or credit card companies. A
message is returned to the merchant. The issuing bank transfers money to acquiring bank if the
payment request is approved. The acquiring bank, in turn, credits the merchant’s account.
Prepared by Tan Kong Han
-5-
School of Computing
Research on Security and Problems in Credit Card Online Transaction
Source:
http://www.cybersource.com/products_and_services/electronic_payments/credit_card_processing
/howitworks.xml
Is credit card fraud failing E-Commerce? ‘Credit card fraud bedevils web! Millions lost to
Internet fraud.’ Although this kind of headlines always appeared in the newspaper to get publics’
attention, the use of credit card is still increasing and will reach $6.8 trillion in 2004. It showed
that the use of credit card is not influenced by the internet fraud and other security reasons.
Credit cards account for the vast majority of payments to the Internet merchants. A recent Gartner
reports states that, while in the offline world, credit cards account for only 19% of payments,
lagging behind cash at 53% and checks at 22%. However, in the online world, credit cards are
used for 93% of all transactions. That statistic should not surprise anyone, as to date cash and
check payments have not been available on the Internet at all, except in a few instances. At least
for checks that may change soon. Most consumers prefer to use credit card electronically rather
than debit cards and other payment methods. Using a credit card electronically does provide an
additional benefit as financial institutions offer consumers a measure of protection against
fraudulent credit card transactions. In most cases, if the cardholders immediately report any
fraudulent credit card transaction made against their credit card, banks will usually hold them
liable for the amount involved and the bank that handling the credit card may undertake a “charge
Prepared by Tan Kong Han
-6-
School of Computing
Research on Security and Problems in Credit Card Online Transaction
back”. In addition, if the consumer immediately report any unauthorized transaction against their
credit card, bank will normally not hold them liable for the amount involved. Often, the liability
for unauthorized use is limited to $50.
Is it safer to use credit card electronically or offline? Security of credit card online transaction
remains the serious concern to Internet users. ‘The NCL’s figures were corroborated by a recent
survey by Internet research firm BizRate.com of 13500 online consumers. The study found that
although more than 50 percent of those surveyed expressed concern that their credit card details
would be stolen during an online transaction, less than 2% had actually experienced credit card
number theft.’ Although there are many reports or newspaper show there is credit card fraud in
electronic payment system, the reality is that web-based transactions are, in many cases, safer
than those that take place over the phone or even with bricks-and-mortar retailers. MasterCard
and Visa International agreed that the rate of credit card fraud between online transactions and
those conducted face-to-face, by email or by phone. Both MasterCard and Visa International rate
less than 0.09% of credit card fraud in electronic payment system. There are always people who
try to create bad impression about credit card online transaction. Both MasterCard and Visa
International stated that there is no problem with the credit card online transaction.
Prepared by Tan Kong Han
-7-
School of Computing
Research on Security and Problems in Credit Card Online Transaction
Chapter 2: Access public perception of credit card online transactions
The use of questionnaire is an information gathering technique that allows systems analysts to
study attitudes, beliefs, behavior and characteristics of several key people in the organization who
may be affected by the current and proposed system. Although it is true that the questionnaire
method can gather different types of information, it requires extensive planning time in its own
right. Open-ended and closed questions are normally used to design a questionnaire. There are
several rules have to be followed when designing a questionnaire e.g. scaling fundamentals,
questionnaire format and order of questions.
Several mistakes are found after designing this questionnaire. First of all, there are unclear
objectives of this questionnaire, respondents do not know under what purposes do this
questionnaire is being designed. Next, the orders of questions are not arranged corresponding to
the importance of the measurements. Lastly, inconsistent in style reduces the efficiency and
quality of this questionnaire.
The purpose of this questionnaire survey is to determine the public perception of credit card in
online transaction. This implies a study of public awareness of credit card in online transaction,
their willingness to conduct credit card online transaction and examine their knowledge of credit
card and its transaction. 50 students are selected randomly from School of Computing to
participate in this questionnaire survey. A face-to-face method will be used to conduct this
survey.
This questionnaire is mainly designed and conducted with an aim to assess public perception
concerning a range of characteristics of credit card in online transaction. The characteristics that
are cited in the literature are anonymity (protecting or concealing customers’ identity), ease of use
(usability), efficiency (ability of payment system to service small and micro system), security,
traceability (ability to trace sources of money, income or physical presence and trust.
Prepared by Tan Kong Han
-8-
School of Computing
Research on Security and Problems in Credit Card Online Transaction
Interpretation of Survey Results:
Approximately 64% of respondents indicate that anonymity is so important to them. The vendors
should keep their identities confidential. Most of the respondents are not satisfy with the level of
privacy provided by the vendors. They fear their confidential identity or credit card number will
be stolen. It is the issue which affects the use of credit card in online transaction and it eventually
loses millions of potential users in electronic commerce. 50% of respondents would prefer that
their purchases are registered to avoid disputes. Ease of use is another concern of public. 63% of
respondents agreed that credit card is more convenient to use compare to debit card. Credit card is
acceptable around the world but the other payment cards may not accepted in certain countries.
The process of make payments electronically should be the same for credit card and other
payment cards, however respondents rated it differently. 60% of respondents feel it is important
and convenience to check the balance of the credit card so that human or transaction errors will
not be happened during purchase process. Security is a serious issue for respondents. 60% of
respondents agreed that the online transaction should be safe under secured system. Since the
credit card frauds happen daily, all users are fear of using credit card electronically and it is
important to increase the security of the credit card online transaction process. In addition, it is
not surprisingly that 72% of respondents refuse or stop to use their credit card electronically if
they hear about a security breach in credit card online processing system. Traceability is another
issue being discussed here. 60% of respondents are aware that no traces should be left from the
electronic payment. They fear their personal identities, credit card number and address will be
stolen. Lastly, Trust is another issue being concerned by the respondents. There are 42% of
respondent will not trust those companies who first establish a new credit card online processing
system and 52% of them will trust only trust those banks who establish the new credit card
processing system. They have an opinion that bank has good reputation compare to those private
company and bank can guarantee compensation if the online credit card transaction occur
wrongly.
Prepared by Tan Kong Han
-9-
School of Computing
Research on Security and Problems in Credit Card Online Transaction
Conclusion:
This survey grew out of an interest in the perceptions and fears of consumers to use their credit
card electronically. It was expected that consumers are unwilling to divulge their credit card
information during an online electronic transaction, generally safety concerns were the main
reason. Hence, improvements in security and encryption technology are making it more difficult
for criminals to intercept credit card online transactions. However, it is insufficient that only
improvements in security and encryption technology to intercept the credit card online transaction
frauds; public should cooperate with the particular agencies e.g. banks to decrease the credit card
online transaction frauds.
Summary of the Survey:
Demographic data:
Gender: Men=30, Women=20
Have performed Internet payment=59.4%
Never performed Internet payment=40.6%
Anonymity
1. Are you aware that banks or shops can keep records about your payments when you use
credit cards?
Yes
No
Yes
64%
No
36%
2. Are you comfortable with the level of privacy that is provided by credit card?
□ Very much
□ Quite likely
□ Neutral
□ Not really
□ Not at all
Very much
14%
Quite likely
12%
Prepared by Tan Kong Han
Neutral
10%
- 10 -
Not really
12%
Not at all
52%
School of Computing
Research on Security and Problems in Credit Card Online Transaction
3. Are you concerned that a shop may know what kind of things you buy when you pay
electronically e.g. with a credit card?
□ Very much
□ Quite likely
□ Neutral
□ Not really
□ Not at all
Very much
18%
Quite likely
32%
Neutral
36%
Not really
8%
Not at all
6%
4. Banks and shops can make mistakes with your money. Do you want to have records of
your purchases to be able to prove these mistakes, like over billing?
□ Very much
□ Quite likely
□ Neutral
□ Not really
□ Not at all
Very much
34%
Quite likely
34%
Neutral
14%
Not really
12%
Not at all
6%
Ease of Use
5. Do you feel more convenience when using credit card over another e.g. debit card
because it’s easier to use?
□ Yes
□ No
Yes
63%
No
37%
6. To what extent did you find it easy to pay over the Internet with a credit card?
□ Easy
□ Neutral
□ Difficult
Yes
63%
Prepared by Tan Kong Han
No
37%
- 11 -
School of Computing
Research on Security and Problems in Credit Card Online Transaction
7. Do you feel more comfortable with payments when you are using something tangible to
pay with credit card?
□ Sure
□ Quiet likely
□ Not at all
Sure
34%
Quite likely
20%
Not at all
46%
8. Is it important that you are able to find out at any moment how much money does you
have?
□ Quite important
□ Very important
□ Neutral
□ Quite unimportant
□ Very unimportant
Quite important
22%
Very important
38%
Neutral
16%
Quite unimportant
14%
Very unimportant
10%
Security
9. Is security of payment important for you when you use credit card electronically?
□ Quite important
□ Very important
□ Neutral
□ Quite unimportant
□ Very unimportant
Quite important
24%
Very important
36%
Neutral
10%
Quite unimportant
14%
Very unimportant
16%
10. Will you stop using credit card if you hear about a security breach in the payment
system?
□ Absolutely yes
□ Quite likely
□ Neutral
□ Rather not
□ Not at all
Absolutely yes
58%
Prepared by Tan Kong Han
Quite likely
14%
Neutral
6%
- 12 -
Rather not
8%
Not at all
14%
School of Computing
Research on Security and Problems in Credit Card Online Transaction
Chapter 3: Problems Encountered in the Credit Card Online Transaction
By virtually any measure, electronic commerce is growing rapidly: ‘According to the Forrester
research company, worldwide Net commerce will ascend from $657 billion in 2000 to $6.8
trillion in 2004.’ However, there are appearances of bad impression to the public about fraud or
problem in the credit card online transaction due to the purposive actions of certain people. Both
the MasterCard and Visa International deny the state of affairs that there are frauds in the
electronic payment systems. They also emphasize that the rate of fraud for Internet transactions is
roughly the same as or even lower for other non-face-to-face transactions such as mail orders and
phone orders.
It is cannot be disputed that there are several problems associated with the credit card online
transaction. Sometimes, the chief among them is the fraud, which is perpetrated by both
individuals and merchants.
The three basic forms of merchant fraud are: nondelivery, and overcharging, and charges for
unwanted goods or services. Nondelivery is defined when the merchants neither deliver the
goods ordered nor deliver the correct item. Meanwhile, overcharging happens when the
merchants charge more than the agreed-upon amount for the correct good or service. The latter
case involves charging for an unwanted good or service; where consumers are simply
fraudulently billed into paying extra charges. In the case of a genuine mistake, it is usually
possible to correct the error. For instance, if a merchant is dishonest in the transaction, typically
the credit card company must be brought in to resolve the payment dispute. ‘Usually, the fraud is
not committed by the actual online retailers, because they have the least protection of all involved
parties. Most fraud is committed by outfits created for that purpose alone.’
Individual fraud on the Internet is generally a more pervasive problem compared to the merchant
fraud. The reason causing that is due to the ease for individuals to remain anonymous or to
impersonate others. Worse, the credit cards were designed to rely on physical signatures for
authentication, a mechanism that is rendered useless in e-commerce. In practice, the prevention of
fraud in the online world is considered difficult for the merchants because there are no security
Prepared by Tan Kong Han
- 14 -
School of Computing
Research on Security and Problems in Credit Card Online Transaction
cameras or other physical mechanisms to catch criminals after the fact. When purchasing an item
or service online, the purchaser does not have to present a physical card, which may contain
additional security features, e.g. additional code numbers, photographs. In this “card-not-present”
situations, the merchant is able to take not only the full cost of the fraudulent purchase, but also
an additional administrative fee (usually $10-15) imposed by the card networks for the “charge
back”. ‘Charge backs can occur up to as high as 2.6% of online purchases, offline purchases
typically have charge back rates many times lower.’ By contrast, the issuers typically carry full
responsibility for card-present purchases with a physical signed receipt, in order to lower the
fraud rates. With the intention to solve retailers’ agonies, the card networks (Visa, MasterCard,
etc.) charge higher per-transaction fees for card-not-present situations to cover their losses, e.g.,
handling complaints and issuing new cards. Credit cards may be needed to pay for goods and
services that may be intangible, such as downloadable software. Simple methods such as
comparing the billing and shipping address are not effective when no physical good are being
shipped. The merchants are unwilling to reject orders and the process of verifying identity of the
purchaser is complex and inconclusive. Providing that the merchants are unable to require all
customers to take additional precautions, insecure credit card systems will run wisely in the
future, even if verification of identity is stronger with newer systems.
Although that the problems encountered are perpetrated by individuals and merchants, public are
still doubts about the safety of the credit card online transaction and the security of the electronic
payment systems. Security and fraudulent issues of credit card online transactions always appear
as the headlines in the newspaper. This will strongly reduce the public confidence to use the
credit card electronically. However, some of the newspaper publishers are so immoral to cover
the truth of the usage of credit card electronically in purpose to increase their sales of the
newspapers. A research from the Visa and the MasterCard brought out that the rate of credit card
online transaction frauds is roughly the same as for the non-face-to-face transactions such as mail
orders and phone orders.
Based on the result of the questionnaire shown in the chapter 2, 60 percent of the students are
concern about the security of the electronic payment system. If they listen to any rumors of the
security breach about the payment system, they will immediately stop using the credit card
Prepared by Tan Kong Han
- 15 -
School of Computing
Research on Security and Problems in Credit Card Online Transaction
electronically, causing the E-Commerce faces great loses of potential and existing users.
Although some credit card users are computer literature, they tend not use their credit card
electronically. The conclusion showed that awareness and knowledge of the use of security
measures during E-Commerce do not necessarily contribute to the fact that consumers will be
more willing to use credit card electronically. In fact, some people even fear to use their credit
card electronically. Although the security of the electronic payment system is quite good, but the
safety of the payment system is still an issue to be considered. In addition, it is more convenient
to use the credit card in retail store rather than Internet; the amount to be debited into the
purchasers’ credit card account can be confirmed and the goods are taken immediately. However,
in certain situation, the use credit card electronically is unavoidable. For example, the usage of
credit card to buy rail ticket online bring more convenient to the purchasers as they do not have to
go to the rail station. Most of the people who have done the surveys think that they will rather
purchase the goods in the retail shop than online purchase unless they need the goods in urgent or
due to convenience issue.
There is certainly a need to improve payment methods to battle credit card fraud, but which
methods will succeed is uncertain. Backwards compatibility and ease of use for consumers are
important to merchants while any methods chosen must appeal to banks in prior, which hold the
balance of power.
Prepared by Tan Kong Han
- 16 -
School of Computing
Research on Security and Problems in Credit Card Online Transaction
Chapter 4: Project management
Gantt chart:
This final year project report took four months to complete. Although I have planned a schedule
for each task, it’s really hard to follow the plan accordingly. Sometimes I decided to delay my
report tasks in a week times in order to finish my assignment in advanced so that no rush was
happened for my assignment. I have made a mistake in the mid stage report mentioned that I was
just analyzed the results of questionnaire at the end stage of my final year project report, but
actually I should completed the remaining parts of the report, made changes for errors of each
chapter and tried to find out more information for each chapter. In addition, I was analyzed the
results of the questionnaire to access the public perception of credit card online transactions.
Response to assessor comments – ‘mid stage review’
Firstly, the assessor has mentioned that the standard of English in the mid stage report was poor. I
decided to invite three friends whom first language is English to check my grammars and
languages to increase my English standard.
Next, the schedule was not clearly identified. In the mid stage report, I have mentioned that I was
going to analyze the results of questionnaire and complete my report. As stated above, I have to
do the analysis task and remaining parts of the reports and gave supervisor some times to have a
look on my report. In addition, there was one sentence in error mentioned that I was going to
analyze and compare the results of the questionnaire against the real world’s perception and
awareness to an e-commerce system. I have conducted a questionnaire with 50 respondents and I
was going to use their answers against those specific questions as my target to generate an
overview of public awareness in credit card online transaction.
As response to the comments of assessor in the mid stage report, this type of research should be
backed up with references to support the claims. I have included all the references in the appendix
to support my claims for the credit card in online transactions.
Prepared by Tan Kong Han
- 17 -
School of Computing
Research on Security and Problems in Credit Card Online Transaction
Evaluation:
Objectives
Identify the problems
Measurements
Extensive literature search, identified consistent top
issues, questionnaire confirms there are issues
Access public perception
Questionnaire, top issues
Analyze security of electronic
Trial version of electronic payments software,
payments
experience of using credit card electronically
Suggest solutions for the problems
Extensive literature search
Identify future work opportunities
Experience of using credit card electronically, extensive
and enhancement
literature search
Measurement:
The assessor has indicated that my mid stage report is such that, apart from questionnaire, the
report is the only delivery. In order to correct this error, I have studied 4 books as my reference
and I listed them in my appendix. In addition, those 5 websites listed in the bibliography is
particularly important for me among all the websites that I have viewed to gather information
about problems and solutions of credit card online transactions.
To identify the problems of credit card online transactions, I have conducted an extensive
literature search on the issues about problems of credit card online transactions. Next, the
conducted questionnaire confirms that there are issues of electronic payments system e.g. fear of
using credit card in online transaction. A questionnaire is conducted to access the public
perceptions of credit card online transaction. Besides that, there are many reports showing that
public are not willing to use their credit card electronically and ‘security of credit card
transactions remains the concern both for Internet users who have yet to make an online purchase,
and for those who have performed an online transaction.’
I have tried the trial version of software e.g. Verisign to analyze the security of electronic
payment systems. In addition, my experience of using credit card electronically to purchase stuffs
in Internet helped me verify the security of the payment systems. I have found several articles and
issues to solve the problems of the credit card online transaction.
Prepared by Tan Kong Han
- 18 -
School of Computing
Research on Security and Problems in Credit Card Online Transaction
In order to get various solutions for a particular problem, I have done plenty of hard work in
research and refer to books, magazines and journals. Besides, I have also search some
information from the Internet. From the experience I gathered by using credit card electronically,
I can differentiate which payment system is better and more secure than others and experience
helps me feels safe to use credit card electronically. In addition, after completed this research, I
also have more knowledge about credit card online transaction.
Prepared by Tan Kong Han
- 19 -
School of Computing
Research on Security and Problems in Credit Card Online Transaction
Chapter 5: Solutions to Combat Problems Encountered in Credit Card Online Transaction
Before this research is done, all the improvements in security of the credit card online transaction
e.g. digital certificates have been done few years ago to increase the security of the credit card
online transaction. That’s why the E-Commerce is growing rapidly and it is estimated that by the
end of 2003, over 85 million online shoppers are expected to spend more than $35 billion
Despite these positive indicators, the presence of Internet fraud is stills tempers the tremendous
opportunity. Although the Visa International and MasterCard stated that the rate of internet fraud
is roughly the same as the phone order or face-to-face retailer, consumers are unwilling to use
their credit card electronically. The safety issue remains the number one concern for the
consumers to use their credit card electronically. All the improvements in security of credit card
online transaction do not really increase consumers’ confidence to use credit card electronically.
Therefore, it is important to increase consumer perception of credit card online transaction and
prove them it is safer to use credit card electronically.
Improvements on security of credit card online transaction:
Improvements on the security of the credit card online transactions are briefly discussed here.
Improvements in security and encryption technology are making it even harder for criminals to
intercept online transactions. Both Netscape Navigator and Microsoft Internet Explorer use
Secure Sockets Layer (SSL) to encrypt data before sending it over the Internet; ‘SSL scrambles
personal data and provides an unbroken key or lock that appears in the bottom of the browser
window.’ Although this technology provides a secure connection that keeps data private during
transmission over the Internet; it does not authenticate the parties at either end of the transaction.
Visa International and MasterCard International, with support from many of the world’s top
financial institutions, are presently working to develop a more advanced encryption process
called Secure Electronic Transaction (SET). SET involves a system of digital certificates
provided by card issuers and encryption. It enables the identity of both merchant and cardholder
to be authenticated, and also ensures that neither the merchant nor cardholder’s bank sees the
purchaser’s credit card number during the credit card transaction.
Prepared by Tan Kong Han
- 20 -
School of Computing
Research on Security and Problems in Credit Card Online Transaction
Credit Cards Offer Consumers Protection against Fraud:
Using a credit card when making purchases online provides an additional benefit as financial
institutions offer consumers a measure of protection against fraudulent credit card transactions. In
most cases, if the cardholder immediately reports any unauthorized transactions made against
their credit card, banks will usually not hold them liable for the amount involved. Often, liability
for unauthorized use is limited to $50. If consumers don’t receive the goods ordered, or the goods
are not in good condition and the goods have been returned, the bank handling your credit card
may undertake a ‘chargeback’. Banks is willing to cancel the transaction and reserve the payment
to the business.
Adding consumers trust and confidence:
Trust in credit card transaction over the Internet clearly plays an important role for consumers
debating whether to purchase goods online. In my opinion, consumers fear that their credit card
details will be stolen during the credit card online transaction and their card will be discharged by
the credit card company. This is the primary reason why consumers refuse to use credit card
electronically. Hence, it is important to consult consumers and build their confidence in order to
pursue them to use credit card electronically. Mass media should use their influences to show
consumers that it is safe to use credit card electronically and at the same time to provide evidence
to prove the safety and security of the credit card online transaction is no longer an issue to
consumers. ‘Consequently, it is important to report that while consumer misgiving regarding the
safety of online financial transactions remains the number one hurdle to more active online
purchasing, this perception of high risk maybe significantly misplaced.’
Prepared by Tan Kong Han
- 21 -
School of Computing
Research on Security and Problems in Credit Card Online Transaction
Appendix A: Reflect upon My Experience
This report took four months to complete. Although I have planned a schedule for this report, it’s
really hard to follow the plan accordingly. It is too critical and pressures to do this report because
it will judge my degree classification in my final term. I can’t follow all the activities I planned
few months ago. Everything is change from time to time. For example, I got DB32 coursework to
be submitted in week 6 and at that time, I am not managed to do the project according to the
schedule. However, I still managed to finish this report on time. As first, my supervisor is worried
about my progress in writing this report; I have used my Easter Holiday effectively to finish this
report. My advice is just start the report as soon as possible or after you have selected the title of
your report and then you will not lack of times to finish the report.
In completing this report, a few mistakes have been tackled by my assessor. First of all, the
assessor is seriously concern my report apart from the questionnaire, is only the delivery. In order
to correct this mistake, a part from questionnaire, a chapter called project management and some
argument issues have been added into this report. Next, the schedule of this report has been
questioned because the last month is only used to analyze the result of the questionnaire and
completing the remaining part which is one of the mistakes I have done. I have changed the Gantt
chart schedule and it can be showed under chapter 4-Project Management. Lastly, this kind of
report should be backed up with references. I have written all the book references, URL and ECommerce article under the Bibliography section.
A lot of experiences have been learned in completing this report. By doing this report, I knew
what are credit card online transaction, history and evolution of credit card and how it works. In
addition, some hot issues have been discussed in this report. The most interesting and surprising
issue is the web-based transactions are, in many cases, are safer than those take place over the
phone or retailers. After finished this report, safety and security problems of credit card online
transaction became useless point for me. Since the web-based transaction is safer than those take
place over phone or retailers, public can use my credit card electronically. In addition, liability of
unauthorized use is limited to $50 also encouraged public to use credit card electronically.
Prepared by Tan Kong Han
- 22 -
School of Computing
Research on Security and Problems in Credit Card Online Transaction
Conclusion, this final year project schedule should be well planned and all delay should be
avoided. Students who are going to take the final year project should start the report as soon as
possible. In addition, after doing various research about the issues of credit card online
transaction, I can explain how the transaction works and I can show other parties the evidence
how safe the credit card online transaction is and give them confidence to use credit card
electronically.
Prepared by Tan Kong Han
- 23 -
School of Computing
Research on Security and Problems in Credit Card Online Transaction
Bibliography
Article:
VNU business publication, (30 October 2002) Computing-The Newspaper for the Networked
Economy
Book:
Walrand, Jean (1998) Communication Network, the McGraw-Hill Companies, Inc (2nd edition)
Shelly, Gary B (1995) Security, Ethics and privacy, using computers a Gateway to Information,
International Thomson Publishing Company
Lawton, George (August 1998) Biometrics: A new Era in Security, Computer and Innovative
Technology for Computer Professionals
Whyte WS (2001) Enabling eBusiness: Integrating Technologies, Architectures and Application,
Wiley
URL:
Steve Patient (April, 4 2000) Reducing Online Credit Card Fraud
http://www.webdevelopersjournal.com/articles/card_fraud.html [16th Feb 2003]
Jim Conley II, MerchantSeek (2003) 10 Ways to Reduce Chargebacks and Fraud
http://www.merchantseek.com/article13.htm [16th Feb 2003]
John Burtzloff (September 09, 2002) Avoiding Credit Card Fraud-Learn how to safeguard your
business without alienating legitimate customers
http://www.entrepreneur.com/Your_Business/YB_SegArticle/0,4621,302952,00.html
[17th Jan 2003]
Dr. Ralph F. Wilson (2003) Getting Customers to Plunk Down Their Credit Card
http://www.wilsonweb.com/articles/plunk-down.htm [25th Jan 2003]
www.noie.gov.au/publications/NOIE/consumer/creditcardfraud.pdf [2nd Jan 2003]
Prepared by Tan Kong Han
- 24 -
School of Computing