Cloud

4/28/2015
05:00 PM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

Bringing Tokenization To Secure Payments & Beyond

HYPR aims to do for everything else what ApplePay has done for payments

If Apple Pay makes tokenization an everyday tech, HYPR may make tokenization an everywhere tech.  

With Apple Pay, a user's iOS device is linked to their bank account. When they make a purchase, the user authenticates to the device with their fingerprint, the device generates a unique token representing their payment data, and that token is provided to the merchant. 

Enter HYPR. What HYPR is trying to do, essentially, is to enable any cloud service or website to do what Apple Pay does, but from any device, and for any purpose; not just payment processing.

It will enable any cloud service to accept biometric authentication in the form of tokens generated by the users' own devices -- enabling stronger identity management without the high costs of issuing biometric scanning hardware.  

In an interview with DarkReading at the RSA conference last week, HYPR CEO George Avetisov said that multi-factor authentication in the cloud just hasn't been scalable, and it's been cumbersome for the user. "There's always an extra component," he said. "Even if it's just a download."

He says his product is eliminating those extra components and facilitating scalability. The company has already received "unanticipated interest" from major banks, OEMs, mobile operators, and mobile payment processors, says Avetisov.

The HYPR software development kit starts shipping in July, and can be reserved now.

Although HYPR could be applied for uses beyond purchases, the payment industry certainly still needs help, as Robert Carr, chairman and CEO of Heartland Payment Systems, made clear when speaking at the InformationWeek conference in Las Vegas today.

According to Carr, in recent conversations with major card issuers they "confirmed that Chip-and-PIN will not be coming to America in the forseeable future." Plus, some end-to-end payment encryption services are charging prohibitive transaction fees, according to Carr.

After Heartland's major breach in 2008, the company created a completely new secure payment system that combines EMV Chip-and-PIN cards, end-to-end encryption, and tokenization. Unfortunately, there aren't many other companies following suit.

Sara Peters is Senior Editor at Dark Reading and formerly the editor-in-chief of Enterprise Efficiency. Prior that she was senior editor for the Computer Security Institute, writing and speaking about virtualization, identity management, cybersecurity law, and a myriad ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Wheitz
50%
50%
Wheitz,
User Rank: Apprentice
5/1/2015 | 5:36:22 AM
Tokenisation compatbility
for those using iphone of the older version without fingerprint reader, will something also be done for them by Hypr?
Ulf Mattsson
50%
50%
Ulf Mattsson,
User Rank: Moderator
4/29/2015 | 4:58:10 PM
PII?
Great if "HYPR may make tokenization an everywhere tech."

I have a concern is that the EMV Chip and PIN Cards does not protect against malware attacks like those we have been reading about in the news. Nor does it prevent card-not-present attacks and not against attacks beyond payment data, as seen in recent breaches.

I recommend a wider use of the promising tokenization technology that is effective to protect the entire data flow of sensitive data. This type of technology can also be used to mitigate the risks associated with other sensitive information, including personal information.

We urgently need the data tokenization approach to defend against the growing trend in data breaches. The hackers tend to be one step ahead of the good guys.

Ulf Mattsson, CTO Protegrity
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
4/29/2015 | 12:38:45 PM
Re: EMV Chip and Pin Cards
It would be nice if the banks were a step ahead of the alternatives but that really isn't their forte. I think even though this is an ease of use security measure this would fall into the domains of tech companies to which the bank is not. By incorporating secure solutions the bank raises customer faith and saves capital hours of investigating fraud, etc but this is no different than any other industry that receives payments. I think more light is shined upon this vertical due to its risk category. More malicious attempts happen upon the financial vertical than many other verticals but that shouldn't effect involvement. Whether your house is subject to many break in attempts or a little you still go to a security firm instead of trying to secure it yourself from a comprehensive standpoint.

I see logic in both stances this is just my own.
MarkMacK77
50%
50%
MarkMacK77,
User Rank: Apprentice
4/29/2015 | 11:59:37 AM
EMV Chip and Pin Cards
Hi Sara,

 

   Great article, can you confirm that the banks are truly not bringing EMV Chip and Pin cards to its clients? I would think in the light of all the credit card hacks over the last few years at big box retailers, and the growing trend for contactless payments, that security for its clients should be paramount?

    We've had EMV cards for some time now in Canada, and while I don't readilly have the numbers on credit/debit card fraud post change, I feel fairly confident it had definitely slowed the skifters, if not stopped them nearly entirely... Apple Pay, and alternatives like the HYPR you mentioned are a step in the right direction, but shouldn't the banks be one step ahead of the alternatives?

    Just curious.

 

Thanks,

 

Mark 
Christian Bryant
100%
0%
Christian Bryant,
User Rank: Ninja
4/29/2015 | 4:18:40 AM
Alternative to Dev SSH Authentication?
Very interesting.  In looking at this further and thinking about all possible applications, I could see value in implementing this form of authentication within a source code management system for commercial software development where securing the code is a must (automobile, aircraft, bank, and government software shops, for instance).  Having the freedom to quickly pull down code securely and push changes back from any device without having to carry a keychain around makes sense.  I'm curious to see the SDK and what guidance comes with it for considering an architecture such as this. 
Equifax CIO, CSO Step Down
Dark Reading Staff 9/15/2017
1.9 Billion Data Records Exposed in First Half of 2017
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/20/2017
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Jan, check this out! I found an unhackable PC.
Current Issue
Security Vulnerabilities: The Next Wave
Just when you thought it was safe, researchers have unveiled a new round of IT security flaws. Is your enterprise ready?
Flash Poll
[Strategic Security Report] How Enterprises Are Attacking the IT Security Problem
[Strategic Security Report] How Enterprises Are Attacking the IT Security Problem
Enterprises are spending more of their IT budgets on cybersecurity technology. How do your organization's security plans and strategies compare to what others are doing? Here's an in-depth look.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.