New PayPal key to help thwart phishers
To fight phishing, PayPal plans to introduce a new two-factor authentication system called the PayPal Security Key

Over the next few months, Ebay will be offering its PayPal users a new tool in the fight against phishers: a US$5 security key.

The PayPal Security Key is actually a small electronic device, designed to clip on to a keychain, that calculates a new numeric password every 30 seconds. PayPal users who sign up to use the device will need to enter their regular passwords as well as the number displayed on the key whenever they log in to the online payment service.

"The key is really going to give users one more layer of security for their accounts," said Sara Bettencourt, a PayPal spokeswoman.

Because the numeric password changes so frequently, even successful phishers will end up with obsolete numeric passwords and will be unable to empty PayPal accounts.

"If you fall for a phishing scam and give away your user name and password ... if you used the PayPal Security Key, a third party couldn't get to your account because they wouldn't have this dynamic digit," Bettencourt said.

The Security Key could be an important tool for PayPal, whose Web site is frequently spoofed by phishers looking to steal user account information.

The PayPal Security Key is being tested by PayPal employees right now, and the test will be opened up to beta users in the U.S., Germany, and Australia "in the next month or so," Bettencourt said. Later this year, the company plans to begin promoting the devices to all PayPal users. News of the new PayPal system was first reported on AuctionBytes.com

PayPal users who want this extra level of security will be able to buy the devices for US$5, but this fee will be waived for PayPal business accounts.

PayPal's device is based on VeriSign's One-Time Password Token product, which is also being tested by Charles Schwab & Co. and U.S. Bancorp.

ETrade Financial also uses a similar system, based on RSA Security's SecurID tokens.

Over the past year, online financial companies have paid more attention to authentication technologies such as the VeriSign tokens, which add a second layer of authentication to online transactions. Adoption of these "two-factor" authentication techniques has been further boosted by new federal guidelines, which require stronger authentication for online transactions.

Still, phishing attacks are becoming increasingly lucrative for criminals.

Research company Gartner estimates that phishers cost U.S. financial institutions about US$2.8 billion last year. The average loss per phishing attack was US$1,244, up from US$256 in 2005.

Recommend this article?
Yes0 votes
No0 votes

Comments

Key Chain

LED lights are incredibly powerful and are being used more and more around the world. With an oval LED key tag light, you will be able to see all around you at night. This one is the popular web site of LED key chain http://www.discountmugs.com/nc/category/keychains/

Its like a guide where we can

Its like a guide where we can know more about pcs i like to purchase replica purses thanks for post.

Truly, the key is really

Truly, the key is really going to give users one more layer of security for their accounts and they can enjoy chatting at online paralegal courses.
Regards,

Thats great that you gaurd

Thats great that you gaurd our accounts for safest transfer of money in
online kazino

my work

Thanks pay pal who is the safest person for our online transactions.

NIce one.......

It states that the numeric password changes so frequently, even successful phishers will end up with obsolete numeric passwords and will be unable to empty PayPal accounts. prodotti tatuaggi

Post new comment

The content of this field is kept private and will not be shown publicly.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

More information about formatting options

Enter the fully qualified URL, eg. http://www.example.com/
Users posting comments agree to the PC World comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Syndicate content
 
Gift Guide
MWave
Samsung

CXO Latest

LED Advisor
 

Colour your world with Samsung

A chance to win with every
Samsung Consumable purchase*