DENVER – Giving rampant fraud in many payments systems, credit unions would be best served by featuring a combination of tokenization and authentication to secure sensitive information and validate member identification, according to one person.
“Fraud can occur at multiple points within the payment ecosystem,” said Robert Jarosinski, senior risk management consultant with CUNA Mutual in remarks to America’s Credit Union Conference (ACUC) and the World Credit Union Conference here.
Jarosinski added that breaches at retailers, processors and card-issuing institutions continue to escalate, while card skimming at ATMs and old-school theft still pose threats. “As payment systems evolve, tokenization and authentication will play a lead role in making the technology safer, simpler, convenient and more efficient.”
Jarosinksi noted that tokenization helps secure data and has been used in various forms since the 1970s but has gained popularity in the payments industry recently with Apple leveraging it through Apple Pay.
The Goal: Worthless Information
“Think of tokenization as a proxy for actual information. Rather than having sensitive information out in the open, a unique stand-in alpha-numeric sequence is put in its place,” he said. “If this information were to fall into a fraudster’s hands, it would be worthless.”
Whether it’s used for employees to log in to remote networks, access sensitive software or as part of a payment solution, tokenization is a powerful tool to help mitigate fraud, he added.
But securing sensitive data is only half the battle, according to Jarosinski. The challenge in the virtual and remote world is knowing who is on the other end of a phone call, email or transaction. “Authentication provides added peace of mind in knowing ‘who’ you are dealing with.”
Most credit unions exude pride in knowing each and every member. While that’s a competitive advantage, membership growth is expanding to the point where continuing to do so in a virtual world is becoming unsustainable, Jarosinski said.
As data breaches rise and more information is exposed, it’s becoming easier for identities to be compromised. Authentication techniques such as asking for a date of birth or Social Security number are out of date, and out-of-wallet questions and verification services that validate information likely obtained through breached data will soon follow.
“For credit unions with an established remote membership, we are seeing a movement to identifying members by the one thing that has become ingrained in their daily lives and that they are rarely without…their mobile phone.”
A Two-Step Process
Jarosinski said that by pairing a mobile phone’s features such as entering information (static PINs), touch capabilities (fingerprinting) and taking photos (facial recognition), mobile phones make for a great authentication device. Whether using it at a branch, ATM, point of sale terminal, at home or for employee log-ins, this type of authentication requires a two-step process:
- Members authenticate their identity on the device by entering a static PIN or biometrics.
- Once the member is authenticated on the device, then it generates dynamic information and a device profile (device ID, geolocation, etc.).
Jarosinski said new technology is helping, but it only goes so far. “If members and employees don’t know about it or use it incorrectly, it’s kind of pointless.”
He stressed the importance of education and encouraged CUNA Mutual Group policyowners to get more information by going to the online Credit Union Protection Resource Center.
