On October 17, 2014, an Executive Order [1] was issued to improve the security of consumer financial transactions.

Executive Order   Improving the Security of Consumer Financial Transactions   The White House

Its 3 main provisions are as follows.

  • Section 1. Securing Payments to the Federal Government — Payment terminals introduced from January 2015 onward will be based on more secure standards. Specifically, they will support IC chips.
  • Section 2. Improving Identity Theft Remediation — 3 measures are listed to substantially reduce the time required to provide relief in typical cases.
  • Section 3. Securing Federal Transactions Online — Access to personal information must support multi-factor authentication and appropriate identity proofing in a manner consistent with NSTIC [2]. Government agencies must comply within 18 months.

Credit cards with IC chips have become mainstream in Japan and Europe, but they are still far from widespread in the United States. Section 1 of this Executive Order is intended to improve that situation. By moving credit-card payments at government agencies to an IC-chip-based system, the aim is to provide an impetus for credit card issuers to start issuing cards with IC chips.

As it happened, on the same day the Daily Telegraph published an article titled

Sorry Mr President; your credit card has been declined
Barack Obama’s card rejected at trendy New York restaurant Estela

The article reported that President Obama was unable to make a payment when he tried to pay at a restaurant called Estela in New York. Because magnetic stripes are easy to duplicate, credit card companies use risk-based authentication based on patterns in past transactions. But since Mr. Obama had hardly used his card after becoming President, the payment at this restaurant was flagged as an unusual transaction. According to the article,

“It seems I don’t use the card very often, so they thought there might be fraud going on. Fortunately, Michelle had a card.”

“I tried to explain to the waitress that I really do pay my bills, but this is what happened.”

President Obama told Richard Cordray, Director of the U.S. Consumer Financial Protection Bureau, that this incident demonstrated the need to introduce an easier way to protect credit card customers.

He praised the IC-card payment system [3], which is commonplace in Europe but not in the United States.

(Source) Rosa Prince: “Sorry Mr President; your credit card has been declined”, Daily Telegraph, 2014/10/17

It does rather feel like a planted story, but that probably shows just how serious they are about this. Incidentally, the story also appeared in AP dispatches and on Fox News. People will not read an article about security, but they will read a more down-to-earth story saying that President Obama could not use his card! The media strategy, based on that calculation, is skillful.

Identity theft has been a social problem for quite some time. Section 2 is a response to it. Rather than prescribing specific measures, however, it is an order to formulate such measures.

Section 3. then raises the level of security for access to government websites when individuals access their own personal information, thereby improving privacy protection. According to what I heard in advance from White House sources, this, like Section 1., is also intended to serve as an impetus for the private sector. It appears that SP 800-63 may be revised in the future to accommodate this [4]. Does setting the deadline at 18 months mean that the FCCX implementation will be completed by then, I wonder?

The announcement happened to coincide with my trip from Tokyo to Mexico, so I was a little late in writing this article, but perhaps this is still the first report on it in Japan….

Well then!

(Written in Mexico City)


 

[1] Executive Order –Improving the Security of Consumer Financial Transactions, http://www.whitehouse.gov/the-press-office/2014/10/17/executive-order-improving-security-consumer-financial-transactions

[2] National Strategy for Trusted Identity in Cyberspace

[3] chip-and-pin payment system

[4] Under the current SP 800-63, multi-factor authentication is LoA 3, but requiring identity proofing at LoA 3 would probably be excessive. Perhaps multi-factor authentication will instead be required at LoA 2, or the credential level and the identity-proofing level may be separated.

Related Articles

Related posts