Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Mobile Wallets: Security First and Growth Will Follow

by The Gurus
December 12, 2016
in This Week's Gurus
Share on FacebookShare on Twitter

According to McKinsey & Company, digital wallets currently facilitate approximately $300 billion in transactions within the U.S. The research firm is predicting that this volume will expand to $1.2 trillion by 2020 to comprise 18-20% of total U.S. retail spending.
This projected growth is expected to become a reality for a number of reasons. First and foremost, mobile wallets create a simple, frictionless buying experience for customers, which they demand. Simultaneously, the technology opens up many new revenue opportunities for banks, fintech companies and retailers. Retailers in particular find the technology integrates well with their existing loyalty and discount programs, and stores are accordingly expected to install POS systems to accommodate and encourage their use.
However, in survey after survey, consumers list security concerns as their primary hesitation for using a mobile wallet. And at least for now, it seems to be warranted.
Fraudsters, shut out by the successful migration to the EMV (Europay, MasterCard and Visa) chip card security standard, have found greener pastures—and mobile wallets are one of the targets of choice.
In 2015, fraudsters were able to compromise approximately 112,000 mobile wallet-related accounts, for the 23 million digital wallet users. When there are 90 million digital wallet users expected to be using this technology by 2019, the number of fraud cases will most likely increase exponentially—unless measures are taken now to shore up the security gaps that currently exist in using this channel.
Mobile Wallet Vulnerabilities
The primary threat to mobile wallet security technology lies in the enrollment process, specifically when a new payment card is added to a wallet.
The mobile wallet provider must, at this point, verify if the card information matches the user information on file. When there is a discrepancy in the records, additional verification is required. That verification is requested either by one-time codes sent via text message or by call center verification.
Unfortunately, both these methods are insecure and potential access points where fraudsters can breach the system.
Text message verification (SMS) is specifically not recommended by National Institute of Standards and Technology (NIST), a unit of the U.S. Commerce Department, because of its vulnerability to man-in-the-middle attacks and other forms of fraud.
And traditional two-factor authentication techniques such as SMS are not only insecure as noted, but cumbersome for customers. Call center verification is equally ineffective. Despite extensive training in security precautions, operators are often easy targets for social engineering scams. Call center interactions are also time consuming and costly for the organization to operate and maintain.
Verification via Device Authentication
A far better and more secure option would be to send requests for additional verification to mobile wallet users via the issuer’s mobile app.
Communication through these dedicated apps, coupled with mobile device authentication software, is a secure method for sending transmissions, as they are point-to-point communication sent along an encrypted path. When verification requests are sent along this channel, fraudsters can be frozen out.
In this scenario, the mobile device then becomes another authentication factor, combined with a secure message that can be pushed to the issuer’s mobile app on a trusted device that the customer can simply click to confirm the card addition to the wallet.
Leveraging the mobile device itself as a trusted token is done through the individual characteristics embedded as part of that device such as its operating system, location, application data and other data. In combination, these attributes form a unique identifier—a permanent identifier that serves as a secure token that the customer will have in their possession.
Then, instead of cumbersome and insecure verification methods like an SMS-based, one-time code, a contextual message can be pushed for the customer to confirm their activity. The message can be encrypted and directed solely to the customer device of record, ensuring that there is no possibility of a man-in-the-middle interception or transmission to the wrong party.
Using this combination of authentication factors creates an innovative method to resolve the common business conflict between security and the need to deliver a satisfactory customer experience.
Looking Toward the Future
Mobile wallets have the potential to improve the shopping and engagement experience for millions of consumers, while simultaneously boosting revenue for retailers, financial institutions, and fintech companies. As mobile wallets continue to gain popularity and adoption grows, those organizations that can ensure the security of their customers and provide them with a heightened level of confidence that their transactions are safe and efficient will emerge as the leaders in their respective space.
About the Author
Michael Lynch serves as Chief Strategy Officer, where he is responsible for leading InAuth’s new products strategy, along with developing key domestic and international partnerships. Lynch brings two decades of experience in key roles within financial services, consulting, and Fortune 500 companies, specializing in security and technology leadership. Prior to joining InAuth, Lynch served as a Senior Vice President for Bank of America, responsible for Authentication Strategy. He served at Bank of America for 14 years in various leadership positions within technology, customer protection, and online and mobile security strategy roles. Prior to Bank of America, Lynch specialized in information technology in various financial services, Fortune 500, and consulting services roles.

ShareTweet
Previous Post

UK CEOs are concerned that EU privacy rules will impact their business once Brexit takes place

Next Post

Internet of Things or Internet of Threats?

Recent News

Frontline Workers Twice as Likely to Use Unapproved AI

Frontline Workers Twice as Likely to Use Unapproved AI

June 4, 2026
Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol