{"id":2878,"date":"2018-11-07T23:45:56","date_gmt":"2018-11-07T22:45:56","guid":{"rendered":"http:\/\/mouillere.com\/universconvergents\/?p=2878"},"modified":"2018-11-12T16:11:04","modified_gmt":"2018-11-12T15:11:04","slug":"vers-la-fin-annoncee-des-sms-dauthentification-des-paiements","status":"publish","type":"post","link":"https:\/\/mouillere.com\/universconvergents\/2018\/11\/07\/vers-la-fin-annoncee-des-sms-dauthentification-des-paiements\/","title":{"rendered":"Vers la fin annonc\u00e9e des SMS d\u2019authentification des paiements"},"content":{"rendered":"<p>Le SMS (SMS-OTP pour \u00abOne Time Password\u00bb) qui permet de valider la plupart des achats sur Internet devra \u00eatre remplac\u00e9 d\u00e8s septembre 2019 par des syst\u00e8mes d&#8217;identification plus performants.<\/p>\n<p><!--more--><\/p>\n<p>Une authentification forte est traditionnellement d\u00e9finie comme l\u2019utilisation de plusieurs facteurs pour authentifier l\u2019utilisateur d\u2019un moyen de paiement :<\/p>\n<ol>\n<li>la <strong>connaissance<\/strong>, qui consiste pour la banque \u00e0 demander quelque chose que seul l&#8217;utilisateur conna\u00eet,<\/li>\n<li>la <strong>possession<\/strong>, qui implique quelque chose que seul l&#8217;utilisateur poss\u00e8de,<\/li>\n<li><strong>l&#8217;inh\u00e9rence<\/strong>, qui n\u00e9cessite la certification d&#8217;un trait physique de l&#8217;acheteur comme la reconnaissance du visage ou des empreintes digitales.<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<p>D\u00e8s lors que deux de ces points sont officiellement v\u00e9rifi\u00e9s, et qu&#8217;ils sont ind\u00e9pendants l&#8217;un de l&#8217;autre, l&#8217;achat en ligne peut \u00eatre officialis\u00e9. \u00c0 noter que l&#8217;authentification par SMS valide deux de ces exigences, la possession (t\u00e9l\u00e9phone portable) et la connaissance (code transmis par SMS), mais que le SMS \u00e9tant re\u00e7u sur le t\u00e9l\u00e9phone, elles ne sont pas ind\u00e9pendantes l&#8217;une de l&#8217;autre. Le SMS de v\u00e9rification, qui transmet un mot de passe unique \u00e0 l\u2019utilisateur, est donc jug\u00e9 trop peu s\u00e9curis\u00e9. Il est en effet possible de d\u00e9tourner ce SMS par divers moyen, que ce soit gr\u00e2ce au vol de carte SIM, l\u2019interception de messages ou tout simplement le vol du t\u00e9l\u00e9phone.<\/p>\n<p>&nbsp;<\/p>\n<p>En cons\u00e9quence et afin de lutter contre la fraude aux paiements en ligne, les banques proposer des moyens d\u2019authentification plus fiables pour les utilisateurs tels que des capteurs d\u2019empreintes sur les cartes biom\u00e9triques ou des applications d\u2019authentification propos\u00e9es par les banques. Pour l&#8217;instant, la carte biom\u00e9trique est le syst\u00e8me le plus d\u00e9velopp\u00e9. Cette nouvelle g\u00e9n\u00e9ration de carte qui int\u00e8gre un capteur d&#8217;empreintes digitales devrait \u00eatre propos\u00e9e d\u00e8s janvier 2019 par certaines banques en France.<\/p>\n<p>&nbsp;<\/p>\n<p>Du c\u00f4t\u00e9 des commer\u00e7ants, si ces nouveaux syst\u00e8mes d&#8217;authentification r\u00e9duiront la fraude, le d\u00e9veloppement de la s\u00e9curit\u00e9 rallonge le processus d&#8217;achat et r\u00e9duit le taux de conversion. C\u2019est tout l\u2019enjeu des nouvelles solutions d\u2019authentification des paiements\u00a0: concilier s\u00e9curit\u00e9 et exp\u00e9rience utilisateur.<\/p>\n<p>&nbsp;<\/p>\n<iframe src=\"\/\/docs.google.com\/viewer?url=https%3A%2F%2Fmouillere.com%2Funiversconvergents%2Fwp-content%2Fuploads%2F2018%2F11%2FRapport-Annuel-2017-Observatoire-de-la-s%C3%A9curit%C3%A9.pdf&hl=fr&embedded=true\" class=\"gde-frame\" style=\"width:100%; height:500px; border: none;\" scrolling=\"no\"><\/iframe>\n<p class=\"gde-text\"><a href=\"https:\/\/mouillere.com\/universconvergents\/wp-content\/uploads\/2018\/11\/Rapport-Annuel-2017-Observatoire-de-la-s\u00e9curit\u00e9.pdf\" class=\"gde-link\">T\u00e9l\u00e9charger (PDF, 1.57Mo)<\/a><\/p>\n<p><a href=\"https:\/\/www.banque-france.fr\/sites\/default\/files\/medias\/documents\/818207_osmp2017_web_vf_v5.pdf\" target=\"_blank\" rel=\"noopener\">https:\/\/www.banque-france.fr\/sites\/default\/files\/medias\/documents\/818207_osmp2017_web_vf_v5.pdf<\/a><\/p>\n<p><a href=\"https:\/\/www.zdnet.fr\/actualites\/sms-d-authentification-des-paiements-vers-une-evolution-en-2019-39876169.htm\" target=\"_blank\" rel=\"noopener\">https:\/\/www.zdnet.fr\/actualites\/sms-d-authentification-des-paiements-vers-une-evolution-en-2019-39876169.htm<\/a><\/p>\n<p><a href=\"http:\/\/www.lefigaro.fr\/conso\/2018\/11\/07\/20010-20181107ARTFIG00208-le-sms-d-authentification-des-achats-en-ligne-devrait-disparaitre.php\" target=\"_blank\" rel=\"noopener\">http:\/\/www.lefigaro.fr\/conso\/2018\/11\/07\/20010-20181107ARTFIG00208-le-sms-d-authentification-des-achats-en-ligne-devrait-disparaitre.php<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Le SMS (SMS-OTP pour \u00abOne Time Password\u00bb) qui permet de valider la plupart des achats sur Internet devra \u00eatre remplac\u00e9 d\u00e8s septembre 2019 par des syst\u00e8mes d&#8217;identification plus performants.<\/p>\n","protected":false},"author":1,"featured_media":2880,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[87],"tags":[],"class_list":["post-2878","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-banking-payment"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/mouillere.com\/universconvergents\/wp-content\/uploads\/2018\/11\/digital-payment.jpg?fit=1170%2C480&ssl=1","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p6jw1p-Kq","jetpack-related-posts":[{"id":2754,"url":"https:\/\/mouillere.com\/universconvergents\/2018\/03\/22\/la-directive-europeenne-sur-les-services-de-paiement-dsp2\/","url_meta":{"origin":2878,"position":0},"title":"La Directive europ\u00e9enne sur les Services de Paiement (DSP2)","author":"Fred","date":"22 mars 2018","format":false,"excerpt":"La Directive europ\u00e9enne sur les Services de Paiement (DSP2) qui r\u00e9forme la premi\u00e8re directive adopt\u00e9e en 2009 et d\u00e9finissant un cadre juridique pour la mise en place d'un march\u00e9 europ\u00e9en unique des paiements, est entr\u00e9e en vigueur le 13 janvier 2018. La DSP2 a pour objectif de cr\u00e9er un march\u00e9\u2026","rel":"","context":"Dans &quot;Donn\u00e9es personnelles&quot;","block_context":{"text":"Donn\u00e9es personnelles","link":"https:\/\/mouillere.com\/universconvergents\/category\/it\/donnees-personnelles\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/mouillere.com\/universconvergents\/wp-content\/uploads\/2018\/03\/CBqt6UsSSPQ-ckxEyiUJkjl72eJkfbmt4t8yenImKBVvK0kTmF0xjctABnaLJIm9.jpg?fit=467%2C226&ssl=1&resize=350%2C200","width":350,"height":200},"classes":[]},{"id":2850,"url":"https:\/\/mouillere.com\/universconvergents\/2018\/10\/15\/tokenisation-paiement-et-authentification\/","url_meta":{"origin":2878,"position":1},"title":"Tokenisation, Paiement et Authentification","author":"Fred","date":"15 octobre 2018","format":false,"excerpt":"En mati\u00e8re de paiement, la tokenisation est le remplacement d\u2019\u00e9l\u00e9ments sensibles comme le PAN (Primary Account Number ou num\u00e9ro figurant au recto de votre carte bancaire) par des \u00e9l\u00e9ments moins sensibles appel\u00e9s tokens (ou jetons) li\u00e9s \u00e0 des appareils (mobiles, tablettes, IoT). L\u2019enr\u00f4lement (ou la demande d\u2019\u00e9mission d\u2019un jeton associ\u00e9\u2026","rel":"","context":"Dans &quot;Banking &amp; Payment&quot;","block_context":{"text":"Banking &amp; Payment","link":"https:\/\/mouillere.com\/universconvergents\/category\/it\/banking-payment\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/mouillere.com\/universconvergents\/wp-content\/uploads\/2018\/10\/tokenization.png?fit=765%2C430&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/mouillere.com\/universconvergents\/wp-content\/uploads\/2018\/10\/tokenization.png?fit=765%2C430&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/mouillere.com\/universconvergents\/wp-content\/uploads\/2018\/10\/tokenization.png?fit=765%2C430&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/mouillere.com\/universconvergents\/wp-content\/uploads\/2018\/10\/tokenization.png?fit=765%2C430&ssl=1&resize=700%2C400 2x"},"classes":[]},{"id":1331,"url":"https:\/\/mouillere.com\/universconvergents\/2015\/11\/03\/pourquoi-le-modele-des-conciergeries-par-sms-est-il-en-train-dexploser\/","url_meta":{"origin":2878,"position":2},"title":"Pourquoi le mod\u00e8le des conciergeries par SMS est-il en train d\u2019exploser ?","author":"Fred","date":"3 novembre 2015","format":false,"excerpt":"Si \u00ab l\u2019application \u00bb Magic a rapidement \u00e9t\u00e9 annonc\u00e9e comme un ph\u00e9nom\u00e8ne, c\u2019est avant tout pour sa simplicit\u00e9 et sa proposition de valeur. Mais simplicit\u00e9 ne signifie pas forc\u00e9ment facilit\u00e9 et pour \u00e9tablir quelques barri\u00e8res \u00e0 l\u2019entr\u00e9e, les \u00e9diteurs de ces conciergeries 2.0 affrontent directement des g\u00e9ants comme Facebook Messenger.\u2026","rel":"","context":"Dans &quot;Marketing&amp;Communication&quot;","block_context":{"text":"Marketing&amp;Communication","link":"https:\/\/mouillere.com\/universconvergents\/category\/publicite-marketing-communication\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/mouillere.com\/universconvergents\/wp-content\/uploads\/2015\/11\/Capture-d%E2%80%99%C3%A9cran-2015-11-05-%C3%A0-10.30.45.jpg?fit=1200%2C672&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/mouillere.com\/universconvergents\/wp-content\/uploads\/2015\/11\/Capture-d%E2%80%99%C3%A9cran-2015-11-05-%C3%A0-10.30.45.jpg?fit=1200%2C672&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/mouillere.com\/universconvergents\/wp-content\/uploads\/2015\/11\/Capture-d%E2%80%99%C3%A9cran-2015-11-05-%C3%A0-10.30.45.jpg?fit=1200%2C672&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/mouillere.com\/universconvergents\/wp-content\/uploads\/2015\/11\/Capture-d%E2%80%99%C3%A9cran-2015-11-05-%C3%A0-10.30.45.jpg?fit=1200%2C672&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/mouillere.com\/universconvergents\/wp-content\/uploads\/2015\/11\/Capture-d%E2%80%99%C3%A9cran-2015-11-05-%C3%A0-10.30.45.jpg?fit=1200%2C672&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":2886,"url":"https:\/\/mouillere.com\/universconvergents\/2018\/11\/25\/vulnerabilitie-des-cartes-didentite-electroniques\/","url_meta":{"origin":2878,"position":3},"title":"Vuln\u00e9rabiliti\u00e9 des cartes d&#8217;identit\u00e9 \u00e9lectroniques","author":"Fred","date":"25 novembre 2018","format":false,"excerpt":"ZDNet consacre un article relatif \u00e0 la vuln\u00e9rabilit\u00e9 du syst\u00e8me de cartes \u00e0 identit\u00e9 \u00e9lectronique (eID) utilis\u00e9 par l\u2019\u00c9tat allemand permettant d'usurper l'identit\u00e9 d'un autre citoyen lors de l'authentification eID. La vuln\u00e9rabilit\u00e9 ne r\u00e9side pas dans la puce d'identification par radiofr\u00e9quence (RFID) int\u00e9gr\u00e9e dans les cartes eID mais dans le\u2026","rel":"","context":"Dans &quot;Banking &amp; Payment&quot;","block_context":{"text":"Banking &amp; Payment","link":"https:\/\/mouillere.com\/universconvergents\/category\/it\/banking-payment\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/mouillere.com\/universconvergents\/wp-content\/uploads\/2018\/11\/german-eid-auth-process.png?fit=600%2C301&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/mouillere.com\/universconvergents\/wp-content\/uploads\/2018\/11\/german-eid-auth-process.png?fit=600%2C301&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/mouillere.com\/universconvergents\/wp-content\/uploads\/2018\/11\/german-eid-auth-process.png?fit=600%2C301&ssl=1&resize=525%2C300 1.5x"},"classes":[]},{"id":5724,"url":"https:\/\/mouillere.com\/universconvergents\/2023\/12\/19\/epic-games-gagne-contre-google\/","url_meta":{"origin":2878,"position":4},"title":"Epic Games gagne contre Google","author":"Fred","date":"19 d\u00e9cembre 2023","format":false,"excerpt":"Breaking news : Google abuse de son monopole sur le march\u00e9 de la distribution d'applications mobiles.Tout le monde le constate depuis des ann\u00e9es mais il aura fallu tout ce temps pour que Google soit condamn\u00e9e, le temps n\u00e9cessaire pour assoir sa domination. Il est grand temps que les autorit\u00e9s de\u2026","rel":"","context":"Dans &quot;IT&quot;","block_context":{"text":"IT","link":"https:\/\/mouillere.com\/universconvergents\/category\/it\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/mouillere.com\/universconvergents\/wp-content\/uploads\/2023\/12\/Gatekeepers-1.jpeg?fit=1024%2C1024&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/mouillere.com\/universconvergents\/wp-content\/uploads\/2023\/12\/Gatekeepers-1.jpeg?fit=1024%2C1024&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/mouillere.com\/universconvergents\/wp-content\/uploads\/2023\/12\/Gatekeepers-1.jpeg?fit=1024%2C1024&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/mouillere.com\/universconvergents\/wp-content\/uploads\/2023\/12\/Gatekeepers-1.jpeg?fit=1024%2C1024&ssl=1&resize=700%2C400 2x"},"classes":[]},{"id":3552,"url":"https:\/\/mouillere.com\/universconvergents\/2020\/01\/15\/projet-de-recommandations-cnil-sur-la-publicite-ciblee\/","url_meta":{"origin":2878,"position":5},"title":"Projet de recommandations CNIL sur la publicit\u00e9 cibl\u00e9e","author":"Fred","date":"15 janvier 2020","format":false,"excerpt":"Apr\u00e8s six mois de concertation, la CNIL vient de publier son projet de recommandation relatif aux cookies et autres traceurs publicitaires afin d'\u00e9clairer les \u00e9diteurs sur les bonnes pratiques \u00e0 suivre en mati\u00e8re de d\u00e9p\u00f4t de cookies et de consentement de l\u2019internaute. La CNIL a d\u00e9j\u00e0 eu l'occasion de rappeler\u2026","rel":"","context":"Dans &quot;Donn\u00e9es personnelles&quot;","block_context":{"text":"Donn\u00e9es personnelles","link":"https:\/\/mouillere.com\/universconvergents\/category\/it\/donnees-personnelles\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/mouillere.com\/universconvergents\/wp-content\/uploads\/2015\/06\/6640564215_b3dc3f033d.jpg?fit=450%2C287&ssl=1&resize=350%2C200","width":350,"height":200},"classes":[]}],"_links":{"self":[{"href":"https:\/\/mouillere.com\/universconvergents\/wp-json\/wp\/v2\/posts\/2878","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mouillere.com\/universconvergents\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mouillere.com\/universconvergents\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mouillere.com\/universconvergents\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mouillere.com\/universconvergents\/wp-json\/wp\/v2\/comments?post=2878"}],"version-history":[{"count":1,"href":"https:\/\/mouillere.com\/universconvergents\/wp-json\/wp\/v2\/posts\/2878\/revisions"}],"predecessor-version":[{"id":2881,"href":"https:\/\/mouillere.com\/universconvergents\/wp-json\/wp\/v2\/posts\/2878\/revisions\/2881"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mouillere.com\/universconvergents\/wp-json\/wp\/v2\/media\/2880"}],"wp:attachment":[{"href":"https:\/\/mouillere.com\/universconvergents\/wp-json\/wp\/v2\/media?parent=2878"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mouillere.com\/universconvergents\/wp-json\/wp\/v2\/categories?post=2878"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mouillere.com\/universconvergents\/wp-json\/wp\/v2\/tags?post=2878"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}