Payment Risk Analysis on the Web

Ian Jacobs

Many Signals Available

Oscilloscope screen

Since the risk landscape changes over time, risk engines want as many useful and trusted signals as they can get.

Device Data APIs

HTTP Headers

Additional Techniques

User Problems

Merchant/Bank Problems

Goals

Is the Status Quo Good Enough?

Opportunity: FIDO 2

Status of WebAuthn and related spec implementation

Image courtesy of Adam Powers.

On FIDO 2

Is FIDO 2 Good Enough?

Are There Use Cases where FIDO 2 is Not Sufficient?

Example scenarios:

Additional Ideas for Browser / Device Data

Discussion

NEXT OPPORTUNITY: To discuss use cases in person is the W3C Workshop on Strong Authentication and Identity, 10-11 December in Redmond, Washington (USA). Hosted by Microsoft. Position papers due 29 October!