Showing posts with label Chip and PIN. Show all posts
Showing posts with label Chip and PIN. Show all posts

Wednesday, March 23, 2011

Alarming News About Chip and PIN (Being Broken Again)


Here's why I say again...
Chip and PIN is Broken say Researchers
(from Finextra at 22-3-2011)
In a presentation at the CanSecWest security conference earlier this month, the researchers from InversePath declared that chip and PIN is "definitely broken" and skimming will become "extremely appealing" to fraudsters.  
The group built a prototype skimming device which it says can be easily installed at any POS terminals or ATMs, is virtually impossible to spot and uses the machines to power itself. EMV cards talk to payment terminals via application protocol data unit (APDU) messages for reading records and issuing commands. InversePath says skimmers can intercept and read every part of the terminal-ICC exchange.  Crooks can then download the data with a special card recognised by the skimmer and use it to perform online transactions that do not require users to give the CVV numbers on the back of their cards.
Download the document from Finextra now2 mb (PDF File)








Enhanced by Zemanta

Monday, June 7, 2010

Gemalto White Paper Suggests it's Time for EMV in U.S.

PYMNTS.com published a whitepaper produced by Gemalto...



EMV stands for the organizations that developed the standard – Europay, MasterCard and Visa. After the development of the standard, Europay became a part of MasterCard, while other card issuers such as JCB and American Express have begun supporting it. EMVCo, an organization jointly owned by American Express, JCB, MasterCard and Visa, now manages the EMV standard. Most countries implementing smart bank cards require the use of a Personal Identification Number (PIN) in each transaction, which is why “chip and PIN” is often used to refer to EMV implementation programs.


Gemalto White Paper Suggests it's Time for EMV in U.S.

PYMNTS.com published a whitepaper produced by Gemalto...



EMV stands for the organizations that developed the standard – Europay, MasterCard and Visa. After the development of the standard, Europay became a part of MasterCard, while other card issuers such as JCB and American Express have begun supporting it. EMVCo, an organization jointly owned by American Express, JCB, MasterCard and Visa, now manages the EMV standard. Most countries implementing smart bank cards require the use of a Personal Identification Number (PIN) in each transaction, which is why “chip and PIN” is often used to refer to EMV implementation programs.


Thursday, April 29, 2010

Walmart Wants Chip and PIN

Retailers to Banks: Give Us Chip and PIN, Electronic Checks









Whether the good ole' U.S. of A. decides to got the route of Chip and PIN or not, the rest of the world has already gone there.  Above is a video of what we believe is the world's first Chip and PIN Card reader designed specifically for eCommerce and mCommerce use.  It was developed by our CTO, Ben Lo and our sister company, BBPOS and is currently going through the certification process.



In the meantime, here is some more information on the BBPOS Chip and PIN Card Reader...


































Reblog this post [with Zemanta]

Walmart Wants Chip and PIN

Retailers to Banks: Give Us Chip and PIN, Electronic Checks









Whether the good ole' U.S. of A. decides to got the route of Chip and PIN or not, the rest of the world has already gone there.  Above is a video of what we believe is the world's first Chip and PIN Card reader designed specifically for eCommerce and mCommerce use.  It was developed by our CTO, Ben Lo and our sister company, BBPOS and is currently going through the certification process.



In the meantime, here is some more information on the BBPOS Chip and PIN Card Reader...


































Reblog this post [with Zemanta]

Wednesday, April 28, 2010

Visa Cuts Swipe Fees In Europe, Raises Them In America

Visa Debit logo
Laura Basset writes for the Huffington Post that while Visa raised it's debit rates (notably the 30% PIN Debit rate increase) here in the good ole' USA, they cut debit fees in Europe.  I found it interesting that Visa is shying away from stating that Europe should have lower debit rates because they use "Chip and PIN" which reduces fraud.  After all, fraud is the basis for...well, "basis points.."  Guess that would put them in a position whereby they couldn't defend the security of America's magstripe system...



Instead, according to the Huffington Post, here's the official statement from a "Visa spokesperson" Editor's Note:  I took the liberty to identify the BSMS* (Both Sides of the Mouth Syndrome) and I highlighted in yellow what the spokesperson's conscience couldn't prevent them from saying... 



A spokesperson for Visa, Inc. said the average Visa Debit transaction fee rose by less than 4 percent.  "Most of Visa's U.S. debit rates have not changed*," she said. "Visa, Inc., did recently make a variety of program and interchange modifications to make digital currency even more convenient for consumers and merchants and to facilitate continued growth for Visa and its clients."

Despite a recent study that found swipe fees are stalling the creation of nearly a quarter million U.S. jobs, Visa raised its debit card interchange rate for American retailers to .95 percent plus $.20 per transaction in April, according to the Retail Industry Leaders Association. In contrast, Visa Europe announced Monday that it would be capping transaction fees at 0.2 percent for the next four years.
Continue Reading at the Huffington Post 

Reblog this post [with Zemanta]

Visa Cuts Swipe Fees In Europe, Raises Them In America

Visa Debit logo
Laura Basset writes for the Huffington Post that while Visa raised it's debit rates (notably the 30% PIN Debit rate increase) here in the good ole' USA, they cut debit fees in Europe.  I found it interesting that Visa is shying away from stating that Europe should have lower debit rates because they use "Chip and PIN" which reduces fraud.  After all, fraud is the basis for...well, "basis points.."  Guess that would put them in a position whereby they couldn't defend the security of America's magstripe system...



Instead, according to the Huffington Post, here's the official statement from a "Visa spokesperson" Editor's Note:  I took the liberty to identify the BSMS* (Both Sides of the Mouth Syndrome) and I highlighted in yellow what the spokesperson's conscience couldn't prevent them from saying... 



A spokesperson for Visa, Inc. said the average Visa Debit transaction fee rose by less than 4 percent.  "Most of Visa's U.S. debit rates have not changed*," she said. "Visa, Inc., did recently make a variety of program and interchange modifications to make digital currency even more convenient for consumers and merchants and to facilitate continued growth for Visa and its clients."

Despite a recent study that found swipe fees are stalling the creation of nearly a quarter million U.S. jobs, Visa raised its debit card interchange rate for American retailers to .95 percent plus $.20 per transaction in April, according to the Retail Industry Leaders Association. In contrast, Visa Europe announced Monday that it would be capping transaction fees at 0.2 percent for the next four years.
Continue Reading at the Huffington Post 

Reblog this post [with Zemanta]

Monday, April 26, 2010

No PIN Needed to Fool Chip and PIN Technology - Cambridge



University of CambridgeChip and PIN has come under further scrutiny today as research shows a vulnerability allowing criminals to use cards without the owner’s number.
By Jennifer Scott, 26 Apr 2010 at 15:47
Chip and PIN
Cyber criminals are able to abuse the Chip and PIN system, even without the cardholder’s four digits, according to new research released today.
The study by Cambridge University’s Computer Laboratory has shown that thanks to a protocol flaw a “man in the middle” attack is possible, whereby criminals can insert an electronic device between the card and the terminal, fooling it into believing the PIN is verified.
Eli Jellenç, head of international cyber intelligence at iD...


No PIN Needed to Fool Chip and PIN Technology - Cambridge



University of CambridgeChip and PIN has come under further scrutiny today as research shows a vulnerability allowing criminals to use cards without the owner’s number.
By Jennifer Scott, 26 Apr 2010 at 15:47
Chip and PIN
Cyber criminals are able to abuse the Chip and PIN system, even without the cardholder’s four digits, according to new research released today.
The study by Cambridge University’s Computer Laboratory has shown that thanks to a protocol flaw a “man in the middle” attack is possible, whereby criminals can insert an electronic device between the card and the terminal, fooling it into believing the PIN is verified.
Eli Jellenç, head of international cyber intelligence at iD...


Monday, April 19, 2010

Nominations Open for Smart Card Alliance 2010 OSCA Awards



PRINCETON JUNCTION, NJ, April 19, 2010 – The Smart Card Alliance today opened nominations for its prestigious “Outstanding Smart Card Achievement” (OSCA) awards, announcing two new categories honoring innovative products and services in payments and security markets.  The 2010 OSCA awards will be presented during the Smart Card Alliance 2010 Annual Conference, May 17th through the 20th at the Camelback Marriott Resort and Spa in Scottsdale, Arizona. 


“North America has been leading the smart card industry in recent years, with some of the most exciting new innovations for payments and security being developed, piloted and deployed in this region,” said Randy Vanderhoof, executive director of the Smart Card Alliance.  “With the OSCAs, we recognize those companies and individuals that have been vital to these achievements, and showcase them to the world.”


All specific criteria for each award, as well as eligibility requirements and nomination forms, can be found on the Smart Card Alliance OSCA award Web site.  All nominations must be received by April 26, 2010.  Nominations are open in four award categories – three for organizations and one for an individual:


  • Outstanding Issuing Organization Award.  This award will be presented to an organization that is issuing smart card technology to its internal clients or external customers for their use in North America.

  • Outstanding Innovation in Payments Technology Award.  This award will go to an innovative new, or existing payments-related product or service using smart card technology for use in a payments application. 

  • Outstanding Innovation in Security Technology Award.  This award will go to an innovative new, or existing security-related product or service using smart card technology for use in an identification, authentication, or access security application.

  • Outstanding Individual Leadership Award.  This award will be presented to an individual who stands out for his or her individual contributions to the smart card industry in North America based on a professional record of leadership, vision, support and commitment to the smart card industry.

A judging panel, consisting of North American smart card industry suppliers and end-users along with individuals from the analyst and media communities, will review all qualified OSCA applications and select three finalists in each category based on the nominee’s merits and qualities outlined in the applications.  The judging panel will apply a score for each nominee that will rank the three finalists in each category and the combined results will determine the winner, the runner-up, and the honorable mention award winners for 2010. 


The 2010 OSCA winners will be announced at the Smart Card Alliance Gala Awards Dinner on Tuesday, May 18th at the Camelback Marriott Hotel in Scottsdale.  The 2009 OSCA Award winners are on the Smart Card Alliance Web site.


The Smart Card Alliance 2010 Annual Conference will address “Smart Cards in Action,” focusing on the issuers and users of smart card technology in payments, security, and mobile markets.  Further information about the conference, with links to event information and registration web site containing the complete agenda, list of exhibitors and registered attendees to date, and full registration details are available on the Smart Card Alliance Web site.   


About the Smart Card Alliance

The Smart Card Alliance is a not-for-profit, multi-industry association working to stimulate the understanding, adoption, use and widespread application of smart card technology. 


Through specific projects such as education programs, market research, advocacy, industry relations and open forums, the Alliance keeps its members connected to industry leaders and innovative thought.  The Alliance is the single industry voice for smart cards, leading industry discussion on the impact and value of smart cards in the U.S. and Latin America.  For more information please visit http://www.smartcardalliance.org.


###




Reblog this post [with Zemanta]

Nominations Open for Smart Card Alliance 2010 OSCA Awards



PRINCETON JUNCTION, NJ, April 19, 2010 – The Smart Card Alliance today opened nominations for its prestigious “Outstanding Smart Card Achievement” (OSCA) awards, announcing two new categories honoring innovative products and services in payments and security markets.  The 2010 OSCA awards will be presented during the Smart Card Alliance 2010 Annual Conference, May 17th through the 20th at the Camelback Marriott Resort and Spa in Scottsdale, Arizona. 


“North America has been leading the smart card industry in recent years, with some of the most exciting new innovations for payments and security being developed, piloted and deployed in this region,” said Randy Vanderhoof, executive director of the Smart Card Alliance.  “With the OSCAs, we recognize those companies and individuals that have been vital to these achievements, and showcase them to the world.”


All specific criteria for each award, as well as eligibility requirements and nomination forms, can be found on the Smart Card Alliance OSCA award Web site.  All nominations must be received by April 26, 2010.  Nominations are open in four award categories – three for organizations and one for an individual:


  • Outstanding Issuing Organization Award.  This award will be presented to an organization that is issuing smart card technology to its internal clients or external customers for their use in North America.

  • Outstanding Innovation in Payments Technology Award.  This award will go to an innovative new, or existing payments-related product or service using smart card technology for use in a payments application. 

  • Outstanding Innovation in Security Technology Award.  This award will go to an innovative new, or existing security-related product or service using smart card technology for use in an identification, authentication, or access security application.

  • Outstanding Individual Leadership Award.  This award will be presented to an individual who stands out for his or her individual contributions to the smart card industry in North America based on a professional record of leadership, vision, support and commitment to the smart card industry.

A judging panel, consisting of North American smart card industry suppliers and end-users along with individuals from the analyst and media communities, will review all qualified OSCA applications and select three finalists in each category based on the nominee’s merits and qualities outlined in the applications.  The judging panel will apply a score for each nominee that will rank the three finalists in each category and the combined results will determine the winner, the runner-up, and the honorable mention award winners for 2010. 


The 2010 OSCA winners will be announced at the Smart Card Alliance Gala Awards Dinner on Tuesday, May 18th at the Camelback Marriott Hotel in Scottsdale.  The 2009 OSCA Award winners are on the Smart Card Alliance Web site.


The Smart Card Alliance 2010 Annual Conference will address “Smart Cards in Action,” focusing on the issuers and users of smart card technology in payments, security, and mobile markets.  Further information about the conference, with links to event information and registration web site containing the complete agenda, list of exhibitors and registered attendees to date, and full registration details are available on the Smart Card Alliance Web site.   


About the Smart Card Alliance

The Smart Card Alliance is a not-for-profit, multi-industry association working to stimulate the understanding, adoption, use and widespread application of smart card technology. 


Through specific projects such as education programs, market research, advocacy, industry relations and open forums, the Alliance keeps its members connected to industry leaders and innovative thought.  The Alliance is the single industry voice for smart cards, leading industry discussion on the impact and value of smart cards in the U.S. and Latin America.  For more information please visit http://www.smartcardalliance.org.


###




Reblog this post [with Zemanta]

Thursday, March 11, 2010

Online Banking Fraud Rises 14% as Criminals Move to Web



Debit and credit card fraud has fallen dramatically as criminals turn their attention to the easier pickings to be had from fleecing online banking customers.  Figures released today by the UK Cards Association revealed a substantial 28% drop in fraud losses from 2008 to 2009, amounting to £170m. This dramatic fall to lowest levels since 2006 was put down to combination of initiatives from banks, including chip and PIN, as well as greater police input.

The picture online was less rosy, however. Online banking losses ramped up 14% in 2009 compared to year earlier figures, totalling £59.7m, as fraudsters targeted the weakest link in the chain – individual banking customers – and tripped them up using phishing or malware attacks. Phishing attacks grew 16% in 2009 compared to year earlier figures, as customers disclosed their banking details to fake email requests or cold callers.


Continue Reading at CBR

Friday, February 19, 2010

Chip and PIN Flaw to be Investigated by EMVCo



ZDNet is reporting that "the body that oversees the technology behind chip-based payment cards is to investigate chip-and-PIN security, following claims that the protocol has been broken."



Chip-and-PIN flaw to be investigated by industry body  Tom Espiner ZDNet UK
The specification body, EMVCo, said it will analyze a paper by researchers from Cambridge University, who demonstrated an attack with a valid payment card that did not require a valid PIN to be entered to complete a transaction.



EMVCo, owned by American Express, JCB, MasterCard and Visa, said those debit- and credit-card payment companies will also scrutinize the paper.



"EMVCo will conduct its own analysis and draw its own conclusions," said the organisation on Wednesday. "The payment systems will do the same."



Last week researchers from Cambridge University said they had found a fundamental flaw in EMV, the protocol behind chip-and-PIN payments. The flaw had allowed them to build a device that modified and intercepted communications between a card and a point-of-sale terminal, and fool the terminal into accepting that a PIN verification had succeeded.



MasterCard confirmed that it would be working with the other card-payment providers to review security around chip-and-PIN, but said this was part of an ongoing process.



"The EMV standard is under constant review by MasterCard and many other major industry players to make sure it evolves to meet emerging product needs," said MasterCard. "These efforts include a frequent and regular review of security to make sure the latest, practical mechanisms are used."



Professor Ross Anderson of Cambridge University, who led the chip-and-PIN research, said there would be no easy fix for the protocol.



"There is much disagreement about [effective] industry measures to fix the vulnerability," said Anderson. "If you look at our blog post [publicising the vulnerability], a significant number of people who claim to be industry experts disagree."



One of the researchers' assertions in their paper, Chip and PIN is Broken, was that the consumer would bear the cost of a fraudulent card transaction if records showed a PIN had been entered into a terminal.



Continue Reading at ZDNet






Disqus for ePayment News