Showing posts with label Derived unique key per transaction. Show all posts
Showing posts with label Derived unique key per transaction. Show all posts

Thursday, August 20, 2009

HomeATM's Weapon of "Phish Destruction"...

There a lot of banking promotions cropping up designed to "lure" customers over.

Want to lure them over? Use phishing. Did I just say "use phishing" to lure them over? I did.

$100 isn't going to do it. When it comes to innovative marketing ideas, bribing a customer has never been near the top of the list. But...instead of customers being lured away from your bank by becoming a victim of phishing, "lure" them to your bank by using "phishing" as bait. It'll work hook, line and sinker.

Here's what I'm thinking. How about running an innovative promotion in which a bank guarantees their customer is 100% protected from phishing. If you lure them by protecting them from the bad guys (which would also protect the $1000's, not $100, of dollars in their bank account), you would attract more customers than $100 would attract AND, at the same time, enhance your bank's image. It's all about security. Here's proof:

HALF (49%) Would Consider Changing Banks Following Card Fraud...22% "Would" Change Banks!

Editors Note: Wow, if I was a financial institution offering "online banking"that headline would haunt me 24 hours a day until I figured out a wayto either change it or use it to create an opportunity for my onlinebank to flourish.

My first thought would be: "If 50% would consider "changing banks AFTER" they get hit by card fraud/onlinebanking/phishing fraud, how many would consider "changing banks" to"AVOID" getting hit?

And to which competitor would they go?

I'd conclude that if they "left because of insecurity" they would probably "come on board BECAUSE of security."

Soif I wanted to open a portal for dissatisfied online banking customers,I would use a uniquely positioned product to ensure my customerssecurity. I'm thinking Swipe vs. Type here. Then I would think...howmany potential customers could my bank procure by "guaranteeing" onlinesecurity? Research would determine if it was millions or only"Hundreds of Thousands." I think I made my point. If not, I challenge you to continue reading...

Banks have a "serious issue" with phishing and I am suggesting that there is a low-cost solution to completely eliminating this on-going threat.
Eliminate typing and you'll eliminate phishing. First a quick backgrounder...

The nature of this beast known as "phishing" is to lure these onlinebanking folks, with a sophisticated and genuine looking trap whichincludes genuine looking emails which provide links to genuine lookingsites. (a new "type" of bait and switch)


Once there, users are simply instructed to do what they've been programmed to do since day one with online banking. And therein lies the problem...
They are told to "type" in their username and password to log-in.

Problem is, once they "type" in their "username | password" they provide full access to their accounts to the phisheries.


Ifyou haven't figured it out already, (something phishy goin' on here) allow me to point out the majorflaw in this process...


If online banking customers had not beenoriginally programmed to "type" anything into a box the first place, then this type of phishing would not have cropped up in the second place. A simple case of "cause and effect."


Case in point: Imagine if you will, that when ATM's first came out, users were instructed to "make up" a username and password for whichwould have provided full access to ATM's? How smart would that havebeen?

Fortunately the banks were smarter than that and they required that their ATM customers insert their card into a built-in card reader AND enter their PIN. Two factor authentication 101. What you "have" (card) and what you "know" (PIN)

Why should it be any different for online banking log-in?

What has happened since then to make them believe "typing" is safer than "swiping?" Why are they suddenly dissin' the card?


Window of Opportunity

Instead of dissin' the card, I say "DISCARD" the antiquated username and password log-in process and instruct customers "USE THEIR CARD" (what they have) and their PIN (what they know) thereby replicatingthe exact same process these customers use gain access to an ATM.

True2FA. The only difference would be that authentication would be done inthe safety (no skimmers/no cameras) of the online banking customers own home...with a PCI 2.x certified (not compliant..."certified") personal PIN Entry Device. (providing 2FA 3DES E2EE DUKPT Security)

If the online banking community introduced their customers to a simple(not) new log-in process, one whereby they require that theironline banking customers log-in the "same way" they do at ATM's...by "swiping" with "THEIR CARD, and securely entering "THEIR PIN" they would greatlyenhance the security of their online banking sites.


This two factor secure log-in would eliminate the issues they arehaving with these phishing attacks altogether. A secure 2FA 3DES E2EE DUKPT log-in would also eliminate threats created by cloned bank websites, cloned cards, DNS Hijacking,etc. The data is never in the clear...so when it comes to becoming a victim of fraud, your customer is in the clear.

In effect, banks would be arming their online banking customers with aweapon of phish destruction, one that fights cybercrime and "empowers"them as mini-profit centers. Does anyone disagree with the statementthat "Bill Payments, Money Transfers, and secure online transactions"ALL make money for banks? (again, see previous post)



That said, I humbly suggest it's high time to "studythree key issues" more closely.

Let's look at "these issues" one at a time:


    • Bank "ISSUES" the Card,
    • Bank "ISSUES" the PIN,
    • Banks ISSUES a $12 PCI 2.x Certified 2FA 3DES E2EE DUKPT Secure Card/PIN Reader

      $12! Yes (in quantity)...banks could save $88 per customer (compared to Citi's offer above) and PROTECT their customer. Protect them from what? Did you know that the average phishing attack costs the bank and thebank customer $350. Want proof?

      Okay, here it is from Gartner Research:

      According to research firm,Gartner, banks, online payment organizations and other financialinstitutions are bearing most of the financial cost of phishingattacks.

      (A survey of nearly 4,000 US consumers revealed a 40% increase in the number of phishing victims in 2008 over the year before to five million.)
      The average loss was $352 per phishing attack, but consumers said they had recovered 56% of their losses from the financial institutions involved. (sounds like the $100 bribe above is lost in the first phishing attack to me)

      "The findings underline the fact that the war against phishing is far from over," said Avivah Litan, analyst at Gartner.
      (Yes, the very same Avivah Litan who says "never" enter your PIN on the Internet unless it's hardware based)

      Want to read more on this subject? Scroll down to the next post. I'll make it easy...click here.














      Reblog this post [with Zemanta]

      Wednesday, August 19, 2009

      Credit Card Scam Raises New Web Security Fears












      Alleged credit card scam raises new web security fears






      Editor's Note: Browsers Are an Open Book


      Everything is relative.  What's new for some is old news for others.  But again, I am gratified that these new "web security" fears are being raised.  We are and have been on the record stating that the web is NOT a safe place to conduct financial transactions...and recent events are pushing others over to our way of thinking. 

      Maybe the publicity over this recent indictment will be the straw that breaks the camels back.   Maybe it will be the meteoric rise in malware threats.  (
      Threats have increased from 125,000 unique pieces of
      malware in 2006 to 1.5 million in 2008 and 1.2 million MORE in the first
      half of 2009 alone) 



      Maybe it will the realization that when consumers "type" hackers "swipe".  Maybe a giant phishing attack like the recent one on CommonWealth Bank will do it.  Certainly no one can argue that when you combine all the threats "web security" clearly has severe flaws.  Our "goal" is to make that as clear as the credit/debit card data that travels through it.  HomeATM doesn't make the argument to "swipe" vs.  "type" BECAUSE we created our PCI 2.x Certified Swiping Device.  We CREATED the device because we knew that when people "type" hackers "swipe."




      In order to "secure" transactions done via the web, they must be conducted "outside" the realm of the open book known as browsers...








      The data must be "instantaneously" encrypted and must be transmitted in it's encrypted form via the "Internet" (not the web) which simply serves as a conduit.   Typing is the "cause" hacking is the "effect." 

      Consider how a "phishing" attack would be successful if consumers didn't type their username / password or credit/debit card number into a box?  DES DUKPT (derived unique key per transaction) encrypted data  would be useless to them. 

      If consumers were mandated to "swipe" vs. "type" there would be no more "phish" in the sea!   Online banking would eliminate phishing completely if they mandated secure two-factor authenticated log-in by replicating the procedure already required for ATM withdrawals.

      Again, it is gratifying to see headlines like the one above.  It's only a matter of time before "everyone" realizes "typing" needs to be eliminated.  Browsers are an open book...

      An excerpt from an article published by the Guardian:


      US companies and law enforcement agencies are facing fresh questions today about the ease with which hackers can penetrate their defenses and make off with vital data about consumers, following the arrest and charging of a Miami man for what is allegedly the biggest credit card scam in history.


      Albert Gonzalez, a 28-year-old former informant for the US secret service who helped the authorities track hackers, was charged with conspiring to steal the details of 130 million credit cards. The charge sheet detailed a complex history of online skulduggery in which Gonzalez used three internet aliases: segvec, soupnazi and j4guar17, each marking different stages in his life.

      The alleged fraud was perpetrated through devices that could penetrate computer networks, steal card data and send it to servers in the US and Europe, prosecutors say. The acting US attorney general, Ralph Marra, praised the investigators "in tracking down cutting edge hacking schemes committed by hackers working together across the globe"...






















      Security firms join working group to fight web threats



      Wednesday, August 19, 2009

      Several
      prominent web security companies are joining together to share
      information and resources to fight the growing threat of malware on the
      web.
      Assembled under the IEEE Standards Association, the working group
      is called the Industry Connections Security Group (ICSG).



      AVG
      Technologies, McAfee, Microsoft, Sophos, Symantec and Trend Micro are
      the initial members of ICSG, which will seek to engage security
      vendors, banks, internet service providers, educational institutions
      and government agencies to promote better security on the web.



      The
      group will develop, document and promote proposals for enhancing
      security, toward the goal of producing consensus approaches and perhaps
      fueling new IEEE standards.



      "We've seen a whole ecosystem develop around threats to computer security," said Jeff Green, ICSG chair and senior vice president of McAfee Avert Labs.





      Green said
      the security industry has fragmented itself among various siloed
      efforts designed to solve very specific problems, such as phishing and
      spyware. ICSG would seek to more comprehensively address the security
      problems. Threats have increased from 125,000 unique pieces of
      malware in 2006 to 1.5 million in 2008 and 1.2 million in the first
      half of 2009 alone, according to McAfee.




















      Reblog this post [with Zemanta]

      Sunday, July 19, 2009

      Online Banking Data Being Fed to the Phishes



      BANKS and bank customers face an array of threats to their security as international criminal groups roll out a new generation of viruses, malware, fake websites and sophisticated phishing emails.

      Internet banking experts say without co-ordinated global action by governments, financial institutions will have to "give up on the internet" because they are losing their war against hackers and criminal fraudsters.
      Editor's Note:  That's what I've been saying for the last 15 months on this blog.  It was (not safe) safer to type your card numbers into a box at a merchant checkout center a year ago than it is today and it's (not safe) safer to do it today than it will be tomorrow. 

      It's satisfying to see "Internet Banking Experts" start to to publicly admit there is an inherent weakness in the system. 

      HomeATM's device (pictured above) is a secure solution to the phishing, DNS attack and cloned web site threats which permeate the online banking world.  Our solution exactly replicates how one would access their cash at an ATM.   1. You swipe your card, and 2. You Enter your PIN.  It's called 2FA (two-factor-authentication) and it would virtually eliminate phishing overnight.  The Track 2 data is "instantaneously" encrypted upon the swipe of the card and the PIN is also 3DES Encrypted and protected by DUKPT (Derived Unique Key Per Transaction).  Our unique end-to-end encryption methodology provides the most secure authentication and payment application available today. Period. 

      Early next week, HomeATM expects to become the only eCommerce Payment company in either hemisphere to be both PCI 2.x Certified and TG-3 certified.  Swipe don't Type.  It's how retailers and consumers have been doing it at brick and mortar locations since the early 80's and it's how it should be done online.  Until now, there wasn't an affordable way to get consumers there very own SwipePIN device.  But HomeATM has gotten the price down to the point that banks could literally give them away...thus empowering their online banking customers to not only log-in securely but pay bills in real-time, send or receive money in real-time and conduct safe, secure online transactions.  I've stated that it is as simple as 1-2-3.  Two are already done.  The bank issues the card, the bank issue the PIN...now the bank can issue the HomeATM Internet POS terminal.   The story continues... 

      Almost one-quarter of the entire Australian population has been affected by identity theft crimes, according to a recent survey by Veda Advantage and that number keeps growing each year.   "Last year some 450,000 Australians were the victims of fraud," NSW Attorney-General John Hatzistergos said last weekend as he announced new laws that effectively duplicate Queensland's cyber crime laws.

      "Nearly a billion dollars was taken from people and confiscated by criminals, using a variety of different techniques, trading in people's personal information, such as passwords, pin numbers, names and addresses.


      The state based approach to the problem will not work says Professor Bill Caelli from Queensland University of technology's Information Security Institute. Prof Caelli says only co-ordinated global action by governments can secure the net.
      Speaking to the Sunday Mail from a major IT conference in Paris where the issue of securing the net is high on the agenda, Prof Caelli claimed "banks were simply not capable of providing secure internet banking."
      There is a big discussion happening globally about web services such as internet banking. The question is, "Can you create large-scale secure transaction systems on the weband the answer is coming back as no."

      Already this year, two of Australia's biggest banks have reported significant attacks on their internet banking portals. Both attacks came after significant investments by the banks to upgrade their online banking platforms.

      "The criminals tend to target one bank and when that institution shuts them down they move to another bank so it goes in circles," said Gary Gill, head of forensics at KPMG.

      Australia's biggest bank, the Commonwealth Bank, reported that a malicious attack had probably contributed to its banking website, Netbank, crashing on the busiest days of the year – the two days before the end of the financial year.

      Steve Batten, the media spokesman for the Commonwealth Bank, said that Netbank was designed to handle 13,000 customers online concurrently.   Last Monday, 18,500 customers were logging in concurrently and 1.59 million hits were registered in the 24-hour period.  Mr Batten said that the bank suspected that some of that traffic was malicious.

      In February ANZ Bank reported a sophisticated scam that led to a fake web page appearing to customers after they logged in to the ANZ internet banking site.







      Reblog this post [with Zemanta]

      Thursday, May 14, 2009

      Web Application Firewalls Hacked

      Researchers Hack Web Application Firewalls

      OWASP Europe presentation demonstrates tools that fingerprint the brand of WAF, as well as bypass it altogether

      By Kelly Jackson Higgins | DarkReading

      A pair of researchers at the OWASP Europe 2009 conference on Wednesday showed how some Web application firewalls (WAFs) are prone to attack.

      Wendel Henrique, a member of SpiderLabs (Trustwave's advanced securityteam), and Sandro Gauci, founder and CSO for EnableSecurity, also foundsome WAFs vulnerable to the same types of exploits they are supposed toprotect Web apps from, such as cross-site scripting (XSS) attacks.


      The researchers used a tool they developed, called WafW00f, todetect and fingerprint the presence -- and in some cases, the brand --of a WAF running in front of a Web application. A second tool createdby Henrique and Gauci, called WafFun, let them exploit and bypass WAFsrunning in blacklisting and whitelisting modes. With a combination ofWafW00f and WafFun, the researchers are able to execute attacks on theWAF invisibly so they can successfully hack the Web-facing applicationsitting behind it.

      Editor's Note:  So let me get this straight...HTTTPS is HTTBS and Firewalls are useless.   4 Questions: 
      • Are you starting to see how unsafe a web browser is? 
      • Are you starting to see why financial transactions SHOULD NEVER be done in a web browser space? 
      • Are you starting to see why HomeATM engineered, patented and manufactures the ONLY PCI 2.0 PED designed for eCommerce use? 
      • Are you starting to see that the 3DES end to end encryption of cardholder data with DUKPT key management is the safest and most secure way to provide consumers and merchants from hackers?      

      "If an attacker knows what product and version, it's easy toexploit it. One of the things [WAF] vendors claim is that they[operate] in stealth [mode]," Henrique says. "But in practice, theyhave a lot of different behaviors that they create...and you can usethose behaviors to identify what WAF is in place."

      Continue DarkReading


      Reblog this post [with Zemanta]

      Friday, May 1, 2009

      3DES, DUKPT and E2EE Explained


      I received a couple questions via email and wanted to take the time to provide a "coupla" of answers.  If you have any questions about anything I've blogged about over the past year, feel free to shoot me one. I've got my email below:

      Here's the first question:

      Q:  Is Triple DES a better encryption standard than DUKPT?  (Derived Unique Key Per Transaction)?

      A:I've used the terms Triple DES and DUKPT quite a bit in recent posts. To clarify, let's just start by saying that DUKPT does not really compete with Triple DES.  Let's go over them one by one.

      The DES stands for Data Encryption Standard, a block cipher that was selected as an official Federal Information Processing Standard (FIPS)for the United States in 1976.

      Triple DES, sometimes shortened further as 3DES, increases the difficulty of cracking the encryption byapplying three rounds of action: an encryption, a decryption and an encryption, each with independent keys.

      3DES has become popular for encrypting financial transactions because it is potentially far more secure than DES, which has been shown to yield its secrets somewhat quickly to relatively cheap hardware.

      Both DES and 3DESuse a symmetric key. In other words, the same key enciphers and deciphers the protected data.  To keep the key secret, a secure key-management system is required.

      Worldwide, POS devices handle billions of transactions per day.  If the keys to even a small portion of that traffic was discovered, we'd have a tremendously huge problem.  Which is my segway to DUKPT.

      One way to prevent fraud is to use a different key for "each transaction," (Derived Unique Key Per Transaction)   HomeATM's secure devices (and thus your transactions) are "Protected by DUKPT" and each one is initialized with a master key.   The master key is from which the unique keys are derived, one for each"per" transaction.

      The benefit of DUKPT is that even if an attacker discovered the key toa particular transaction, none of the other transactions from the same device would be able to be decrypted with that key.

      That  said, a potential attack point (from a fraudster) would be the master key stored in the encrypting device. However, because HomeATM uses DUKPT, our device is built so that tampering with the device wipes this master key out.
       
      These derived keys are used to encrypt transaction data with a symmetric cipher such as 3DES. HomeATM also takes it one step further and encrypts the Track 2 data as well.  If you ever have any questions regarding financial transaction security or how HomeATM provides true end-to-end-encrypted transactions, feel free to email me

      Before I get to the next question, I've got one for you. 

      When you "type" your card number into a "box" on a merchant website, is it protected by DUKPT?  Is it encrypted?  If so, DES or 3DES?  First one to send me the correct answer gets a Free HomeATM PED!

      Q: What is TRUE end-to-end encryption?  (E2EE)


      A: First of all, "true"end-to-end encryption can only occur with a PIN based transaction.  It doesn't exist outside of that scope because there is a point in the process where the cardholder data is decrypted and before it is re-encrypted is that is the point where it is vulnerable. 

      With that said, Heartland's proposal for end-to-end encryption has promulgated E2EE into a hot topic.

      I would point out that Heartland's E2EE proposal came "AFTER" their breach...while HomeATM instituted their end-to-end encryption from "the very beginning."  I'm not bragging.  I'm proudly displaying our insight into the weaknesses inherent in the payments system and  how we improved upon said weaknesses.

      But let's get back to Heartland, shall we?  In this post I will attempt to explain why they CANNOT magically snap their fingers and introduce E2EE on their own.  They need cooperation from others in the industry.

      While it's true that some large U.S. retailers encrypt cardholder data while in transit,  it's also true that most don't.  Therefore...in order for E2EE to work, a lot of retailers would need to revamp their system(s).  Very costly indeed.

      In addition, the top full-service U.S. payment processors also don't currently support E2EE;  thus, retailers that encrypt card data in transit typically must decrypt it before they send it to their processor. 

      The key word here is decrypt.  That is the weak point, the vulnerability,  and as such, also the problem. 

      That said, PIN Debit is an entirely different animal.  Card brand standards require that PINs are encrypted end-to-end.   In fact, speaking about Heartland's quest for E2EE, Distinguished Gartner Analyst Avivah Litan stated: 
      End-to-end encryption would be most effective if data was encrypted from the time a card was swiped at a POS until it reached the card issuer, similar to the way personal identification numbers (PINs) currently are encrypted according to card brand standards.
      Starting to get the point?  If not here's some more insight as Ms. Litan went on to state:
      "Heartland is limited by the scope of systems it manages and from which it accepts datait can only seek to influence the card industry to carry end-to-end encryption beyond the processor stage, through the card networks and onto the card issuers."The proposal's success also depends on merchants' willingness to invest in terminal upgrades that support card data encryption."

      (Editor's Note: For instance...HomeATM's PCI 2.0 Certified SafeTPIN PED which also encrypts the Track 2 data.)  Avivah continues:

      "If Heartland implements its proposed project more securely than it has managed in the past with its network, it will make payment card processing more secure for merchants, especially if they don't manage the encryption keys and leave key management to their processor. 
       
      Nevertheless, the process will always include vulnerabilities at the point where data is encrypted and decrypted

      "These vulnerabilities can be limited by using "sound key management practices" and enforcing extra security measures, such as "requiring two separately managed sets of keys for cryptographic operation
      Can you provide an example of a "sound key management practice?  That's why HomeATM is the closest thing to TRUE end-to-end encryption in the industry.  (our industry being eCommerce payments and Real Time Money Transfer.) 

      In the bricks and mortar world, end-to-end encryption doesn't exist and the whole system would need to be revamped.  You can learn more about that in this related post where Avivah Litan asks:




      Reblog this post [with Zemanta]

      Monday, April 13, 2009

      Security or Convenience? How About Both?

      American's "DEFINITELY" want security.

      In fact American's worry more about credit and debit card fraud than they do about a terrorist attack...according to a new report from Unisys.

      So one has to ask...why are there applications that push convenience OVER security?

      Because people "used" to like convenience. But one could easily argue that those days are over. "Sure it would be convenient to whisk through airport security without having to take off your shoes or take out your laptop, or get the frisk wand, but, like I said those days are over.

      So I have another question...

      If we accept security over convenience in the name of national security, AND we're MORE WORRIED about Credit and Debit card fraud than we are about National Security (see graph on left)... then doesn't it make sense that "security" is the most important variable when it comes to credit and debit card transacting?

      Of course it does...right?

      HomeATM has taken security to a new level for eCommerce. We can eradicate the worries associated with ALL credit and debit card fraud, at least when it comes to eCommerce.. Using military grade encryption, we 3DES the card information (including ALL the Track 2 data) AND utilize DUKPT key management, which further reduces the risk of a breach to (worst case scenario) ONE card.

      Oh, getting back to convenience...let's pretend we're ignorant...and argue that security is unimportant, that "convenience" is the "key" to a sucessful payment application. Ready? Okay.

      Agree or Disagree with this statement.

      "It's more CONVENIENT" to "TYPE" in my 14-16 digit credit card number...then have to type in my expiration date, then have to turn my card over and type in my CVV code ...

      "OR"
      "It's MUCH more convenient to simply "SWIPE" my card."

      What's your answer?

      If you said, it's obviously more convenient to have to type in the 14-16 digits consisting of my Primary Account Number, then type in my expiration date data and follow that up with having to type in my CVV code, then you took my request to "pretend we're ignorant" too seriously...

      If you said, "It's obviously faster and more convenient to simply "swipe my card" and have a "secure transaction", than to "type" in ALL my card data...AND be subjected to fraud"...then you've "secured" the correct answer!


      Convenience AND Security...that's the HomeATM difference!





      Reblog this post [with Zemanta]

      Thursday, March 5, 2009

      Nostra(para)digmus


      I
      've posted quite a few times that we're in the midst of a major Paradigm Shift. (use the HomeATM search bar on the right and "enter paradigm shift" to read) I took a moment to outline (see graphic on left) some of the finer points which provide e-vidence of this impending shift.

      I am positive that convenience will be forced to take a backseat to security which is clearly going to be in the drivers seat.

      Likewise, I am more confident that in order to secure a transaction it has to be done by Hardware. No predictions there...just fact. To the engineers at HomeATM...it's a foregone conclusion. It doesn't matter what anyone says today... tomorrow always shows us the truth.

      Truth is, hardware is not a "better" option, it's the only option. Software is breached 92% of the time vs. only 1% for hardware.

      One doesn't need to be Einstein to figure out that if something is breached 92 times more than something else, then the "something else" MUST be more secure.

      Question: If something is breached 1% of the time vs. 92%, then wouldn't it be at least 92 times easier to to "fix" what causes 1% of breaches?  In the case of hardware being breached, tampering was virtually to blame everytime. So we made our SwipePIN device tamper proof. We're done.



      When you consider new cracks in Secure Socket Layer(SSL) websites , DNS hijacking, Man-in-the Middle Attacks (MITM) Malware, bots, and combine that with the fact that there's been3 Major Processor Hacks in 3 Months, these are indeed dangerous times. This doesn't even take into account the YTBD hacks which will occur in the near future.


      We're all at risk for loss if we believe that a PIN Based solution can be peripheraless. Once again, Hardware is not an option. IBM came to the same conclusion whilst looking at how to best secure online banking. See: IBM Agrees with HomeATM....Hardware Required.

      Information security will become the number one priority for EVERYONE, and the ONLY way to securely transact an e-commerce transaction is via hardware. There is NO other way. Besides...what's the anti-convenience rhetoric about Hardware anyway?  Doesn't it make it more convenient when you don't have to type in a bunch of digits, expiration dates or CVV's. 

      Besides...we're used to hardware...don't you have to plug a cigarette adapter into your iPhone or Blackberry to charge it? How hard is that?  Well, in addition to processing PIN Debit, you can plug in the HomeATM SwipePIN device and "charge it."  What's the difference?  Plug in cell-phone to charge it...Plug in SwipePIN device to charge it. 
      (Don't forget about our PIN my Card application which allows you to securely assign a PIN number to your credit card, providing a more secure dually-authenticated transaction) 


      The Internet is demonstrating significant power to provide "Net"profit", Cash has been replaced as King, having being "overthrone" by King Debit, and information security is more important than ever. It doesn't take Nostradamus to write a quatrain predicting that EFT Networks will want their piece of the PIN Debit/Credit Internet Pie.  And rightly so!  Why should they be "shut out" from Internet transactions?  

      PIN Debit leads Signature Debit 45%-35% in the physical world, but doesn't yet exist in the virtual one. Can you possibly disagree that the paradigm shift will contribute towards bringing PIN Debit to the web? Problem is...in the past retailers were the focal point of hackers. Got the Personal Account Numbers but never the PIN. Now it's processors. 100 Million Personal Account Numbers...Zero PIN's.

      PIN's are the Holy Grail to Hackers. Doesn't ANYONE SEE (beside's Avivah Litan, HomeATM and IBM) what's going to happen if we attempt to secure them in a software environment?

      Nostra(para)digmus predicts that no matter what we see today, tomorrow will show us the truth.

















      Reblog this post [with Zemanta]

      Disqus for ePayment News