Showing posts with label Personal identification number. Show all posts
Showing posts with label Personal identification number. Show all posts

Wednesday, January 19, 2011

Acculynk Bringing PaySecure to the Mobile Channel

PaySecure, the first software-only service for PIN debit payments on the Internet, will be available on mobile phones in Q1

ATLANTA--(BUSINESS WIRE)--Acculynk announced today that it is bringing the security and convenience of its PaySecure® Internet PIN debit product to mobile smartphones early this year.
The growing prevalence of mobile transactions coupled with merchant demand prompted Acculynk to extend the capabilities of PaySecure beyond the Internet channel.PaySecure Mobile will allow consumers to authenticate their transactions by entering their bank-issued PIN on Acculynk’s graphical, scrambling PIN-pad, which has been specially designed for mobile smartphone platforms.
“We were approached by major merchants last year wanting to know how PaySecure would fit with their developing mobile channels, so we started work on a mobile application,” said Ashish Bahl, CEO of Acculynk. “After several months of development, we’ll be ready to launch PaySecure mobile in Q1 2011, allowing our merchants and partners to benefit from the higher security of PaySecure in not just one but two major purchasing channels. Additionally, PaySecure Mobile is well positioned to add an additional layer of authentication to NFC payments on smartphones, since the phone is something you have but the PIN offers something you know.”
PaySecure Mobile is built on Acculynk’s patented encryption and authentication platform, which is also the backbone of Acculynk’s PaySecure Internet PIN debit product. Introduced in March 2009, PaySecure Internet PIN debit is today supported by 9 U.S. EFT networks and implemented on over 1,000 U.S. merchant websites.
But Acculynk is looking beyond Ecommerce payments in 2011, with new applications for PaySecure including money transfer, Peer to Peer (P2P) authentication, online banking authentication, and PIN debit entry on a kiosk.
“In 2010, we established PaySecure as the standard for PIN debit payments on the Internet, with a growing base of merchants, issuers and EFT networks,” said Bahl. “In 2011, our goal is to expand the channels where PIN debit can be accepted, like a mobile phone and even kiosks – giving consumers a consistent payment experience and merchants lower fraud and lower costs – while introducing new applications for the product within those channels, such as P2P payments and online banking authentication.”
PaySecure Mobile will be available on the iPhone, Android, Blackberry and Windows-7 platforms.
About Acculynk
Acculynk secures online transactions with a suite of software-only services backed by a patented authentication and encryption framework provide greater security for issuers, EFT networks, merchants and payment processors. Acculynk has introduced the first software-only service for Internet PIN debit payments, PaySecure®, which utilizes a graphical PIN-pad for the secure entry of a consumer’s PIN. PaySecure is currently enabled on over 1,000 merchant websites. Acculynk has partnerships with 9 EFT networks to process PaySecure transactions and with six leading payment processors to distribute the product. Visit http://www.acculynk.com.

Contacts

Acculynk
Danielle Duclos, 678-894-7013
press@acculynk.com
Permalink: http://www.businesswire.com/news/home/20110119005996/en/Acculynk-Bringing-PaySecure-Mobile-Channel
http://acculynk.com http://www.paysecure.com

www.ePINDebit.com www.e-PINDebit.com www.iPINDebit.com www.PINDebit.mobi
Enhanced by Zemanta

Tuesday, December 14, 2010

Visa Mobile Application Now Available on iPhone, Providing Merchant Offers in Time for the Holiday Season


Visa Account Holders Can Take Advantage of Merchant Offers and Location-Based Services During Holiday Shopping Season
SAN FRANCISCO--(BUSINESS WIRE)--Visa Inc. (NYSE: V), the world’s largest retail electronic payments network1, today announced it is making shopping easier and more convenient for budget-conscious consumers by offering the Visa Mobile application for the iPhone. Through a simple tap of the finger Visa account holders now have access to more than 50 unique merchant offers ranging from clothing and dining to entertainment. The Visa Mobile application is now available as a free download from the iTunes app store.
http://www.visa.com
“Merchants are looking for new and more efficient ways to reach customers, while budget-conscious consumers expect a more rewarding and convenient shopping experience”
Visa is working with a select list of popular merchants to deliver exclusive offers to Visa account holders, helping them save money on every-day purchases. More than 50 merchants including some of the most popular retailers in the U.S. such as 24 Hour Fitness, Jos. A. Bank, Meineke, New York & Company, and Zales are providing discounts through the Visa Mobile application, helping them reach more consumers with targeted offers. Offers are automatically delivered and stored in the application, can be tailored to consumers’ life styles and preferences, and can be redeemed either online or at physical retail locations. The application uses location-based technology to provide consumers with a map and directions to a nearby retailer where they can redeem merchant offers.
“Merchants are looking for new and more efficient ways to reach customers, while budget-conscious consumers expect a more rewarding and convenient shopping experience,” said Bill Gajda, Head of Mobile at Visa Inc. “The Visa Mobile application meets the needs of both merchants and consumer and brings one of the most trusted brands in payments to the iPhone.”
Visa is working closely with handset manufacturers, mobile network operators and technology providers around the globe to bring the reliability, scalability and trust of Visa payments to the mobile channel. The Visa Mobile application for the iPhone was developed in partnership with Monitise plc, a UK business which is a global-leading mobile banking and payments platform. Visa signed a global alliance with Monitise in June 2009 to custom-develop mobile services for Visa across a spectrum of handsets to ensure Visa account holders have a consistent, user-friendly, and secure mobile payment experience.
Visa Mobile Application Features
Visa account holders simply download the Visa Mobile application from the iTunes app store and immediately have access to more than 50 unique merchant offers. Key application features include:
Offers:
  • Visa Offers can be tailored to match consumer lifestyle and interest. Visa Account holders can select from several merchant categories such as clothing, dining, jewelry, travel, entertainment, or retail goods. This ensures consumers only get offers they want, and can help increase merchant traffic, loyalty and customer satisfaction.
  • Participating merchants include Planet Hollywood, Papa John’s Pizza, 24-Hour Fitness, Jos A Banks, Tourneau, New York & Company, Holiday Inn, Ramada, Crowne Plaza, Pearle Vision, Meineke, Buca di Beppo, Cold Water Creek, and Hard Rock CafĂ©.
  • Account holders with Visa Signature cards will receive special Visa Signature offers in addition to the standard offers.
  • Visa is continuously adding and enhancing merchant offers available through the Visa Mobile application. A list of participating merchants can be found at www.visa.com/mobile.
Location-Based Services:
  • Using location-based technology, the Visa Mobile application will show consumers nearby merchant locations and provide directions to locations where they can redeem offers and allows them to find the nearest ATM.
About Visa
Visa is a global payments technology company that connects consumers, businesses, financial institutions and governments in more than 200 countries and territories to fast, secure and reliable digital currency. Underpinning digital currency is one of the world’s most advanced processing networks—VisaNet—that is capable of handling more than 20,000 transaction messages a second, with fraud protection for consumers and guaranteed payment for merchants. Visa is not a bank and does not issue cards, extend credit or set rates and fees for consumers. Visa’s innovations, however, enable its financial institution customers to offer consumers more choices: pay now with debit, ahead of time with prepaid or later with credit products. For more information, visit www.corporate.visa.com.
About Monitise
Monitise plc (LSE: MONI.L) is a global leader in Mobile Money solutions, with the proven technology and expertise to enable financial institutions and other service providers to offer a wide range of mobile banking and payments services to their customers in both developed and developing territories.
With live services in the UK and in the USA, where it is in partnership with FIS, the company is currently working with international partners to deliver similar safe, secure mobile banking and payment services in territories worldwide, including India and the Asia Pacific region. Current key partners include Visa, VocaLink, FIS, HSBC, Lloyds TSB, First Direct, Royal Bank of Scotland, NatWest, Travelex, Ulster Bank, Standard Chartered Bank, Vodafone, Orange, O2, T-Mobile, 3 UK, Best Buy, The Carphone Warehouse and First Eastern.
For more information, visit http://www.monitisegroup.com
1 Based on payments volume, total volume, number of transactions and total number of cards in circulation.

Contacts

Press Only - Contacts:
Visa Inc.
Elvira Swanson, +1-415-932-2564
globalmedia@visa.com
or
Monitise
Charli Beale, Bell Pottinger Business & Brand
Direct dial: + 44 20 7861 3029
Mobile: +44 7800 582266
cbeale@bell-pottinger.co.uk
or
Stuart Disbrey, Bell Pottinger Business & Brand
Direct dial: +44 20 7861 2495
Mobile: +44 7789 500465
sdisbrey@bell-pottinger.co.uk
or
Adam Powell, Bell Pottinger Business & Brand
Direct dial: +44 20 7861 2514
Mobile: +44 7753 832916
apowell@bell-pottinger.co.uk
Permalink: http://www.businesswire.com/news/home/20101214006058/en/Visa-Mobile-Application-iPhone-Providing-Merchant-Offers



http://www.ePINDebit.com http://www.iPINDebit.com http://www.e-PINDebit.com http://www.PINDebit.mobi
Enhanced by Zemanta

Monday, June 7, 2010

Gemalto White Paper Suggests it's Time for EMV in U.S.

PYMNTS.com published a whitepaper produced by Gemalto...



EMV stands for the organizations that developed the standard – Europay, MasterCard and Visa. After the development of the standard, Europay became a part of MasterCard, while other card issuers such as JCB and American Express have begun supporting it. EMVCo, an organization jointly owned by American Express, JCB, MasterCard and Visa, now manages the EMV standard. Most countries implementing smart bank cards require the use of a Personal Identification Number (PIN) in each transaction, which is why “chip and PIN” is often used to refer to EMV implementation programs.


Gemalto White Paper Suggests it's Time for EMV in U.S.

PYMNTS.com published a whitepaper produced by Gemalto...



EMV stands for the organizations that developed the standard – Europay, MasterCard and Visa. After the development of the standard, Europay became a part of MasterCard, while other card issuers such as JCB and American Express have begun supporting it. EMVCo, an organization jointly owned by American Express, JCB, MasterCard and Visa, now manages the EMV standard. Most countries implementing smart bank cards require the use of a Personal Identification Number (PIN) in each transaction, which is why “chip and PIN” is often used to refer to EMV implementation programs.


Monday, April 26, 2010

No PIN Needed to Fool Chip and PIN Technology - Cambridge



University of CambridgeChip and PIN has come under further scrutiny today as research shows a vulnerability allowing criminals to use cards without the owner’s number.
By Jennifer Scott, 26 Apr 2010 at 15:47
Chip and PIN
Cyber criminals are able to abuse the Chip and PIN system, even without the cardholder’s four digits, according to new research released today.
The study by Cambridge University’s Computer Laboratory has shown that thanks to a protocol flaw a “man in the middle” attack is possible, whereby criminals can insert an electronic device between the card and the terminal, fooling it into believing the PIN is verified.
Eli Jellenç, head of international cyber intelligence at iD...


No PIN Needed to Fool Chip and PIN Technology - Cambridge



University of CambridgeChip and PIN has come under further scrutiny today as research shows a vulnerability allowing criminals to use cards without the owner’s number.
By Jennifer Scott, 26 Apr 2010 at 15:47
Chip and PIN
Cyber criminals are able to abuse the Chip and PIN system, even without the cardholder’s four digits, according to new research released today.
The study by Cambridge University’s Computer Laboratory has shown that thanks to a protocol flaw a “man in the middle” attack is possible, whereby criminals can insert an electronic device between the card and the terminal, fooling it into believing the PIN is verified.
Eli Jellenç, head of international cyber intelligence at iD...


Tuesday, March 9, 2010

FDIC: Hackers Took More Than $120M in Three Months



This is the "type" of news we will continue reading until we stop entering/typing passwords and start authenticating ourselves the same way we authenticate ourselves at an ATM or at the Point of Sale in a retail store.  Swipe your Bank Issued Card and Enter Your Bank Issued PIN. .  Why should the internet be any different?  The web inherently makes people think everything should be software-based. NOT financial transactions.   They MUST be conducted "outside the browser space." It's just the way it is.  Extremely sensitive financial information (either online banking credentials or credit/debit card numbers) have no business being entered/typed.  It makes it readily available to hackers.  Why do you think they call it a "browser?"  Various keylogging/malware and phishing attacks have now risen to the tune of $120 million in the 3rd quarter of 2009.  I have a sneaky suspicion that the Q4 numbers will be higher.  If the online banking credentials or cardholder data was encrypted inside a separate machine there wouldn't be anything to obtain.  It would all be gobblygook protected by Derived Unique Key Per Transaction end-to-end encryption.  It's why we have the only PCI certified PED designed for eCommerce financial transactional use.  Don't you believe it's time for a change?

Robert McMillan, IDG News Service



Online banking fraud involving the electronic transfer of funds has been on the rise since 2007 and rose to over US$120 million in the third quarter of 2009, according to estimates presented Friday at the RSA Conference in San Francisco, by David Nelson, an examination specialist with the FDIC.



The FDIC receives a variety of confidential reports from financial institutions, which allow it to generate the estimates, Nelson said.



Almost all of the incidents reported to the FDIC "related to malware on online banking customers' PCs," he said. Typically a victim is tricked into visiting a malicious Web site or downloading a Trojan horse program that gives hackers access to their banking passwords. Money is then transferred out of the account using the Automated Clearing House (ACH) system that banks use to process payments between institutions.



Even though banks now force customers to use several forms of authentication, hackers are still stealing money. "Online banking customers are getting too reliant on authentication and on practicing layers of controls," Nelson said.


Thanks for Visiting - Bookmark us or Add to your Favorites and Find Out What's Going on Tomorrow in the Payments Industry

Thursday, February 18, 2010

New UK Cyber Team to Target Online Banking Fraudsters

QCK.com is reporting that the government in the UK is forming an online banking cyber investigative unit.  Again, at the risk of sounding redundant, the "practice" of "typing" online banking login credentials into a box in a browser is the "cause" of the problem  So we need to "effectively" change the way we authenticate an online banking session.   We must stop the practice of using a browser to authenticate.  Authentication must be done "outside the browser."   It makes complete sense to use "existing cards, PINs and bank rails" to authenticate.



We at HomeATM have long stated that the trusted process used by ATM's to dispense $200 a thousand miles away from it's main branch, at 2:00 AM, can be trusted to secure the online banking session.  1. What you have (your card) and 2. what you know (your PIN)  Our PCI certified PIN Entry Device allows online banking users to swipe their card...and enter their PIN.













Online Banking Authentication Should be Done Using the Same Trusted Process to Access your Account at an ATM


New cyber team to target online banking fraudsters
February 17, 2010 - By Mark Warner


The government is setting up a new "cyber enforcement team" to tackle fraudsters who target consumers' online banking accounts.



Online banking log-on details are regularly stolen by criminals who send emails inviting individuals to register for a free item - such as an iPod - only for the recipient to download "spyware" onto their computer without realising.



This then gives fraudsters access to people's online banking log-on details...Editor's Note:  Not if we stopped typing.  No typing, no access.



Continue Reading







Monday, February 8, 2010

A PIN for All Reasons - GreenSheet







The GreenSheet
is publishing a story on PIN Debit written by Scott Henry of Verifone.  In it they say:







  • A PIN pad for every countertop. (or laptop) Those words might be as effective an economic stimulus as anything else we have tried over the past year or so.

  • Losses for PIN debit were just 15 cents per card issued in 2008, compared to $1.81 for signature debit. (translation: Signature Debit is 12+ times more likely to to incur a loss)

  • PC-integrated PIN pads: Personal computer-based payment processing is attractive to a growing number of storefront merchants; especially appealing is a bundled solution that includes hardware and payment processing software.

  • Merchants who are missing out on the trend toward PIN debit are paying for it in additional interchange fees. According to a Federal Reserve report (PDF) on interchange published in May 2009, interchange fees for PIN debit "typically average 35 cents to 50 cents per transaction; interchange fees for a typical signature debit transaction are about 1.2 percent of the transaction value; and interchange fees for a typical credit card transaction for Visa and MasterCard are in the range of 1.5 to 2 percent of the transaction value."

  • PIN debit use was up 12.8 percent compared to the same period in 2008, while credit and signature debit were up just 5.8 percent. 

  • PIN debit is "preferred by 45 percent of consumers, while 35 percent prefer signature (20 percent have no preference).





Here's the article:



February 08, 2010
  •  Issue 10:02:01


A PIN for all reasons 

By Scott Henry

VeriFone


A





PIN pad for every countertop. Those words might be as effective an economic stimulus as anything else we have tried over the past year or so. Just about everyone - merchants, payments industry businesses and individual consumers - have felt pinched by the impact of the credit crunch.



For consumers, sky-high interest rates are prompting more and more cardholders to dump their credit cards in the drawer and rely increasingly on debit cards instead.



For example, the National Retail Federation released a survey in November 2009 that indicated 45 percent of consumers planned to use debit or check cards to pay for gifts this past holiday season. Those planning to use credit cards for similar purchases fell to 28 percent.



In May 2009, Visa Inc. reported that in the three months ending Dec. 31, 2008, spending volume on debit cards exceeded that of credit cards for the first time. By the end of June 2009, debit accounted for more than 70 percent of all Visa transactions.



Consumer choice



Not only is debit card use increasing at the expense of credit cards, but consumers are more often opting for PIN debit. First Data Corp.'s SpendTrend report for November 2009 showed that PIN debit use was up 12.8 percent compared to the same period in 2008, while credit and signature debit were up just 5.8 percent.



In the 2008 Study of Consumer Payment Preferences conducted by BAI Research and Hitachi Consulting, it was reported that PIN debit is "preferred by 45 percent of consumers, while 35 percent prefer signature (20 percent have no preference).



Those preferring PIN debit consider it more secure, faster and easier to use than signature. Consumers preferring signature debit do so for the security, lack of fees, their inability to remember a PIN and, in some cases, rewards programs."



Paying for steerage



Is it any wonder that consumers are often steered to signature debit when they check out at the grocery store? As the Boston Globe reported in late 2007, banks "prefer the credit option for debit cards because they make more money in fees.



For example, on a $200 transaction, a bank would make $1.99 if the customer chooses 'credit' and signs his or her name; according to one estimate that would be more than three times the 60 cents they make from customers who choose 'debit' and enter a PIN."
Merchants who are missing out on the trend toward PIN debit are paying for it in additional interchange fees. According to a Federal Reserve report (PDF) on interchange published in May 2009, interchange fees for PIN debit "typically average 35 cents to 50 cents per transaction; interchange fees for a typical signature debit transaction are about 1.2 percent of the transaction value; and interchange fees for a typical credit card transaction for Visa and MasterCard are in the range of 1.5 to 2 percent of the transaction value."


It may seem counterintuitive to tell merchants how they can lower their transaction fees, but remember, anything that helps merchants achieve greater profitability will increase loyalty and retention.



Security is a value-add



There's no doubt consumers today are more aware of card fraud issues than they were three or four years ago. Millions of cards have been replaced due to breaches of retailer and processor data centers, as well as payment networks.



PIN debit is inherently more secure than signature debit, which requires just a signature that few store clerks attempt to verify. According to the 2009 Debit Issuer Study, commissioned by Discover Financial Service's Pulse network, POS losses for PIN debit were just 15 cents per card issued in 2008, compared to $1.81 for signature debit. (Signature Debit is 12 times more likely to to incur a loss, yet Visa still pushes the less secure signature debit.)






Nevertheless, when you're selling PIN debit you need to be ready to answer questions about skimming incidents in which criminals have been able to surreptitiously obtain card data and associated PINs.



These incidents have been attributed to the compromise of pre-Visa PIN entry device (PED)-approved systems. Amazingly, there are still PIN pads in use that predate any security certification. As of July 1, 2010, these pre-Visa PED systems must be removed from service.



Today's Payment Card Industry (PCI) PED systems feature certified tamper prevention and tamper detection schemes designed to ensure that efforts to compromise systems will be immediately visible and unsuccessful. Merchants can use their new systems as a compelling marketing point to show customers that security is a priority.



PIN for any counter



There is no merchant scenario (except eCommerce, even though Visa, MasterCard, Discover, AMEX and JCB PCI Certified the PED manufactured by HomeATM) that cannot accommodate a PIN debit solution in this day and age.



PIN debit can easily be added by selling merchants PCI PED devices containing an internal PIN pad or by adding a secure PIN pad to an existing terminal. With security requirements becoming ever ore stringent, many merchants must upgrade their terminals anyway, so why not provide them with solutions that offer more flexibility and payment options?



Among those options are:

  • Terminal-driven PIN pad peripherals: Compact PIN pads that attach to existing payment terminals and take up little counter space are a quick and easy way to equip merchants for PIN acceptance.

  • Customer-activated PIN pads: Once seen only in supermarkets and high-end department stores, consumer-activated facing terminals that integrate with cash register systems are suited to high-traffic venues.

  • PC-integrated PIN pads: Personal computer-based payment processing is attractive to a growing number of storefront merchants; especially appealing is a bundled solution that includes hardware and payment processing software. (don't need payment processing software with HomeATM...just plug-in our PCI 2.0 Certified PED to any USB port and you are good to go)



PIN is In
(and only HomeATM can provide it for eCommerce)  Editor's Note:  If you're thinking, what about Acculynk, remember...Acculynk isn't really  a PIN Debit transaction.  It is simply an alternative payment designed for eCommerce.  Using Acculynk's payment scheme, the consumer must TYPE their debit card number into a box on a website in the browser, putting the user at risk.  A Genuine PIN Debit requires the card to be present because the magnetic stripe must be swiped and the PVV and PVKI must be captured by the card reader.  Because Acculynk's scheme requires the user to type in their PAN (primary account number) it is, by definition,  a "card not present" transaction.  This technically disqualifies/eliminates it as a genuine PIN debit transaction.  Card Not Present PIN Debit does not exist.  Therefore, ONLY HomeATM offers genuine PIN Debit for eCommerce merchants.  HomeATM is the only eCommerce solution in the world which instantly encrypts the the magnetic stripe data (including the Track 2 data) at the mag-head.  It is also the only eCommerce solution in the world which provides true end-to-end encryption for the PIN, using Derived Unique Key Per Transaction. (DUKPT)  



ISOs and merchant level salespeople able to offer merchants a variety of PIN-entry device options will ensure maximum adaptability and security. When you combine the cost savings associated with PIN debit with increasing card volume, given current consumer trends and the higher security standards for PIN debit transactions, you've got a winning formula for sales now and in the future.






Scott Henry is Director, North America Product Marketing, for VeriFone. He can be contacted at scott_henry@verifone.com










Thursday, May 28, 2009

80% of Phishing Attacks Use Hijacked Websites

I've blogged about this subject plenty of times over the last year, and my concern is specifically targeted towards the inherent weaknesses in the username/password systems used with online banking. If a consumer is tricked/phished into providing their username/ password, then the phisher is successful.

The average phishing attack results in a loss of $350 to a bank.

According to research firm,Gartner, banks, online payment organizations and other financial institutions are bearing most of the financial cost of phishing attacks. (A survey of nearly 4,000 US consumers revealed a 40% increase in the number of phishing victims in 2008 over the year before to five million.)

The average loss was $350 per phishing attack, but consumers said they had recovered 56% of their losses from the financial institutions involved. (That's $196 to the banks and $154 to the consumers) "The findings underline the fact that the war against phishing is far from over," said Avivah Litan, analyst at Gartner. (Yes, the very same Avivah Litan who says "never" enter your PIN on the Internet unless it's hardware based)
Guess what? The HomeATM "SafeTPIN" device would not only eliminate "phishing attacks" but it would also eliminate the threat of "cloned cards," "cloned bank sites", AND provide "True 2FA." for online banking customers.

HomeATM provides a very simple cure to this maliciousness. Use a PCI 2.0 certified SwipePIN device and require online banking users to swipe their bank issued card and enter their bank issued PIN. The data is encrypted and is NEVER in the clear. So, in the event a consumer is tricked into swiping and entering their PIN, as opposed to typing in their log-in credentials, the phisher has nothing.

And nothing is something banks should want phishers to have.

More Than 80% Of Phishing Attacks Use Hijacked, Legitimate Websites - DarkReading

More Than 80% Of Phishing Attacks Use Hijacked, Legitimate Websites
New research from the Anti-Phishing Working Group shows how phishers are better covering their tracks -- and what to do when phishers compromise your Website

May 27, 2009 | 04:23 PM
By Kelly Jackson Higgins
DarkReading

It used to be that researchers could sometimes track a phishing exploit by the notorious cybercrime ring behind it, like the Rock Phish gang, but no more: New research from the Anti-Phishing Working Group (APWG) has found that most phishers are setting up shop on legitimate Websites to be inconspicuous when they steal valuable information from victims.

In the second half of 2008, roughly 57,000 phishing attacks worldwide targeted a specific brand or organization, up from around 47,300 in the first half of 2008, according to a newly released report (PDF) from the APWG. The attacks were waged on 30,454 different domain names, only 5,591 of which were domains the phishers set up themselves. The rest were from legitimate Websites they had hijacked to carry out their exploits.

The average amount of time a phishing site was up: 52 hours, according to the report.

Continue Dark Reading


Reblog this post [with Zemanta]

Friday, January 30, 2009

Gemalto Chippin' In with Venezuelan Bank Card Leaders

Gemalto teams with Venezuelan bank card market leaders to accelerate EMV migration

Digital security provider Gemalto is teaming up with CorporaciĂłn Cardtech, Venezuela’s largest supplier of magnetic stripe bank cards, and Newtech Solutions, a consulting and technical support organization that specializes in EMV to help banks in Venezuela move to the new, smart credit card that will better protect their customers from fraud and identity theft.  Under the new agreement, banks in Venezuela working with the two companies will have access to expertise, consulting services, smart cards and technology from Gemalto. The partners estimate that eight million cards will be issued in the first year, starting in June 2009. Close to 16 million debit and credit cards are currently in use in Venezuela.

"Venezuelan banks are faced with constantly increasing card fraud, mostly due to illegal copying of magnetic stripe information to create “cloned” credit cards. The problem, that affects all of Latin America, has led to a liability shift which penalizes card issuers and merchants that do not issue or accept EMV cards. This liability change for non-EMV cards becomes effective in Venezuela starting July 2009."

EMV cards, also known as Chip and PIN, include a microprocessor and software with security features that work together with the payment transaction authorization network to prevent card fraud and identity theft. Unlike with magnetic stripe only cards, smart card based transactions cannot be easily cloned, which is a primary source of fraud throughout Latin America.

Editor's Note:  While it's true that they can't be cloned and easily used" at a retail location, they  certainly can  be  "easily" cloned and used online.  This is because the magstripe is still present on the back of the smart cards and that is what is "lifted" when cloning a card.

That, in large part, is why UK Fraud is 14 times higher overseas, (see related stories below) and why 1 in 4 Brits have experienced credit or debit card fraud.  (and why Gemalto wants EMV in the US.)  Online Transactions (web based) are currently (and HATM can change that) Card Not Present transactions.

So in order to
protect both online shoppers and online retailers, online (PIN) debit should be utilized.  HomeATM is the only provider of such a solution  which has been deemed both PCI 2.0 compliant, and offers "End to End Encryption" on all of it's PIN Based Transactions. 





In addition, HATM is EMV ready and it's personal swiping device transforms Card Not Present transactions into Card Present transactions, adding a layer of security with two factor authentication. (what you have and what you know, the card and the PIN respectively)

HATM's end-to-end encryption protects the consumers PIN throughout the whole transaction, as it is NEVER in the clear.     

For more information on how HomeATM's PIN Based Transactions can benefit your organization, visit
www.homeatm.net





Reblog this post [with Zemanta]

Tuesday, January 13, 2009

PIN Debit and PCI Compliance

Howard Riell, in an article written for Convenience Store Decisions, writes about PCI compliance.  As you'll undoubtedly notice while reading the article, PIN entry devices, or PED's are an integral part of PCI certification. The long and the short of it is that all PED's must be certified by PCI-approved laboratories and encrypt PIN's with Triple DES.  I know how that's done with a hardware device...(we're in the midst of getting our personal swiping device tested and approved for PCI compliance) but I'm not quite sure how it would/could/should be done with a software application.  (See "Software Breach 92 Times More Likely Than Hardware")

Here's some snippets from from the CSN story, entitled: "The High Stakes Of Compliance:"

It was in September 2006 that the credit card companies formed the PCI Security Standards Council in the hopes of battling fraud. Today, all merchants who accept payment card transactions must comply with the PCI Data Security Standard or face sizable penalties.  Indeed, the passing grade for PCI is 100%, which means failing even one of the criteria will bring consequences...

Editor's Note:  So, it's obvious that these Triple DES mandates are an integral element of PCI compliance and in 5+ months TDES is required on "all debit transactions." Since Jan. 1, 2008, all newly manufactured debit card processing terminals must incorporate PIN entry devices that have been certified by PCI approved laboratories

  • By January 2009, newly installed fuel pumps that accept debit cards must feature PCI-compliant encrypted PIN pads.  See "Triple DES for GAS" 
  • Manufacturers have to begin installing key pads capable of implementing a new Triple Data Encryption Standard (TDES), which requires that data be encoded several times through an encrypted PIN pad.
  • By July 1, 2009, TDES will be required for all debit transactions and by
  • June 30, 2010, all fuel dispensers will need to be able to encrypt PINs according to the TDES.
The very next day, July 1st 2010, pumps that process debit transactions must be upgraded with encrypted PIN pads, and in-store POS terminals have to be certified as PCI-compliant.  The devices must also process all debit transactions using TDES.

One of my favorite lines from the article comes from Bruce Snyder,
manager of IP retail systems for 395-store Kwik Trip based in La Crosse, Wis“ who instead, sounds like a spokesman for Gemalto.  (see: Gemalto Wants EMV in US)  Apparently he doesn't like the implementation costs (retailers will need to replace outdated hardware) and thinks that as long as they have to get new equipment anyway, then V/MC and the banks should spend billions to implement EMV and when they're done, he'll replace Kwik Trip 'sexisting equipment with Chip and PIN readers.  Problem is, it won't be Kwik...it'll be years, if they started today.  (don't hold your breath)


"We have this silly little mag stripe that is so vulnerable and penetrable and we are building an infrastructure around it to protect the information, and a lot of people are making good money on that,” Snyder said. “With the new rulings on EPPs, if I want to continue to do debit we have to replace all of our dispenser doors and PIN pads at a huge expense to us to remain compliant. What we have to do is put in an encrypted PIN pad at the dispenser if we want to continue to do debit there.” But the new door and PIN pad will cost $1,500 per dispenser. (Ouch!  Consumers can get our SwipePIN device for merely the cost of shipping and handling, which in the face of $1500...makes for a rather compelling value proposition)

“Start doing the math on that and now you have to make a decision: can we afford to do this? And what happens if we don’t?” Snyder said. “We need to change that method of presenting ourselves for a credit transaction and make it more secure so that we don’t have to build all of this stuff around it to try to protect a very flawed method...”


Read the complete story at Convenience Store Decisions







Reblog this post [with Zemanta]

Disqus for ePayment News