Showing posts with label Two-factor authentication. Show all posts
Showing posts with label Two-factor authentication. Show all posts

Wednesday, May 19, 2010

Smart Card Alliance Presents 2010 Outstanding Smart Card Achievement Awards



  
Winners: Bank of America, ViVOtech, Gemalto, and Kelli Emerick



SCOTTSDALE, AZ--(PIN Debit Blog - May 19, 2010) - 
SMART CARD ALLIANCE 2010 ANNUAL CONFERENCE - The Smart Card Alliance today announced the winners of its prestigious"Outstanding Smart Card Achievement" (OSCA) awards. The awards were announced during the Smart Card Alliance 2010 Annual Conference, being held this week at the Camelback Marriott Resort and Spa in Scottsdale, Arizona.

"If one word were to describe our OSCA winners this year, it would be 'innovative,'" said Randy Vanderhoof, executive director of the Smart Card Alliance. "All of our winners have made exciting and groundbreaking contributions to the smart card market this year, from making our payments more secure and convenient, to increasing our national security. We are proud to be able to recognize these achievements and the innovators that made them happen."
Outstanding Issuing Organization

The 
Outstanding Issuing Organization Award was given to Bank of America for its revolutionary smart card-based two-factor authentication program, SafePass, for online banking. Bank of America's SafePass card is a contact smart card with a display built right into the card. Consumers press a button on the card, and the chip creates and displays a one-time password (OTP) right on the card. By entering the OTP as part of online banking transactions, Bank of America customers get two-factor authentication, providing an extra layer of security when authorizing sensitive transactions.
Outstanding Innovation in Payments Technology

The 
Outstanding Innovation in Payments Technology Award went to ViVOtech's Citi Tap and Pay NFC Mobile pilot in Bangalore, the largest pilot program of its kind to date. ViVOtech provides an end-to-end solution for consumers equipped with NFC handsets to easily download their credit, debit, prepaid or loyalty cards over the air (OTA) and store them securely on their mobile phones. They can then go to any merchant enabled with a contactless payment reader, select the payment method and just wave their phone at the reader to make a payment. 
Outstanding Innovation in Security TechnologyThe Outstanding Innovation in Security Technology Award was given to Gemalto's Smart Guardian (SG) FIPS, a smart card-based, encrypted USB drive for government employees and/or contractors that often have to handle sensitive or confidential data. Gemalto's SG FIPS USB is a zero-footprint secure flash drive, meaning it is self-contained and does not require any software installations or downloads. It is FIPS-140-2 certified, and meets Military Standard 810-F environmental standards. It also offers additional security and interoperability with federal Personal Identity Verification (PIV) credentials. 
Outstanding Individual Leadership

The 
Outstanding Individual Leadership Award went to Kelli Emerick, the executive director of theSecure ID Coalition. Over the last seven years, Ms. Emerick has had a significant impact on the smart card industry, and the efficiency of our government through the use of smart card technology. With her leadership, the smart card industry has provided testimony three times before Congress: the Veterans Affairs committee on card technology; the Homeland Security committee on the subject of RealID and Western Hemisphere Travel Initiative (WHTI); and the Senate Judiciary committee on biometric cards for identity protection.
A distinguished panel representing practitioners, technology providers and media, all with extensive smart card technology experience and industry visibility, selected the award winners. The jury evaluated all qualified OSCA applications and scored them according to the award criteria and eligibility rules.
Finalists

The Smart Card Alliance also recognized finalists in each of the award categories. 
  • Outstanding Issuer Organization Award finalists: LifeMed Card, Inc., and the Transportation Worker Identification Credential (TWIC) program. 

  • Outstanding Innovation in Payments Technology Award finalists: Giesecke & Devrient'sMobile Security Card® RF and HID Global's US Bank PayID card program.

  • Outstanding Innovation in Security Technology Award finalists: the CodebenchPIVCheck Software Suite, and Oberthur Technologies' ID-One™ PIV BIO card. 

  • Outstanding Individual Leadership Award finalists: Paul Contino, vice president of Information Technology, Mount Sinai Medical Center; and Thomas Lockwood, senior technical consultant to the U.S. Department of Homeland Security, Noblis.

Council Member Recognition

The Smart Card Alliance industry councils have made significant contributions to the smart card industry, a result of the tremendous commitment of the many individuals who participate in and contribute to Council projects. New this year, the Smart Card Alliance celebrated this hard work by recognizing the top three individual contributors in each of the industry councils. They are:
  • Contactless and Mobile Payments Council: Deborah Baxley, Independent; Simon Hurry, Visa, Inc.; and Mohammad Khan, ViVOtech. 

  • Healthcare Council: Paul Contino, Mount Sinai Medical Center; Dale Grogan, LifeMed Card Inc.; and Michael Magrath, Gemalto. 

  • Identity Council: Sal D'Agostino, IDmachines LLC; Gilles Lisimaque, Identification Technology Partners, Inc.; and Neville Pattinson, Gemalto. 

  • Physical Access Council: Sal D'Agostino, IDmachines LLC; Roger Roehr, Roehr Consulting; and Lars Suneborn, Hirsch Electronics. I

  • Transportation Council: Jerry Kane, SEPTA; Mike Nash, ACS, A Xerox Company; and Brian Stein, Independent. 

The Alliance also recognized an "honor roll" for each council, comprised of the individuals who were leading contributors and participants in the council projects and activities. Each honor roll can be found, along with more information about the Smart Card Alliance 2010 Annual Conference, OSCA winners and finalists including past winners, on the Alliance Web site at:http://www.smartcardalliance.org/pages/activities-osca-awards
About the Smart Card Alliance

The Smart Card Alliance is a not-for-profit, multi-industry association working to stimulate the understanding, adoption, use and widespread application of smart card technology. 
Through specific projects such as education programs, market research, advocacy, industry relations and open forums, the Alliance keeps its members connected to industry leaders and innovative thought. The Alliance is the single industry voice for smart cards, leading industry discussion on the impact and value of smart cards in the U.S. and Latin America. For more information please visit http://www.smartcardalliance.org.
Media Contact:Deb Montner

203-226-9290

dmontner@montner.com

Montner & Associates Tech PR Agency

http://www.montner.com/


Reblog this post [with Zemanta]

Smart Card Alliance Presents 2010 Outstanding Smart Card Achievement Awards



  
Winners: Bank of America, ViVOtech, Gemalto, and Kelli Emerick



SCOTTSDALE, AZ--(PIN Debit Blog - May 19, 2010) - 
SMART CARD ALLIANCE 2010 ANNUAL CONFERENCE - The Smart Card Alliance today announced the winners of its prestigious"Outstanding Smart Card Achievement" (OSCA) awards. The awards were announced during the Smart Card Alliance 2010 Annual Conference, being held this week at the Camelback Marriott Resort and Spa in Scottsdale, Arizona.

"If one word were to describe our OSCA winners this year, it would be 'innovative,'" said Randy Vanderhoof, executive director of the Smart Card Alliance. "All of our winners have made exciting and groundbreaking contributions to the smart card market this year, from making our payments more secure and convenient, to increasing our national security. We are proud to be able to recognize these achievements and the innovators that made them happen."
Outstanding Issuing Organization

The 
Outstanding Issuing Organization Award was given to Bank of America for its revolutionary smart card-based two-factor authentication program, SafePass, for online banking. Bank of America's SafePass card is a contact smart card with a display built right into the card. Consumers press a button on the card, and the chip creates and displays a one-time password (OTP) right on the card. By entering the OTP as part of online banking transactions, Bank of America customers get two-factor authentication, providing an extra layer of security when authorizing sensitive transactions.
Outstanding Innovation in Payments Technology

The 
Outstanding Innovation in Payments Technology Award went to ViVOtech's Citi Tap and Pay NFC Mobile pilot in Bangalore, the largest pilot program of its kind to date. ViVOtech provides an end-to-end solution for consumers equipped with NFC handsets to easily download their credit, debit, prepaid or loyalty cards over the air (OTA) and store them securely on their mobile phones. They can then go to any merchant enabled with a contactless payment reader, select the payment method and just wave their phone at the reader to make a payment. 
Outstanding Innovation in Security TechnologyThe Outstanding Innovation in Security Technology Award was given to Gemalto's Smart Guardian (SG) FIPS, a smart card-based, encrypted USB drive for government employees and/or contractors that often have to handle sensitive or confidential data. Gemalto's SG FIPS USB is a zero-footprint secure flash drive, meaning it is self-contained and does not require any software installations or downloads. It is FIPS-140-2 certified, and meets Military Standard 810-F environmental standards. It also offers additional security and interoperability with federal Personal Identity Verification (PIV) credentials. 
Outstanding Individual Leadership

The 
Outstanding Individual Leadership Award went to Kelli Emerick, the executive director of theSecure ID Coalition. Over the last seven years, Ms. Emerick has had a significant impact on the smart card industry, and the efficiency of our government through the use of smart card technology. With her leadership, the smart card industry has provided testimony three times before Congress: the Veterans Affairs committee on card technology; the Homeland Security committee on the subject of RealID and Western Hemisphere Travel Initiative (WHTI); and the Senate Judiciary committee on biometric cards for identity protection.
A distinguished panel representing practitioners, technology providers and media, all with extensive smart card technology experience and industry visibility, selected the award winners. The jury evaluated all qualified OSCA applications and scored them according to the award criteria and eligibility rules.
Finalists

The Smart Card Alliance also recognized finalists in each of the award categories. 
  • Outstanding Issuer Organization Award finalists: LifeMed Card, Inc., and the Transportation Worker Identification Credential (TWIC) program. 

  • Outstanding Innovation in Payments Technology Award finalists: Giesecke & Devrient'sMobile Security Card® RF and HID Global's US Bank PayID card program.

  • Outstanding Innovation in Security Technology Award finalists: the CodebenchPIVCheck Software Suite, and Oberthur Technologies' ID-One™ PIV BIO card. 

  • Outstanding Individual Leadership Award finalists: Paul Contino, vice president of Information Technology, Mount Sinai Medical Center; and Thomas Lockwood, senior technical consultant to the U.S. Department of Homeland Security, Noblis.

Council Member Recognition

The Smart Card Alliance industry councils have made significant contributions to the smart card industry, a result of the tremendous commitment of the many individuals who participate in and contribute to Council projects. New this year, the Smart Card Alliance celebrated this hard work by recognizing the top three individual contributors in each of the industry councils. They are:
  • Contactless and Mobile Payments Council: Deborah Baxley, Independent; Simon Hurry, Visa, Inc.; and Mohammad Khan, ViVOtech. 

  • Healthcare Council: Paul Contino, Mount Sinai Medical Center; Dale Grogan, LifeMed Card Inc.; and Michael Magrath, Gemalto. 

  • Identity Council: Sal D'Agostino, IDmachines LLC; Gilles Lisimaque, Identification Technology Partners, Inc.; and Neville Pattinson, Gemalto. 

  • Physical Access Council: Sal D'Agostino, IDmachines LLC; Roger Roehr, Roehr Consulting; and Lars Suneborn, Hirsch Electronics. I

  • Transportation Council: Jerry Kane, SEPTA; Mike Nash, ACS, A Xerox Company; and Brian Stein, Independent. 

The Alliance also recognized an "honor roll" for each council, comprised of the individuals who were leading contributors and participants in the council projects and activities. Each honor roll can be found, along with more information about the Smart Card Alliance 2010 Annual Conference, OSCA winners and finalists including past winners, on the Alliance Web site at:http://www.smartcardalliance.org/pages/activities-osca-awards
About the Smart Card Alliance

The Smart Card Alliance is a not-for-profit, multi-industry association working to stimulate the understanding, adoption, use and widespread application of smart card technology. 
Through specific projects such as education programs, market research, advocacy, industry relations and open forums, the Alliance keeps its members connected to industry leaders and innovative thought. The Alliance is the single industry voice for smart cards, leading industry discussion on the impact and value of smart cards in the U.S. and Latin America. For more information please visit http://www.smartcardalliance.org.
Media Contact:Deb Montner

203-226-9290

dmontner@montner.com

Montner & Associates Tech PR Agency

http://www.montner.com/


Reblog this post [with Zemanta]

Wednesday, April 28, 2010

FireID Partners with Cirrus Management Solutions to Bring Mobile Two-Factor Authentication Solutions to the UK Market






Photo Courtesy of Paul Gilowey -  CapeTown Daily Photo

FireID Well-Positioned for Rapid Growth in the UK Market via Channel Partnerships

Infosecurity Europe 2010
LONDON--(BUSINESS WIRE)--FireID (Pty) Ltd, a leading provider of world-class security applications for strong two-factor authentication, today announced its expansion into the UK market through a distribution partnership with Cirrus Management Solutions Ltd, a company specialising in assisting technology vendors to launch or grow their business in the UK. With Cirrus as its distributor, FireID is rapidly building a network of channel partnerships to deliver its solutions to UK enterprises.
“No other company is as disruptive to this space as FireID and we see tremendous potential for both FireID and the channel in the UK market.”
Headquartered in Stellenbosch, South Africa, FireID provides authentication software which enables end-users to use their mobile phones to generate one time passwords and securely log in to online banking, e-commerce websites, cloud-based applications and virtual private networks, without the need to remember multiple passwords or carry a hardware token. In addition, FireID’s Transaction Verification Solution secures payments and transactions against sophisticated attack methods for thwarting two-factor authentication, including man-in-the-browser (MITB) attacks.
Cirrus assists technology companies in all aspects of business development and has been involved in FireID’s sales and marketing strategy for the UK. With more than 30 years of global experience in IT security and networking solutions, services and distribution with direct and indirect enterprise and services providers, Cirrus has the expertise and connections required to help companies succeed in the market. Cirrus has been instrumental in securing partnerships for FireID with leading security and storage resellers and technical support providers.
“Authentication remains a critical issue for banks, e-commerce companies and enterprises, as hackers develop increasingly sophisticated methods of attack. Unfortunately, many organisations put sensitive data at risk by relying on inadequate solutions,” said Jenny Dugmore, CEO, FireID. “By partnering with Cirrus to distribute FireID’s mobile two-factor authentication solutions, we are providing companies in the UK with a powerful alternative to traditional authentication solutions that can help reduce online fraud.”
“We see the a shift in the authentication sector that FireID is uniquely positioned to fill, as companies move away from hardware tokens and embrace the power and convenience of mobile applications to protect their customers and businesses from data theft,” said Mark Kacary, director, Cirrus Management Solutions. “No other company is as disruptive to this space as FireID and we see tremendous potential for both FireID and the channel in the UK market.”
Please visit FireID and Cirrus Management Solutions in stand N80 at Infosecurity Europe 2010.
About FireID
FireID is a leading provider of mobile two-factor authentication. Founded in 2006, FireID is located in Stellenbosch, South Africa and has offices in the USA and UK with a broad international network of distributors and resellers. With increased transaction fraud and identity theft, strong authentication has become an essential component for any online or mobile application. FireID's world-class authentication solutions meet the growing authentication needs of corporations, government agencies and end-users who require highly secure and convenient online access to password protected accounts. For more information, visit http://www.fireid.com.


Reblog this post [with Zemanta]

FireID Partners with Cirrus Management Solutions to Bring Mobile Two-Factor Authentication Solutions to the UK Market






Photo Courtesy of Paul Gilowey -  CapeTown Daily Photo

FireID Well-Positioned for Rapid Growth in the UK Market via Channel Partnerships

Infosecurity Europe 2010
LONDON--(BUSINESS WIRE)--FireID (Pty) Ltd, a leading provider of world-class security applications for strong two-factor authentication, today announced its expansion into the UK market through a distribution partnership with Cirrus Management Solutions Ltd, a company specialising in assisting technology vendors to launch or grow their business in the UK. With Cirrus as its distributor, FireID is rapidly building a network of channel partnerships to deliver its solutions to UK enterprises.
“No other company is as disruptive to this space as FireID and we see tremendous potential for both FireID and the channel in the UK market.”
Headquartered in Stellenbosch, South Africa, FireID provides authentication software which enables end-users to use their mobile phones to generate one time passwords and securely log in to online banking, e-commerce websites, cloud-based applications and virtual private networks, without the need to remember multiple passwords or carry a hardware token. In addition, FireID’s Transaction Verification Solution secures payments and transactions against sophisticated attack methods for thwarting two-factor authentication, including man-in-the-browser (MITB) attacks.
Cirrus assists technology companies in all aspects of business development and has been involved in FireID’s sales and marketing strategy for the UK. With more than 30 years of global experience in IT security and networking solutions, services and distribution with direct and indirect enterprise and services providers, Cirrus has the expertise and connections required to help companies succeed in the market. Cirrus has been instrumental in securing partnerships for FireID with leading security and storage resellers and technical support providers.
“Authentication remains a critical issue for banks, e-commerce companies and enterprises, as hackers develop increasingly sophisticated methods of attack. Unfortunately, many organisations put sensitive data at risk by relying on inadequate solutions,” said Jenny Dugmore, CEO, FireID. “By partnering with Cirrus to distribute FireID’s mobile two-factor authentication solutions, we are providing companies in the UK with a powerful alternative to traditional authentication solutions that can help reduce online fraud.”
“We see the a shift in the authentication sector that FireID is uniquely positioned to fill, as companies move away from hardware tokens and embrace the power and convenience of mobile applications to protect their customers and businesses from data theft,” said Mark Kacary, director, Cirrus Management Solutions. “No other company is as disruptive to this space as FireID and we see tremendous potential for both FireID and the channel in the UK market.”
Please visit FireID and Cirrus Management Solutions in stand N80 at Infosecurity Europe 2010.
About FireID
FireID is a leading provider of mobile two-factor authentication. Founded in 2006, FireID is located in Stellenbosch, South Africa and has offices in the USA and UK with a broad international network of distributors and resellers. With increased transaction fraud and identity theft, strong authentication has become an essential component for any online or mobile application. FireID's world-class authentication solutions meet the growing authentication needs of corporations, government agencies and end-users who require highly secure and convenient online access to password protected accounts. For more information, visit http://www.fireid.com.


Reblog this post [with Zemanta]

Tuesday, April 20, 2010

VASCO Showcases DIGIPASS for Mobile at MEFTEC

OAKBROOK TERRACE, Ill., and ZURICHApril 20 /PRNewswire-FirstCall/ -- VASCO Data Security Inc. (Nasdaq: VDSI;www.vasco.com ), a leading software security company specializing in authentication products, will showcase its DIGIPASS for Mobile authentication solution at MEFTEC (Bahrain International Exhibition Centre, 20th and 21st April, booth H301). DIGIPASS for Mobile is VASCO's authentication solution which leverages Internet enabled mobile phones for authentication purposes. DIGIPASS for Mobile can be used for two factor authentication and digital signature.
DIGIPASS for Mobile offers a solution to banks who want to secure multiple customer facing channels including e-banking, m-banking, phone banking using IVR and cash retrieval at the ATM.
An increasing number of banks protect their e-banking channels against fraud attacks, such as phishing and man-in-the-middle attacks, with two factor authentication. Banks are also increasingly introducing m-banking for their generation Y customers or in regions where the mobile phone penetration is higher than the Internet penetration. M-banking is facing similar challenges as e-banking when it comes down to protecting user accounts. VASCO's DIGIPASS for Mobile can be used to protect both the e-banking and m-banking channels using a one-time password (OTP) to access the banking application and e-signature to sign online transactions.
Furthermore the use of DIGIPASS for Mobile can be extended to phone banking. Most phone applications use Interactive Voice Response (IVR) which allows the customer to access their bank via a touchtone telephone or voice recognition. These systems often use simple passwords like: who are you and what is your mother's name. This information can easily be retrieved online using social engineering techniques. As a result the use of dynamic authentication messages becomes more important to avoid impersonation. DIGIPASS for Mobile can easily be integrated in an IVR system: when calling the bank the IVR system would immediately recognize the customer who would be prompted for a user ID and OTP to further access the banking system.
The use of DIGIPASS for Mobile can also secure cash retrieval at the ATM. ATMs have always been subject to fraud. Nowadays skimming techniques and ghost ATMs are used to obtain card details and plunder accounts. DIGIPASS for Mobile strong authentication can be added without having to change the existing ATM network, PIN validation will simply be replaced by OTP validation. The bank customer will activate the authentication application on his phone using a PIN-code. On PIN-insertion an OTP will be generated which the banking customer will type on the ATM keyboard.
"We are using VASCO's DIGIPASS for Mobile for 'Cep Sifrematik' which runs on a mobile phone. Our customers can access the Garanti Online/Mobile Branch using a one-time password generated by Cep Sifrematik. Since the mobile phone is used as an authentication device, customers can access their bank account whenever and wherever considering that they have their authentication device always in their pocket. Whether they want to access their account from somebody else's PC or in an Internet cafe they can do so in total security," says M.Feridun Aktas, Chief Security Officer at Garanti Bank (Turkey).
"The use of strong authentication for online banking is mandatory by the Turkish Banking Association. Halkbank's Sifrebazuses DIGIPASS for Mobile. It is very straightforward in use; simple and fast: we send the authentication application by SMS to our customers. They will download the application on their mobile phone and choose a password.



Every time they want to use Sifrebaz they will enter their password to generate a one-time password to access the online banking application," says Cenk Niksarli, Chairman of IT from Halkbank (
Turkey).
DIGIPASS for Mobile uses proven VASCO VACMAN® authentication technology and supports more than 400 types of mobile phones and operates on Java phones, Blackberry, iPhone and Windows Mobile and platforms such as NTT Docomo.
"The mobile platform not only is becoming more attractive to hackers as more and more mobile applications are introduced, the mobile phone is also a loyal companion never leaving our side. As a result it is an excellent platform for strong authentication. Since the mobile phone is always in our pocket it can be used for user authentication at the ATM or to access e- and m-banking applications anywhere and any time," says Jan Valcke, President and COO at VASCO Data Security.
About VASCO
VASCO is a leading supplier of strong authentication and e-signature solutions and services specializing in Internet Security applications and transactions. VASCO has positioned itself as global software company for Internet Security serving a customer base of almost 9,500 companies in more than 100 countries, including approximately 1,400 international financial institutions. VASCO's prime markets are the financial sector, enterprise security, e-commerce and e-government.
Reblog this post [with Zemanta]

VASCO Showcases DIGIPASS for Mobile at MEFTEC

OAKBROOK TERRACE, Ill., and ZURICHApril 20 /PRNewswire-FirstCall/ -- VASCO Data Security Inc. (Nasdaq: VDSI;www.vasco.com ), a leading software security company specializing in authentication products, will showcase its DIGIPASS for Mobile authentication solution at MEFTEC (Bahrain International Exhibition Centre, 20th and 21st April, booth H301). DIGIPASS for Mobile is VASCO's authentication solution which leverages Internet enabled mobile phones for authentication purposes. DIGIPASS for Mobile can be used for two factor authentication and digital signature.
DIGIPASS for Mobile offers a solution to banks who want to secure multiple customer facing channels including e-banking, m-banking, phone banking using IVR and cash retrieval at the ATM.
An increasing number of banks protect their e-banking channels against fraud attacks, such as phishing and man-in-the-middle attacks, with two factor authentication. Banks are also increasingly introducing m-banking for their generation Y customers or in regions where the mobile phone penetration is higher than the Internet penetration. M-banking is facing similar challenges as e-banking when it comes down to protecting user accounts. VASCO's DIGIPASS for Mobile can be used to protect both the e-banking and m-banking channels using a one-time password (OTP) to access the banking application and e-signature to sign online transactions.
Furthermore the use of DIGIPASS for Mobile can be extended to phone banking. Most phone applications use Interactive Voice Response (IVR) which allows the customer to access their bank via a touchtone telephone or voice recognition. These systems often use simple passwords like: who are you and what is your mother's name. This information can easily be retrieved online using social engineering techniques. As a result the use of dynamic authentication messages becomes more important to avoid impersonation. DIGIPASS for Mobile can easily be integrated in an IVR system: when calling the bank the IVR system would immediately recognize the customer who would be prompted for a user ID and OTP to further access the banking system.
The use of DIGIPASS for Mobile can also secure cash retrieval at the ATM. ATMs have always been subject to fraud. Nowadays skimming techniques and ghost ATMs are used to obtain card details and plunder accounts. DIGIPASS for Mobile strong authentication can be added without having to change the existing ATM network, PIN validation will simply be replaced by OTP validation. The bank customer will activate the authentication application on his phone using a PIN-code. On PIN-insertion an OTP will be generated which the banking customer will type on the ATM keyboard.
"We are using VASCO's DIGIPASS for Mobile for 'Cep Sifrematik' which runs on a mobile phone. Our customers can access the Garanti Online/Mobile Branch using a one-time password generated by Cep Sifrematik. Since the mobile phone is used as an authentication device, customers can access their bank account whenever and wherever considering that they have their authentication device always in their pocket. Whether they want to access their account from somebody else's PC or in an Internet cafe they can do so in total security," says M.Feridun Aktas, Chief Security Officer at Garanti Bank (Turkey).
"The use of strong authentication for online banking is mandatory by the Turkish Banking Association. Halkbank's Sifrebazuses DIGIPASS for Mobile. It is very straightforward in use; simple and fast: we send the authentication application by SMS to our customers. They will download the application on their mobile phone and choose a password.



Every time they want to use Sifrebaz they will enter their password to generate a one-time password to access the online banking application," says Cenk Niksarli, Chairman of IT from Halkbank (
Turkey).
DIGIPASS for Mobile uses proven VASCO VACMAN® authentication technology and supports more than 400 types of mobile phones and operates on Java phones, Blackberry, iPhone and Windows Mobile and platforms such as NTT Docomo.
"The mobile platform not only is becoming more attractive to hackers as more and more mobile applications are introduced, the mobile phone is also a loyal companion never leaving our side. As a result it is an excellent platform for strong authentication. Since the mobile phone is always in our pocket it can be used for user authentication at the ATM or to access e- and m-banking applications anywhere and any time," says Jan Valcke, President and COO at VASCO Data Security.
About VASCO
VASCO is a leading supplier of strong authentication and e-signature solutions and services specializing in Internet Security applications and transactions. VASCO has positioned itself as global software company for Internet Security serving a customer base of almost 9,500 companies in more than 100 countries, including approximately 1,400 international financial institutions. VASCO's prime markets are the financial sector, enterprise security, e-commerce and e-government.
Reblog this post [with Zemanta]

Monday, April 5, 2010

Are you a Typer or a Swiper?

Internet Retailer published an article on alternative payments and I found the first line to be the most interesting....



By Thad Rueter - Internet Retailer




When most online shoppers get to the payment page of an e-commerce site they type in a credit or debit card number.





Editor's Note: ...and therein lies the problem (behind the continuing escalation of online payment fraud.)



When brick and mortar shoppers get to the POS they Swipe their card. They don't write their primary card number down on a piece of paper and leave it at the store's checkout counter.  But that's exactly what you are doing when you type your card numbers into a browser.



The simple fact is that In order to properly secure the card holder data, instead of "typing" we should be "swiping." It's what we do in the brick and mortar world...and for good reason. That said, It is extremely important to note that it's not simply the act of "swiping" that makes the transaction secure.



As the eCommerce marketplace matures, (i.e. realizes that browsers are not safe) there has been a couple "swiping" devices introduced over the course of the last year. Square, SmartSwipe, etc.  Yet, to this day, only one device in the world has been PCI 2.0 Certified. Why is that? It is because "encryption is the key" to securing cardholder data.


\

HomeATM understood the importance of strong encryption long ago which is why utilize 3DES encryption for the Track 2 data. (We encrypt the data at the magnetic head of the card reader so it is NEVER in the clear.)



Because our secure hardware solution incorporates a PIN Entry device, it enables us to further protect the online financial transaction with DUKPT encryption for the PIN. (Derived Unique Key Per Transaction)



So if you are curious as to why we are PCI certified and our competitors are not, think encryption. Neither Square, nor SmartSwipe incorporates a PIN Entry Device, so two factor authentication and DUKPT encryption does not, cannot, come into play. It is important to note that neither one 3DES encrypts the Track 2 data.  


So, ask yourself "two questions" the next time you are asked to "type" your card number into a box on a checkout page of a website. 




1. Does it make logical sense for me to be typing my card number into a box?

2. What hardware device best protects my sensitive data.



You'll have to answer the first question yourself, (see related articles below if you are stumped) but the answer to the second question is clearly HomeATM's PCI 2.0 PED certified technology.  Contact me to learn more about how our technology can eliminate phishing and chargebacks and render malware useless.



Editor's Note:  We also have an EMV ready Chip and PIN reader hardware device which will allow online banking authentication, online payment, online bill pay and real-time instant P2P money transfers.  










Reblog this post [with Zemanta]

Disqus for ePayment News