Wednesday, December 24, 2008

PC's Are Insecure...So Are You?

PC's are insecure and hackers constantly exploit flaws in their security.  This article provides some insight as to why software based solutions designed to run on a PC are sitting ducks for potential hackers... which, once again, is why HomeATM has taken a personal swiping device approach to bringing PIN debit to the web.  It's how they've done it in the stores, and it's how it should be done online.  Keep in mind that the Internet was not designed for eCommerce, it was originally designed as the "information highway." 

With our approach, the transaction is done "outside" the browser space, therefore "man-in-the-browser" attacks are nullified, as are keylogging, screen capturing and a symposium of  other hacking methods designed to drain  data from your PC.

Someone's eventually going to be swipin' your credit/debit card data...shouldn't you be the one doing the SwipePIN?  Any doubts?  See how easy it is..."to hack a PC"  

This, from the Wired Blog Network:

SecuniaImage via WikipediaHardly anyone runs a PC without known holes that hackers can exploit, a Danish security company reports. Of those who run the company's free security-scanning tool, nearly half have more than 11 out-of-date programs.

Secunia Software's Personal Software Inspector checks programs installed on a user's computer to see if the latest, patched version is installed. More than 98 percent of users had at least one program that wasn't the latest version, the company found in a study of 20,000 users of its software.

The sobering statistics are not surprising, but they come as malware makers turn from simply exploiting easy holes in Windows.

In addition, hackers have been finding vulnerabilities in browsers, media players and file-reading software as a way into other people's computers.

While it may not seem likely that a hacker would rig a website to exploit a patched hole in a lesser-known media player like VLC, hacking tools make it increasingly easy for an infected webpage to check for many vulnerabilities in a person's computer.

Number of insecure programs per PC/user:
0 insecure programs: 1.91% of PCs
1-5 insecure programs: 30.27% of PCs
6-10 insecure programs: 25.07% of PCs
11+ insecure programs: 45.76% of PCs

Secunia's Mikkel Winther says the study shows that its just as important to keep programs up to date, as it is to have a good firewall and anti-virus programs. He also says the real numbers in the general populace are likely worse, because their sample is of people who have looked for security software.

"The results are shocking and prove as well as emphasize the need for a patching solution for private users," Winther said. Keeping up with software updates can be quite tedious and annoying, even as software makers like Microsoft and Mozilla have built better update tools. Those who don't care to download Secunia's software can try it's online scanner, though it only checks version numbers on a hundred or so programs.

Secunia does not sell security software to individuals, but does market a networked version of this scanner to companies.

Reblog this post [with Zemanta]

B2C E-Commerce in Canada - 2007-2012

In the previous post I featured eMarketer's report on e-Commerce projections in the UK through 2012...here's their projections for Canadian eCommerce...

Canadians Are Warming Up to Online Shopping

In 2007, Canadian retailers sold C$13.8 billion ($12.9 billion) of consumer products and travel bookings online. But by 2012 eMarketer projects that Canadian business-to-consumer (B2C) e-commerce sales will reach C$22.8 billion ($22.2 billion).

That means that between 2007 and 2012, Canadian B2C e-commerce sales will show a compound annual growth rate (CAGR) of 10.6%. Not bad numbers in a tough economy.

But the numbers could be better.

“Until Canadian consumers show a larger appetite for buying big-ticket physical goods online, such as home furnishings and consumer electronics, the Canadian e-commerce market will remain small compared with other G-7 countries,” says Jeffrey Grau, eMarketer senior analyst and author of the new report, Canada B2C E-Commerce.

Consumers in Canada are avid online product researchers, on par with their US counterparts. But they are much more likely to make a subsequent purchase in-store rather than on a Website.

“The fact that Canadian Web retailers are required to charge sales tax is certainly a disincentive to online buying,” says Mr. Grau.

Because of the tax structure, Canadian shoppers have never seen much of a price advantage to buying online. This is one reason why Canadian e-commerce has grown at a more gradual pace compared with the explosive growth that occurred in the US.

“The upside of this is that the Canadian market is enjoying a longer period of solid growth,” says Mr. Grau, “albeit on a much smaller scale.”

Another factor that has depressed the growth of B2C e-commerce in Canada is the lack of product selection online. In fact, many prominent Canadian retailers have not found the ROI compelling enough to run an online sales channel.

“While Canada has about one-tenth the population of the US, the cost of running a transactional Website is about the same,” says Mr. Grau. “This creates a challenge for small to medium-sized retailers with fewer financial resources.”

Nevertheless, Canadian retailers are in a better position than foreign merchants to understand the needs and interests of local consumers. And like consumers across the world, those in Canada prefer to shop with indigenous retailers.

Reblog this post [with Zemanta]

B2C E-Commerce in UK, 2007-2012


According to eMarketer, Business 2 Consumer E-Commerce in the UK will continue it's strong growth pattern.  The tough economic climate will not affect e-commerce as much as it will bricks and mortar retail.  Here's their analysis:

UK e-commerce revenues will remain strong in 2009, as Internet stores continue to weather the recessionary storm better than their brick-and-mortar counterparts. In September 2008, eMarketer forecast that UK business-to-consumer (B2C) online sales in 2009 would be worth £68.4 billion ($127.9 billion), and we have seen no reason to alter that forecast.

B2C E-Commerce: UK, 2007-2012

Major online retailers that upgrade to offer true multichannel shopping and delivery/return options, as well as value for money, will gain market share while a number of second-rank e-shops stagnate or go out of business. But market leaders will spend more than in 2008 to ensure they attract and keep consumers’ attention.

Most online retailers will continue to court shoppers with money-off promotions and discounted delivery charges, and at least one supermarket chain will experiment with large-scale e-mail distribution of promotional coupons for grocery products bought in-store.

Mobile marketing will take significant steps next year—albeit from a small base—as more UK advertisers, heartened by the growing number of high-specification (3G) mobile users, move to exploit this always-on medium. Data from the Office for National Statistics suggested that 19% of adults ages 16 and older accessed the Web via their mobile phone in the three months prior to polling in early 2008—and this was before the highly successful UK launch of the 3G iPhone in July.

The 2009 mobile growth spurt will take two main forms: increasingly sophisticated usage of SMS, short codes and bar codes in direct-response campaigns, and microsites designed for mobile users. November 2008 research by mobile marketing agency Sponge found that 40% of UK e-retailers polled already had a transactional Website that was mobile-friendly. Another 50% said they planned to create such a site in the next 12 months. Moreover, one in five online retailers reported having used mobile microsites to drive promotions during 2008.

Reblog this post [with Zemanta]

Mother of All Hacks Coming?

There is a disturbing development brewing in the payments world.   It's bad enough when a retailer's computer  security is breached but now we've got us a completely different ballgame.  When hackers penetrate the computer systems of major acquirers and processors, well to use a famous quote, "We've got a problem Houston." 

This could turn out to be a "Royal pain in the ***" for Visa and Mastercard themselves because acquirers like Royal Bank of Scotland link directly into their networks. 

On the surface, this appears to be "one small step for hackers but it's "one giant step" for hack-kind."  
 
According to reports I've read this morning,  according to Gartner Research analyst Avivah Litan, this could be the beginnings of the mother of all hack attacks...

“It’s very bad news,” says distinguished analyst Avivah Litan. Unlike retailers’ computer systems, processors’ systems connect directly to the networks of Visa Inc. and MasterCard Inc. “An attacker that breaks into a processor conceivably can get into the heart of the system,” and attacks on acquirers and processors are increasing."

Here's the press release:

RBS WorldPay Announces Compromise of Data Security and Outlines Steps to Mitigate Risk

ATLANTA, Ga. – December 23, 2008 – RBS WorldPay (formerly RBS Lynk), the U.S. payment processing arm of The Royal Bank of Scotland Group, today announced that its computer system had been improperly accessed by an unauthorized party.  RBS WorldPay has urgently taken a number of important steps to mitigate risk in response to this situation.

The issue, which affected pre-paid cardholders and other individuals, was identified on November 10 and law enforcement agencies and federal regulators were notified by RBS WorldPay shortly thereafter. RBS WorldPay’s internal security professionals and outside experts are working with federal and state law enforcement authorities in an investigation of this event.  The affected pre-paid cards include payroll cards and open-loop gift cards. Personal information associated with certain payroll cards may have been improperly accessed. PINs for all PIN-enabled cards have been or are being reset.

Affected individuals are being notified and information has been posted on the RBS WorldPay Web site, www.rbsworldpay.us.
The fraud that has been identified to-date is associated with RBS WorldPay’s computer system supporting its U.S. pre-paid and open-loop gift card issuing business. Actual fraud has been committed on approximately 100 cards. Cardholders will not be responsible for unauthorized activity associated with this event. Certain personal information of approximately 1.5 million cardholders and other individuals may have been affected and, of this group, Social Security numbers of 1.1 million people may have been accessed.

RBS WorldPay is offering impacted individuals whose Social Security numbers may have been affected a complimentary one-year membership in a national subscription credit monitoring service that provides access to individuals’ consumer credit reports and daily monitoring of their credit files from all three national consumer reporting agencies.

Gift cards that have already been purchased retain their value and can be used wherever they are accepted by merchants. Those gift cards that had not been purchased have been deactivated and are being removed for destruction from stores as an additional precaution.

Ben Barone, president and CEO of RBS WorldPay, said, “Privacy is important to RBS WorldPay and we regret any inconvenience this may cause affected individuals. We have taken important, immediate steps to mitigate risk and none of the affected cardholders will be responsible for unauthorized activity on their account resulting from this situation. We are working closely with leading computer security firms to further safeguard our system, and with law enforcement agencies, which we hope will result in the criminals being brought to justice.”


Reblog this post [with Zemanta]

Kohl's Leads Online Sales in Unique Way

According to Internet Retailer Kohl's enjoyed  the sharpest rise in holiday traffic this season...

Among 10 top retail sites, Kohl's has the sharpest rise in holiday traffic

Providing more evidence of the increasing importance of the online channel to retail chains, the e-commerce site of nationwide chain Kohl's Department Stores showed the sharpest year-over-year growth in the number of unique visitors, at 53.1%, in a recent survey of 10 sites. Amazon.com posted the second-large increase, up 48.5%, while Macy's was up 36.1%.

The survey, conducted by Compete Inc., was based on unique visitor totals from Nov. 1 through Dec. 13, 2008, the latest day for which data was available, compared to the same period of 2007. Overall, the number of unique visitors at the 10 surveyed sites rose 25.6% to 765.99 million visitors.

The year-over-year changes were affected, however, by the later start of the 2008 peak holiday shopping season. Thanksgiving, typically the official kickoff of peak holiday shopping, fell on Nov. 27 this year, compared to Nov. 22 in 2007.

Following are the 10 sites surveyed by Compete with their year-over-year rise in unique visitors and their total number of visitors (in millions) for the period Nov. 1 through Dec. 13, 2008:
  1. Kohl's, 53.1%, 38.55
  2. Amazon.com, 48.5%, 382.02
  3. Macys.com, 36.1%, 35.69
  4. Sears, 25.1%, 58.62
  5. Walmart.com, 22.8%, 181.62
  6. ToysRUs.com, 21.7%, 60.04
  7. Target.com, 20.3%, 137.23
  8. JCP.com, 18.2%, 60.04
  9. BestBuy.com, 12.3%, 77.51
  10. Overstock.com, -9.8%, 42.01


Reblog this post [with Zemanta]

Tuesday, December 23, 2008

Visa "Anti-Trust Worthy" Discover's Morgan Stanley

As I mentioned in a post on December 5th, Morgan Stanley apparently had "secret talks" with Visa behind Discover's back and now they are suing each other over the $2.75 billion take that Discover collected from Visa in an antitrust lawsuit. What was Morgan Stanley thinking?


Bottom line is that Discover says it's not paying a dime to Morgan Stanley because they tried to sabotage the settlement talks behind their back and thus forced them to settle for less than they would have. Kind of puts a new twist on antitrust, and once again Visa is involved. Morgan Stanely should have just left well enough alone, but since they were capped at 1.5 billion, Discover claims they had no vested interest in seeing the case go to trial.

As the title of this post suggests, my guess is that Visa played Morgan Stanley in order to reach a lower settlement...and it worked. Now there's a whole new court case that is arising out of the settlement of another. It's a crazy world, but that's life, and life accepts Visa! Apparently, Visa is worthy of forever being associated with antitrust...

I'll continue to follow the case here on the PIN Debit blog. As it looks right now, the case won't reach trial until the end of 2009, but I'm sure there will be some interesting tidbits in the meantime, and I'll cover those tidbits here.

From todays New York Post:
"The negotiations with Visa and MasterCard dragged on, and the two sides were set to go to trial this October.

But the weekend before the trial was to start, Discover claims that it learned for the first time that Morgan Stanley was talking separately to Visa and MasterCard to try to settle case before it moved to trial. Fearing that Morgan Stanley had in some way compromised its trial strategy, Discover says that it was forced to settle the case for much less than what it might have gotten at trial.


Discover then refused to pay Morgan Stanley its cut of the settlement, claiming that Morgan Stanley violated the terms of their agreement that Discover had sole negotiating power.

Morgan Stanley sees things quite differently. It has sued Discover to get its $1.3 billion cut of the $2.75 billion payout.

Morgan Stanley claims that Discover always knew it was speaking with Visa and MasterCard in order to work out a deal. It even gave up $100 million of its cut to get Visa to sign on to the $2.75 billion, nonnegotiable figure proposed by the arbiter of the case.

Discover has now countersued, claiming that Morgan Stanley’s attorneys were under pressure from John Mack, Morgan Stanley’s chief executive, to settle the case quickly. Discover claims that since Morgan would not get a penny over $1.5 billion, it had no interest in seeing the case go to trial, where Discover could have reaped more cash

Continue Reading at NY Times



Reblog this post [with Zemanta]

TSYS Enters Turkish Payments Market


TSYS Hires New Business Development Director for Turkey

Columbus, Ga. and London, 22 December 2008 — TSYS today announced Bulent Senver as Business Development Director for its entry into the Turkish payments market.

Mr. Senver brings more than 25 years experience and extensive knowledge of the Turkish banking and card payments industry. He has worked with more than 20 Turkish and foreign banks in an advisory role as a management consultant and as a senior executive in the bank environment, a position in which he was named 'Banker of the Year' by the Turkish Press Institution.

Kelley Knutson, executive vice president of Global Services for TSYS, said, "TSYS is very pleased to welcome Bulent as Business Development Director for Turkey. He has helped achieve many milestones in his respective market, including the first photo credit card, the first soccer club debit card and the first telephone banking system. He has in-depth knowledge of the payments industry and local market requirements, and embodies the service excellence and integrity associated with the TSYS brand."

"With a strong, stable economy, growing population and rising income levels, we believe that the Turkish card market shows tremendous potential for further growth. It is a key, strategic market to TSYS and we are fully committed to investing long-term in the region," added Knutson.

The Turkish payments market has grown at an accelerated rate during the last five years and is now the third-largest card market in Europe. In terms of payment options and product differentiation, Turkey is one of the most sophisticated and innovative markets in the world.


TSYS, which grew its international operations 33 percent in 2007, confirmed its intent to participate in the Turkish marketplace with its unique value proposition, TS Prime, an efficient server-based issuing and acquiring card management platform adopted by more than 100 financial institutions worldwide.

TSYS supports more than 300 clients in 75 countries and has been a leader in the global payments industry for more than 25 years. Its market presence extends to 18 offices supported by more than 8,000 personnel.

About TSYS
TSYS (NYSE: TSS) is one of the world's largest companies for outsourced payment services, offering a broad range of issuer- and acquirer-processing technologies that support consumer-finance, credit, debit, debt management, healthcare, loyalty and prepaid services for financial institutions and retail companies in the Americas, EMEA and Asia-Pacific regions. For more information, contact news@tsys.com or log on to www.tsys.com. TSYS routinely posts all important information on its website.

Reblog this post [with Zemanta]

Chip and PIN Coming to Dubai

Decision to switch based on recent hack and rise in card related fraud.
Many banks across the UAE experienced a concerning rise in the instances of card related fraud in the latter part of this year.

Much of the fraud involved card “skimming” which is when a device is attached to an ATM or a Point-Of-Sale card reader and details are copied from the card’s magnetic strip. Details copied would include the card’s PIN number making it possible for fraudulent transactions to be made.

To help combat this Lloyds TSB Middle East has taken the decision to launch Chip and PIN cards – a more protected system for cards.

Chip and PIN cards contain a chip, making them more difficult and more expensive to counterfeit. Signatures can easily be forged and are often not checked carefully. So entering your PIN at a till instead of signing a receipt helps to prevent someone else from using your card.

One of the World's biggest banking groups, today announced that the bank will launch its Chip and PIN offering in January 2009. Following the increase in card-related fraud activity across the UAE, Lloyds TSB Middle East has accelerated the launch of its Chip and PIN credit and debit cards to ensure their customers' banking experience is even more secure.

"We are committed to delivering excellent customer service and protecting our customers", said Richard Musty, Consumer Banking Director. This is why we have brought forward the launch of our Chip and PIN credit and debit cards. These cards will offer our customers a more secure way to pay and improved protection against card-related fraud. Furthermore, our sophisticated fraud monitoring system will give us an early warning signal to potential fraudulent activity so we will be able to proactively tackle it.

Cards will be issued to existing customers on a renewal basis
Reblog this post [with Zemanta]

Visa's WarChest: $1.1 Billion


Visa Inc. (NYSE:V) today reported that it has deposited $1.1 billion into the litigation escrow account previously established under the company's retrospective responsibility plan (the "Plan").

Under terms of the Plan, when Visa funds the litigation escrow its U.S. financial institutions, the sole holders of Class B shares, bear the expense via a reduction in their as-converted share count.

"This transaction not only adds the necessary funds to our litigation escrow, but effectively acts as a $1.1 billion Class B share repurchase program," said Joseph Saunders, Visa's chairman and chief executive officer. "It has always been our stated intent to return excess cash to our shareholders in the form of dividends and share repurchases. We are obviously pleased that our strong financial position and excess cash flow allows us to do this."

The Plan was established at the time of Visa's initial public offering. It provides coverage and a payment mechanism for judgments or settlements in specific U.S. legal cases, protecting Visa and its Class A and Class C shareholders from any direct losses.

The deposit of the funds into the escrow account reduces the conversion ratio applicable to Visa's Class B common stock outstanding from 0.7143 per Class A share to 0.6296 per Class A share. On a converted basis, the 245,513,385 Class B shares currently outstanding are equal to 154,566,658 Class A shares of common stock.

The deposit of loss funds has the effect of a repurchase of 20,800,824 Class A common share equivalents from the Company's Class B shareholders. The amount paid per share represents the volume weighted average price (VWAP) of the Company's Class A common shares for the 15-day trading period December 1, 2008 to December 19, 2008.

About Visa: Visa operates the world's largest retail electronic payments network providing processing services and payment product platforms. This includes consumer credit, debit, prepaid and commercial payments, which are offered under the Visa, Visa Electron, Interlink and PLUS brands. Visa enjoys unsurpassed acceptance around the world and Visa/PLUS is one of the world's largest global ATM networks, offering cash access in local currency in more than 170 countries. For more information, visit www.corporate.visa.com .

Source: Company press release.


Reblog this post [with Zemanta]

Sorry Charlie...You've Been...Hired!

Last August I wrote a couple posts (Sorry Charlie...Youve Been Hacked and Sorry Charlie...The Cat's Outta the Bag) about the three MIT students that hacked into Boston's subway payment card system. (CharlieCard)

They had planned to present their findings at Defcom, but instead were sued by the Massachusetts Bay Transit Authority. The MBTA took legal action just before the students were scheduled to discuss: "generating fare cards","reverse-engineering magnetic stripes", and "hacking the RFID technology in the cards".

Instead, a judge issued an injunction ordering them to refrain from doing so. Now they've been "hired" by the MBTA. Ironically, yesterday I wrote a post entitled "Who Says Crime Doesn't Pay" and today, I saw this article that the MBTA had "hired" the three hackers who broke into their system.

So apparently it also pays to hack into a system and threaten to publicly share the results in a presentation at a hack convention.

It's a different world out there...the only "Hack" I ever heard of as a kid was "Hack Wilson" who set the record for most RBI's in a season (191) in 1930 for the Chicago Cubs.

Anyway, it's been an interesting turn of events so here's a follow up on the Sorry Charlie series from Yahoo news.

SAN FRANCISCO - A trio of Massachusetts Institute of Technology students who found a way to hack into the Boston subway system's payment cards have agreed to partner with transit officials there to make the system more secure.

The Electronic Frontier Foundation announced the agreement Monday, two months after the Massachusetts Bay Transportation Authority dropped a lawsuit against the students, who were represented for free by the EFF, a civil-liberties group that frequently takes up cases involving security researchers and computer hackers. The transit agency had sued to stop the students from presenting findings at a computer-security conference.

The students — Zack Anderson, R.J. Ryan and Alessandro Chiesa — have argued all along they were trying to help the MBTA by giving it advance notice of their planned talk last summer and keeping specific details of their hack secret. But the MBTA worried of widespread fare fraud if students discussed how they were able to add hundreds of dollars in value to MBTA's two primary payment cards — CharlieCard and CharlieTicket.

Before they could take the stage at the DefCon hacker conference in Las Vegas in August, the students were slapped with a lawsuit and a restraining order preventing them from giving the talk. Everyone found out what they were going to say anyway: All 87 slides of the students' presentation were already online, having been given out to conference attendees on CDs before the lawsuit was filed.

The MBTA argued it needed time to fix the problems, but the issue touched off a legal battle about whether the students' free-speech rights were violated and prompted the EFF to take up the students' case.

The judge eventually lifted the gag order and the transit agency dropped its lawsuit in October. The two sides have been working since then on how they would collaborate to make the fare system more secure and have the students' work taken seriously, said Jennifer Granick, the EFF's civil liberties director.

Reblog this post [with Zemanta]

Monday, December 22, 2008

Skim Milks Bank Accounts Dry


I don't know how good of an idea it is to print stories like this.  Law enforcement is, in essence, admitting that these types of crimes are very difficult to solve. 

Criminal Minds have to be thinking that, compared to robbing a bank, for example, skimming  seems to provide less danger, (non-violent) a higher  take (not many bank robberies result in an $800k purse),  and the risk of getting caught is lower.  Scary thought, yes, but off base?  Me thinks not.  I covered this story back in July...the update is that there is no update.  They haven't made any headway as far as identifying who the culprits are...

Gas debit thieves still on the loose

Police still haven’t caught up with the scam artists who made off with half a million dollars this summer from debit card information stolen at two Pierce County gas stations. Local agencies are coordinating with police in California and with federal agents to stop what they believe is a crime spree that spans the West Coast. The patient and wily thieves are believed to have left a wake of at least 675 victims and $800,000 in losses, according to police and news accounts.

“We are in touch with multiple agencies up and down the West Coast and the FBI is involved,” Pierce County Sheriff’s Department spokesman Ed Troyer said Friday. “We’re swapping photos and other information.”

But despite those efforts, the thieves remain steps ahead of their pursuers.

“We haven’t really made any headway as far as identifying who these people are,” said Puyallup police detective Jason Visnaw said Thursday. His case alone has 283 victims with losses of more than $268,000.

The crimes have several common features:

• The thieves target ARCO stations, which take debit cards but not credit cards.

• They use card-reading devices placed on the payment machine to “skim” account and PIN information.

• They often wait for months after taking the card information before making withdrawals – which is long enough for surveillance video to be taped over.

• They raid their victims’ accounts over holiday weekends, when there’s a better chance the thefts will go undetected for an extra day.

The thieves drew on accounts stolen from the station at 1502 South Meridian St. over Memorial Day weekend. Over the July Fourth holiday, more than 125 people who used their debit cards at the ARCO at 11608 Meridian Ave. E in South Hill became victims; they had all used their cards at the station the previous August.

The July Fourth case was investigated by the Pierce County Sheriff’s Department. A total number of victims and losses was not immediately available. Earlier estimates placed Pierce County losses around $500,000.

A May San Jose Mercury News article said a group that had targeted stations in South San Jose and Los Altos was “likely the same group that has been targeting stations statewide.”

San Jose detective Patrick Ward told The News Tribune that his case alone involved another 190 victims and another $210,000 in losses. The Los Altos case has more than 80 victims and $100,000 in losses.

Los Altos detective Wes Beveridge said the case is being investigated by a high-tech task force composed of officers from several jurisdictions in northern California and the FBI.  “We’ve got one of the suspects identified,” he said, noting it was unclear how big the group is. “I’ve got six different suspects in my cases.”

The information police have gathered indicates the group may have been active in Florida and Arizona before making southern California its home base. Members of the group are thought to be from Eastern Europe and are likely sending the proceeds overseas, possibly to fund other illegal activities, Beveridge said.

A comprehensive estimate of victims and losses was not available. Photographs from several ATMs where the thieves made their withdraws have been released to the public.

“Right now we’re all kind of in the same boat,” Ward said. “We’re trying to contact as many local agencies as possible. At this time, we don’t know exactly what the entire scope of it really is. It’s still an ongoing investigation.”



Reblog this post [with Zemanta]

Who Says Crime Doesn't Pay?

According to Brian Krebs, a Computer Security journalist with the Washington Post, Cybercriime is a lucrative business and is growing exponentially.  He refers to McAfee's annual "Virtual Criminology Report" (pdf) which states that online scams quadrupled in the last quarter of 2008. 

Also, (see chart on left) the number of viruses/bots, trojans and potentially unwanted programs (PUPs) are not only on the rise, but almost off the charts.  Why is this relevant?  Because (see 3 Key Findings illustration below) based on the report, law enforcement is "ill-equipped" to cope with this growing (insurmountable?) surge in PC attacks designed to steal personal information. 

So apparently "Crime Does Pay"...at least cybercrime. 

Put in simple terms,  software is soft... which is why HomeATM's Internet PIN debit approach is hardware based.  As long as hardware isn't tampered with (I  would find it highly unlikely that anybody's going to break into one's home to tamper with HomeATM 's Personal Card Swiping Device) it's the safest, most secure way to transact.  It's more convenient too...just swipe versus type!  But convenience takes a back seat to security, and if you have any doubts about how easy it is for cybercriminals to see what you type, then Google "PC Hijacking" or "keylogging." 

He's a snippet from Mr. Krebs article.

Report: Cybercrime is Winning the Battle Over Cyberlaw

Law enforcement agencies worldwide are losing the battle against cyber crime at a time when criminals are increasingly using the global economic downturn to make headway in recruiting more computers and computer users to further illegal online activities, a scathing new report from security vendor McAfee concludes.

McAfee's annual "Virtual Criminology Report" (PDF) notes that the number of compromised PCs used for blasting out spam and facilitating a host of online scams has quadrupled in the last quarter of 2008 alone, creating armies of spam "zombies" capable of flooding the Internet with more than 100 billion spam messages daily.

In an increasing number of cases, those missives are playing on public fears over the battered economy, pitching recipients on too-good-to-be-true job offers aimed to enlist them in cybercrime operations, McAfee said.

"Cybercriminals are cashing in on the fact that the economic downturn is causing people worldwide to increasingly turn to the Web to seek the best deals and jobs, and to manage their finances," the report charges. "They are preying on fear and uncertainty and taking advantage of the fact that consumers are often more easily duped and distracted during times of difficulties. In fact, opportunities to attack are on the rise."

At the forefront of this worsening problem are so-called "money mule" scams, in which criminals make use of third parties -- often unsuspecting consumers -- to launder stolen funds. Mule recruitment is an integral part of many cybercrime operations because money transferred directly from a victim to an account controlled by criminals is easily traced by banks and law enforcement.

The mules, therefore, serve as a vital buffer, making it easier for criminals to hide their tracks. However, criminals tend to view money mules as expendable resources, because those unwitting accomplices usually either are confronted by authorities or lose money as a result of their participation in the scams.

In most cases, money mules are recruited via online job postings touted in spam. McAfee said that some 873 money-mule recruitment Web pages were detected in Britain alone in the first half of 2008, a 33 percent increase over the first half of 2007. That data was gathered by APACS, the United Kingdom's payment-industry trade group.

An investigation by washingtonpost.com earlier this year into a money mule network uncovered a database of thousands of U.S. citizens who had responded with interest to a single money mule scam e-mail campaign.

(continue reading at the Washington Post) or go to the McAfee Report here




Reblog this post [with Zemanta]

Gemalto Wants EMV in USA


In an article written by Kirk Ladendorf of the American Statesman, he talks about Gemalto's preference to do away with  the magnetic stripe.  Most of Europe has already converted from magstripe to Chip and PIN, as has Australia and Canada...along with many other parts of the world.  The USA is the last vestibule for Gemalto, and they believe America will convert to EMV in the next 5 to 6 years.  At least one analyst does anyway. 

"The world's largest smart-card supplier shipped 1.2 billion of its cards last year and has more than 1 billion users around the world. It recorded sales last year of 1.6 billion euros (about $2.2 billion U.S.). The company says its growth this year is running about 10 percent in the face of a weakening economy.

Now, the Amsterdam, Netherlands-based company is looking for new worlds to conquer, including the United States, which traditionally has been a smart-card laggard. The company is relying on its 150-person marketing and engineering team in Austin to develop products, services and business alliances that help keep its revenue growing.

North America is a comparatively undeveloped market for Gemalto in part because many of the big banks here remain wedded to old-fashioned "magnetic stripe" bank credit cards and debit cards, rather than to smart cards, which predominate in Europe and other parts of the world.

Despite some reports of increased fraud cases involving magnetic stripe cards, many U.S. banks are hesitant to change because of their heavy investment in the technology, said analyst Ed Kountz with Jupiter Research.

"Our (banks') willingness to make a change is somewhere between kicking and screaming on the payment side of things," Kountz said.

Smart cards can contain 1,000 times as much information as a magstripe card and can contain multiple software applications that enable them to handle more functions. More data and more software translates into more security and more functionality, Gemalto says.

As the rest of the banking world adopts smart cards, the analyst expects U.S. banks will eventually follow in the next five or six years.

If the banks are slow to move, other U.S. customers, including the federal departments of Defense and State, have moved faster. Gemalto is one of two main suppliers of smart cards that go into the State Department's new e-passports, which began in 2006. It has also won over big security-conscious corporate customers including Boeing Co., Chevron Corp. and drugmaker Pfizer Inc..

Some of those companies have begun using a new Austin-developed product, the Smart Enterprise Guardian, that can be used to authorize user access to computer networks, the secure transport of stored digital files and digital signatures for e-mail documents to make an official record.

Pfizer is using the "digital signature" feature to reduce the logistical requirements, money and time involved in creating an official record for its complex drug development process.

The SEG was developed to work with Microsoft Corp.'s Windows operating system.Gemalto's technical team in Austin keeps close ties to Microsoft's operating system developers.

"Microsoft is a huge supporter of Gemalto because we are the largest provider of secure devices in the world," said Paul Beverly, who heads the company's North American operations and also serves as the global company's executive vice president for marketing. "What we are seeing is, we are in a position where things are evolving in our direction. The pressure is coming from various mandates for increased security, and there is a lowering of the technical barriers to adoption."

Microsoft founder Bill Gates has said that one of the major points of vulnerability to computer networks lies in its heavy dependence on passwords as the main form of authorization for users. Passwords can be stolen or lost, and they can create an administrative burden to manage.

Gemalto says it offers a way around the problem.

"We all realize that we can make the world more secure and more convenient if we can get rid of the damned password," Beverly said. "That is our mission, to get rid of the password, because it creates so many problems" for computer systems administrators...

(continue reading in a new window)


Reblog this post [with Zemanta]

Sunday, December 21, 2008

Debit Card Fraud 101


Beginner's guide to: Credit/debit card fraud
What are the most common types of card fraud?

The most common type of card fraud in Britain is known as "card not present" fraud. This is where fraudsters obtain your card details, and use them to buy products on the internet or over the telephone. 

(Editor's Note:  Card Not Present Fraud can be eliminated by providing a means to make the card present, which is what HomeATM has done with it's personal swiping device.)

How do fraudsters get my card details?

There are a number of ways. One method is "phishing", whereby a fraudster will email you posing as your bank or an official institution, and ask you to verify your details.

Fraudsters also use "skimming" devices to copy card details. When you hand your card to a shop attendant to pay for something, it is possible that they could pass it through a device underneath the counter. This records all your card details, which they can then use later. Fraudsters can also extract your details from your computer if you do not have adequate firewalls and virus software.

Wasn't Chip & PIN supposed to stop card fraud?

Chip & PIN has reduced fraud in Britain, but many other countries do not have the same technology. So criminals can clone cards in the UK, and then use them overseas.

How can I protect myself against fraud?

Don't let your cards out of your sight. With Chip & PIN technology, you shouldn't need to hand your card to the cashier. Also, be wary of emails asking for your personal information. Your bank would never email you asking you to enter your account or card details. Finally, make sure your home computer network is secure. Buy the latest virus packages, and secure your internet connection.

Will I have to pay up if I am a victim of fraud?

As long as it's not your fault, your bank will cover the cost of any fraud on your cards. However, if there's any evidence that you haven't taken proper care to protect yourself, you may have to pick up the bill. For more information about card fraud, visit www.apacs.org.uk.






Reblog this post [with Zemanta]

Video - ATM Card Skimming Tech Bar Raised

This is just the beginning of more sophisticated equipment being used to "skim" your card details.  Look for more advancements in technology both at ATM's and in the store as the skimming market evolves from it's current infancy mode into adolescence.  In this particular case, the technology was good, but c'mon man...a speaker?  What possible need would there be for a speaker at an ATM machine?  At least there's the blatant possibility these fraudsters can be outsmarted...








Reblog this post [with Zemanta]

Saturday, December 20, 2008

eCommerce Sales Up 19%


Consumer technology e-commerce sales rose 19 percent in the first two weeks of the holiday shopping season, industry tracker NPD Group said Friday, providing a bit of good news in an otherwise gloomy period for retailers.

Online sales in the two weeks ended December 6 climbed to $700 million, with LCD TVs, notebook computers and digital cameras leading the way.

"It's up in an environment where everything else is down," said NPD analyst Stephen Baker. "The economy is in play because people at least perceive that pricing is cheaper online."

E-commerce sales showed strength even as traditional holiday sales are faltering.

Last week, NPD said U.S. consumer technology brick-and-mortar sales showed their first-ever decline during the week of Black Friday, from November 23 through November 29, falling more than 8 percent to $2.03 billion .

Baker said consumers continue to migrate to the Web to make their technology purchases. Online buyers tend to be higher-income and a bit more gadget-savvy, so it's not so surprising that e-commerce technology sales are faring better than traditional sales, he said.

Reblog this post [with Zemanta]

Discover Releases 4Q Results


Discover releases fourth quarter results

Riverwoods, Ill., Dec. 18, 2008 -- Discover Financial Services (NYSE: DFS) today reported results for the quarter and year ended November 30, 2008 as follows:

Full year income from continuing operations was $1.1 billion, up 10% from last year. Fourth quarter income from continuing operations was $444 million, up from $210 million in the fourth quarter of 2007. Income from continuing operations includes antitrust litigation settlement proceeds of approximately $535 million (after-tax) in the fourth quarter of 2008. Discontinued operations relates to the sale of the Goldfish business.

Fourth Quarter Highlights
  • The company grew managed loans 6% from last year to $51 billion; Discover Card sales declined 2% to $22 billion.
  • The fourth-quarter managed net charge-off rate was 5.48% and the managed over 30 days delinquency rate was 4.56%.
  • The company added reserves in excess of charge-offs of $415 million.
  • Owned loans grew $3.5 billion from the third quarter, including $2.6 billion due to maturing securitizations retained on the balance sheet.
  • Total deposits grew 15% to $29 billion, including $6 billion of direct-to-consumer deposit balances.
  • Third-Party Payments segment volume grew 39% to $34 billion, including $7 billion of Diners Club International volume.
“Our results and financial position reflect our conservative orientation toward growth, credit risk and capital management as we position Discover to weather the economic downturn,” said David Nelms, chief executive officer of Discover Financial Services. “As part of our capital management, we are seeking to participate in the Treasury’s Capital Purchase Program which will further support our consumer lending operations.”

Settlement of Antitrust Litigation

On October 27, 2008 Discover reached a $2.75 billion settlement of its antitrust lawsuit with Visa and MasterCard. Discover received an $863 million payment in November 2008, and expects to receive the remaining proceeds in equal $472 million installments over the four quarters of 2009. The proceeds will be reflected as revenue in Discover’s U.S. Card segment in the period earned.

At the time of the spin-off of the company, Morgan Stanley and Discover entered into an agreement governing the manner in which the antitrust case was to be pursued and settled and how proceeds of the litigation were to be shared. The company has notified Morgan Stanley that it breached the agreement and the amount of the dividend to Morgan Stanley, if any, is a matter of dispute.

Liquidity and Capital

The company continues to maintain liquidity and capital positions that it believes are appropriate for the current environment. Cash liquidity was $9.4 billion and tangible equity was $5.5 billion, or 11.0% of net managed receivables, at November 30, 2008. The company applied to the U.S. Treasury to participate in the Capital Purchase Program and to the Federal Reserve to become a bank holding company. Segment Results (Managed Basis):

U.S. Card


Managed loans grew to $51 billion, up 6% from last year and 1% from last quarter as decreased consumer spending and balance transfer activity were offset by lower cardmember payments and growth in installment loans. Sales volume decreased 2% versus fourth quarter of 2007, and increased 2% on a full year basis.

Credit performance of the Card portfolio was consistent with Discover’s expectation as charge-offs rose, reflecting the deteriorating economic environment. The managed over 30 days delinquency rate of 4.56% was up 71 basis points from the third quarter of 2008, and 98 basis points from last year. The managed net chargeoff rate increased to 5.48% for the fourth quarter of 2008, up 28 and 163 basis points, respectively, from last quarter and last year. The full year net charge-off rate was 5.01% up 118 basis points from last year. Based on current trends within the portfolio and in the economic environment, the company believes that the managed net charge-off rate in the first quarter of 2009 will exceed 6%.

Fourth Quarter

Pretax income was $646 million in the fourth quarter of 2008, including other income of $863 million related to proceeds from the antitrust settlement. Pretax income was $321 million for the fourth quarter of 2007.

Managed net interest income increased $162 million, or 18%, an improvement of 79 basis points over fourth quarter of 2007. Higher net interest income benefited from lower cost of funds, growth in loan balances and accretion of balance transfer fees previously included in loan fee revenue, partially offset by higher interest chargeoffs. Provision for loan losses increased $521 million, or 89%, due to higher net chargeoffs and an increase in loan loss reserves in excess of charge-offs in the quarter. The reserve increase in excess of charge-offs of $415 million resulted from a higher reserve rate as well as higher on-balance sheet loans due to maturing securitizations.

Other income increased $630 million, reflecting the antitrust settlement partially offset by a reduction in the fair value of the interest-only strip receivable. The decline in the fair value of the interest-only strip receivable was due to no securitization gains in the fourth quarter as the company did not enter into new securitization transactions, along with higher anticipated charge-offs in the current environment.

Expenses decreased $54 million, or 9%, primarily attributable to lower compensation and marketing expense partially offset by increased professional fees. Compensation expense included a $39 million one-time benefit due to curtailment of the company’s pension plan. Marketing declined due to lower account acquisition and balance transfer volume as well as lower advertising costs.

Full Year

Pretax income was $1.6 billion in 2008, including other income of $863 million related to the antitrust settlement. Pretax income was $1.5 billion for 2007. Managed net interest income increased $551 million, or 15%, an improvement of 79 basis points over 2007, reflecting an increase in interest income and a decrease in interest expense. Interest income benefited from growth in loan balances and the transfer of balance transfer fees to interest income, partially offset by higher interest charge-offs and lower investment income. Interest expense decreased reflecting a lower cost of funds, partially offset by higher borrowings to fund higher loan balances.

Provision for loan losses increased $1.2 billion, or 66%, due to higher net chargeoffs and an increase in loan loss reserves in excess of charge-offs during the year. The reserve increase in excess of charge-offs of $615 million resulted from a higher reserve rate as well as higher on-balance sheet loans due to maturing securitizations.

Other income increased $673 million reflecting the antitrust settlement and higher discount and interchange revenue, partially offset by a write-down of the interest4 only strip receivable and the transfer of balance transfer fees to interest income. Discount and interchange revenue benefited from growth in sales volume. Expenses decreased $79 million, or 3%, primarily attributable to the pension curtailment benefit; lower account acquisition and promotional marketing activity; and a decrease in costs related to litigation.

Third-Party Payments


Fourth Quarter

The Third-Party Payments segment transaction volume was $34 billion, up 39% from last year, reflecting the addition of Diners Club International volume of $7 billion, as well as increased volumes on the PULSE and Discover networks. Pretax income of $21 million was up $13 million from the fourth quarter of 2007. Diners Club International contributed $4 million to the segment’s pretax income. Revenue increased $24 million due to increased volumes and fee revenues, as well as a $15 million contribution from Diners Club International. Expenses increased $11 million due to the inclusion of Diners Club International.

Full Year

The Third-Party Payments segment transaction volume was a record $125 billion, up 36% from last year, reflecting the addition of Diners Club International volume of $13 billion, as well as increased volumes on the PULSE and Discover networks. Pretax income of $81 million was up $44 million from 2007 including $11 million related to Diners Club International, which was acquired in June 2008. Revenue increased $61 million due to increased volumes and fee revenues as well as a $28 million contribution from Diners Club International. Expenses increased $17 million due to the inclusion of Diners Club International.

Discontinued Operations


Discontinued operations represent the company’s Goldfish business in the United Kingdom, which was sold to Barclays Bank PLC on March 31, 2008. In the fourth quarter of 2008, the company recognized a loss from discontinued operations, net of tax, of $12 million versus a loss of $266 million in the fourth quarter of 2007. The fourth quarter of 2007 included an impairment charge to write down goodwill and intangibles to fair value of $279 million, after-tax.

Dividend Declaration/Stock Repurchase Program


The company’s board declared a cash dividend of $.06 per share, payable on Jan. 22, 2009, to stockholders of record at the close of business on Jan. 2, 2009. No stock repurchases were conducted under the stock repurchase program during the fourth quarter.

Conference Call and Webcast Information


The company will host a conference call to discuss its fourth quarter results on Thursday, Dec. 18, 2008, at 10 a.m. Central time. Interested parties can listen to the conference call via a live audio webcast at http://investorrelations.discoverfinancial.com .


Source: Company press release.



Reblog this post [with Zemanta]

Disqus for ePayment News