Citi reiterates a 'Sell' rating on MasterCard (NYSE: MA). Price target $140
Citi analyst says, "While the stock has been strong recently and we have underestimated expense cuts, we believe slower net rev growth from the global consumer pullback will drive multiple contraction. We also believe the two key positive catalysts (expense cuts and price increases) are past the halfway mark. We are maintaining our est's and would expect the same for consensus. MA is a high-quality franchise, but we believe the multiple is stretched given the environment. We also believe the US consumer will not snap back as strong as some expect, as many are overextended and credit availability is constrained. Prefer Visa (NYSE: V) due to debit." (Citi maintains a Hold rating on Visa)
MasterCard Incorporated (MasterCard) is a global payment solutions company that provides a variety of services in support of the credit, debit and related payment programs of over 24,000 financial institutions and other entities that are its customers.
To see more analyst (all different :--) ratings on MA click below:
- Goldman Sachs Removed Mastercard (MA) from its Conviction Buy List
- Deutsche Bank Upgrades MasterCard (MA) to Buy, To Cheap Compared to Visa
- Buckingham Research Reiterates an 'Accumulate' Rating on MasterCard (MA); Raises 2009 EPS Estimates
Stocks Mentioned
Tuesday, May 5, 2009
Citi Says Sell, Deutshe Says Buy MasterCard
Monday, May 4, 2009
MasterCard Interchange Rates
PIN Debit Challenge!
"Card Not Present" PIN Debit rate!
MasterCard interchange rates are established by MasterCard, and are generally paid by acquirers to card issuers on purchase transactions conducted on MasterCard® cards. Interchange rates are only one of many cost components included in a MDR, (Merchant Discount Rate) and are a necessary and efficient method by which MasterCard maintains a strong and vibrant payments network.
Although MasterCard interchange rates have generally been available to merchants through requests to acquirers or other card acceptance service providers, MasterCard believes that providing easy access to our interchange rates will provide additional transparency to merchants.
Accordingly, MasterCard is publishing interchange rates that apply to U.S.-merchants’ transactions, which include U.S. interchange rates (that is, the interchange rates that apply to transactions conducted on a U.S.-issued card at a U.S. merchant) and Interregional interchange rates (that is, the interchange rates that apply to transactions conducted on a non–U.S.-issued card at a U.S. merchant). MasterCard has included a Merchant Category Guide, as well as the key criteria associated with each interchange rate and a Glossary of Terms, to help merchants determine which of the many interchange rates may apply to their transactions.
The interchange rate tables are organized by product type. Each interchange rate has a series of requirements, all of which must be satisfied in order for a transaction to qualify for that rate. The requirements include such factors as: merchant category; the time between authorization and clearing; the presence or absence of magnetic stripe data; the submission of enhanced transaction data; and a merchant’s MasterCard sales and transaction volume. MasterCard systems ensure that all requirements are met when a transaction is submitted for a particular interchange rate. Merchants and acquirers should strive to meet all of the criteria necessary to qualify transactions for the rate(s) that are most advantageous to them.
MasterCard interchange rates are typically updated semiannually, and MasterCard will publish its interchange rates generally concurrent with each rate update.
Visa & Interlink Interchange Rates (Reimbursement Fees)

Visa U.S.A. Inc. Interchange Rates/Fees
The file link below contains tables that set forth the interchange reimbursement fees applied on Visa financial transactions completed within the 50 United States and the District of Columbia.Take the PIN Payments News Blog Challenge!See if you can find the "Card Not Present" PIN Debit Rate in
Visa or Interlinks Published Interchange Fees!
Visa uses interchange reimbursement fees as transfer fees between financial institutions to balance and grow the payment system for the benefit of all participants.
Merchants do not pay interchange reimbursement fees; merchants pay "merchant discount" to their financial institution.
This is an important distinction, because merchants buy a variety of processing services from financial institutions; all of these services may be included in their merchant discount rate, which is typically a percentage rate per transaction.
If you have any questions about Visa's interchange rates or your merchant discount, please contact your financial institution.
Visa U.S.A. Interchange Reimbursement Fees - April 2009 PDF | 283K
Interlink Interchange Reimbursement Fees - April 2009 PDF | 44K
Elavon Put in Angie's List Penalty Box?
Now it appears (the processors blame it on the recession and possible bankruptcy filings) that credit card processors such as Elavon are using the small print in their processing agreements to withhold huge sums of earnings from companies. BusinessWeek has an excellent article on the subject. Here's an excerpt regarding Angies List and Elavon withholding $2.5 million dollars. It's bad enough eCommerce companies have to pay "card not present" fees, but when the "money is not present" because companies like Elavon hold them back under the guise of "reserves" it can have severe repercussions on the business...
"The ramifications on even a well-established company can be dramatic.
"In two weeks we would have been in bankruptcy," says Angie's List CEO Bill Oesterle, whose processor, Elavon, tried to withhold a reserve of $2.5 million from his $35 million company.
Oesterle was instead able to change processors quickly, and with help from his lawyers, got his money back in about three weeks.
"The Indianapolis-based company and was growing at more than 50% per quarter as of July 2008, when Oesterle got a call notifying him that Elavon was holding on to $2.5 million in his credit-card transactions and intended to use that money for a reserve. Elavon also wanted to examine the 356-person company's financials, and cited Angie's List's surge in credit-card transactions as the reason for its concern." Editor's Note: It's called growth Elavon. You want to see their financials but you can't spend an hour on google to figure out that they've been seeing tremendous growth? If you did you'd see that they raised $35 million dollars last April...and you wanted about 7% of that cause you're worried about "refunds?"When a processor agrees to clear a company's credit-card transactions, the processor then becomes responsible for providing customer refunds. When an unhappy consumer asks their credit-card company for a refund, the credit-card issuer gets that money from the processor.
Editor's Note: Does anyone else find it ironic that a company who reports on "unhappy customers" has their credit card transaction earnings withheld because Elavon would have to refund "unhappy customers?" I wonder if they did a review of Elavon on their site....or if they put them in their "penatlty box"? $2.5 million dollars for reserves? That's waxing 'em. Elavon...Elavoff!
Read the Entire Story at Business Week
elavon, elavoff, angies list, reserves, fricking crazy, unscrupulous
Amazon Payments Expanded

Amazon (NASDAQ: AMZN) announced that 25 new shopping cart providers including Magento, Miva Merchant and ShopVisible, will support Amazon Payments, which lets online store owners use the e-tail giant's back-end system to process online purchases.
In addition, Convio, a software and services provider to the non-profit community, is integrating Amazon Payments into its fundraising platform to enable its client base to accept alternate payment methods for online donations. Also, updated plug-ins for open source e-commerce platforms, such as osCommerce and ZenCart, are now available for the integration of Amazon Payments.
"Working with shopping cart and e-commerce solution providers to make sure their solutions seamlessly integrate with Amazon Payments was one of our immediate priorities when we launched Amazon Payments less than a year ago," Mark Stabingas, general manager of Amazon Payments, said in a statement. "Now businesses have an additional option for getting started with Amazon Payments and reaching Amazon's tens of millions of customers with the easiest way for customers to complete a purchase, while also enjoying the benefits of Amazon's fraud-detection technologies."
Amazon.com is promoting a free payment processing offer to businesses and organizations that begin accepting Checkout by Amazon or Amazon Simple Pay as April 29 as it continues to build its new Amazon Payments division. Amazon Payments services are available for merchants, service providers and nonprofits. Tools include Checkout by Amazon, which offers customers access to their Amazon.com address book and payment information to buy quickly and easily and transact using Amazon's 1-Click ordering. Amazon Simple Pay allows customers to use payment information from their Amazon.com accounts without the need to re-enter the information and is designed for Web sites selling digital goods, offering subscriptions or services, or accepting donations.More than 25 shopping cart and e-commerce service providers now include Amazon Payments as part of their offering. This makes it is easy for Web sites to begin offering Amazon Payments within the framework of the e-commerce solution already provided to them by these companies.
Nonprofit software provider Convio is integrating Amazon Payments into its fundraising platform to enable its client base to accept alternate payment methods for online donations. In addition, plug-ins for widely-used open source e-commerce platforms, such as OsCommerce and ZenCart, are now available for quick and easy integration with Amazon Payments.
“Working with shopping cart and e-commerce solution providers to make sure their solutions seamlessly integrate with Amazon Payments was one of our immediate priorities when we launched Amazon Payments less than a year ago,” said Mark Stabingas, GM of Amazon Payments, in a statement.
The free processing offer runs through September 30.
Wolfram Alpha...Better than Segway!
The last time I heard this much hype about how something was going to forever change the world all we got was a Segway...and the world hasn't changed much at all.
But the Wolfram Alpha sounds different.
For those who haven't yet heard, the Wolfram Alpha, showcased at Harvard University in the US last week, takes the firststep towards what, many consider to be the internet's Holy Grail (so as not to confuse you, it's only Hackers who consider the Holy Grail to be your PIN) -- aglobal store of information that understands and responds to ordinarylanguage in the same way a person does.
Here's an excerpt from yesterday's edition of "The Independent" If you'd like to learn more about Wolfram Alpha, here's a link to the WolframAlpha Blog
An invention that could change the internet for ever
Revolutionary new web software could put giants such as Google in the shade when it comes out later this month. Andrew Johnson reports
The biggest internet revolution for a generation will be unveiled this month with the launch of software that will understand questions and give specific, tailored answers in a way that the web has never managed before. Although the system is still new, it has already produced massive interest and excitement among technology pundits and internet watchers.
Computer experts believe the new search engine will be an evolutionary leap in the development of the internet. Nova Spivack, an internet and computer expert, said that Wolfram Alpha could prove just as important as Google. "It is really impressive and significant," he wrote. "In fact it may be as important for the web (and the world) as Google, but for a different purpose.
Wolfram Alpha will not only give a straight answer to questions such as "how high is Mount Everest?", but it will also produce a neat page of related information – all properly sourced – such as geographical location and nearby towns, and other mountains, complete with graphs and charts.
The real innovation, however, is in its ability to work things out "on the fly", according to its British inventor, Dr Stephen Wolfram. If you ask it to compare the height of Mount Everest to the length of the Golden Gate Bridge, it will tell you. Or ask what the weather was like in London on the day John F Kennedy was assassinated, it will cross-check and provide the answer. Ask it about D sharp major, it will play the scale. Type in "10 flips for four heads" and it will guess that you need to know the probability of coin-tossing. If you want to know when the next solar eclipse over Chicago is, or the exact current location of the International Space Station, it can work it out.
Dr Wolfram, an award-winning physicist who is based in America, added that the information is "curated", meaning it is assessed first by experts. This means that the weaknesses of sites such as Wikipedia, where doubts are cast on the information because anyone can contribute, are taken out. It is based on his best-selling Mathematica software, a standard tool for scientists, engineers and academics for crunching complex maths.
"I've wanted to make the knowledge we've accumulated in our civilization computable," he said last week. "I was not sure it was possible. I'm a little surprised it worked out so well.""It will understand what you are talking about," he said. "We are just at the beginning. I think we've got a reasonable start on 90 per cent of the shelves in a typical reference library."
The engine, which will be free to use, works by drawing on the knowledge on the internet, as well as private databases. Dr Wolfram said he expected that about 1,000 people would be needed to keep its databases updated with the latest discoveries and information.
Dr Wolfram, however, did not rule out working with Google in the future, as well as Wikipedia. "We're working to partner with all possible organisations that make sense," he said. "Search, narrative, news are complementary to what we have. Hopefully there will be some great synergies."
Worldwide network: A brief history of the internet
1969 The internet is created by the US Department of Defense with the networking of computers at UCLA and the Stanford Research Institute. (damn, they forgot to mention Al Gore...he must be steaming! Hmmm, I wonder if steaming causes global warming?
1979 The British Post Office uses the technology to create the first international computer networks.
1980 Bill Gates's deal to put a Microsoft Operating System on IBM's computers paves the way for almost universal computer ownership.
1984 Apple launches the first successful 'modern' computer interface using graphics to represent files and folders, drop-down menus and, crucially, mouse control.
1989 Tim Berners-Lee creates the world wide web – using browsers, pages and links to make communication on the internet simple.
1996 Google begins as a research project at Stanford University. The company is formally founded two years later by Sergey Brin and Larry Page.
2009 Dr Stephen Wolfram launches Wolfram Alpha.
The TJX Case: It Lives! With a New Theory of Liability: “Unfairness”

Posted on May 2nd, 2009 by David Navetta InfoSecCompliance.com
The last two plaintiff-banks still breathing after 1st Circuit Appeal
Little know (or at least discussed) fact: despite announcing settlements with VISA and Mastercard in 2007, the TJX data security litigation is still going. In fact most of the issuing banks impacted by the TJX breach are no longer pursuing TJX and/or have settled via VISA and Mastercard dispute resolution processes.
However, two financial institutions (Amerifirst Bank and SELCO Community Credit Union - hereinafter “Issuing Banks” or plaintiffs) have pressed forward with an appeal of various dismissals and class certification motions to the U.S Court of Appeals for the First Circuit (the “Appellate Court”). The 1st Circuit’s opinion sheds some more (high level) light on the liability risk of payment card data breach security cases. Ultimately, the Appellate Court allowed three theories of liability to proceed, including a previously dismissed theory alleging that TJX’s inadequate security amounted to an unfair business practices under Massachusetts’s unfair and deceptive business practices law.The main issue on appeal was the ruling on a motion to dismiss by the U.S District Court for the District of Massachusetts (the “District Court”). TJX and Fifth Third Bank (TJX’s merchant bank; collectively referred to as “defendants”) had asked the District Court to dismiss all of the counts alleged in the Issuing Bank’s complaint, including: (1) negligence; (2) breach of contract; (3) negligent misrepresentation; and (4) unfair or deceptive business practices under chapter 93A (Massachusetts’s consumer fraud statute). The District Court dismissed the negligence and breach of contract claim, but allowed the negligent misrepresentation claim and the 93A claim (which was based on negligent misrepresentation) to proceed.
Negligent Misrepresentation
The Appellate Court ultimately refused to dismiss the plaintiff’s negligent misrepresentation claim. However, the Court took a different path than the District Court. First, the court noted that the plaintiffs were not alleging any actual misrepresentation, but rather the plaintiff’s “negligent misrepresentation” was based purely on the defendants’ conduct in performing credit card transactions (in fact, the Appellate Court also referenced the defendants’ conduct in the form of entering contracts requiring certain credit card security measures). While conduct can be part of a misrepresentation, the link between the conduct and the implication must be “tight.” This link may be established by a combination of words and conduct concerning the alleged misrepresentation.
Continue Reading at InfoSecCompliance.com
Way Systems Gains Momentum
Download this press release as an Adobe PDF document.
Momentum Payment Systems recently announced a new strategic partnership with Way Systems Inc. and will now offer Way Systems' Mobile Transaction Terminal and Printer.
Houston, Texas (PRWEB) April 30, 2009-- Houston, TX based Momentum Payment Systems, www.MomentumPayments.com, a full service electronic payment processing provider, recently announced a new strategic partnership with Way Systems Inc. and will now offer Way Systems' Mobile Transaction Terminal and Printer.
The Mobile Transaction Terminal makes it possible to accept payments any time and anywhere by combining low-cost mobile phone technologies with the capabilities of a point-of-sale terminal. The terminal can process credit, pin-based debit and smart cards and can be paired with the mobile printer through its infrared wireless connection in order to print receipts quickly and easily. Unlike many other wireless units currently on the market they are easily portable. The printer and the terminal are small and lightweight, weighing only 5 and 8.8 ounces respectively."We believe that Way Systems' products will offer us another cost-effective and technologically-advanced wireless solution that we can offer our merchants in order to fit their payment processing needs," said Mark Harrelson, Chief Sales Officer.
About Momentum Payment Systems
Momentum Payment Systems, LLC is a fast growing merchant acquirer that specializes in providing small and medium-sized businesses throughout the United States with comprehensive electronic transaction processing solutions. Momentum offers traditional credit card, debit card, ATM card, gift card, prepaid card, EBT and check processing services. Momentum also proudly offers 24 hour customer service and technical support.
For further information, visit Momentum Payment Systems online at www.MomentumPayments.com
###
See the original story at:
http://www.prweb.com/releases/2009/05/prweb2378324.htm
What is Cloud Computing - Salesforce.com Video
From the Pardalis Data Ownership Blog
Traditional business applications and platforms are too complicated and expensive. They need a data center, a complex software stack and a team of experts to run them.This short video explains what Cloud Computing is and why it's faster, lower cost and doesn't eat up your valuable IT resources.
Sunday, May 3, 2009
Heartland Reinstated to Visa's List of PCI DSS Providers
Heartland Payment Systems Returns to Visa's List of PCI DSS Validated Service Providers
PRINCETON, N.J., May 01, 2009 (BUSINESS WIRE) -- Following the completion of its annual Payment Card Industry Data Security Standard (PCI DSS) assessment, Heartland Payment Systems has successfully validated its compliance with PCI DSS. As such, Heartland is returning to Visa's List of PCI DSS Validated Service Providers. According to Visa, Heartland will appear on the list - which can be found at www.visa.com/cisp -- on Monday, May 4.
About Heartland Payment Systems
Heartland Payment Systems, Inc., a NYSE company trading under the symbol HPY, delivers credit/debit/prepaid card processing, payroll, check management and payments solutions to more than 250,000 business locations nationwide. Heartland is the founding supporter of The Merchant Bill of Rights, a public advocacy initiative that educates merchants about fair credit and debit card processing practices. For more information, please visit www.HeartlandPaymentSystems.com and www.MerchantBillOfRights.com.
SOURCE: Heartland Payment Systems
Picture Compliments of the PIN Payments Blog, Clockwork Orange and Milk
Heartland Payment Systems Jason Maloni, 202-973-1335 jason.maloni@e-hps.com
MasterCard Debit GDV Grew 10.7% in Q1, Shares dip 7%
Highlights From MA's Q1 Conference Call:MasterCard Incorporated, together with its subsidiaries, provides transaction processing and related services to customers principally in support of their credit, deposit access, electronic cash and automated teller machine payment card programs, and travelers cheque programs.
- (CEO) While our net revenues for the quarter declined 2.2% on an as reported basis, net revenue grew 1.8% on a constant currency basis.
- We have taken considerable cost reduction actions to deliver a strong operating margin of 48.6%, an improvement of 5 percentage points over Q1 of 2008 and the highest quarterly margin to-date that we recorded as a public company.
- (CFO) Q1 net revenues of 1.2 billion declined 2.2% over the comparable period last year. This decline was primarily driven by the unfavorable impact of foreign exchange and higher rebates and incentives partially offset by pricing, increased process transactions and increases of other payment related services.
- Worldwide debit GDV grew 10.7% for the quarter. This compares to about 17.8% growth in worldwide debit in the first quarter of last year, but is more inline with the growth on a sequential basis.
- The decline in gas prices on a year-over-year basis accounted for approximately 40% of the decline in U.S. purchase volumes. Gross dollar volumes were down 0.7% on a local currency basis or approximately 14% on a U.S. dollar converted basis.
- Looking now to process transactions, they increased 5.8% compared with the year ago quarter to 5.1 billion in the first quarter.
- The number of MasterCard's branded cards worldwide grew 4% to 967 million in the quarter and excluding the U.S., the rest of the world card issuance grew 12.1%.
- Cross-border volume fees decreased by11.3% versus Q1 '08. While cross-border volumes were essentially flat on a local currency basis, they declined by 14% on a U.S. dollar basis which impacted this revenue line.
- We generated $416 million in cash from operations and ended the quarter with cash and cash equivalents and current investments of 2.3 billion.
Saturday, May 2, 2009
BofA Targeted by Malicious Code Phishing Attack

I have been, and will continue to, blog about the enormous risk involved with "typing" vs. "swiping." Here's yet another recent example (the phishing story below) of why I do what I do. It shows how obsolete the "Username: Password:" authentication is. It simply "amazes" me that financial institutions in the USA continue to use them for logging on to their websites.
Again...here's a common-sensical approach to protecting both the bank and bank customers from phishing attacks, DNS Hijacking, Cloned Websites, and more. The best part is it's easy as one-two-three, and two of them are already in place!
1. The "bank" issues a "bankcard" the customer "possesses" the bankcard.
2. The"bank" issues a "PIN" the customer "possesses" the PIN
There's only ONE step missing:
3. The "bank" issues a SwipePIN device and the customer "possesses" it.
Thus, in order to provide a "secure" 2FA (two factor authentication) encrypted log-in environment all they need is one more piece of the puzzle. A PCI 2.0 Certified Magstripe Reader with PIN Entry Device. So send them one, along with a note that says:
"In a move designed to protect the financial information of our valued customers, we have vastly upgraded the security of our online banking website. Enclosed you will find a PCI 2.0 Certiified Magnetic Card Reader with a Built-In PIN Pad. It simply plugs into your USB port and is immediately ready for use. No software or drivers are needed.
Beginning June 1st, online banking customers will be required to log-in by swiping your bank issued ATM Debit card and entering your PIN. This device provides our customers with 100% end-to-end encryption of your cardholder data and in addition to logging on to our site, this device will also enable you to securely transfer money from your account to any other account (see money transfer instruction, included) and purchase items online by simply swiping your card and entering your PIN just as you do in a retail environment.
That's it. Simple as one-two-three. The missing piece of the puzzle.
Think about it. Why do banks issue a card and a PIN? So you can swipe it and enter the PIN. So what's with the Username Password stuff? It needs to change.
Until then, you'll continue to read posts like the one below. Oh, and did I mention that the average phishing attack comes at a cost of $350.00 and ours costs $12? (see below at end of article or in a post entitled: Something Phishy About Banks Not Using 2FA from HomeATM)
One thing is for sure...(see graphic below right) Malicious Code isn't going away...
Banking / Finance Alerts
Scam / Fraud / Hoax Alerts
Source: TrendMicro
Complete item: http://blog.trendmicro.com/invoice-spam-finds-new-target-worldpay/
Description: After spam runs related to UPS, FedEx, and Western Union, another form of invoice spam strikes again!
We caught a new invoice spam that is purportedly from WorldPay, a division of the Royal Bank of Scotland that specializes in handling secure online payments from all over the world.
The spammed email message informs users that their transaction with Amazon Inc. has been successfully processed by WorldPay. The said email contains a .ZIP file, which holds a malicious file named WorldPay_NR9712.exe. This file is detected by Trend Micro as TSPY_ZBOT.BEO through the Smart Protection Network. TSPY_ZBOT.BEO downloads a configuration file from a remote site. This file contains a list of bank-related Web sites, which the spyware monitors in the Internet browser address bars.
The URLs listed in the downloaded configuration file may change at any time. As of this writing, the file contains links to the legitimate sites of Bank of America.
When a user accesses any of the listed banks site URLs, the spyware logs keystrokes to capture data entered in login boxes, including sensitive banking information such as user names and passwords.
The gathered information is saved in a file, which is then sent to a remote site through HTTP post.
Editor's Note: One more thing. Our device would cost banks $12.00 and save them $100's "per" phishing attack.
This from Gartner Research:
- Phishing attacks are costly:
According to research firm,Gartner, banks, online payment organizations and other financialinstitutions are bearing most of the financial cost of phishingattacks. (A survey of nearly 4,000 US consumers revealed a 40% increase in the number of phishing victims in 2008 over the year before to five million.)Guess what? The HomeATM "SafeTPIN" device would not only eliminate "phishing attacks" but it would also eliminate the threat of "cloned cards," "cloned bank sites", AND provide "True 2FA." for online banking customers.
The average loss was $350 per phishing attack, but consumers said they had recovered 56% of their losses from the financial institutions involved. (That's $196 to the banks and $154 to the consumers) "The findings underline the fact that the war against phishing is far from over," said Avivah Litan, analyst at Gartner. (Yes, the very same Avivah Litan who says "never" enter your PIN on the Internet unless it's hardware based)
Additional benefits include empowering online banking customers with the ability to perform:As I said, I don't mean tooversimplify WHY they banks should investigate our solution further,but sometimes the simplest things in life are the best...aren't they? Where am I wrong here?
- Person to Person Money Transfers,
- Bill Payment Online (with "True PIN" vs. PINless Debit)
- Secure online transactions with online retailers.
E-Secure-IT
https://www.e-secure-it.com
Related articles by the PIN Payments News Blog
Fraudsters Go Postal! USPS Probes Breach
USPS Probes Security Breach - CBS News
Data Companies Issue New Warnings About Breach That Could Lead To Potential Compromise Of Credit Cards
(CBS) CBS News has learned of another data breach potentially compromising the personal information of thousands of people. Companies Lexis Nexis and Investigative Professionals have notified up to 40,000 people whose “sensitive and personally identifiable” information may have been viewed by individuals who should not have had access.
The United States Postal Inspection Service is investigating a data breach at both companies that resulted in sensitive information being used in a crime. Those individuals have been notified.
Sources tell CBS News that the data breach is linked to a Nigerian Scam artist who used the information to incur fraudulent charges on victims’ credit cards.
Peter Rendina, a spokesman for the Postal Inspectors Service said that of the 40,000 individuals whose information was accessed, up to 300 were compromised and used to obtain fraudulent credit cards.
Continue Reading at CBS
Friday, May 1, 2009
3DES, DUKPT and E2EE Explained
I received a couple questions via email and wanted to take the time to provide a "coupla" of answers. If you have any questions about anything I've blogged about over the past year, feel free to shoot me one. I've got my email below:
Here's the first question:
Q: Is Triple DES a better encryption standard than DUKPT? (Derived Unique Key Per Transaction)?
A:I've used the terms Triple DES and DUKPT quite a bit in recent posts. To clarify, let's just start by saying that DUKPT does not really compete with Triple DES. Let's go over them one by one.
The DES stands for Data Encryption Standard, a block cipher that was selected as an official Federal Information Processing Standard (FIPS)for the United States in 1976.
Triple DES, sometimes shortened further as 3DES, increases the difficulty of cracking the encryption byapplying three rounds of action: an encryption, a decryption and an encryption, each with independent keys.
3DES has become popular for encrypting financial transactions because it is potentially far more secure than DES, which has been shown to yield its secrets somewhat quickly to relatively cheap hardware.
Both DES and 3DESuse a symmetric key. In other words, the same key enciphers and deciphers the protected data. To keep the key secret, a secure key-management system is required.
Worldwide, POS devices handle billions of transactions per day. If the keys to even a small portion of that traffic was discovered, we'd have a tremendously huge problem. Which is my segway to DUKPT.
One way to prevent fraud is to use a different key for "each transaction," (Derived Unique Key Per Transaction) HomeATM's secure devices (and thus your transactions) are "Protected by DUKPT" and each one is initialized with a master key. The master key is from which the unique keys are derived, one for each"per" transaction.
The benefit of DUKPT is that even if an attacker discovered the key toa particular transaction, none of the other transactions from the same device would be able to be decrypted with that key.
That said, a potential attack point (from a fraudster) would be the master key stored in the encrypting device. However, because HomeATM uses DUKPT, our device is built so that tampering with the device wipes this master key out.
These derived keys are used to encrypt transaction data with a symmetric cipher such as 3DES. HomeATM also takes it one step further and encrypts the Track 2 data as well. If you ever have any questions regarding financial transaction security or how HomeATM provides true end-to-end-encrypted transactions, feel free to email me.
Before I get to the next question, I've got one for you.
When you "type" your card number into a "box" on a merchant website, is it protected by DUKPT? Is it encrypted? If so, DES or 3DES? First one to send me the correct answer gets a Free HomeATM PED!
Q: What is TRUE end-to-end encryption? (E2EE)
A: First of all, "true"end-to-end encryption can only occur with a PIN based transaction. It doesn't exist outside of that scope because there is a point in the process where the cardholder data is decrypted and before it is re-encrypted is that is the point where it is vulnerable.
With that said, Heartland's proposal for end-to-end encryption has promulgated E2EE into a hot topic.
I would point out that Heartland's E2EE proposal came "AFTER" their breach...while HomeATM instituted their end-to-end encryption from "the very beginning." I'm not bragging. I'm proudly displaying our insight into the weaknesses inherent in the payments system and how we improved upon said weaknesses.
But let's get back to Heartland, shall we? In this post I will attempt to explain why they CANNOT magically snap their fingers and introduce E2EE on their own. They need cooperation from others in the industry.
While it's true that some large U.S. retailers encrypt cardholder data while in transit, it's also true that most don't. Therefore...in order for E2EE to work, a lot of retailers would need to revamp their system(s). Very costly indeed.
In addition, the top full-service U.S. payment processors also don't currently support E2EE; thus, retailers that encrypt card data in transit typically must decrypt it before they send it to their processor.
The key word here is decrypt. That is the weak point, the vulnerability, and as such, also the problem.
That said, PIN Debit is an entirely different animal. Card brand standards require that PINs are encrypted end-to-end. In fact, speaking about Heartland's quest for E2EE, Distinguished Gartner Analyst Avivah Litan stated:
End-to-end encryption would be most effective if data was encrypted from the time a card was swiped at a POS until it reached the card issuer, similar to the way personal identification numbers (PINs) currently are encrypted according to card brand standards.Starting to get the point? If not here's some more insight as Ms. Litan went on to state:
"Heartland is limited by the scope of systems it manages and from which it accepts data; it can only seek to influence the card industry to carry end-to-end encryption beyond the processor stage, through the card networks and onto the card issuers."The proposal's success also depends on merchants' willingness to invest in terminal upgrades that support card data encryption."
(Editor's Note: For instance...HomeATM's PCI 2.0 Certified SafeTPIN PED which also encrypts the Track 2 data.) Avivah continues:
"If Heartland implements its proposed project more securely than it has managed in the past with its network, it will make payment card processing more secure for merchants, especially if they don't manage the encryption keys and leave key management to their processor.
Can you provide an example of a "sound key management practice? That's why HomeATM is the closest thing to TRUE end-to-end encryption in the industry. (our industry being eCommerce payments and Real Time Money Transfer.)Nevertheless, the process will always include vulnerabilities at the point where data is encrypted and decrypted.
"These vulnerabilities can be limited by using "sound key management practices" and enforcing extra security measures, such as "requiring two separately managed sets of keys for cryptographic operation"
In the bricks and mortar world, end-to-end encryption doesn't exist and the whole system would need to be revamped. You can learn more about that in this related post where Avivah Litan asks:
- Hacked! Is Visa Next? (pindebit.blogspot.com)
Debit Surpasses Credit for the1st Time in Visa History (Volume & Transactions)
"The reality is that the vast majority of consumers want to pay as they go," said Stacey Pinkerd in a press release. Pinkerd oversees Visa's debit-card business.
Visa's growth in its debit card segment far exceeded analyst's predictions. (Editor's Note: Not the analyst I know. See Debit is King, Replaces Cash on Throne So that I'm on the record for future developments when they occur:
- PIN Debit will increase it's margin on signature debit,
- eCommerce will "eventually" overtake Brick and Mortar
- Hackers will continue to outsmart and their attacks will continue to breach software applications, until we finally realize that:
- Hardware is the only tried and true method to conduct secure online transactions, (and a 2FA 3DES E2EE PCI 2.0 PED that encrypts Track 2 data and utilizes DUKPT does it best).
- Analysts will realize and start writing that Software PIN Debit is not really True PIN Debit especially when:
- Online Merchants Start Demanding Card Present and TRUE PIN Debit Interchange Rates which they cannot derive from a software based POS solution.
- True PIN Debit will become ubiquitous on the web by 2014.
MasterCard also witnessed a major shift toward debit cards, reporting its debit card transactions rose 13 percent last year while credit card purchases dropped more than 2 percent.
Payment cards have long been the preferred purchase method for American consumers, with credit and debit card purchases for retail goods and services outmatching cash and check payments since 2003. Debit cards have slowly approached the levels of credit card use in the 21st century, according to a release by the Nilson Report.
The switch in payment cards is reflected in debt levels and types of accounts nationwide, with the U.S. government reporting in March that personal saving rates rose to 5 percent in January, the highest in 14 years. Meanwhile, revolving debt from credit cards plummeted more than 9 percent, said the Federal Reserve.
However, the Nilson Report projected debit cards will also eventually be reined in, with the buildup in both credit and debit spending slowing to single digits after five consecutive years of double-digit growth.
FIS Reports Strong Earnings Growth
Adjusted EPS of $0.31, up 19.2%/Adjusted EBITDA margin of 22.7%, up 100 basis points
Free cash flow increases to $119 million
JACKSONVILLE, Fla., May 1st, 2009 PIN Payments News Blog -- Fidelity National Information Services, Inc. (NYSE: FIS), a leading global provider of technology services to financial institutions, today reported financial results for the quarter ended March 31, 2009.
Consolidated revenue of $797.8 million declined 3.9% in U.S. dollars and increased 0.3% in constant currency compared to $830.3 million in the first quarter of 2008. Non-GAAP adjusted net earnings increased 19.2% to $0.31 per share in U.S. dollars, compared to $0.26 in the prior year, and increased 23.1% in constant currency. The increase is attributable to improved operating performance, lower interest expense and a lower share count, partially offset by a slightly higher tax rate. GAAP net earnings from continuing operations attributable to common stockholders totaled $34.3 million, or $0.18 per share compared to $0.06 per share in the prior period. Free cash flow (cash from operations less capital expenditures) was $119.2 million compared with $4.9 million in the prior year quarter.
"FIS's strong first quarter performance in the midst of ongoing economic uncertainty reflects the continued solid execution of our business plan and the strength of our operating model," stated William P. Foley, II, executive chairman of FIS.
"We are very pleased with the strong growth in earnings, profit margins and free cash flow," stated Lee A. Kennedy, president and chief executive officer. "Despite very difficult market conditions, our disciplined focus on improving efficiency and managing costs drove a 100 basis point improvement in our EBITDA margin, and contributed to the 19.2% increase in earnings per share. Although we expect challenging market conditions to persist throughout 2009, we remain confident in our ability to achieve solid earnings growth and strong free cash flow."
Supplemental Information
Consolidated revenue in the first quarter of 2009 was $797.8 million, compared with $830.3 in the prior year quarter, a decrease of 3.9% in U.S. dollars. Excluding a $34.9 million unfavorable impact of foreign currency resulting from a strengthening of the U.S. dollar, consolidated revenue increased 0.3% driven by strong growth in International.The effective tax rate in the first quarter of 2009 was 34.5% compared to 33.1% in the first quarter of 2008.
- Financial Solutions revenue declined 3.2% to $271.3 million compared to $280.4 million in the prior period, as increased demand for risk management and commercial outsourcing services was offset by lower software license and professional services revenue;
- Payment Solutions revenue declined 2.3% to $364.7 million compared to $373.3 million in the 2008 quarter, due primarily to a $9.7 million decline in the company's retail check guarantee business. Excluding Check Services' revenue from both periods, Payment Solutions revenue increased 0.4%;
- International revenue declined 8.3% to $162.3 million in U.S. dollars, compared to $176.9 million in the prior year quarter.
- International revenue increased 11.5% in constant currency, driven by 16.3% growth in payments and 4.5% growth in financial solutions.
- Adjusted EBITDA increased 0.7% to $181.2 million in the first quarter of 2009 compared to $180.0 million in the 2008 quarter. The adjusted EBITDA margin improved 100 basis points to 22.7% compared to 21.7% in the prior-year quarter, driven by increased operating leverage and ongoing expense management.
- Financial Solutions EBITDA declined 2.9% to $102.0 million, due primarily to a decline in high margin software sales. The 37.6% margin was comparable to the prior period;
- Payment Solutions EBITDA increased 11.5% to $95.2 million, and the margin increased 320 basis points to 26.1%. The improvement is attributable to increased operating efficiency;
- International EBITDA decreased 8.6% to $23.4 million due to a $5.2 million unfavorable currency impact. The International margin of 14.4% was comparable to prior year.
Balance Sheet
FIS had $272.0 million in cash and cash equivalents at March 31, 2009. The company repaid $54.0 million of debt during the first quarter, reducing total debt outstanding to $2.46 billion, of which $2.1 billion has been swapped to fixed interest rates. The effective interest rate was 5.2% as of March 31, 2009.
Continuing an intensive focus on capital spending, capital expenditures totaled $45.3 million in the quarter, which is a 42% reduction from the $78.3 million spent in the prior year.Acquisition Update
On April 1, 2009, FIS announced plans to acquire Metavante Technologies, Inc. (NYSE: MV). The transaction is subject to approval by FIS and Metavante shareholders, receipt of regulatory approvals and the satisfaction of customary closing conditions. Subject to receiving the required approvals, FIS expects to complete the transaction in the third quarter of 2009.
2009 Outlook
FIS reaffirmed its full year outlook for adjusted net earnings of $1.60 to $1.66 per share. This guidance does not reflect the proposed acquisition of Metavante. FIS will update its fiscal 2009 guidance to include Metavante's results following the completion of the transaction.
Use of Non-GAAP Financial Information
Generally Accepted Accounting Principles (GAAP) is the term used to refer to the standard framework of guidelines for financial accounting. GAAP includes the standards, conventions, and rules accountants follow in recording and summarizing transactions, and in the preparation of financial statements. In addition to reporting financial results in accordance with GAAP, the company has provided non-GAAP financial measures which it believes are useful to help investors better understand its financial performance, competitive position and prospects for the future. These non-GAAP measures include earnings before interest, taxes and amortization (EBITDA), adjusted net earnings, and free cash flow. Adjusted EBITDA excludes the impact of merger and acquisition and integration expenses, LPS spin-off related costs, certain stock compensation charges and certain other costs. Adjusted net earnings exclude the after-tax impact of merger and acquisition and integration expenses, LPS spin-off related costs, certain stock compensation charges, acquisition related amortization and certain other costs. Any non-GAAP measures should be considered in context with the GAAP financial presentation and should not be considered in isolation or as a substitute for GAAP net earnings. Further, FIS's non-GAAP measures may be calculated differently from similarly-titled measures of other companies. A reconciliation of these non-GAAP measures to related GAAP measures is included in the press release attachments.
Conference Call and Webcast
FIS will host a call with investors and analysts to discuss first quarter 2009 results on Wednesday, April 29, 2009, beginning at 8:30 a.m. Eastern daylight time. To register for the live event and to access a supplemental slide presentation, go to the Investor Relations section at www.fidelityinfoservices.com and click on "Events and Multimedia." A webcast replay will be available on FIS' Investor Relations website, and a telephone replay will be available through May 13, 2009, by dialing 800-475-6701 (USA) or 320-365-3844 (International). The access code will be 996633. To access a PDF version of this release and accompanying financial tables, go to http://www.investor.fidelityinfoservices.com.
About Fidelity National Information Services, Inc.
Fidelity National Information Services, Inc. (NYSE: FIS), a member of the S&P 500 Index, is a leading provider of core processing for financial institutions; card issuer and transaction processing services; and outsourcing services to financial institutions and retailers. FIS has processing and technology relationships with 40 of the top 50 global banks, including nine of the top 10 and was ranked the number one banking technology provider in the world by American Banker and the research firm Financial Insights in the 2008 FinTech 100 rankings. Headquartered in Jacksonville, Fla., FIS maintains a strong global presence, serving more than 14,000 financial institutions in more than 90 countries worldwide. For more information on Fidelity National Information Services, please visit www.fidelityinfoservices.com.










![Reblog this post [with Zemanta]](https://img.zemanta.com/reblog_c.png?x-id=042b2ac2-d27f-4e2e-84e8-85c75b7b90d2)
