Thursday, July 9, 2009

Magstripe 101

What Is The Stripe On the Credit Card?
What Is The Stripe On the Credit Card?

Each day we use our bank issued credit card. Swiping our cards on stores card readers to buy our purchases. Now, how it is that something so small can keep all your bank information. What allows the card reader to see that information? And what is that dark strip on the back of our cards.
The stripe on the back of a credit card is a magnetic stripe, or also called “MagStripe”. The magnetic strip is made up of tiny iron-based magnetic particles in a plastic-like film. Each particle is really a tiny magnet bar about 20-millionths of an inch long.

The magnetic stripe can have data written because the tiny magnet bar can be magnetized in either a north or South Pole direction. The magnetic strip very similar to a cassette tape.
A magnetic stripe card reader can then understand the information that has been written on the three-track stripe.
If the credit card isn’t being accepted, your problem is probably either:

* A dirty or scratched MagStripe
* An erased magnetic stripe
o The most common causes for erased MagStripe are exposure to magnets, like the ones that hold notes &pictures on your refrigerator, or exposure to a store’s EAS (Electronic Article Surveillance) tag demagnetizer.
* Or you are just out of money.

These Three Tracks Stripes on the magnetic stripe each have tracks that are about 1/10th of an inch wide. The ISO/IEC standard 7811, which is used by some banks, specifies:

* Track one – 210 bpi (bits per inch), and holds 79 6-bit plus parity bit read-only characters.
* Track two – 75 bpi, and holds 40 4-bit plus parity bit characters.
* Track three – 210 bpi, and holds 107 4-bit plus parity bit characters.

Credit Card typically uses only tracks-1 & 2. Track-3 is a read/write track (which includes your encrypted PIN, country codes, currency units and amount on your account); this is not standardized among all banks.
The information on track-1 is contained in two formats: A, which is reserved for proprietary use of the card issuer, and B, which includes the following:

* Start sentinel – one character
* Format code=”B” – one character (alpha only)
* Primary account number – up to 19 characters
* Separator – one character
* Country code – three characters
* Name – two to 26 characters
* Separator – one character
* Expiration date or separator – four characters or one character
* Discretionary data – enough characters to fill out maximum record length (79 characters total)
* End sentinel – one character
* Longitudinal redundancy check (LRC) – one character LRC is a form of computed check character.

The format for track two, developed by the banking industry, is as follows:

* Start sentinel – one character
* Primary account number – up to 19 characters
* Separator – one character
* Country code – three characters
* Expiration date or separator – four characters or one character
* Discretionary data – enough characters to fill out maximum record length (40 characters total)
* LRC – one character

There are three basic methods for determining whether your credit card will pay for what you’re charging:

* Voice authentication – Small Merchants do using a touch-tone phone.
* Electronic data capture – (EDC) MagStripe-card swipe terminals
* Virtual terminals on the Internet

How all of this works:
After the credit card is swipes through a reader, the EDC software at the point-of-sale (POS) terminal dials a stored phone number (using a modem) to call an acquirer. An acquirer is an organization that collects credit card authentication requests from merchants and provides the merchants with a guarantee payment.
When the acquirer company gets the credit-card authentication request, it checks the transaction for validity and the record on the MagStripe for:

* Merchant ID
* Valid card number
* Expiration date
* Credit-card limit
* Card usage

With Single dial-up transactions, they are processed at 1,200 to 2,400 bits per second (bps), while direct Internet attachment uses much higher speeds via this protocol. Using Internet protocol, the cardholder enters their personal identification number (PIN) using a pin pad.
The PIN is not on the card — it is encrypted in the database. Creation of your PIN can be interred in on the bank’s computers in an encrypted form.
Also, the communications between the ATM and the bank’s central computer are encrypted to prevent would-be thieves from tapping into the phone lines, recording the signals sent to the ATM to authorize the dispensing of cash and then feeding the same signals to the ATM to trick it into unauthorized dispensing of cash.
If all of this isn’t enough protection, there are now cards that utilize even more security measures than your conventional credit card: Smart Cards.




, , ,

Consumers’ fears about online fraud 

New Consumer Research from the Secure POS Vendor Alliance Underscores Need for Greater Payment Security Measures

Global survey results are call to action for industry players to increase consumer trust

Seventy-three percent of consumers surveyed in the United States, France and Great Britain say that more stringent standards are required before they will trust the security of their credit card transactions.

And almost half (46 percent) are concerned about the potential for a security breach when paying with their credit or PIN-based cards, according to an international survey released today by the Secure POS Vendor Alliance (SPVA), a non-profit business organization created by Hypercom (NYSE: HYC), Ingenico S.A. (EURONEXT: ING) and VeriFone (NYSE: PAY).

SPVA focuses on standardized implementation of existing security standards, security of the payment device lifecycle and security threat analysis and intelligence.

“Security is clearly a pivotal issue for the industry and consumers,” said Christophe Dolique, SPVA Chairman and EVP, Global Marketing & Transaction Services at Ingenico. “These findings confirm the strong correlation between the strength and quality of security and consumers’ views and behaviors toward using card payment systems presenting the payments industry with a unique opportunity to come together and achieve positive change.”

When paying for goods, consumers are entering their PIN number when making purchases using their cards 74% of the time.
Figures vary in the UK (84%), USA (56%) and France (74%


 Growing awareness of data breaches that industry experts have been working to combat for years, leads 62 percent of consumers to feel particularly worried about using their card and PIN to make a purchase if the outlet had suffered a data breach.

Eighty-four percent say that companies that suffer a data breach should be required to make the incident public, reinforcing the idea that vendors and retailers run the risk of devastating their brand if a breach occurs.

Sixty-five percent of respondents report that they are often or always concerned about Internet fraud.


Download this press release (PDF)
Download the SPVA Global Consumer Survey Key Findings (PDF)
Download the SPVA Global Consumer Survey Data (XLS)

###

The SPVA survey results represent 1,030 consumers: 407 UK, 303 USA, 320 France (51 percent male, 49 percent female, average age 40). It has a three percent margin of error and was conducted by Loudhouse Research, a London-based research consultancy firm. Complete survey data can be found at www.spva.org.

About SPVA (www.spva.org)
The Secure POS Vendor Alliance (SPVA) is a non-profit organization that works with the multiple stakeholders of the payment value chain. Its aim is to develop an end-to-end security framework and to enhance security elements of payment solutions which protect cardholder information and defend merchants and acquirers against security breaches, while helping reducing fraud and lowering risk for all electronic payment stakeholders.

About Hypercom (www.hypercom.com)
Global payment technology leader Hypercom Corporation delivers a full suite of high security, end-to-end electronic payment products and services. The Company's solutions address the high security electronic transaction needs of banks and other financial institutions, processors, large scale retailers, smaller merchants, quick service restaurants, and users in the transportation, petroleum, healthcare, prepaid, unattended and many other markets. Hypercom solutions enable businesses in more than 100 countries to securely expand their revenues and profits. With its acquisition of Thales e-Transactions in 2008, Hypercom became the second largest provider of electronic payment solutions and services in Western Europe, and solidified its position as the third largest provider globally.

About Ingenico (www.ingenico.com)
Throughout the world, banks and retailers rely on Ingenico for secure and expedient electronic transaction acceptance. Ingenico solutions leverage proven technology, established standards and unparalleled ergonomics to provide optimal reliability, versatility and usability. This comprehensive range of products is complemented by a global array of services and partnerships, enabling businesses in a number of vertical sectors to accept transactions anywhere their business takes them.

About VeriFone Holdings, Inc. (www.verifone.com)
VeriFone Holdings, Inc. (“VeriFone”) (NYSE: PAY), a global leader in secure electronic payment technologies, provides expertise, solutions and services for today with a migration strategy for tomorrow. VeriFone delivers solutions that add value to the point of sale, resulting in improved merchant retention and the generation of new sources of revenue for its partners and customers. VeriFone solutions are specifically designed to meet the needs of vertical markets including financial, retail, petroleum, government and healthcare.

 

Reblog this post [with Zemanta]

UATP Addes Virgin America as New Merchant



UATP adds Virgin America as new merchant

Washington, July 9, 2009 -- Universal Air Travel Plan, Inc. (UATP) continues its expansion adding Virgin America as its newest merchant effective immediately. To meet customer demand, Virgin America adds UATP as a form of payment to help expand its market share in the airline industry.

"As a new airline, we've quickly recognized the demand for UATP acceptance and want to expand our corporate client base while lowering distribution costs," said Diana Walke, Vice President of Planning and Sales at Virgin America. "Virgin America is injecting some healthy competition into the airline industry with our award-winning service, low fares and upscale amenities - and corporate travelers are responding."

Launched in August 2007, Virgin America is a new California-based airline on a mission to make flying good again - with brand new planes, attractive fares, topnotch service, and a host of innovative amenities that are reinventing domestic air travel. UATP will enhance Virgin America's strategic plan through UATP's mission of helping airlines lower distribution costs with low merchant service fees and a global network available to all corporate travelers. Ticket purchases are available to the UATP Network through traditional channels and Virgin America will continue to enhance availability for all UATP cardholders.

"Focusing on the key drivers for success, a strong business strategy and expanding services, Virgin America has positioned itself for rapid growth," Ralph Kaiser, president and CEO, UATP stated. "The Virgin brand is a leader in the airline industry and Virgin America will be able to increase its market share in the corporate travel arena."

The airline's base of operations is San Francisco International Airport's ultra-modern International Terminal. Virgin America flies to San Francisco, Los Angeles, New York, Washington D.C., Seattle, Las Vegas, San Diego, Boston and Orange County.

For more information, visit http://uatp.com or www.virginamerica.com .

About UATP

UATP accounts are accepted as a form of payment for corporate business travel by Amtrak(R), airlines and travel agencies worldwide. UATP accounts are issued by: Air New Zealand (ANZFF.PK), American Airlines (NYSE: AMR), Austrian Airlines (AUALF.PK), Continental Airlines (NYSE: CAL), Delta Air Lines (NYSE: DAL), Japan Airlines (JALSY.PK), Northwest Airlines, Qantas Airways, Ltd. (QUBSF.PK), United Airlines (Nasdaq: UAUA), and US Airways (NYSE: LCC). AirPlus International issues the UATP-based Company Account for: British Airways (LSE: BAY.L), Continental Airlines (NYSE: CAL), and Lufthansa German Airlines.

Source: Company press release.

Alipay Knocks Out Paypal as World's Largest eCommerce Payment Platform

Alipay Punches in as #1 Contender for First Time...


Editor's Note:  Could not resist using the picture on the right.  The first thing that came to mind when I read the Alipay article below was Ali "delisting" Liston as champion. Speaking of List-on PayPal is now List-ed as #2 as Alipay registered it's 200 millionth user.  (PayPal had 180 million at last count)

No worries PayPal...China is kicking our butt in everything, internet users, video games, etc. so I would take it with a grain of (smelling) salt. 

Here's the story:

From China Tech News

Chinese online payment platform Alipay has announced that the company has gained over 200 million users, exceeding the world's largest e-commerce payment platform Paypal.

According to news on Sohu.com, at the end of August 2008, the number of Alipay users reached 100 million. It took five years for Alipay to accumulate the 100 million users since it first appeared on Taobao.com in October 2003. During the past ten months, the number of Alipay's users further increased from 100 million to 200 million.

Prior to this, the world's largest third-party payment platform PayPal said it had about 180 million users in 190 countries and regions around the world. With the 200 million users, Alipay exceeds PayPal for the first time to become the world's largest third-party online payment platform by user scale, and its users are mainly from the Chinese market.

Shao Xiaofeng, president of Alipay, told local media that though Alipay's current trading value is still lower than that of Paypal, the company is expected to exceed the latter within three years.

Alipay's rapid development has close relationship with the fast growth of the number of Chinese netizens and the development of the Internet economy of the country. Statistics released by China Internet Network Information Center show that by May 2009, China had 320 million netizens and about 62.5% of these netizens are users of Alipay. In addition, the number of Chinese netizens is expected to reach over 600 million in the next two years.





Reblog this post [with Zemanta]

eBillMe Introduces CashBack Loyalty Program

First Rewards Program for Online Cash Checkout Announced by eBillme

Online shoppers who pay using eBillme will now receive cash back for every purchase
This is truly a landmark offering for online cash payments


Rye Brook, NY (PRWEB) July 9, 2009 --Cash back rewards, a loyalty program traditionally associated with expensive credit cards, has now entered the cash world.

Starting today, eBillme(TM), the payment option that enables consumers and small businesses to shop debt free and pay securely with cash, will give consumers 1% cash back for every purchase made using the cash checkout option. All consumers are eligible for the eBillme Rewards Program.

"This is truly a landmark offering for online cash payments," says Marwan Forzley, President and CEO of eBillme. "More consumers are shifting away from credit and making better financial decisions. We want to reward shoppers who pay with cash by offering the perks of shopping online with a credit card but without the interest fees and debt. Not only does eBillme offer a higher level of protection and more safeguards than a credit card with our buyer protection program, but now, every eBillme purchase will earn consumers cash rewards. There could not be a better time for consumers to try secure cash checkout with eBillme."

In order to qualify, online shoppers select eBillme for checkout at one of over 800 online merchant sites offering the credit card alternative payment option. Consumers can then sign-up for eBillme's cash back rewards and immediately start earning 1% cash back for every order. Once $10 in rewards has been earned, the cash can be redeemed on eBillme merchant sites, or shoppers may choose to continue earning before redeeming.

eBillme is the most secure way to pay online. When shoppers choose the option at checkout, their order is confirmed with an eBill sent to their e-mail address. Consumers simply pay the eBill through their online checking or savings account - the same way they pay utilities, loans, insurance, and other bills. The transaction occurs securely, bank to bank, with no personal or financial information required or transmitted over the Internet. And with buyer protection features including a satisfaction guarantee, best price guarantee, in-transit protection, and fraud protection, consumers can shop with confidence knowing their eBillme transaction is guaranteed and protected.

ABOUT eBillme
eBillme(TM) is the only online payment solution that extends the convenience of online banking to the merchant's checkout process. The service enhances security for online shoppers, and enables merchants to increase sales while reducing transaction costs. No financial data is exposed and the payment transaction is securely transferred from the customer's bank to the retailer's bank. Consumers can shop online, by catalog or through call centers, and pay for their purchases at their bank, credit union, or bill pay portal using the security and convenience of online banking. For more information, please visit eBillme.com or eBillme's Online Debt-Free Shopping Mall, ShopDebtFree.com.

Links

eBillme Website: eBillme.com
eBillme Blog: blog.ebillme.com
Reblog this post [with Zemanta]

Want to Read Something Scary? DDoS Attacks from North Korea?

Report: North Korea May Be Behind DDOS Attacks On U.S., Korean Government Sites
By Tim Wilson | DarkReading

Supporters of North Korea may be behind a series of denial-of-service attacks that have crippled U.S. and South Korean government Websites during the past five days, a news report says.

According to an Associated Press report, an unnamed South Korean lawmaker's aide stated that intelligence agencies believe North Korean sympathizers are behind the distributed denial-of-service attacks, which overwhelmed at least a dozen U.S. government sites and 11 South Korean sites, including the U.S. White House and South Korea's Blue House.

The National Intelligence Service -- South Korea's main spy agency -- told AP it couldn't immediately confirm the report.

Other news reports say the attacks also targeted nongovernment sites, including the New York Stock Exchange, the Nasdaq stock market, and The Washington Post.




, , , ,

Study: Encryption Reduces Risk of Data Breach

Encryption reduces risk of data breach: study - Computer Business Review : News
Well here's a surprising insight.  A new study from the Ponemon Institute found that...are you ready?  "Encryption reduces risk of data breach"  I guess the next study should be whether or not it's safer to type or swipe.  Because swiping your card means the data is encrypted.  I can save them the cost of performing the study.  Swiping Reduces the Risk of Cardholder Data Being Breached!

Published:08-July-2009  By Kevin White

Enterprise encryption technology not fully exploited


Encryption does help reduce the likelihood of an enterprise data loss or data breach incident latest research has confirmed, but organizations are still not doing as much as they could with the technology.

In a study carried out by the reputable Ponemon Institute for PGP Corp, a third of those companies reporting no data loss incident in the last year claimed to have had instigated an enterprise-wide encryption policy.

In contrast, organizations experiencing the highest number of data loss incidents were found to be the least likely to have introduced a consistently enforced, company-wide strategy governing the use of data encryption technologies.

Of firms reporting more than five loss incidents, none had any kind of encryption strategy in place.

The study found that 57% of UK businesses are now using some type of encryption solution in order to protect sensitive information, with around 36% having introduced a partial strategy to protect certain applications, departmental activities or data such as credit card numbers.

“Encryption is most widely used to protect the data held on file servers, Virtual Private Networks (VPN) and databases. VOIP and mainframe encryption are the least deployed applications,” the report noted.

Despite the widespread use of smartphones, only 34% of the study partcipants said they believe it is only sometimes necessary to encrypt the confidential data held on portable devices. Some 13% think it completely unimportant.

As many as 615 IT security professionals at enterprises and public sector organisations were polled for the study, which found that 70% of UK organisations have been hit by at least one data breach incident within the last year. That number is up from 60% in the previous year.

To Read the Full Report Click Here  (requires registration)

In its 2009 Annual Study: UK Enterprise Encryption Trends, Ponemon notes that the public sector experienced the highest number of data loss incidents in the last year.

Phillip Dunkelberger, CEO of PGP said, “This study underlines the critical importance of implementing an encryption strategy that encompasses all aspects of an organisation’s data, not to just meet privacy or data security regulations but to also protect against brand damage and loss of customers."

Yesterday, Kent-based Jubilee Managing Agency Ltd became the latest company to be found in breach of the Data Protection Act, after the insurance company had to report the loss of an unencrypted disk containing the personal details of around 2,100 individual UK policyholders.

It has been instructed by the ICO to sign a 'formal undertaking' to enhance its data protection methods.

The Ponemon Institute has estimated the average UK data breach costs a total of £1.7 million - said to be the equivalent of £60 for every record compromised.




, ,

Suicide Linked to TJX Probe - Hackers 11

Former Teen Hacker’s Suicide Linked to TJX Probe



A Miami man who achieved fame as a teenager for hacking NASA and the Pentagon took his own life last year after Secret Service agents accused him of being part of the conspiracy responsible for the largest identity theft in U.S. history, his family says.

Jonathan James, 24, was found dead of a self-inflicted gunshot wound in his home on May 18, 2008, less than two weeks after agents raided his house in connection with a hacking ring that penetrated TJX, DSW and OfficeMax, among others. In a five page suicide note, James wrote that he was innocent, but was certain federal officials would make him a scapegoat.

“I have no faith in the ‘justice’ system,” he wrote. ” Perhaps my actions today, and this letter, will send a stronger message to the public. Either way, I have lost control over this situation, and this is my only way to regain control.”

The note was provided to Wired.com this week by James’ father, Robert, who kept the details of his son’s death quiet for over a year because of the ongoing prosecutions over the retail hacks.

James apparently suffered from depression; agents executing the search warrant found another suicide note James had written years earlier, but did not seize his gun. The Secret Service declined to comment on the matter Wednesday, citing the continuing TJX prosecutions.

“Sometimes I thought he was pretty smart,” says his father. “Sometimes I thought, oh my God, I’ve raised an idiot. And the jury is still out.”

Continue Reading at Wired
Reblog this post [with Zemanta]

Guide to Internet Scams, Hacks and Hoaxes

As Internet scams increase in sophistication, Network Box advises users to be more alert, with the publication of a whitepaper regarding common hoaxes, hacks and Internet horrors.  The whitepaper looks at the different kind of common attacks, with examples of each, and simple ways for IT managers and employees alike to avoid falling victim to them.  Editor's Note:  As the graphic on the left depicts, people could avoid getting hit with these by exercising a little common sense. 

Hacks:
The ‘hacks’ section looks at attacks through application vulnerabilities and SQL attacks, and gives a number of examples of high profile recent hacks, including the attack on hosting company, Vaserv.com, which had more than 100,000 websites deleted from its systems.

Hoaxes:
The guide shows an example of the log in page of a hoax site (pretending to be Natwest) next to the real site, to show how sophisticated some of these fraudulent sites can be now. It advises users to look out for the padlock symbol, indicating the authenticity of the site; https, rather than http – always used by real sites for sending secure information over the Internet; and the real URL, as opposed to a bogus URL – commonly (and easily) overlooked by users.

The guide is available in PDF format here.






CFIB Urges Code of Conduct for Card Issuers, MasterCard's Response

Canadian Federation of Independent Business urges credit card issuers, banks to adopt a Code of Conduct

The Canadian Federation of Independent Business is calling on credit card companies and local banks to sign up to a Code of Conduct for small business.

The code includes ten practices which are meant to strengthen the collaboration between credit card companies, card processing companies and banks on the one hand and their small business customers on the other.

According to the proposed Code of Conduct, Credit card companies should not introduce a "percentage of sale" fee in case they become active on the debit card marketplace, premium cards should never be distributed without the request of customer, while merchants should be aware of the total fee associated with a card before accepting it. They also should have the possibility to exit a contract without penalty in case of modified contract terms.

The organization has had this initiative as "small firms across Canada are outraged with the dramatic rise in credit card merchant fees and the introduction of new premium cards by Visa, Mastercard and Canadian banks" according to Dan Kelly, the organization's senior vice-president of legislative affairs, cited by Yahoo! Finance.

Canadian Federation of Independent Business is an alliance of Canadian independent small and medium-sized businesses which has been giving small firms a voice in the public arena.
CNW Group | MASTERCARD CANADA | Statement from MasterCard Canada re: CFIB Proposal

Statement from MasterCard Canada re: CFIB Proposal

TORONTO, /CNW/ - MasterCard Canada agrees with the Canadian Federation of Independent Business that a non-regulated solution to small merchant concerns about credit and debit card acceptance is best.

MasterCard has already been in discussions with the CFIB and made proposals to address issues of concern and has requested and received details of the CFIB proposal today. MasterCard looks forward to continued productive discussions in upcoming meetings.

Canada has a dynamic and well-functioning payments system where merchants and consumers enjoy unparalleled access to numerous payment methods.  "Any consideration of changes to the system needs to look at therealistic impacts on consumers and their ability to make safe, secure and convenient purchases and merchants to conduct business effectively," said Kevin Stanton, President MasterCard Canada. "We applaud the CFIB's proposal as a good start toward reaching a commercial solution that addresses small merchant concerns without harming or disrupting a payments system that flawlessly facilitates over $260 billion in Canadian commerce each year. 

MasterCard continues to work with the retail sector towards practical, meaningful solutions that serve the best interests of both consumers and merchants."

For further information: Jennifer Reed, MasterCard Canada, (416) 365-6664, jennifer_reed@mastercard.com





Reblog this post [with Zemanta]

Wednesday, July 8, 2009

EV SSL Encryption Is Safe! "Yeah...Right!"

I posted many times that a web browser is not safe. "Especially" not safe for financial transactions. I've also posted that there was less of a risk that your cardholder data would be stolen if you "typed" your credit/debit card number in a box 2 years ago than there is today.  Tomorrow will see even more risk than today. 

That being the case, how well will we prepared for what "tomorrow" brings?

I stand firm, and I stand tall in my belief that a web browser WAS NOT/IS NOT designed for eCommerce.  Therefore financial transactions MUST be done outside the browser space.

 

Much to my chagrin,  some industry "experts" callously (in my opinion) disagree and argue that it is in fact safe to type credit/debit card numbers into a box at a merchant website. (after all, we all need convenience, right?)

I've even read where they try and back it up with statements such as:
  "Oh, if you go to a site with where it says: "https://, the "s" stands for "secure" and that means the web page you are on is "definitely" safe.

Two words: "Yeah...Right...." (See "https = httBS")


Or I've heard these "experts" quoted as saying
"Those "SSL certificates" are great, they definitely tell you that the web page you are visiting is protected by "secure socket layers" and that means for sure you are safe!

Two Words: "Yeah...Right..." (See
: "99% of SSL Secure Websites Are Not")

Then I've read where these "so-called experts" say
"We need websites to move over to the "more secure" gran-daddy of them all... EV SSL digital certficates!   A website that implements Extended Valuation SSL is even "safer than safe!"  It's the "safest!" 

Here's more on them "gushing" about the security of EV SSL...


Extended Validation (EV) SSL is considered by all to be more secure than SSL: Calls for widespread EV SSL implementation are on the rise as SSL threats increase. Two years after its rollout, the "more secure" Extended Validation
Secure Sockets Layer (EV SSL) digital certificate for authenticating Websites and securing Web sessions is used on more than 11,000 Websites worldwide."

"Calls for EV SSL adoption have intensified amid concerns of new man-in-the-middle (MITM) attacks targeting newly discovered weaknesses in SSL, namely the
MD5 encryption algorithm hack that allows the creation of forged CAX.509 digital certificates, and the MITM attack demonstrated at Black Hat DC that basically makes users think they are visiting a secure Website when they are not. "


Cool, EV SSL sounds great. So go ahead... if you see a website "protected" by EV SSL, then by all means, listen to the experts, because, after all...they know best. Their "analysis" should give you confidence to feel free to type your credit/debit card numbers into EV SSL protected websites. No worries!   
Wow, yeah, sounds great, that's the ticket! When will all the websites move to EV SSL, because EV SSL "really guarantees" a safe environment!   But before they do, I have just...

Two Words: (besides "Caveat Emptor")
"Yeah, Right!"  (see below)

Researchers to demonstrate new EV SSL man-in-the-middle hacks


Twosecurity researchers' assault on Extended Validation (EV) SSLcertificates will continue next month at the Black Hat Briefings.Alexander Sotirov and Mike Zusman, building on work presented in Marchat the CanSecWest 2009 security conference, are expected to demonstratenew attacks, including an offline hack that poisons a site protected byan EV certificate

EV SSL certificates are supposed  to offer an extra layer ofprotection for websites.

Sites protected with EV SSL encryption display the familiar green icon in the URL address bar. EV SSL certificates are more expensive than traditional SSL certificates(often by hundreds of dollars).

They also require substantial vetting of the buyer up front, including, in most instances, articles of incorporation, a verifiable physical location, a designated corporate agent who must be validated, and proof the organization is not prohibited by some sort of government embargo from doing business with a certificate authority, among other requirements.

While EV SSL certificates can guarantee to a degree that awebsite visitor has indeed landed on a legitimate website, they cannot guarantee the security of the elements on the site. Sotirov and Zusman have proved this conclusively.

Their research demonstrates that EVSSL-protected sites, once thought invulnerable to man-in-the-middle attacks, are indeed as susceptible to them as non-EV sites, largely because of a flaw in Web browsers' security models..

The flaws are universal,
Sotirov said.

Editor's Note: Wait a minute, did they say "once thought invulnerable" followed by "susceptible" and then admitted there is a universal "flaw in Web Browser's security models?" 

Does that mean it's NOT okay to Enter/Type your credit/debit card numbers into a browser?  No matter what?  Even if they say it's safe?   Wow...who would of imagined? 
Next thing ya know, there will be a report that analyzes alternative payments and concludes it's safe to "mouse click" PIN numbers into a web browser. Yeah...Right!


Continue Reading the EV SSL Man in the Middle Attack Susceptibility Article











Reblog this post [with Zemanta]

Analysts Say Google OS Threat to Microsoft

Analysts: Google has muscle for long-term battle with Microsoft Windows

Upcoming Chrome OS is latest weapon in Google's ongoing 'guerilla war' with Microsoft

Computerworld - As Google Inc. acknowledges that its engineers are working on an operating system for netbooks and PCs, analysts say it's the company in the best position to take on Microsoft Corp. and its vaunted Windows software.



In a blog item posted Tuesday night, Sundar Pichai, vice president of product management at Google, said the company is working to deliver the new Google Chrome OS in the second half of 2010. Noting that Google's engineers are "rethinking what operating systems should be," Pichai said the Chrome OS will be lightweight and open source.



It's a bold move for any company to tread in a market that has so long been stubbornly held in Microsoft's grip. Others have tried and failed to make a noticeable dent in Microsoft's worldwide share of the operating systems market. But Google, which would be considered the Goliath in most industry duels, has the financial muscle, the engineering might and the industry clout to actually put up a fight with an industry powerhouse like Microsoft, analysts said.



"I think they are fighting a guerilla war with Microsoft, with the goal of chipping away and gaining more market share over time. And this is well within their capabilities," said Dan Olds, principal analyst with The Gabriel Consulting Group. "It's also important to remember that Google doesn't need an OS to support its revenue stream. They have lots and lots of revenue from their advertising bread and butter. That means they have staying power and that's critically important in this market. If anyone is going to take on Microsoft successfully, Google has the resources, engineering, and time to do it."



Continue Reading at ComputerWorld Operating Systems




By the way, doesn't the Chrome Logo look the the Simon Game? I wonder if "Simon Says" so?



Apparently, I'm not alone as somebody put together the Chrome/Simon (they called it Chromon)



Here it is:



It Might Pay Again to Discover


Discover Financial Services Announces Pricing of Public Offering of Common Stock

  • Press Release
  • Source: Discover Financial Services
RIVERWOODS, Ill.--(BUSINESS WIRE)--Discover Financial Services (NYSE:DFS - News) today announced the pricing of a public offering of 54,054,055 shares of its common stock at a public offering price of $9.25 per share. The company has granted the underwriters a 30-day option to purchase up to an additional 8,108,108 shares to cover over-allotments, if any.

Discover will receive estimated net proceeds from the offering of approximately $480.3 million, or approximately $552.4 million if the underwriters choose to exercise the over-allotment option in full. The offering is expected to close on July 13, 2009. The net proceeds from the offering will be used for general corporate purposes, which may include capital contributions to the company’s subsidiary, Discover Bank, possible investments in the company’s businesses, or possible repurchase of fixed rate cumulative perpetual preferred stock issued by Discover to the U.S. Treasury under its Capital Purchase Program (subject to regulatory approval).

J.P. Morgan Securities Inc. is acting as the sole book-running manager for the common stock offering. A copy of the prospectus supplement and prospectus relating to these securities may be obtained, when available, by contacting J.P. Morgan Securities Inc., Attn: Prospectus Department, 4 Chase Metrotech Center, CS Level, Brooklyn, NY 11245 or by calling 1-718-242-8002

Meanwhile, here's "Barron's Take" on the offering:  It Will Pay Again to Discover


Reblog this post [with Zemanta]

United Airlines on the Brink - Need Help from Processors

Cash squeeze may put United Airlines in a bind -- chicagotribune.com
The global recession has caused airline ticket sales to plunge deeper than anyone -- carriers or analysts -- anticipated.

Rather than banking cash from peak-season flying this summer as they normally do, United and its peers are paying a king's ransom to borrow money to get them through the winter months, when demand for air travel usually chills.

But after leveraging everything from frequent-flier miles to spare jet engines, United is running low on assets that it can use as collateral for debt or sell to raise cash. That limits the Chicago carrier's options as it faces requirements by its credit card processors to keep unrestricted cash near the present level of $2.5 billion, analysts said.

The prospect of another lean winter for U.S. carriers could spur more consolidation, analysts said, with United and Houston-based Continental Airlines as the likeliest carriers to head back into merger negotiations.

Cash is tight across the airline industry, and Ft. Worth-based American Airlines and Tempe, Ariz.-based US Airways could also face liquidity crises if conditions deteriorate, analysts warned. American faces steep debt payments over the next year and pressure from a credit card processor. US Airways has little debt but thin cash reserves.

"The whole industry is looking at an erosion of liquidity and cash flow," said Bill Warlick, senior director and lead airline analyst with Fitch Ratings. "It's a very grim revenue picture."

The need for action is especially pressing for United. If its cash holdings decline, two major credit card processors, JPMorgan Chase & Co. and American Express, could require it to set aside hundreds of millions of dollars to safeguard advance bookings in case the company folds.

Under an agreement that took effect March 1, American Express requires United to pony up money on a sliding scale if its unrestricted cash falls below $2.4 billion. The lower United's cash, the greater the amount it must set aside. United may also pledge aircraft, real estate and other assets as collateral.

As of January 2010, Chase will require United to hold at least $2.5 billion, a provision that would have cost United $134 million had it been effective in May. If United's cash falls to $1 billion, Chase would require it to set aside half of its monthly credit card charges, according to a Securities and Exchange Commission filing.

While credit card firms pushed Frontier Airlines into bankruptcy last year, (See: Mayday! Mayday! Mayday! ) analysts think it very unlikely that they'd pursue similar drastic measures with United unless operations deteriorate to the point where the airline isn't viable.

Chase, in particular, has a deep partnership with United that gives it a vested interest in keeping the carrier aloft. Chase's Mileage Plus affinity card is one of its most popular credit cards, while the bank last year gave United $600 million for the advance purchase of frequent-flier miles. A Chase spokesman declined to comment.

"When you have big boys at the table like credit card companies, and a big airline like United, nobody is going to throw anybody into bankruptcy," King said. "They're going to find a way around it, unless there's no way around it."

Continue Reading at the Chicago Tribune





, , , , , , ,

Reblog this post [with Zemanta]

MoneyGram Signs Money Transfer Deal for ATM's with Saudi Bank


Forbes: MoneyGram International Inc. has signed a deal with National Commercial Bank, the largest bank in the Middle East, to offer a money transfer service at the bank's 1,400 ATM locations in Saudi Arabia. Financial terms were not disclosed.

Click to continue

UATP Announces VP Global Sales; Focus on Growing UATP Programs

UATP Announces Vice President, Global Sales; Focus on New Issuers and Growing UATP Programs | SYS-CON INDIA
WASHINGTON, July /PRNewswire/ -- Universal Air Travel Plan, Inc. (UATP) has a new Vice President, Global Sales, K. David Holmes III who has been promoted from Regional Commercial Director, The Americas, UATP, effective immediately. Holmes will focus on the recruitment of new airline Issuers and Merchants, growing existing UATP Issuer programs and expanding UATP's partner program with non-traditional forms of payment companies.

"Dave has extensive knowledge of travel payment as it interfaces with the airline industry and a successful sales record finding solutions for carriers," said Ralph Kaiser, president and CEO, UATP. "With over eight years at UATP, Dave is well positioned to continue his success as Vice President and grow UATP's global market share. His knowledge will continue to drive UATP into new channels and capitalize on expanding UATP's successful partner program, connecting airlines to non-traditional forms of payment."

UATP currently has eight payment partners including: Bill Me Later, HomeATM, Moneta, PayPal, Paysafecard, Stored Value Solutions, Acculynk and Ukash. For more information contact, sales@uatp.com

Contact K. David Holmes, III, Vice President, Global Sales at dholmes@uatp.com

About UATP

UATP accounts are accepted as a form of payment for corporate business travel by Amtrak, airlines and travel agencies worldwide. UATP accounts are issued by: Air New Zealand (ANZFF.PK), American Airlines (NYSE: AMR), Austrian Airlines (AUALF.PK), Continental Airlines (NYSE: CAL), Delta Air Lines (NYSE: DAL), Japan Airlines (JALSY.PK), Northwest Airlines, Qantas Airways, Ltd. (QUBSF.PK), United Airlines (Nasdaq: UAUA), and US Airways (NYSE: LCC). AirPlus International issues the UATP-based Company Account for: British Airways (LSE: BAY.L), Continental Airlines (NYSE: CAL), and Lufthansa German Airlines.




, ,

Unpredicatable Gas Prices Push Shoppers Online

Chart of the Week: Unpredictable Gas Prices Push Shoppers Online


Consumers are comparing products online and doingmore shopping at online retailers in an apparent concern about risingand unpredictable gasoline prices.

Internet marketing trend and research analysis firm eMarketerreported that some 14 percent of U.S. consumers were doing moreshopping online and that 32 percent of U.S. consumers had done or woulddo more online price comparison as a result of fluctuating gas prices.The eMarketer analysis was based on a June 2009 survey that theNational Retail Federation had commissioned to measure consumerattitudes ahead of the Fourth of July holiday.

Respondents to that survey generally planned to take fewer shoppingtrips (42.9 percent), shop sales more often (42.6 percent), and shopcloser to home (40.4 percent) when the made purchases from traditionalbrick-and-mortar retailers.




Reblog this post [with Zemanta]

CashStar Partners with Coupons.com Offers eGift Cards

CashStar Throws Its Gift Cards on the E-tail Table

It seemed like a logical leap: If you already provide shoppers withcoupons online, what's to stop you from offering them an online sourcefor e-gift cards? So the founders of online gift card company CashStarpooled resources with online shopping coupon mogul Coupons Inc. tocreate an outlet for merchants to offer more services than areavailable from plastic gift cards hanging on pegs in stores. ThoughCashStar's founders quickly were met with lots of encouragement, theyhad few takers in their efforts to sign up merchants to try out thee-gift card experience.

ID90 Technologies Partners with Moneta to Expand Payment Options


ID90T Partners with Moneta to Expand Payment Options – 50,000 Airline Employees May Choose Moneta for Online Travel Payments

ID90T, part of the ID90 Group, has partnered with Moneta Corporation to offer Moneta online payments to its fast-growing base of 50,000 airline employee users. Moneta, a growing alternative payment choice for online transactions, offers consumers and merchants a convenient, safe and affordable method for Internet ACH debit transactions directly from a consumer’s bank deposit account. ID90T provides online and Interline e-ticketing solutions for airline employee travel via its advanced web based Interline Fare Calculator® (IFC), the end-user interface to its Interline Ticketing Platform. ID90T facilitates immediate cost savings and unprecedented conveniences for airlines and their employees, while protecting and enhancing the travel privileges currently enjoyed by each airline employee.

“By partnering with Moneta, we realize significant savings on interchange while offering airline employees a safe, convenient way to pay for discounted travel,” said Tristan Schukraft, Managing Director of ID90T. “We are able to pass some of this cost savings along to airline employees as discounts for Moneta-based payments during the initial rollout period. During beta testing, we discovered that customers paying with Moneta had a higher average ticket spend, suggesting that this payment method was preferred over credit card transactions. We are very excited about the impact of the Moneta partnership to our bottom line.”

The ID90T partnership will rapidly expand Moneta’s existing user base of 70,000 enrolled members as the two companies pursue joint marketing programs to the 50,000 airline employees ID90T currently serves.

“The ID90T partnership demonstrates the opportunity for Moneta as a preferred alternative payment method for online retailers,” said Guido Sacchi, CEO of Moneta. “Travel providers and leading merchants like ID90T face many challenges in keeping costs low. We are committed to working with online retailers and travel providers to provide the lowest cost payment methods available.”

About Moneta Corporation

Moneta Corporation is a leading payments company offering secure, convenient methods for consumers to pay online merchants directly from their checking or money market accounts. Moneta partners with online merchants to accept and process payments, while providing financial institutions branding opportunities during the transaction process. Moneta’s rapidly growing partner network enables online retailers and travel providers to attract valuable customers with a preference for paying directly from their well-established bank accounts. Moneta is a privately-held company headquartered in Atlanta, Ga. For more information visit www.monetacorp.com

About ID90T

ID90 TECHNOLOGIES, LLC (ID90T), provides innovative online and Interline e-ticketing and NIET solutions for airline employee travel via its advanced web based Interline Fare Calculator ® (IFC). ID90T facilitates immediate cost savings and unprecedented conveniences for airlines and their employees, helping airlines become compliant with IATA’s 100% e-ticketing mandate. Visit www.ID90T.com.

Author Information

Carol Kleywegt
Moneta Corporation
 
Reblog this post [with Zemanta]

Microsoft Death Blow Plot: Google Operating System

Google Plans to Launch Operating System for PCs
 - WSJ.com


Google Inc. is preparing to launch an operating system for personal computers, a direct assault on the turf of software giant Microsoft Corp., which has long dominated the market for software that runs PC applications.

The Silicon Valley Internet giant announced the new move in a blog post late Tuesday night. It said the software, which will initially target low-end portable PCs called netbooks, would be based on its Chrome Web browser and available to consumers in the second-half of 2010.

The post--by Google's Sundar Pichai, vice president of product management, and Linus Upson, its engineering director -- said the ...

Continue Reading at Wall Street Journal
(subscription required) or here's a link to 1130 Related Articles

Here's one of the better ones from the Baltimore Sun:

And now, faithful readers, we receive news that Google is planning its own operating system, in a direct challenge to Microsoft and its Windows hegemony. The New York Times and tech-news site Ars Technica, broke the news on their respective websites. Inquiries from the press forced Google to disclose the news a day earlier, last night, on their official blog, which gives a light rundown on why they're doing what they're doing. In a nutshell, Google is looking to expand its Chrome web browser as an operating system for the cheap netbooks that have proliferated in the marketplace. Some initially believed we'd see a version of Android, Google's mobile computing platform, transmogrified into some type of operating system. But Google went with the Chrome platform instead. In the company's own words:

Speed, simplicity and security are the key aspects of Google Chrome OS. We're designing the OS to be fast and lightweight, to start up and get you onto the web in a few seconds. The user interface is minimal to stay out of your way, and most of the user experience takes place on the web. And as we did for the Google Chrome browser, we are going back to the basics and completely redesigning the underlying security architecture of the OS so that users don't have to deal with viruses, malware and security updates. It should just work.
So what does this all really mean? From a competitive standpoint, some folks, like the guys at TechCrunch, see it as Google dropping "a nuclear bomb" on Microsoft, which dominates the personal computer OS market.

Continue Reading at Baltimore Sun









Disqus for ePayment News