Tuesday, January 6, 2009

Barclay Up the Wrong Tree?

From what I've read the jurys still out on whether NFC is secure.  WEP wasn't.  We'll see. Barclayscard is smart...they're playing both sides, everything remains the same with their IC debit cards, except for the addition of embedding an NFC chip.  If Near Field Communications is proven secure by then, Barclay's will be ready by 2011.  Will NFC be?

Barclays Goes Contactless on Debit Cards

Barclays customers will soon be able to pay their way with the wave of a card as the bank is set to be the first in the UK to roll-out contactless VISA debit cards to its customers.

From March, most Barclays debit cards that are issued or reissued will have contactless technology built in as standard. More than three million customers are expected to be using contactless debit cards by the end of the year.

The cards use contactless technology to enable transactions of £10 or less to be paid for by holding the card up to a special reader, without the need to enter a PIN or insert the card into a terminal. The transaction is debited directly from the customer's current account in the same way that a standard card transaction is. The cards will still have chip and PIN which will be used for purchases and for ATM transactions. Periodically the card will prompt for the PIN to be entered to verify the customer's identity.

Mark Parsons, Managing Director of Current Accounts for Barclays, said: "Barclays has long been a pioneer in banking. We were the first to launch the debit card in 1987 and now we are the first to give our customers the latest incarnation ­- the contactless debit card. This gives people a new way to pay for things that is quick, secure and convenient and we are confident that it is going to be really popular with customers."

Over 8000 retailers already accept contactless payments with more installing the technology every week. Barclaycard was the first to introduce contactless technology on credit cards in the UK in September 2007 with the launch of Barclaycard OnePulse, the three in one oyster, credit and contactless card.

For more information on Barclays contactless debit cards go to barclays.co.uk/contactless. To search for outlets which accept contactless payments visit the Visa website at visapaywave.co.uk

Source: Press Release


Reblog this post [with Zemanta]

E-Commerce Not Safe in Web Browser Followup

SSL Crisis Averted -- For Now - DarkReading
Last Friday,  I posted about a "serious vulnerability" within ALL web browsers and " that a "key piece of of Internet technology that banks, e-commerce sites,  and financial institutions rely on to keep transactions safe suffers from a serious security vulnerability.

(see my post "
E-Commerce and Browsers Don't Mix)

Yesterday, Dark Reading said the SSL crisis has been "possibly" (there's no way of knowing)  averted...for now anyway.  (as a die-hard Cub fan, I cannot resist the temptation to add the famous "Wait til next year" mantra. Wait...since last week, this week IS next year...)

Anyway, here's a portion of that article.  To read it in it's entirety, click the link at the bottom of this post...


SSL Crisis Averted -- For Now

VeriSign quickly fixes vulnerable SSL digital certificates at risk of newly revealed hack, but experts say there's no way to know for sure if phony certificates exist from previous attacks 

Jan 05, 2009 | 02:55 PM
By Kelly Jackson Higgins - DarkReading

It took VeriSign only four hours to close a hole that had left customers of some of its digital certificates vulnerable to a new attack revealed by researchers just before the new year. White-hat hackers exploited a known weakness in the algorithm in some digital certificates that allowed them to impersonate secure Websites.

While the attack was considered deadly due to its transparency and ability to mimic a secure Website, the good news is that it was isolated to only a minority of digital certificates that use the older and less secure MD5 algorithm. According to Netcraft, about 15 percent of all digital certificates in December were signed with MD5.  (Editor's Note:  The bad news is that 15 percent of all digital certificates were signed with MD5)

The researchers demonstrated at the 25th Chaos Communication Congress in Berlin last week how they were able to purchase a legitimate certificate from RapidSSL, which is part of VeriSign, and then forge a phony trusted certificate authority.

Story continued at Dark Reading
  (but before you go...here's an additional snippet)

End of (threat) story? Not exactly. Although researcher Alexander Sotirov admits it's unlikely the attack has been performed before, he and other researchers say there's still no way to know for sure: "Even though it's unlikely, the theory behind our attack has been published since 2007, and it is possible that somebody else has been able to implement it. In this case, any one of the certificates issued by RapidSSL since 2007 could have been malicious, but there is no way to detect which one," he says.





Reblog this post [with Zemanta]

Monday, January 5, 2009

Global Smart Card Outlook


Smart card applications make transactions safer

New Dehli, India, Jan. 05, 2009 -- RNCOS in its new research report "Global Smart Card Market Outlook" says that the financial/retail sector is expected to continue to represent the largest application area for the global smart card industry. And the shipment of smart cards in financial/retail/loyalty is estimated to increase by 15% in the current year.

According to the report, the rising applications of smart cards in diverse sectors are due to the high security they provide. Consequently, smart cards are being widely used in financial applications such as payment cards and ATM or banking cards.

With robust growth in the global financial market, particularly in the Asia-Pacific region, the opportunities for the global smart card industry have increased tremendously, says the report. Rising number of fraudulent cases has highlighted the risks associated with using magnetic strip cards for transactions. Moreover, the growth opportunities for smart cards have further increased by the decision taken by Visa and MasterCard to use Europay, MasterCard and Visa (EMV) specification worldwide.

Besides, the banking sector represents an area of tremendous opportunities for smart card industry because its functionalities, such as value-added services and enhanced consumer benefits, have made smart card viable and the safest option for end users. Thus, the demand for smart cards is expected to grow at an unprecedented rate.

"Global Smart Card Market Outlook" provides in-depth and comprehensive information on the growing marketplace for smart cards at the global and national level. It contains thorough analysis along with statistical data on the present market trends, emerging markets and future growth prospects for the smart card industry.

Apart from this, the report contains statistical information on value, shipments and applications of smart cards at the global and national level that helps clients to identify critical opportunities for growth of the smart card industry. It helps clients to evaluate key factors driving growth in the industry and future avenues. The study also provides forecast on the number of mobile subscribers and smart card shipment by region.

Source: Company press release

Reblog this post [with Zemanta]

Mob Implicated in Credit Card Scheme

Armenian Mob Imiplicated (sic) in Credit Card Scheme - beaconcast.com
Don't know if they spelled it wrong or if because they were illegal immigrants, they added the "Imi in plicated", but nontheless, here's a snippet from Beaconcast on an Armenian Mob Ring in Alpharetta, GA.

It all started around late August when four alleged Russian gang members of Armenian descent, all of them likely near the bottom of the crime mob totem pole, descended on Alpharetta from Glendale, Ca. to set up crime operations. All four entered the country illegally. No one knows exactly how the four made their way into the U.S. But like the millions of other foreigners who are in America illegally, they did...
Once established, the suspects engineered an elaborate credit card fraud scheme they perpetrated on unsuspecting late night BP customers. This involved changing out the electronic credit card swipe machine when no one was around and replacing the BP supplied one with their own version by simply unplugging BP’s and plugging in their counterfeit replica. This bogus machine would do everything the BP device did, like send the funds to the BP clearing bank, print out a BP receipt and balance BP’s cash register. What it also did was capture the name of the card user, the credit card number and electronically encode the metallic stripping.

Each time a customer would buy something in the store with a credit or debit card, Khalatyan caught the information in his fraudulent machine. The suspect would ask the customer if it was a debit. If so, the user would then enter his or her pin number in the device, and Khalatyan would capture that too by using a small hidden camera...

continue reading at Beaconcast

Reblog this post [with Zemanta]

Macy's Multiple Debits = Multiple Questions?


Evan Shuman (and Fred J. Aun) wrote an interesting story regarding the recent "multiple debits" charged to 8000 Macy's debit card customers.  Like the recent RBS breach, (see: Mother of All Hacks Coming?) it was "quietly" announced (purposefully?) during the busy holiday season when many reporters are on holiday.  Unlike the RBS breach, and to Macy's credit...er...debit, they didn't wait 2 months  (see below) to announce it.  Here's the story from StorefrontBackTalk.com 

Questions Surround Some 8,000 Macy's Debit Cards That Got Charged Repeatedly
When Macy's distributed a very cryptic statement on Dec. 23 that "some" debit card customers had been charged had seen "multiple" debits for single transactions, it went virtually unnoticed.

Much of that had to do with the very quiet way Macy's shared that knowledge, by E-mailing it to a handful of reporters, many of whom were on vacation. Unlike the typical way Macy's—and others—make statements, there was no statement issued to any of the major news release wires nor was it was placed on their own news release page. It was ideally handled if someone wanted to say that they "announced" something but have no one know about it. 

Continue Reading at StorefrontBackTalk


In a related story, BTN came down on RBS for waiting two months before announcing that 1.5 million of it's customers were breached.
"The institution discovered the breach shortly after Halloween, yet apparently waited almost two months—an eternity in ID theft time—before making a public announcement.  That has some people scratching their heads. “Two months? That’s enough time for someone to go out and apply for a loan under your name, to get a credit card, to mess up your credit. The way to build trust in relationships is with communication,” says Jacob Jegher, an analyst at Celent."

Reblog this post [with Zemanta]

Skim Through this Card Skimming Article

In addition to the fact that E-Commerce is outpacing bricks and mortar in several sectors, (see previous story) there is a mounting problem with bricks and mortar POS devices.  They've been tampered with, they've had skimmers attached to them, or they've been replaced with clones and then taken back filled with credit/debit card numbers. 

I am adamant in my beliefs that the safest transaction is online debit for online shopping.  You swipe your own device outside the browser space and because you're left to your own devices, they are not in danger of being tampered with.  So swipe your own card, with your own device...in your own home...and your card information will remain your own...

Here's a story about a Buffalo man, who is to be sentenced shortly.  I'm curious to see how much time he'll do.

According to today's Buffalo News, a local skimmer was convicted and is scheduled to be sentenced 1/22.  It'll be interesting to see how long this skimmer will be a "jail bird". 

If you'd like to read the "entire" article, click the headline below.  Otherwise you can "skim" through Dan Herbecks report below: 

Skimmers prey on credit card users


By Dan Herbeck
NEWS STAFF REPORTER

Skimmer fraud is a growing international problem, according to police, and it all starts with a process that is so routine that it happens millions of times every single day at businesses all over the world.

A customer walks into a store or restaurant, makes a purchase and hands a credit card to a cashier. The cashier then swipes the card through an electronic device that reads the information on the card.

Usually the purchase is approved, but sometimes a dishonest cashier also swipes the card through a small, illegal, hand-held device called a skimmer.

This device — no bigger than a pager — steals information from the card and activates a form of identity theft that causes headaches for consumers and, in recent years, has cost credit card companies billions of dollars.

Fraud experts say these scams occur every day — often on a much bigger scale — in businesses all over the world. Some of the skimming operations are run by organized crime.

“Credit card scams and shady waiters can easily turn customers into identity theft victims,” said Dawn Handschuh of CreditFYI.com, an online educational forum on personal finance issues.

“Credit card skimming occurs when someone swipes the magnetic strip on a customer’s credit card to get the account number with a device small enough to hide in a pocket or hand. It takes about two seconds.”

Skimmers usually cost a few hundred dollars and can be purchased over the Internet, police said. Some Web sites even offer information on how to make such a device.

In Europe, a growing number of restaurants are fighting this form of fraud by using small portable devices that allow consumers to pay their bill at their table. A limited number of restaurants in the United States have begun using them.

“Industry and law enforcement sources estimate credit card fraud losses exceed a billion dollars annually. And it’s no wonder why, when thousands of skimmed credit card numbers can be sold and e-mailed anywhere around the globe in seconds,” the Consumer Affairs office of the State of Georgia said in a recent advisory on skimming.


Skimming affects every consumer because fraudulent credit transactions are sometimes charged back to the merchant who accepted the card. The merchant ultimately winds up raising prices to make up for the losses, the Georgia office said.

Authorities also warn about a second form of skimming that does not require the participation of dishonest cashiers. Some skimming rings have learned how to install skimming devices on automated teller machines, gasoline pumps and other legitimate devices that read credit cards or banking cards.

According to federal prosecutors in Orange County, Calif., a man pleaded guilty in 2007 after agents learned that he put illegal skimming devices on gas pumps at several gas stations in the region.  The man admitted that he obtained credit card and debit card information from 90 customers and then used the information to steal $186,000 from his victims’ accounts.


Reblog this post [with Zemanta]

E-Commerce Outperforms Bricks-and-Mortar Across Many Sectors


"eCommerce continues to grow says "JPMorgan Analyst Imran Khan  as he pointed out in a research note that while U.S. retail sales grew just 2 percent in the first nine months of 2008, eCommerce grew by 8 percent.

Meanwhile...comScore, a leader in measuring the digital world, today released online spending data by category for the online holiday shopping season, which showed that
trends in online spending outperformed offline in several key product categories. The study compared comScore e-commerce data to overall (online and offline) consumer spending data published by MasterCard Advisors' SpendingPulse Unit for the period of Nov. 1 -- Dec. 24 vs. year ago.

"For an online holiday shopping season that recorded a disappointing 3-percent decline in sales, a positive note is that e-commerce trends outperformed overall consumer spending in several product categories, which is to say that e-commerce continued to capture an increasing share of consumers' wallet," said comScore chairman Gian Fulgoni.

"Clearly, 2008 was an extremely challenging time for many retailers, and the beginning of 2009 may not be much better. But when the consumer economy eventually does rebound, e-commerce is poised to benefit from its emergence as an important consumer sales channel."


Wealthiest Households Spent More Online this Holiday Season

comScore also analyzed non-travel e-commerce spending by household income segment for the holiday shopping season, revealing that growth in online spending only occurred (up 7 percent) within households making at least $100,000 in annual income, while lower income segments logged significant declines in spending. Those households earning less than $50,000 per year appear to be the most affected by the current economic environment, with their online spending declining by 13 percent versus year ago.

Source: Company press release.




Reblog this post [with Zemanta]

MC inC: "MasterCard inControl" of Orbiscom




After RBS implemented a commercial application called "MC inC," a collaboration between Orbiscom and MC, they have decided to purchase the company.

Deal enhances MasterCard's ability to deliver advanced and customizable payments solutions for today's demanding marketplace
PURCHASE, N.Y., Jan. 5 /PRNewswire-FirstCall/--

MasterCard Incorporated (NYSE: MA) announced today the acquisition of Orbiscom Ltd., a Dublin, Ireland-based leading payments solutions software provider for major financial institutions. The purchase price is approximately $100 million, a portion of which is contingent upon the future performance of Orbiscom's business.
The acquisition builds on the companies' existing partnership that created MasterCard inControl, an innovative platform featuring an array of advanced authorization, transaction routing and alert controls designed to assist financial institutions in creating new and enhanced payment offerings.

In 2008, Royal Bank of Scotland became the first financial institution to implement MasterCard inControl for its commercial card customers.

Click the following link to read the entire press release:MasterCard Acquires Orbiscom to Accelerate Development of Innovative Payment Solutions | MasterCard®


Friday, January 2, 2009

Graphic: Soft vs. Hardware

400+ Breaches: Software Responsible for: 92% Hardware: only 1%
According to a Trustwave review of 400+ breaches,
  • 67% were from POS Software,
  • 25% from an Online Shopping Cart, (also software)
  • 7% from Back-end Systems while...
  • only 1% from a Hardware Terminal.
    (and those were tampered with, which won't happen with our personal card swiping device)

Reblog this post [with Zemanta]

Browsers & E-Commerce Don't Mix


As the name implies, "Browsers" are for "browsing" when you're done, and it comes time to make that online purchase, it should be done "outside the browser."

There are reports of a serious vulnerability with all browsers which makes e-commerce unsafe. This is a sobering moment in e-commerce history... but it's nothing that we at HomeATM didn't see coming...(see the post: It' Safe to Say It's Not Safe..)

Browsers are e Commerce handicapped.

HomeATM has long taken the position that a software only approach to providing PIN based transactions to the web is ripe with insecurity. There are too many holes within the browser space to guarantee a secure transaction. Typing your credit or debit card information in a browser is simply put, "not a wise thing to do" as there's "no such thing" as a "secure site" as the story at the end of this post demonstrates.

So, now there's further proof HATM is right. There's no such thing as a secure website...thus there's no such thing as a secure e-commerce transaction. If you've any doubts simply google: web browser flaw (I've provided a link to make it easy) and you get 17,000+ hits..."Pardon my sarcasm, but "Enter your PAN" (personal account number) into the browser space, and you'll get hits from hackers.This time around, it may have taken 200 Playstation 3 consoles but what about this year...or the year after that?

E-Commerce is NOT safe in a browser space.

This is why the engineers at HomeATM decided to take the "hard"ware approach and manufacture, then distribute a "personal point of sale device.

Sure, by all accounts, it would have been much easier to roll out an Internet PIN debit platform with a software only approach. But that would be taking the "easy way" out. "Soft"ware is, by it's own descriptive, "soft." When you take a software only approach..., and this is a big caveat, we believe it 's only a matter of time before a major breach occurs. It's not so much the software, as it is the consumers PC.

Therefore, in the interest of protecting the consumer AND the merchant, we know that we had no choice but to do it the "hard" way and create a small, easy to use, secure point of sale device . It's the way it's been done since the beginning of electronic payments and...

According to a Trustwave review of 400+ breaches, 67% were from POS Software, 25% from an Online Shopping Cart, 7% from Back-end Systems and only 1% from a Hardware Terminal. (click here to see the graph)

By utilizing (pictured on left) our personal swiping device, (which plugs into a PC's USB port in seconds), the transaction is safely done "outside the browser space" utilizing existing secure bank rails, which have yet to be compromised in 40 plus years. The connection bypasses the user's PC, which could be infected with viruses and other malware that make sending financial information over the Internet unsafe. Here's the latest about browser insecurity...
There's a "proof of concept" that a "key piece of of Internet technology that banks, e-commerce sites, and financial institutions rely on to keep transactions safe suffers from a serious security vulnerability."

At this point, an "I told you so" doesn't do anybody any good, so we'll continue to focus on what we do best...providing a secure environment for PIN based transactions. But rest assured, if a software only approach to PIN debit is released, when it's breached, expect a resounding "I told you so" from the folks at HATM.

With that said, it's relatively baffling to us that an EFT switch Firserv's Accel/Exchange...click to read story (PDF) is willing to "toss the dice" and pilot a browser enabled approach to securing PIN based e-transactions.

Mr. Kelly, currently the GM of Accel/Exchange and pictured on the right, is adamant in his belief that it's safe. We respectfully disagree, and time will tell, we just hope it's won't be at the expense of an entire sector (PIN Debit for the web) being tarnished because of a massive breach. They point out that it would cost millions to distribute a personal POS device like the one produced by HomeATM, but we've got the costs down to the point where, in quantities above 100,000 we could provide them for free, if the consumer/etailer covered the $4.95 cost of shipping and handling. What would cost millions, maybe even billions, would be a breach resulting in the exposure of consumers PAN and PIN.

Of course, we're not alone with our analysis...ask Gartner's distinguished analyst, Avivah Litan how much she would trust a software only approach to bringing PIN based transactions to the web.

You've most likely heard the term "Caveat Emptor"? HomeATM wishes to protect both the buyer and the e-tailer with our approach. At the same time, we also wish to avoid providing fraudsters with the means to carry out "Account Emptor" which is exactly what would happen once they got a hold of your PAN and your PIN.

Anyway, moving on to the story behind all this. A group of researchers have demonstrated a "proof of concept" of an exploit that bypasses Secure Sockets Layer (SSL) security safeguards. Another words, "every web browser (Explorer, Firefox etc.) that implements SSL can be spoofed into displaying the padlock". Translation: Invert the p in "https" and you'll get the picture..."httbs".

This is certainly not good news, but as I've mentioned a couple of times already, for the engineers at HomeATM, it's old news. So, don't be surprised by any more "surprise announcements" about how insecure e-commerce is. As I've vehemently stated, many times over in this blog, the web was originally designed to be an information highway and "Highway robbery "is not a new concept.

Once again, and I want to state this for the record...unequivocally...

In order to secure a PIN based transaction, it needs to be done "outside" the browser space. Period. End of story.


Which brings me to the beginning of the story that instigated this post, (from CNET, written by Jonathon Stray).

Web browser flaw could put e-commerce security at risk | Security - CNET News
BERLIN--A key piece of Internet technology that banks, e-commerce sites, and financial institutions rely on to keep transactions safe suffers from a serious security vulnerability, an international team of researchers announced on Tuesday.

They demonstrated how to forge security certificates used by secure Web sites, a process that would allow a sufficiently sophisticated criminal to fool the built-in verification methods used by all modern Web browsers--without the user being alerted that anything was amiss.


The problem is unlikely to affect most Internet users in the near future because taking advantage of the vulnerability requires discovering some techniques that are not expected to be made public (Editor's Note: too late, cat's outta the bag..now that they know it can be done, it'll be done again) as well as overcoming engineering hurdles: performing the initial digital forgery consumed approximately two weeks of computing time

(Editor's Note: yeah, the "initial" digital forgery took that long, but now that they know how to do it how long would it take? Besides, the potential monetary reward for two weeks work is huge ) on a cluster of 200 PlayStation 3 consoles.

In addition, a criminal needs to find a way to reroute traffic from a legitimate Web site to his own, perhaps through techniques that have become well-known in the last few years. (Editor's Note: What? It's unlikely to happen unless hackers use "well-known techniques?" They're kidding right? That's what the kid with the paper is selling, but I'm not buyin' it.)

Yet if one group can do it today, others eventually will. (Editor's Note: at least that line is clearly stated) "We have a proof-of-concept that allows us to impersonate any supposedly secure Web site on the Internet," said David Molnar, a doctoral student in computer science at the University of California at Berkeley.

Molnar and six other researchers presented their findings during an afternoon session of the Chaos Computer Club's annual conference here on Tuesday. Other team members include Jacob Appelbaum and Alexander Sotirov.

Their work has focused on finding vulnerabilities in a technology known as Secure Sockets Layer, or SSL, which was designed to provide Internet users with two guarantees: first, that the Web site they're connecting to isn't being spoofed, and second, that the connection is encrypted and is proof against eavesdropping. SSL is used whenever a user navigates to an address beginning with "https://". SSL certificates essentially stand for the claim that, for instance, etrade.com actually belongs to E-Trade Inc., and is not being operated by a thief hoping to steal account passwords.


Most browsers indicate that SSL is active by displaying a small padlock icon. (see pic on right) An attack using a forged authentication certificate--which is what the researchers say they have done--is insidious because the browser can't detect it and the padlock icon would still appear.

Unlike most security issues, this problem cannot be fixed with a simple software update. "The bug is not in anyone's software," Sotirov said. "It's not the browser that's at fault. The browser does exactly what it's supposed to do... The problem is that what it's supposed to do is wrong."

The attack exploits a mathematical vulnerability in the MD5 algorithm, one of the standard cryptographic functions used to check that SSL certificates (and thus the corresponding Web sites) are valid. This function has been publicly known to be weak since 2004, but until now no one had figured out how to turn this theoretical weakness into a practical attack.

An SSL certificate is a small file that ties a real-world corporate identity to a Web site address and a corresponding public encryption key. This is presented to a private certificate authority firm, which is supposed to verify the link between identity and domain name and then cryptographically "sign" the certificate to vouch for it.

The problem arises when someone else is able to forge the same signature... continue reading at CNET News



Reblog this post [with Zemanta]

Global Payments Wins Processing Award

Global Payments wins top internet card processing award - Taiwan News Online
Global Payments Asia-Pacific Limited ("Global Payments") was recently named by MasterCard Worldwide as its Top Processing Partner for the Global WebPay(TM) product that leverages the MasterCard Internet Gateway Service (MiGS) for online card processing. Global Payments was chosen from more than 69 bankcard acquirers that use MasterCard's Internet gateway today across Asia Pacific, the Middle East and Africa.

Global Payments' win is attributed to Global WebPay's unique solution that provides online merchants with the capability to process multi-country, multi-sales channel and mult-currency card transactions. The Global WebPay product offers merchants a Web-based user interface to integrate their online stores, call centers and IVR sales through a single connection. This single interface requires minimal integration which significantly reduces operating costs and allows merchants to seamlessly integrate all their card-not-present transactions across multiple jurisdictions in Asia.

Global WebPay is currently available in 9 Asian markets: Hong Kong, Brunei, India, Malaysia, the Maldives, the Philippines, Singapore, Sri Lanka and Taiwan. This product offers online merchants more than 50 transaction currencies and ten payment currencies, thereby allowing merchants to receive funding in local Asian currencies and minimize forex related costs.
Reblog this post [with Zemanta]

Thursday, January 1, 2009

Carpe Diem - Dominus Providebit

Today is the first day of the rest of the year!
"Seize the Day"

Dominus Providebit


Reblog this post [with Zemanta]

Wednesday, December 31, 2008

Tuesday, December 30, 2008

Worst Holiday Since 1970...maybe 1929?

Worst holiday shopping season since "at least 1970"  
CNN Money reports that the recession, discounts and bad weather are to blame.
NEW YORK (Reuters) -- The U.S. holiday shopping season is the worst since at least 1970 due to the recession, heavy discounting and harsh winter weather just before Christmas, the International Council of Shopping Centers said Tuesday.
Sales at U.S. chain stores fell 1.8% in the week ending Dec. 27 compared with the previous year, while sales fell 1.5% compared with the prior week, according to the ICSC-Goldman Sachs Weekly Chain Store Sales index.

The ICSC expects holiday sales in November and December to fall 1.5% to 2%.

That would represent the first decline since the ICSC began tracking holiday sales in 1969...(so it could be the worst since '29?)


Related Stories at CNN Money



Reblog this post [with Zemanta]

Holiday Top 40 - Satisfied?

ForeSee Results - Holiday 2008 Top 40 Online Retail Satisfaction Index
Holiday 2008 Top 40
Online Retail Satisfaction Index

The Top 40 Online Retail Satisfaction Index assessed customer satisfaction with leading online retailers during the holiday shopping season, the most critical time of the year. 2008 was the fourth year in a row that ForeSee Results conducted this research, allowing for valuable insights on year-over-year performance by individual retailers.

Overview Commentary: This report ranks the Top 40 retailers in terms of how well they satisfy customers online and contains high-level insights into drivers of customer satisfaction during the critical holiday shopping season. Highlights include:

  • Amazon and Netflix top the list and are the only two online retailers to score above 70.
  • Only 10 websites improved satisfaction year-over-year, while more than 40% saw satisfaction decline.
  • More than a quarter of all websites scored 70 or lower, well below industry standards

To download the free report you'll need to fill out a form on ForeSee's website.  They also have a free report on the Top 30 online retailers in the UK available for download.  

To read more, the NY Times Blog has a story on it in today's publication. Click here to read "How E-Commerce Sites Stack Up" there.

Here's a snippet: 

Those that score 80 or greater are classified as excellent. Only Netflix and Amazon.com, which tied at 84, made the cut, which might help explain why Amazon.com recently reported its best holiday season ever during the worst holiday season for e-commerce as a whole. Close behind were QVC, the Apple Store, Barnes & Noble, L.L.Bean, Walmart.com and Newegg.com (which sells computer parts.)
Tying at 69, the lowest score in the group, were Circuit City, HSN, Overstock.com, (that's what happened) HomeDepot.com, Neiman Marcus and Gap...

Reblog this post [with Zemanta]

Consumers Don't Trust Mobile Security - Javelin Research

Javelin Strategy and Research » Consumers fear mobile banking security threats – study
Consumers fear mobile banking security threats – study


The Paypers- Another widespread opinion among consumers who chose not to sign up for mobile banking is the fact that since mobile transactions are not yet mainstream, mobile banking services providers cannot anticipate the type of attacks fraudsters could launch against users once mobile banking adoption rates climb. Despite inherent safety features such as real-time transaction alerts and transaction level validation, the research indicates that consumers overlook advantages and mainly fear security threats such as malware, which are not widespread or can be easily blocked in mobile devices.

Thus, 73 percent of consumers fear hackers can remotely access their phones, 68 percent of interviewees are concerned sensitive mobile banking data can be stolen using a wireless signal despite encryption, and 54 percent of consumers worry that their mobile phones can be stolen.

The same study points out that all the major US mobile banking platform vendors offer authentication tools which comply with the standards set out by the Federal Financial Institutions Examination Council (FFIEC), however 56 percent of them have not implemented strong authentication systems for their mobile banking platforms.

The study was conducted by financial services market research company Javelin Strategy & Research. Read Full Article

Reblog this post [with Zemanta]

E-payment Fraud up 11% Over 2007

E-payment fraud projected to hit $4 billion in 2008, up 11% over 2007

E-commerce fraud losses in the U.S. and Canada are expected to reach $4 billion in 2008, an 11% increase from $3.6 billion in 2007, according to CyberSource Corp's 10th annual survey of e-commerce fraud.

Chargebacks accounted for almost half of 2008 online payment fraud losses. The percentage of online revenue lost to fraud held steady from 2007 at 1.4% of online sales, the report says.

Merchants fight only about 50% of the fraud chargebacks they receive, with a third of merchants challenging less than 10%. Merchants that do challenge chargebacks recover, on average, 28% of that revenue, CyberSource says.

The consumer electronics category showed the highest 2008 fraud rate at 2%, nearly double the average among the eight industry segments measured. Merchants with online revenue of $5 million to $25 million faced the most fraud.

The annual survey also found that order-rejection rates tied to suspicion of fraud showed a significant drop to 2.9% of incoming orders, down from 4.2% in 2007. On average, 1.1% of accepted orders were fraudulent, CyberSource says. Merchants have made little progress in minimizing the time spent manually examining good orders, CyberSource says.

Merchants in 2008 accepted an average of 73% of orders they manually reviewed, roughly the same percentage as in 2007. About half of merchants accepted 90% or more of the orders they reviewed.

CyberSource surveyed 400 online merchants in the U.S. and Canada between Oct. 21 and Nov. 11.



Reblog this post [with Zemanta]

Only 1% of US Consumers Will Charge More


It looks like 2009 is going to be the "Year of the Debit Card."  According to a US Banker poll, only 1%  of U.S. Consumers are going to use their credit cards more this year.  In the wake of 3% growth in 2008, look for a decline in 2009.  Meanwhile, according to The Nilson Report, debit card usage grew at 13% in 2008.  Look for growth in prepaid and debit cards to surge in 2009...

New Poll Finds Only One Percent of U.S. Consumers Plan to Charge More - 01..2009 - U.S. Banker Article

U.S. credit cardholders are not in the mood to charge, according to national poll results recently released by Bankrate, Inc. The phone study was conducted from December 5 through December 7.

Just one percent of those surveyed plan to charge more in 2009, while 32 percent are likely to use their cards less frequently and 15 percent won’t be taking out the plastic at all. Forty percent of these consumers wouldn’t care if their credit lines were cancelled.


As far as credit availability goes, 41 percent of those polled reported that their credit lines were increased, while 44 percent said their lines were unchanged; only six percent experienced a decrease.

Reblog this post [with Zemanta]

Credit Line Cuts Could Backfire

Credit Line Cuts Could Boomerang - 12.29.2008 - American Banker Article

Credit line reductions, account repricing, and other steps that card issuers are taking to control risk could soon start causing their customers to do something many homeowners did this year: walk away from their obligations.

In the past month current and former industry executives and observers have raised concerns that prevalent risk management tactics may spur such behavior — even among customers who still have the capacity to pay.

For example, some observers said aggressive repricing could lead to a spike in "bust-outs" — when cardholders decide to run up as large a balance as possible before abandoning the account. In the past, bust-outs have typically been perpetrated by fraudsters who always planned to default, but they may soon become more common among regular consumers who obtained their cards in earnest, these observers said...

continue reading at American Banker
Reblog this post [with Zemanta]

Facebook Scraps Payments Initiative


According to "Inside Facebook"  the company has temporarily abandoned its initiative to launch a platform payment system which would enable retailers to conduct e-commerce transactions and accept payments directly inside their Facebook applications." 


Facebook announced the beta test version of a payments platform initiative in December 2007. It was originally billed as a means to allow Facebook users to carry out transactions and purchase virtual and physical goods and services without resorting to third party payment platforms such as Paypal.

Facebook Payments was also initially designed to act as a revenue generator for Facbook via payment processing commissions, and a means for the social networking website to gather consumer data to facilitate future direct transactions such as the purchase of Facebook’s virtual gift offerings.

However, one year after the initiative was made public, the payment system has not yet been developed and Facebook representatives have confirmed that no further developments are currently conducted regarding the project.



China Online Growth Continues

The Paypers. Insights in payments.

China's online transaction volume to reach EUR 9.4-9.9 billion in Q4 2008

In Q4 2008, the online transaction volume is expected to reach between EUR 9.4 and 9.9 billion in China.

In spite of the financial crisis, the online transaction volume is on an upward curve as a result of the expansion of payment channels and application fields and boosted by the launch of new online payment services. Alibaba's online payment services provider Alipay has made an online payment system available for utility payment, allowing Chinese internet users to pay online for water, electricity, town gas, and mobile phones. Tenpay and PayEase have had similar initiatives, the first teaming up with ten partners for the delivery of online payment services for air tickets. The total transaction volume of online shopping in China reached EUR 7.51 billion in Q3 2008. Data has been released by market research firm iResearch Consulting Group.

According to estimates for the full year of 2008, the volume of e-commerce transactions is to jump to EUR 27.2-28.3 billion.



Reblog this post [with Zemanta]

RBI to Allow Outward Remittances?


Sending money overseas instantly could soon become a reality with the Reserve Bank of India (RBI) considering proposals to allow non-banking
entities like online money transfer portals to undertake wire transfers for outward remittances from India. At the moment the facility is limited to inward remittances, while only banks are permitted to carry out outward remittance orders.

According to sources close to the development, the central bank has been approached by a number of players to enable outward remittance facilities on their money transfer channels. The banking regulator is in the process of working out the know-your-customer (KYC) norms that are to be followed while sending cash abroad via online payment web-portals.

The first half of the ongoing financial year has witnessed outward remittances to the tune of $ 431 million, marking a sharp rise compared to $440.5 million during the full financial year of 2007-08, according RBI data...

continue reading

Reblog this post [with Zemanta]

Debit Growth for 2008

Americans switch purchasing options

Americans are turning away from credit cards and "shifting" to debit card usage.

Debit card purchases...at the end of 2008...are forecast to climb by 13% for the year, according to an industry newsletter by The Nilson Report.

Credit card purchases are predicted to be up a mere 3%.

The numbers seem to indicate a strong "shift" away from credit as the economy tries to find its way out of recession.   Look for more disparity in 2009...

Disqus for ePayment News