Wednesday, February 11, 2009

$37 Billion Savings if You PrePay?

I found the following Aite report to be interesting, especially in the wake of MasterCard's recent joint venture with Accor.  Allow me to provide a backgrounder.  A couple of days ago MasterCard and Accor Services, Europe's largest hotel chain, set up a joint venture to target Europe's fast growing prepaid market. 

MasterCard now hold a 33% stake in Accor's subsidiary, PrePay Technologies...which they acquired last year.  PrePay Technologies has issued more than 20 million pre-paid cards in the UK and holds a license to issue e-money in 17 European countries.  While Accor will continue to go after the corporate and public sector markets, it is believed that MasterCard will tout the pre-pay opportunity to member banks.  That's where it got interesting for me.

The problem that I see with offering a prepay opportunity to banks is simply  that banks make "way too much" money on overdraft charges (ODC) they derive from signature debit and checking accounts. 

A prepaid card would be declined, showing insufficient funds were available, the way debit cards originally did.  This would take a huge bite out of the $37 billion in overdraft, and ironically, overdraft "protection" charges. (ODP)   How many billion? Yes, I said 37 of those bigboys.

I get my data from a new study by management consulting firm Bretton Woods which found that banks and credit unions collected a staggering $37 billion in non-sufficient funds and overdraft fees in 2008.  This represents an increase of 97% over the past 3 years.  In fact, while I'm on the subject, I'll share some more data from that report.  It's amazing:  



  • Bank and credit union income from non-sufficient funds (NSF) and overdraft program (ODP) fees exceed $37 billion.
  • The national annual NSF cost per household with checking accounts is approximately $368.
  • Active households pay $1,472 in annual NSF fees.
    (defined as the 20.2 million households with bank or credit union accounts)
  • The average United States household with a banking account incurs 12.7 NSF fees per year.
  • Bank and credit union data used in Bretton Woods’ modeling was determined from 1.28 billion separate check and electronic NSF items.
So why mess with a good thing?  Prepaid cards, as the Aite reports suggests, may be a "very credible" alternative to checking acccounts for consumers, make that..."consumme'rs. (Soups On!)  Banks are the real "consumers" here as they're the one's eating us alive with $37 billion worth of ODC.  It's okay...we'll bail 'em out, they've had our babyback for years. 

Certainly I would expect for banks to come up with new ways to nickle  and dime  us to death on a prepaid solution, but compared to $35 a pop, nickles and dimes are "insufficient funds" and won't add up to $37b.  So the question is can they craft a $37 billion dollar way to ream prepaid card users?  That 's going to be tougher.  Of course, if bank customers want to take a bite out of, or eliminate overdraft charges altogether,  they  can simply enter their PIN...which transforms the transaction into a real-time debit.

PIN Based transactions are the equivalent of saying to the banks..."No Soup for You!"  
 

Prepaid Debit Cards: A Credible Alternative to Checking Accounts

Aite Group reveals that at least 14% of bank customers would be better off using prepaid debit cards than checking accounts. 

Boston, MA, February 11, 2009 – A new report from Aite Group, LLC argues that prepaid debit cards represent a competitive threat to banks' checking account relationships. It also provides insights into how banks, prepaid debit card providers, payday lenders and other parties can take advantage of prepaid debit cards.

For years, banks in the United States have viewed unbanked and underbanked consumers as a promising segment they could address through traditional checking account relationships. Few banks have realized that new technology and financial products may actually render the checking account relationship less attractive to this customer segment. In fact, at least 14% of checking account holders would be better off switching to a prepaid debit card.  

"This is not just doom and gloom for banks,"
says Gwenn Bézard, research director with Aite Group and author of this report. "The most sophisticated among them could profit on the appeal of prepaid debit cards, as can other obvious stakeholders such as prepaid debit card marketers and payday lenders. For example, banks could rapidly gain market share by striking co-brand deals with leading prepaid debit card marketers that have a head-start in this race."

This 29-page Impact Report contains 24 figures. Clients of Aite Group's Retail Banking service can download the report by clicking on the icon to the right.


Related Aite Group Research:





Reblog this post [with Zemanta]

How to Hack an ATM

Use an "ATM" BOMB:

Finextra: Australian ATM explosion gang strike again

Australian police are appealing for information after a gang of thieves blew up a St George ATM and escaped with an undisclosed sum of money in the early hours in Sydney.

Witnesses have told police four men fled the scene in two cars, a silver/grey Audi and a black BMW station wagon.

The crime is the latest in a spate of explosive attacks on cash machines in Australia.

In November thieves blew up four St George Bank cash machines with acetylene gas in Sydney, successfully stealing money from one. Police say they are investigating reports of seven successful attacks dating back to July this year.

In December, police arrested a couple in connection with the explosion of a Bank of Queensland cash machine in the city of Brisbane.

The crimewave has prompted the formation of a special police task force and rewards of up to $150,000 for information leading to convictions.



Reblog this post [with Zemanta]

Data Security Summit Host Says Don't Type...Swipe!


ProPay, who by the way, also apparently believes you should be "Swiping instead of Typing" is hosting the 2009 Data Security Summit.

Here's ProPay's press release on the Summit.
Industry experts address payment trends at Data Security Summit

Orem, Utah, Feb. 10, 2009 -- ProPay is gathering the brightest minds in the digital transaction industry to educate attendees about the latest trends and best practices to protect sensitive customer data at the 2009 Data Security Summit on March 18-19, 2009, at the Snowbird Resort in Salt Lake City, Utah.

Headlining the Summit’s speakers are Bob Russo, General Manager, PCI Security Standards Council; Chris Mark, CPISM/A, CISSP, CIPP, Founder, Society of Payment Security Professionals; Dr. Heather Mark, CPISM, CISSP, CIPP, Executive Director, Society of Payment Security Professionals; and Michael Dortch, Founder and Managing Editor, DortchOnIT.com. Speakers will address the latest in PCI compliance, risk mitigation, security, and other relevant topics pertaining to the payment industry.

Bob Russo, General Manager, PCI Security Standards Council

Mr. Russo brings more than 25 years of high-tech business management, operations and security experience to the PCI Security Standards Council. Most recently, he served as the vice president of Commercial Sales for Secure Info, a provider of security, risk and compliance services and software. He was also a founder of a number of software and security companies including Network-1 Software & Technology and ATC Security, a security compliance company created to assess compliance of payment industry stakeholders, later acquired by Ambiron LLC.

Chris Mark, CPISM/A, CISSP, CIPP, Founder, Society of Payment Security Professionals

Chris is an experienced information security professional and recognized payment card industry security expert. Chris is a co-founder of The Aegenis Group and the Society of Payment Security Professionals. From 2007-2009, the Aegenis Group was the worldwide trainer for all Qualified Security Assessors (QSA) and trained over 2,800 QSA. Additionally, the company contracts with Visa Inc. to conduct PCI related training internationally to merchants and banks. Chris has conducted PCI and payment security training in over 10 countries on 5 different continents.

Dr. Heather Mark, CPISM, CISSP, CIPP, Executive Director, Society of Payment Security Professionals

Dr. Mark is an experienced information security and privacy professional that is both well known and respected within the Payment Services industry. Prior to joining Halcyon, Dr. Mark co-founded a Qualified Security Assessment Company and worked at various technology companies supporting PCI efforts. Dr. Mark helped to develop a variety of assessment methods and practices that assisted companies in achieving compliance in a cost-effective, timely manner.

Michael Dortch, Founder and Managing Editor, DortchOnIT.com


Michael Dortch is Founder and Managing Editor of DortchOnIT.com, and has been an IT industry analyst, consultant, evangelist, speaker, writer, and "information entrepreneur" for more than 30 years, focused on enabling and emerging technologies and their effects on business value. Before starting DortchOnIT.com, Michael was a Senior Research Analyst at Aberdeen Group, and Director of IT Infrastructure Management Strategies and Executive Editor for Robert Frances Group. Michael has worked with IT users and both established and start-up vendors to help them align their strategies with business goals. He has been widely quoted and is a frequent and popular speaker at industry events. He began his career in the 1970s at The Yankee Group after attending the Massachusetts Institute of Technology (M.I.T.). He lives and works in Santa Rosa, CA, approximately an hour north of San Francisco.

Representatives from the various card brands and payment industry companies, as well as experts from law enforcement agencies and the FBI will be on hand to network with attendees and talk about the latest from their businesses and organizations.

“The landscape of the payment industry is ever-changing and the need to educate the market on best practices and the latest technology to protect businesses is essential to the survival of every company,” said Greg Pesci, ProPay Executive Vice President of Business Strategy. “This Summit is a great opportunity to bring experts and non-experts together to educate each other on the trends in the market and the pains customers and businesses are experiencing in regards to digital transactions.”

For more information about the 2009 Data Security Summit and how to register, please visit www.propay.com/summit or e-mail Jennifer McClintock at events@propay.com.

About ProPay

Since 1997, ProPay has led the market in providing simple, safe and affordable credit card processing and electronic payment services for businesses ranging from the small, home-based entrepreneur to multi-billion-dollar enterprises.

ProPay understands the unique needs of these businesses and has created merchant services specifically for them. With ProPay, merchants can set up accounts online and begin accepting credit cards without buying special equipment or making long-term commitments or investments. ProPay leads out in educating merchants about how to reduce or eliminate the risk of touching or holding sensitive cardholder data. The company also leads the payments market in the development of secure end-to-end solutions for protecting sensitive data and of alternative payment options that significantly reduce business costs.

ProPay is a privately held company, headquartered in Orem, Utah. For information, visit
www.propay.com/pressroom .

Source: Company press release.




Reblog this post [with Zemanta]

Tuesday, February 10, 2009

PayPal Says Don't Type...Swipe

I've been saying that for  about a year now, you know..."You Should Be SwipePIN instead of Typin'." 

Apparently PayPal, Magtek and Dell all agree as today they announced the new Magtek personal swiping device for use with PayPal.  You can buy it at Dell.

You may purchase the Magtek personal swiping device from PayPal here for $86.99 WITHOUT a PIN Pad

Or,  you can get ours WITH a PED (PIN Entry Device) which also enables you to carry out  a secure P2P (person to person) money transfer.  The HomeATM Slider can be yours for much less money.  One more thing...you don't have to download any software for our to work, which is not the case with the MagneSafe Secure Card Reader. 

Here's today's press release:

PayPal Virtual Terminal Safeguards Merchant Transactions with MagneSafe Secure Card Reader from MagTek
SEAL BEACH, Calif.  February 10, 2009 - MagTek®, Inc., a global leader in secure electronic payment technology, today announced that users of PayPal Virtual Terminal can save time and reduce errors by using the MagneSafe Mini secure card reader from MagTek. Designed to provide superior card data privacy as well as authentication for credit and debit card transactions, the MagneSafe Mini helps merchants avoid keying errors and speeds card transaction processing.

The MagneSafe Mini easy-to-use card reader plugs directly into a computer’s USB drive, and provides maximum security for all face-to-face transactions. The reader can be used anywhere there is a computer, Internet access, and a customer’s debit or credit card. With one quick swipe, the MagneSafe Mini reader captures the customer’s name, card number, expiration date, and card type and they are then all posted automatically to the merchant’s PayPal Virtual Terminal order form.

"PayPal Virtual Terminal is a powerful solution to help merchants expand their business, save money and deliver faster products and services for their customers, " said Doug Free, Vice President, Retail Business Unit for MagTek. "By using the MagneSafe Mini reader merchants can take the value of their Virtual Terminal services one step further with the assurance of encrypted data for enhanced security and PCI compliance."

Merchant benefits of the MagneSafe Mini secure card reader include:

  • Increased data accuracy: By swiping credit and debit card information, instead of typing, merchants can avoid keying errors and speed up the credit card payment process.
  • Assured security: Encryption provides increased security for credit card information and reduces risk relating to opportunity for stolen card data at PayPal merchant locations.
  • PCI Compliance: The MagneSafe Mini secure card reader meets PCI DSS requirements for secure cardholder data encryption.

"Today’s online merchants are looking for ways to shorten transaction processing times without risking information accuracy," said Rahul Bhargava, senior director of merchant solutions at PayPal. "The MagneSafe Mini secure card reader, in combination with PayPal Virtual Terminal, is a great solution because it saves time, reduces errors and gives merchants confidence that their customers’ data is always safe and secure."

About the MagneSafe Mini Secure Card Reader

At just 100mm in length, the MagneSafe Mini secure card reader has been specifically designed to meet PCI DSS requirements to secure cardholder data via 3 DES DUKPT encryption. Self-powered through a USB port, the secure reader can be connected to any PC or terminal with a USB interface. The device features MagnePrint card authentication technology that enables secure transactions for magstripe documents including credit cards, debit cards, gift cards, ATM cards and ID cards.

Pricing and Availability

The MagneSafe Mini is available now by ordering direct from Dell. Pricing starts at $79.99 USD. For more information, please visit: www.paypal.com/vtswipe


About MagTek
Founded in 1972, MagTek, Inc. is the leading provider of technology that makes electronic transactions safer, speedier and more comfortable. With its secure card readers, dependable check scanners, instant card personalization, robust PIN management, and identity verification systems, the company’s products and components are used today in thousands of companies around the world. Every day at supermarkets, gas stations, banks and credit unions, restaurants, casinos and hotels, on airplanes and time clocks, in ATMs, kiosks and POS terminals you may not see the MagTek logo, but the odds are great that you are using one of its products. Based in Seal Beach, California, MagTek has sales offices throughout the United States, Europe, and Asia, with independent distributors in over 40 countries.
Source: Press Release




Reblog this post [with Zemanta]

CashEdge Executes $50 Million in Online Transfers



Bank Customers Transfer Nearly $50 Billion Online in 2008 Using CashEdge Intelligent Money Movement(TM) Products

Volume Up Over 32 Percent from 2007

NEW YORK, Feb. 10 /PRNewswire/ -- CashEdge Inc. (www.cashedge.com), the leader in Intelligent Money Movement(TM) products for financial institutions, announced today that in 2008, the Company executed nearly $50 Billion in online transfers, a more than 32 percent increase over 2007 volume. Furthermore, the Company reported an over 30 percent growth in the number of end users accessing its services, indicating a continued growth in user demand for online funds transfer services. The transfers were initiated through CashEdge's Intelligent Money Movement(TM) solutions that are currently in use at hundreds of leading financial institutions, including the majority of the nation's largest banks.

"This transaction volume and the significant increase in use of online funds transfer services demonstrate the demand in the market for solutions that enable consumers and small businesses to easily and safely move their money online," said Sanjeev Dheer, CEO, CashEdge. "With CashEdge's online transfer and payment products, including Me-to-Me Transfers and Third Party Transfers, financial institutions can meet this growing demand using solutions that are supported by industry-leading risk management tools, including fraud detection and prevention. As demand continues to grow, we expect to see additional transfer solutions - such as person-to-person payments - being offered by banks as well."

The growth in online transfers was also illustrated in the 2008 CashEdge Consumer Survey, which indicated that consumers are moving more money online and demanding additional funds transfer services, including the ability to transfer funds to their friends and family. In the survey, 88 percent of consumers polled expressed interest in direct account-to-account funds transfers to other people, such as friends and family, in lieu of cash or check, using account information provided by the recipient.

CashEdge's industry-leading products include TransferNow(R) for Consumers, TransferNow for Small Businesses and OpenNow(R)/FundNow(R) for new account opening and funding. The TransferNow for Consumers Product Suite includes Me-to-Me Transfers and Third Party Transfers, which enable financial institutions to offer their customers secure funds transfer services for inter-institution transfers between their own accounts or directly to third parties. The TransferNow for Small Businesses Product Suite is comprised of several offerings that can be used as either stand-alone services or as part of a cash management suite, including Small Business Invoicing and Payments, Employee Payments and Vendor Payments, and Small Business Me-to-Me Transfers.

All TransferNow modules leverage industry-leading risk management tools that satisfy all business, risk and compliance requirements, thus enabling safe and secure transfers between accounts held at over 23,000 banks, credit unions and brokerages via the ACH network.

To learn more about CashEdge's Intelligent Money Movement services, visit www.cashedge.com.

About CashEdge

CashEdge is the leader in Intelligent Money Movement(TM) services that enable financial institutions to engage customers in new ways. CashEdge's Intelligent Money Movement services provide a single point of access, through an online banking portal or mobile application, for multiple easy-to-use consumer and small business transfer routes. CashEdge's industry-leading products include OpenNow(R)/FundNow(R) for new account opening, TransferNow(R) for Consumers which includes Me-to-Me Transfers and Third Party Transfers, and TransferNow for Small Businesses which includes Invoicing and Customer Payments, Employee Payments and Vendor Payments, and Me-to-Me Transfers. These products are supported by industry-leading risk management capabilities that leverage comprehensive, proprietary technology, helping institutions mitigate risk and decrease fraud exposure.

CashEdge currently serves hundreds of leading financial institutions, including the majority of the nation's largest banks. The Company has offices in New York, Silicon Valley and India. For more information, visit www.cashedge.com.


SOURCE CashEdge Inc.




Reblog this post [with Zemanta]

Less Than Half Strongly Support UAE's Move to Chip and PIN

Joanna Hartley writes for Arabian Business.com that a little less than half of those polled welcome the UAE's recent Chip and PIN move.

Poll shows 50% support chip and PIN move in UAE - Banking & Finance - ArabianBusiness.com
Almost half of all responders to a poll have said they think the new chip and PIN idea that is to be rolled out across the UAE is a great idea that will have a major impact on fraud.

Last week's announcement by the UAE Central Bank that all banks in the country will be required to move to chip and PIN technology called widespread debate, with some experts citing the move as useless against the type of fraud residents suffered last summer at the hands of international gangs.

However, Arabian Business’s online survey showed that 48.6 percent strongly welcomed the move, with just 10.4 percent thinking it would be a better to invest in more advanced biometric tests, such as eye scans, to stop fraud.

continue reading

Hacker Breaches Kapersky - Dark Reading

Hacker Lays Claim To Breaches Of Two Security Vendors' Websites
SQL injection attack conceded by Kaspersky U.S.; subsequent attack on BitDefender Portugal still awaiting confirmation
 

By Tim Wilson -DarkReading

A single Romanian hacker claims he has broken through the Website defenses of two prominent security vendors in an attempt to show vulnerabilities in their security.

Kaspersky, one of the industry's best-known antivirus and security software makers, today gave a press conference confirming that a Romanian hacker had launched an SQL injection attack on its newly implemented U.S. customer support site, exposing a potentially data-threatening vulnerability in its Website. The attacker did not publish any sensitive data, even though he could have gained access to it, Kaspersky said.


The hacker, known as "unu," claims to have launched a similar SQL injection attack on the Website of security vendor BitDefender in Portugal. "It seems Kaspersky aren't the only ones who need to secure their database. Bitdefender has the same problems," unu said in an online message. As of this posting, BitDefender had not confirmed whether unu's claims were accurate.

continue reading



Reblog this post [with Zemanta]

InterSwitch Introduces Africa's First Chip and PIN Card

InterSwitch introduces Africa’s first chip and PIN card
InterSwitch, Nigeria’s premier payment transactions switching company has launched the first African branded MasterCard MChip4 payment card brand into the vibrant e-payment market in Nigeria . This is in line with the Central Bank of Nigeria’s (CBN) directive which mandates all banks to convert all existing magnetic stripe cards to a more secure Chip and PIN platform by the end of 2009. The new product, Verve is accepted and being used across all available payment channels in Nigeria . Verve Cardholders can carry out payment transactions on over 11, 000 Point of Sale (PoS) terminals, 7, 300 Automated Teller Machines (ATMs), 200 Web merchants sites, and on 50, 000 mobile phones.

Mitchell Elegbe, chief executive officer (CEO) of InterSwitch, who spoke to newsmen at the verve media parley, noted that the CBNs directive is in the best interest of banks, merchants and cardholder as it is in tandem with global best practices.

This, he said, is because existing magnetic stripe cards have limited storage capabilities, offer little flexibility for business development and are easy to duplicate. He disclosed that the company has launched a campaign tagged “Get More Out of Life” to educate and enlighten Nigerians about the features of the verve card brand.


Elegbe explained that the Verve Chip and PIN card is specially designed by Nigerians for the world. Commenting on InterSwitch contribution to the development of the Nigerian e-payment space, Elegbe said: “Today, there are over 7, 300 ATMs on our network, over 12, 000 PoS terminals as at the last day of January, we have all the 24 banks in Nigeria connected to the switch while 19 state governments rely on the platform for the collection of internally generated revenue. There are over 28 million InterSwitch enabled cards active on the network as at today”.

He pointed out that despite the global switch to Chip and PIN cards the company and its partner banks in 2003 opted for the simple magnetic stripe technology because of its adaptability and cost at that point in time.

“Therefore, the next level for us is to begin to replace the 26 million cards out there with this new technology that is
more secure and customer friendly. After an extensive research and design that spans over two and the half years, we have come up a card that delivers more security features, more channels, more reward, more value to cardholders, banks and merchants”, he added. In terms of security, the Interswitch MD boasted that the company’s Chip and PIN smart card is one of the smartest cards around. “We have woven a number of security features and fraud management solutions incorporated into it. These fraud initiatives were developed to address various types of fraud which have been observed in the last couple of years.”

They include: Fraud Aware (this is the Cardholder Awareness initiative – aimed at educating cardholders about the importance of safeguarding their PINs), Fraud Insure – card fraud Insurance, Money Guard – SMS alert and response system.Also, Data Guard – this ensures that international standards such as PCI DSS standards, ISO 27001, Identity Guard – a token for two-factor authentication, Chip Authentication Program (CAP), Fraud Watch – a portal and email for fraud reporting.

Author of this article: Ben Uzor Jr

January E-Commerce Shows Some Bright Spots


Order dollar value up

January was a month of casual browsing, with limited purchases at online retailers, according to a report from marketing firm Coremetrics.

The number of online sessions in which consumers browsed a Web site, viewing at least one product page, stayed largely flat compared to December 2008. The number of sessions in which consumers actually completed an order was down 21 percent.

The only categories that saw increases were intimate apparel (up 5.5%) and office supplies retailers (up 8%). Specialty retailers reported a 56 percent drop in online orders, the largest decrease in any retail category tracked by Coremetrics.

"Our data suggest that consumers are very nervous about the economy and that an economic recovery fueled in large part by online consumer spending has not happened yet," said John Squire, chief strategy officer for Coremetrics. (pictured on right)

"It isn't all doom and gloom, however. Some categories are actually doing a good job of attracting consumers. And when we look at the average number of items per online order, we see that those consumers who actually decided to buy online bought more items for a higher total dollar amount."

Compared to December 2008, the average number of items that consumers purchased per order increased 23 percent in the online retail category as a whole. The average dollar value of those orders also rose by 8 percent.

continue reading

Mazooma Launches Alternative Payment

Here's an article from Digital Transaction News on the launch of Mazzoma, which purports to allow consumers to pay for online purchases in real time directly from their bank. 
A downward-spiraling economy is accelerating what had already been a rapidly developing trend for startups to introduce online payment methods as alternatives to bank cards. Indeed, one such company, Miami-based Mazooma Inc., launched a cash-based commercial service on Tuesday with the premise that consumers are looking for ways to buy online without using credit. “It’s a Zeitgeist product right now,” says Sean Kelly, chief executive of Mazooma and a former retail entrepreneur, referring to what he sees as a consumer trend toward cash and frugality. “If you don’t have the money you don’t want to spend it [on credit].”

Kelly says 12-employee Mazooma currently processes for seven online sellers, but expects to bring on another 20 to 25 that are in the “integration queue.” Helping in the effort to attract merchants is Mazooma’s inclusion in the widely used Centinel platform managed by CardinalCommerce Corp. The platform, which features a number of alternative-payment and online-authentication products, allows client merchants to more readily adopt new payment methods. Mazooma is seeking more such deals with gateways and third-party processors, Kelly says.

But Mazooma is entering a crowded market that seems to attract more companies by the week. Just last week, Amazon.com Inc. launched the commercial version of its Flexible Payments Service, a product that allows wide-ranging customization by merchant developers and handles payments through multiple channels (Digital Transactions News, Feb. 5). And this week, Noca Inc., a startup founded and run by a former Visa Inc. executive, announced its beta version of a service that relies on the automated clearing house network.

The challenge for Mazooma, as well as for its many competitors, is getting consumers to change ingrained behavior patterns while online. “From a branding and behavior-change perspective, it’s going to be difficult in the early going,” says Bruce Cundiff, director of payment research and consulting at Pleasanton, Calif.-based Javelin Strategy & Research.

Mazooma is betting on more than the sour economy to attract consumers and merchants. Its service allows consumers to use their online-banking programs to pay merchants by authorizing a transfer from their demand deposit accounts to a holding account maintained by Mazooma. The company then wires payments to merchants, with next-day settlement. Transactions are authorized and authenticated through the online-banking system used by the consumer, but Mazooma doesn’t offer a funds guarantee to the merchant. “It’s extremely difficult for the consumer to repudiate [these transactions],” Kelly says. “It’s not guaranteed, but it’s as close as possible without being guaranteed.” The fee to the merchant starts at 1% for very high-volume retailers and goes up from there. A merchant in the range of $30 million to $40 million in annual sales would pay about 1.5% plus 20 cents, Kelly says.

To make the system work with as many consumer accounts as possible from the start, Mazooma offers connections to 14 major banks representing what Kelly says amounts to 70% of the country’s checking accounts. “And it’s growing,” he says. Unlike other payments systems that rely on online-banking programs—for example, the Secure Vault Payments product now in a pilot sponsored by NACHA, the regulator of the ACH—Mazooma’s service establishes no formal ties to the banks. Instead, it uses consumer log-in credentials to initiate an automated session with the chosen bank program to verify identity and funds availability. “We act as an intelligent agent for the consumer,” says Kelly. Mazooma’s servers, he says, do not store these credentials. “There’s nothing to breach,” Kelly says. As a result, Mazooma is designed for spontaneous online transactions rather than functions like recurring bill payments

To use Mazooma, consumers at checkout click on a Mazooma button with the tag line, “Would you like to pay directly from your bank account?” First-time users are asked to fill in five fields of information, including name, address, and date of birth, and to create a password. After that, Mazooma handles the log in to consumer accounts in the background and returns a confirmation to the consumer and merchant. Merchants must integrate a Mazooma application programming interface, a process Kelly says can take five hours, more for some merchants. With the system in place, consumers are briefly redirected to Mazooma’s servers but believe they are on the merchant site throughout the session.

The “intelligent agent” model may make for a smooth consumer experience, but it could present complications with consumers worried about malware that could enable links that appear to be legitimate but aren’t. The Mazooma model is “a double-edge sword,” says Cundiff. “How do I know I’m really connected to [my bank] right now? I’m popping my log-in in there, and I don’t know what I’m popping it into.”

Still, Kelly says Mazooma’s timing may have been just right. “The credit crisis is terrible, but we’ve had a ton of attention over the past few months,” he says. “Mazooma is a great product for the time.”





, , , ,

New Payment Rules Before Parliament

On Friday I posted a press release announcing how the European Parliament wanted to strengthen the security of online payments.  Yesterday they met and new rules have been laid out. 

According to information provided by international law firm Pinsent Masons on their their webite:  www.out-law.com,  yesterday some new Payment Services Regulations were been laid before Parliament.  They include (as have I) links to the 81 page 2009 Payment Services Regulations  and the Explanatory memo from the HM Treasury.

Here's there report:

The regulation of credit and debit cards and other payment services will be tightened in the UK from November. New rules were laid before Parliament yesterday that aim to deliver greater competition in the market for payment services.

The Payment Services Regulations will apply to everyday payments such as cash deposits and withdrawals, credit transfers, direct debits, credit and debit card payments, money remittance payments and other digital payment services.

The Regulations implement the EU's Payment Services Directive (PSD) of 2007 into UK legislation. They are due to come into force on 2nd March 2009 and the PSD regulatory regime will be in place on 1st November 2009. The Financial Services Authority will be the regulator for most aspects of the regime.

The Directive stipulates the information that providers must give or make available to their customers before, during and after a transaction is made, for example, how long the payment will take to get to the recipient, and ensuring they are informed of the exchange rate and charges for any currency conversions prior to initiation.

It introduces a maximum one-month notice period for customers to be able to terminate a payment service contract with their provider, with no charges allowed for terminating a contract after 12 months.

The Directive also establishes what users must do, for instance in protecting their PIN number, and what providers must do, for instance in ensuring there is a phone line or other means of contact for the user at all times, in the event that their payment card is lost or stolen. The rules also explain what happens when things go wrong with a payment, providing refund rights for disputed payments, and set out the circumstances in which the payment service provider (e.g. the bank) will be liable.

The new Regulations affect domestic payments made in Sterling, in Euro and other non-Euro EU currencies, as well as cross-border EU payments from Sterling and other non-Euro EU currencies into Euro.

Lord Myners, Financial Services Secretary to the Treasury, said: "This legislation will drive competition in the market for payment services, leading to greater efficiency, transparency and more innovation, bringing further benefits and certainty to UK consumers and businesses making everyday payments."

"It will also enhance consumer protection, with the new rules for payment service providers," he said.

The PSD will also enable UK-based, non-bank businesses to enter and compete in the EU payments market on the basis of a licence obtained from the FSA in the UK. Licensing requirements are based on a prudential authorisation regime. Small firms operating in the UK only will only need to register with the FSA, and comply with the relevant anti-money laundering supervisory requirements.

The legislation also introduces statutory EU-wide conduct of business rules, requiring providers to properly inform their customers about the payments they are making, and rights and responsibilities for providers and users, to increase certainty about the way payments will be delivered.

The FSA will shortly be issuing guidance for businesses.



Reblog this post [with Zemanta]

Monday, February 9, 2009

HomeATM Client UATP Unveils New Website

UATP Unveils New Public Web Site

UATP is a global travel payment network. UATP accounts are actively issued by 15 member airlines and accepted as a form of payment for corporate business travel by more than 200 airlines worldwide.

Airlines currently issuing UATP accounts include Aer Lingus, Air New Zealand, Alitalia, American Airlines, Austrian Airlines, British Airways, Continental Airlines, Delta Air Lines, Japan Airlines, KLM Royal Dutch Airlines, Lufthansa German Airlines, Qantas Airways, Ltd., Scandinavian Airlines System, United Airlines and US Airways. For information, visit uatp.com. (PRNewsFoto/UATP)

WASHINGTON, DC UNITED STATES

WASHINGTON, Feb. 9 /PRNewswire/ -- Universal Air Travel Plan, Inc. (UATP), announced today the launch of its re-designed public web site: uatp.com. The new site focuses on UATP's core corporate charge card program, as well as UATP's new and successful business lines including:


"The new site offers targeted information to airlines, travel agents, corporations and travelers; it is part of our global effort to raise UATP brand awareness," said UATP President and CEO, Ralph Kaiser. "We've had significant growth in the past few years and want our brand to reflect that success; launching the new web site is just the beginning."

The new design features vastly improved navigability, enhanced internal search engine, upgraded events and press section as well as improved UATP information for Issuers, Merchants and corporate customers alike. New features to the site include information available in several micro-sites in Chinese, French, German, Japanese Portuguese and Spanish. Additional micro-sites will be added as UATP continues to expand its international reach.

UATP had a record year in 2008 with approximately US$12 billion in total charge volume.

About UATP

UATP accounts are accepted as a form of payment for corporate business travel by airlines and travel agencies worldwide. UATP accounts are issued by: Air New Zealand (ANZFF.PK), American Airlines (NYSE: AMR), Austrian Airlines (AUALF.PK), Continental Airlines (NYSE: CAL), Delta Air Lines (NYSE: DAL), Japan Airlines (JALSY.PK), Northwest Airlines, Qantas Airways, Ltd. (QUBSF.PK), United Airlines (Nasdaq: UAUA), and US Airways (NYSE: LCC). AirPlus International issues the UATP-based Company Account for: British Airways (LSE: BAY.L), Continental Airlines (NYSE: CAL), and Lufthansa German Airlines.

Contact:
UATP Corporate Communications
Wendy Ward, wward@uatp.com
+1 202 626 4077


SOURCE Universal Air Travel Plan, Inc.

Comments Have Been Enabled on the HomeATM Blog

With the rising number of people visiting the HomeATM PIN Debit Payments Blog, I have decided to enable a "Comments" feature in order to make the blog more interactive.

To leave a comment, click the title of the post your wish to leave one on and the "Comments" feature will be located on the bottom of the post.

Please feel free to leave your thoughts, questions, criticisms, or ideas on how to make the blog better in the comments section. Comments will be moderated to prevent spam comments.

Melissa Antonelli, a regular contributor to the TrialPay blog, gets credit for the first (1st!) comment (left) and actually sparked the the idea that maybe I should enable comments.

Thanks Melissa for your kind words. TrialPay recently surpassed 20 million users...("TrialPay Adds 5 Million Users in 54 Days!")...maybe we can discuss how HomeATM and TrialPay can mutally benefit each other at the Retail West show here in Phoenix/February 21-23rd.

And once again, to everyone else, thanks for following the HomeATM blog and we welcome and encourage you to share any thoughts and ideas you may have...

JBF and the folks at HomeATM!

M-Cube Offers Prepaid Mobile Banking

Banking Technology reports that M-Cube, which is a part of VeriSign, is offering a Prepaid Mobile Banking Platform...

M-Cube offers mobile banking for Ryanair prepaid members | Banking Technology magazine - UK

M-Cube has launched the M-Cube M-Payments Platform, a mobile banking application for consumers using prepaid cards in the UK and Ireland. This application will be immediately available to members of the M-Cube Ryanair Prepaid Programme and should be functional across the range of M-Cube backed prepaid cards.

The Ryanair Prepaid Programme, launched in November 2008, is a mass market multi-brand prepaid programme created by a prepaid card provider in the UK and Ireland. Holders of other M-Cube backed prepaid cards will also be offered access to the mobile application.

Using the M-Payments Platform, cardholders should be able to carry out a range of transactions directly from their mobile phones without the need to sign into their account via a computer. The services available to cardholders include:

  • Activation of a new prepaid card
  • Checking account balances
  • Obtain a mini-statement of recent account transactions
  • Top up prepaid card with funds
  • Report a prepaid card as lost or stolen
  • Live chat
  • Foreign currency transfers
  • Transfer between accounts

The M-payments application has been developed in partnership with information security experts Network Security Solutions using the firm's proprietary mobile text messaging security backbone, Xecure Message Service.

Surprise! ID Theft on Rise

ID theft on the rise, but costs down - Phoenix Business Journal:
The number of reported identity theft cases jumped 22 percent from 2007 to 2008 in the U.S., to 9.9 million, according to Javelin Strategy and Research, but the financial impact on victims has dropped.  Editor's note:  Financial impact on "individual victims" has dropped...because there's 22% more of them. 

The cost per incident -- including unrecovered losses and legal fees -- fell 31 percent, to less than $500, the San Francisco firm reports.

Identity fraud is defined as the unauthorized use of another person’s personal information to achieve illicit financial gain.

The survey says almost half of the cases are linked to stolen wallets, while only 11 percent of the victims had their identities stolen over the Internet. (Editor's Note: I expect that number to jump, maybe even double this year, until there's end-to-end encryption)  Heartland will contribute as will other breaches this year. 

We still don't know what's going on with Adele Services either. See: (Major Credit Card Hack Starting?)

Women were 26 percent more likely to be victims of identity theft.

“The good news is research shows consumers have more control than they may think and more of them are actively taking steps to protect themselves,” said James Van Dyke, president and founder of Javelin Strategy & Research, in a company statement. “Additionally, the financial industry has made significant strides to resolve fraud incidents for their customers and put stronger controls in place to limit fraud, which is lessening the impact of this crime”

Javelin Strategy & Research has been researching identity fraud for five years with 24,000 U.S. respondents involved in its survey. In October, nearly 4,800 telephone interviews were conducted to for the study.

Sorry Noca...NoCanDo

Rafe Needleman at CNET writes about a startup that is offering a new online payment system.  The problem is that users have to enter their checking account AND routing numbers via a keyboard online. 

If "noca" believes that enabling consumers to pay directly out of their checking accounts by typing their Checking Account Number (CAN) and bank routing numbers into a browser space with a keyboard they might want to revisit that idea. 



Followers of this blog undoubtedly know my stance on typing/entering any account numbers online.   Sorry...No Can Do...I'm just not the type.


Anyway...during a demo of a $10 transaction, Rafe needled the CEO about the security of the system (it asked for a mobile phone number, then called it and gave it a PIN) but the CEO, said that if it was a bigger amount, it "may have" incorporated  a tougher question.  May have?  Brilliant!

Now I don't know if the CEO (pictured on right)  was sleep walking when he did the interview, but  "PJ" Gupka, (who stated he was formerly in charge of VIsa network architecture) said that his system is more secure than Visa's

I would think that when scheduling a demo in front of CNET,  purporting your system "is more secure than Visa's" (especially with security being such a hot topic following the Heartland breach), you may want to choose the amount that actually incorporates those "tougher security measures."  At the end of the day though, if you are typing your "CAN" with a keyboard, (and your routing number) it doesn't matter how they encrypt it or what type or how many algorithms they use.  The data is fair game UNTIL it's encrypted.  It appears that it's not encrypted until it's captured, and my concern is that via a myriad of hacker inspired methodologies, it can be captured by them first.  Since the  security of a transaction is only as secure as it's "weakest" link, then this doesn't appear to be very secure at all. 

End-To-End Encryption (E2EE) is the only way to guarantee a secure transaction.  That's why Heartlands CEO is calling for it, (after a potential 100 million card breach) and more importantly, why HomeATM has provided E2EE on ALL it's transactions since January of '07.  Now I'm no security expert, I know (maybe) enough to be dangerous (to myself) but I think I'm within my rights to recommend that you don't buy the "type hype." Malware, keylogging, sniffers, bots, etc will tell you that.  Heck, Heartland got hacked and they were PCI certified.  They got nailed when they "unencrypted" the card data.  Nobody "typed" their card, oh excuse me, in this case, their checkiing account numbers online.  Sounds like a good idea 5 years ago...not today. 


Here's the story...with some of my comments included:
A new way to pay: Noca's credit card alternative
Rafe Needleman - Rafe Needleman writes about start-ups, new technologies, and Web 2.0 products, as editor of CNET's Webware.  e-mail Rafe.

When you buy a product online and use either a credit card or Paypal, a significant percentage of your transaction cost--from 2.5 percent to 4 percent when all the fees are considered--goes straight to either the credit card processing company or to PayPal.  With so many retailers operating at such slim margins already, this is a material expense. While payment processing will probably never be free, a new company, Noca, is launching today that undercuts payment processing by an order of magnitude: It charges just 0.25 percent for transactions.  (Editor's Note:  I think they meant .0025% if it's 2.5 basis points)


Noca, CEO PJ Gupta told me, does not enable credit of any sort. Rather, it's a financial interchange platform that lets consumers pay for goods through direct checking account withdrawals.

Gupta told me he was formerly in charge of Visa's network architecture, and that Noca is built in a more efficient way. "There's no reason to use IBM servers today," as the credit card processing companies do. "There are two to three order of magnitude of inefficiencies there." (Editor's Note:  He sure likes that "order of magnitude" line, doesn't he?  I wonder to which order of magnitude his system blows away the efficiency of Visa and IBM)


He also says that Noca is more secure. Transactions are handled and encrypted by Noca's servers; merchants never see the checking account and bank routing numbers consumers enter (the same is true of PayPal transactions). Editor's Note:  The merchants are NOT the one's I'm worried about...it's the "hackers."  If a user "types or clicks" his Credit Card, Debit Card, PIN number, Social Security Number, it doesn't matter, online, it can be had )  An additional, adaptive security comes in to play depending on the type and amount of the transaction.  (Editor's Note:  It doesn't matter, it's fair game when you type instead of swipe.)

In a live demo where Gupta was buying $10 worth of digital goods from early Noca customer Klatcher, the system asked for a mobile phone number, sent a PIN to it, and required the user to enter that PIN on the transaction form. I didn't see how that added any security at all.  
(the buyer could give out any mobile number), but Gupta told me that if the transaction had been for more money or for physical goods, the verification process "might have" incorporated Yodlee's system of challenging the buyer to produce personal information from financial records, such as selecting an accurate previous address or amount of the buyer's regular mortgage check.

To pay using Noca, get out your checkbook and copy down some numbers. (Editor's Note: Get out my checkbook?  Did I go back in time?  Copy down some numbers...yes apparently I did) 

Gupta believes that the technology he's built to link into the banks, prevent fraud, and do so cheaply is a competitive barrier. But I am surprised that his customer roster at launch is sparse--only three vendors, and probably not one you've heard of. (Editor's Note:  ya think?) There are a dozen companies evaluating the system or getting closer to launching with it, Gupta says. There will be major vendors online with Noca, "well before June 30," he promised. (Editor's Note: More proof PJ is sleeping...now he's even dreaming)

One downside: (Editor's Note:  That was the punchline) Noca doesn't offer chargeback or dispute arbitration services. That's between merchants and their customers. But it does give consumers far more detailed transaction statements than credit cards or bank accounts.  (I don't know how smart that is either)

The author concludes by saying that Noca is a smart company for the current economy. Credit is tight for everyone, including consumers, some of whom are losing or just throwing out their credit cards.  Noca makes online purchasing easy and secure even without credit. And its lower fees could help make goods purchased online less expensive, too. 

Editor's Note:  Smart?  I didn't read anything I tought was smart about it.  For current economy? Question: Does anyone 14-41 years old even have a checkbook anymore, (NO Checking Accounts) or remember what drawer it's in?  "Makes online purchasing easy and secure?"  Typing in all those numbers, both your Checking Account Number (CAN) AND your routing number is neither convenient, nor easy and it's definitely NOT secure.

In closing, I guess there's two ways to make my point that noca will never do online, (ndo) 1. 1.  Add the "ndo" acronym to the end of their name and it creates a whole new message: Nocando. 

Put another way  Sorry noca, but:

N
O

Checking
A
ccount
Number
Done
Online 

In closing, I woke up in a sarcastic mood this morning (again) and used this story to further demonstrate that it is not safe to type any numbers (credit card, debit card, checking account, social security, etc) into a web browser.  If noca feels I went overboard, I would welcome their rebuttal and gladly post it here.  If you have any comments, click the title of this post and a comment form will appear at the bottom of the post.  Remember...Instead of Typin'...





Reblog this post [with Zemanta]

On Visa, Barclays and Heartland

Barclays Trounces Forecasts, Posts Flat Net
Wall Street Journal - USA
... the disposal of its life insurance book, and booked €291 million in profits on the initial public offering of VISA and sales of shares in MasterCard. ...
See all stories on this topic
Image representing Seeking Alpha as depicted i...Image via CrunchBase
Visa Rally May Be Short Lived
Seeking Alpha - New York,NY,USA
Investors in Visa and MasterCard will argue that this doesn’t matter because these companies simply process the transactions and do not have credit risk. ...
See all stories on this topic
Recent local debit card threat noted by Midwest Bank
York News-Times - York,NE,USA
Visa and MasterCard are working proactively with merchants, who are required to make changed in the way they store customer data and are required to report ...
See all stories on this topic
Reblog this post [with Zemanta]

Internet Growth Could Double Shares of Payment Provider - Barron's


Wirecard shares could double: Barron's

NEW YORK (Reuters) - Shares of Wirecard, a German online-payment processor, have fallen to about 4.40 euros from 11.65 euros last May, but the selloff is probably an overreaction and the shares could double in value, according to Barron's.

Wirecard is not immune from the contraction in consumer purchasing but the recession could actually accelerate growth in Internet purchasing, Barron's said.

The company has about an 8 percent share of Europe's 100 billion annual online transactions and could add another 1,000 customers this year as retailers outsource their Internet payment processing to cut costs, Borge Endresen, a portfolio manager of the AIM European Small Company Fund, told Barron's. AIM owned more than 300,000 wirecard shares as of December 31.

(Reporting by Helen Chernikoff; Editing by Bernard Orr)

Reblog this post [with Zemanta]

Video: Debit Card Thefts on Rise - Consumer Reports

Consumer Reports: Debit Card Thefts On The Risk
With the economy in trouble, all kinds of theft are on the rise, including criminals who are targeting debit cards. They've found a way to steal your PIN code and your money with the help of a device called a skimmer, which they install on ATM machines. Thieves then use the stolen information to create a new card.

Your whole account could be wiped out, including money you had set aside for your mortgage, for your car payment, or for other payments.

Attorney John Campbell, who helps victims of bank-card fraud, says you're most vulnerable at places such as gas stations, convenience stores, and airports, where it's easier to install skimmers. But even at your bank's ATM, check to make sure nothing looks loose or out of place.

Fortunately, Consumer Reports says there is one simple thing you can do to get better protection. When you're making a purchase with your bank card, press "credit" not "debit." The money is still deducted like a debit, but you don't use your PIN code...and so a criminal can't steal it. And by using the "credit" option, in most cases you'll only be responsible for $50 of any loss.

Consumer Reports says another important way to protect against debit-card theft is to check your account frequently online. That way, you can spot any suspicious activity right away.

Consumer Reports has no commercial relationship with any advertiser or sponsor appearing on this Web site.

Heartland Breach Won't "Disappear"

Huge bank card scam hits Bermuda
Bermuda Sun


Hundreds of debit and credit card customers in Bermuda have been dragged into one of the world's biggest security breaches.

Bank of Bermuda and Butterfield Bank are warning customers to be on guard after cyber-crooks hacked into the computer system of an overseas payment company.  Individuals and businesses with Visa and MasterCard cards are said to be at risk from the data breach at Heartland Payment Services.  Some 'compromised customers' have already had their bank accounts closed and replacement cards with new account numbers issued.

And the island's two biggest banks are now advising all card customers to monitor their statements to look for any suspicious activity.

Tech-security experts said the breach could set a worldwide record. It is believed that the scam could be the result of a "widespread cyber fraud operation" and the stolen data could be used to make fake cards.Bank of Bermuda confirmed its customers had been affected and it was doing all it could to protect them.


Lisa Fox, head of card services at the Bank of Bermuda, said the bank was working to safeguard its affected customers by contacting them directly, closing compromised accounts and issuing replacement cards.


Robert O. Carr, Heartland's chairman and CEO, said he "sincerely regretted any inconvenience caused" by the data breach. He stressed that no personal information such as cardholder's PIN numbers, addresses or telephone numbers had been stolen.  Mr. Carr said: "We will not rest (in peace?) until we have the answers to how and why this breach occurred so we can prevent any future attacks at Heartland and elsewhere.

Full Story from Bermuda Sun







Reblog this post [with Zemanta]

Disqus for ePayment News