Welcome to the new IRNewsLink Financials Welcome to the new monthly IRNewsLink Financials newsletter. Understanding the financial performance of retailers and the technology and services providers who serve them has never been more important than in today’s economy. With this new monthly edition of IRNewsLink, readers can follow key financial and operations metrics. Included in this report are charts and articles that summarize the monthly activity of retailers’ web sales, the financial performance of key vendors, new equity deals, recent mergers and acquisitions, and Internet Retailer’s new stock index. Web sales continue to increase Internet retailers continue to grow sales both on a quarterly and an annual basis. The combined quarterly sales of 17 web retailers that broke out sales in January and early February grew by 14.1% to $8.25 billion in 2008 from $7.23 billion in the comparable quarter in 2007. The combined annual sales of 14 retailers grew by 24.6% to $23.04 billion in 2008 from $18.49 billion in 2007.
Quarterly vendor sales grow slightly The combined quarterly sales of 11 companies in January and early February grew by just 0.6% to $21.12 billion in 2008 from $20.99 billion in 2007. The combined annual sales of 10 vendors grew by 11% to $84.40 billion in 2008 from $76.03 billion in 2007. Service & technology providers
Rising Above - Not Just Surviving - The Economic Storm
The Internet Retailer 2009 Conference & Exhibition, America's Fastest Growing Show *, will be held June 15-18, 2009 at the Boston Convention & Exhibition Center. IRCE 2009 is devoted to the strategies and tools that e-retailers can use to thrive in a recession. It draws e-retailers from all channels with the most comprehensive conference agenda and the largest display of e-retailing technology. Hear 179 E-Retail Pros in 94 conference sessions, visit 350 exhibiting companies and network with 5,000 E-Retailers.
Bank Info Security is reporting that the first arrests have been made in the Heartland Breach as the list of banks (157 yesterday) has now grown to 220. They have outstanding coverage on the Heartland Breach. To visit their coverage of the breach, click here. Here's a snippet from their report:
The list of financial institutions impacted by the Heartland Payment Systems (HPY) breach now tops 220. In related news, three men in Florida were arrested earlier this week on multiple charges of credit card fraud, and some of the card numbers they allegedly used are tied to the Heartland hack. Heartland Payment Systems data breach coverage
The Leon County, FL. Sheriff's office arrested area residents Tony Acreus, Jeremy Frazier and Timothy Johns, who had allegedly used stolen credit card numbers since November, according to Sgt. Tony Drzewiecki, spokesman for the sheriff's office.
According to the Tallahassee, FL. Democrat, the suspects were running "a very sophisticated and complex criminal enterprise." Law enforcement is investigating how the three men were able to obtain credit card numbers from the Heartland breach, which was first announced on January 20.
Meanwhile, in just over a week, the number of financial institutions that have come forward to say they have been contacted by their credit card companies Visa and MasterCard in relation to the breach has jumped from fewer than 50 to more than 200...
Did you know that the fear of Friday the 13th is called "paraskavedekatriaphobia",a word derived from the concatenation of the Greek words Paraskeví (Παρασκευή) (meaning Friday), and dekatreís (δεκατρείς) (meaning thirteen), attached to phobía (φοβία) (meaning fear)? Now you do.
This is a specialized form of triskaidekaphobia, a simple phobia (fear) of the number thirteen, and is also known as friggatriskaidekaphobia. The term triskaidekaphobia was derived in 1911 and first appeared in a mainstream source in 1953.
Personally, I consider Friday the 13th to be a day of good luck, however that's not true for many. Some Frigga'n people walk around afraid the sky is falling. Which reminds me, did the stimulus bill pass yet?
Tarmo Virki, a European technology correspondent writes for Reuters about the mobile banking business. Apparently, one of the issues holding mobile banking back is who's going to get the most buck outta the bang...
HELSINKI (Reuters) - The mobile banking business is growing in countries like Kenya, Turkey and Japan, while the combining of wallets with cell phones has been held back elsewhere by disagreements over sharing revenues.
In Kenya and Turkey, millions of people use phones to send money or access their bank accounts; in Japan, more than 50 million people, or about half of all cell phone users, already carry phones capable of serving as wallets.
The technology for paying with cell phones by flashing them near reading equipment in stores or on public transport is ready, and the initial feedback is good, said Mary Carol, head of mobile in Visa Europe (V.N).
"Trials show that consumers overwhelmingly like it," Carol said. "The biggest problem has been the business model." It will also take at least until 2010 before phones equipped with such technology are widely available, and the financial industry and telecom operators need to agree on some kind of revenue and role split, industry executives say.
The meeting of the two industries will be one of the key topics next week at the Mobile World Congress trade show in Barcelona.
"Both -- the financial sector and telecom operators -- want to own the relationship with the client, this is one of the hottest issues," said Juha Murtopuro, chief executive of Valimo Wireless, which provides cell phone identification technologies.
Murtopuro and other industry players said they expect a compromise to be eventually found, with solutions to vary from market to market. But the ingredients are already there, given the number of consumers already owning both a mobile phone and bank account.
There is no question that the Internet is now a mainstream medium.
eMarketer estimates the US Internet population will grow to nearly 200 million users this year. By 2013, some 221 million people will be online.
Nearly 65% of Americans use the Internet today, and by 2013 that figure will rise to nearly 70% of the population.
“The US Internet population more closely reflects the general population than ever,” says Lisa E. Phillips, eMarketer senior analyst and author of the new report, US Internet Users.
“More females are online than males—although males tend to spend more time once they go online,” says Ms. Phillips.In fact, eMarketer projects that females will make up 51.8% of the US Internet population this year, and males 48.2%.
Not unexpectedly, the economy is having an effect on Internet usage.According to comScore, 18.8 million people conducted online job searches in December 2008, a 51% increase in unique visitors compared with a year earlier.To learn more about who’s online, and what they are doing, download the new eMarketer report, US Internet Users, today.
In the wake of what might be the biggest breach ever, Heartland founder and CEO said that if there was end-to-end encryption (E2EE), the breach would not have occurred.
End-to-end encryption (E2EE) encrypts clear (red) data at source with knowledge of the intended recipient, allowing the encrypted (black) data to travel safely through vulnerable channels to its recipient where it can be decrypted (assuming the destination shares the necessary key-variables and algorithms).
Since January of '07 every transaction HomeATM has processed was encrypted from the beginning to the end, thus preventing any data from ever being in the clear.
So, whereas Heartland is calling for E2EE after the fact, HomeATM has done it that way for well over a year now. What exactly is encryption and what exactly is E2EE? Here's a basic primer:
First, lets define encryption, which is the method of encoding information using a password, in order to hide the real information from others. The technique is used for transferring data between computers and wireless networks.
Encryption occurs through mathematical algorithms, which interpret the information to be hidden and create the encrypted data. Encryption is very common in both the computer security field and some everyday technologies. It plays an important role in assuring that data remains confidential.
Numerous methods of encryption exist for different purposes, and some of the more common algorithms include RSA, DES (HomeATM uses Triple DES) and AES. The strength of encryption is based on the size of the key used in the algorithm. Most algorithms rely on a 128-bit key, which is the standard for most algorithms approved by the Government. The use of longer keys, such as a 256-bit key, creates a stronger security level for encryption.
Virtual Private Network (VPN) VPNs are used to create secure connections between a remote host and a network. These are typically used when telecommuters working from home connect to an office network to do work. VPNs use secure channels to transfer data, which is encrypted between the remote computer and network to protect private information.
Secure Socket Layer (SSL) SSL is an encryption method used for secure Internet communication. SSL is used for shopping websites, online banking, and any other secure login or credit card processing websites. The use of SSL on websites ensures that the transferred information cannot be captured by packet sniffers. Or at least it used to.
Sensitive data that travels over a network are securely encrypted from the point of data entry to the point where the data is processed. Sensitive data may be user name, password, credit card number, etc. The network can be the Internet, wireless, WAN and local LAN. Data are normally entered via the browser or a client application and the data will need to reach the application server to be processed or stored in the database.
So, doesn't HTTPS performs data encryption from one point to another? Well, in most cases, only partially.
In a multi-tier architecture, it is usually the dedicated Web Server that is handling the HTTPS. The link from the Web Server to the Application server or the Database server is most likely in the clear. If the Web Server is compromised, a simple net-sniffing will reveal all the data that is posted.
In closing, Dark Reading has an article regarding encryption today. Here's a snippet:
A group of vendors have proposed a new industry standard designed to simplify the implementation and management of encryption technology across large enterprises.
Brocade, HP, IBM, LSI, RSA, Seagate, and Thales (formerly nCipher) today announced the creation of the Key Management Interoperability Protocol (KMIP), a jointly developed specification for enterprise key management. KMIP is designed to provide a single protocol for communication between enterprise key management services and encryption systems, the companies say.
The problem with encryption, particularly in large enterprises, is that there are so many products and methods of doing it, observers say. Companies often deploy separate encryption systems for different business uses, such as laptops, storage, databases, and applications. And each encryption product typically has a different method of generating, distributing, storing, expiring, and rotating encryption "keys" -- the technologies that code and decode the data.
The concept of "key management" -- the practices associated with generating and storing encryption keys across an enterprise -- has been debated for decades. But vendors and cryptographers have never been able to agree on the best way to do it, leaving enterprise security managers stuck with the largely manual process of managing keys separately for each vendor or product. This administrative issue has made enterprises slow to roll out encryption on a broad scale.
DCS has entered into partnership with Postilion to offer financial institutions an integrated system for card management, instant issuance and PIN selection. Maybe they should be partnering with Heartland too. The question I have is whether this was done to meet the demand created by the Heartland Breach or whether this was done because they are banking on another major one? (Got Hacked? Bank on It) Here's the press release. That's two today for Postilion.
Dynamic Card Solutions or DCS has entered into a partnership with Postilion, a division of S1 Corporation, to offer financial institutions an integrated system for card management, instant issuance and PIN selection, by connecting DCS's patented CardWizard services with Postilion for card issuers. (Editor's Note: Sounds like they see the opportunity created by the Heartland breach...)
Postilion said that instant card issuance provides banks with improved service for new account holders and allows for the immediate replacement of lost or stolen cards for current customers. Dynamic Card Solutions (DCS) CardWizard instant issue software personalizes the chip, encodes the magnetic stripe, and prints or embosses cardholder details on each card. (Sounds like they should be partnering with Heartland too)
Postilion for Card Issuers provides complete life cycle management for a range of card products with full support for Europay, MasterCard and Visa (EMV), including contactless, and PIN control. The integrated system also enables customers to select their own PINs at the time of issue, which is expected to increase activation rates, allows for the immediate use of the card, and eliminates the costs of PIN mailers.
Mark McMurtrie, marketing director of Postilion International, said: "Instant issuance is now both easy to implement thanks to advances in technology, and it makes an ideal complement to our product suite. This service, which includes immediate card replacement and the freedom for customers to choose their own card designs, can support card issuers with customer acquisition, retention and portfolio profitability."
The Arab National Bank has selected a Postilion, (a division of S1) solution to manage its card issuance programme.
The implementation will meet the bank’s international EMV compliancy needs, as well as provide it with complete lifecycle management for debit cards, including the preparation of production files, PIN generation, and account status management.
The enterprise level system sits in the bank’s computer centre and runs on Microsoft Windows Server technology, as well as making use of SQL Server database. Postilion says that the comparatively low cost of the Microsoft hardware and applications transferred directly to a lower total cost of ownership for the implementation, thus making it a more compelling offer for the bank.
The bank also plans to introduce instant card issuance at its branches with the help of Dynamic Card Solutions (DCS). This is expected to improve service for new customers and facilitate the rapid replacement of lost or stolen cards for current customers. The CardWizard instant issue software fully personalises the chip, encodes the magnetic stripe, and prints cardholder details on each EMV debit card