Monday, March 2, 2009

Who Needs an Ounce of Prevention...We Have 10 pounds of Cure!

Barclays bank has rolled out a contactless Visa debit card - ZDNet.com.uk

From Monday, Barclays customers will receive new or replacement cards containing RFID technology that will allow contactless transactions of up to ten pounds, without entering a PIN. (Editor's Note:  Limiting transactions to 10 pounds ($14.10 US) is not a testament to the security of the methodology is it?)

Cards will continue to be used for chip and PIN transactions and bank machine withdrawals.  (Editor's Note:  HomeATM uses the same bank rails used for bank machine withdrawals)

The protocol behind the contactless technology has not been made available to academic security researchers, according Cambridge University researcher Steven Murdoch, who expressed concerns that any security holes in the technology won't be found until after it has been rolled out.

"The problem with the UK contactless system is that it's secret, which means we have to reverse engineer it to point out vulnerabilities," Murdoch told ZDNet UK on Monday. "Contactless payment has been rolled out, but any security vulnerabilities will be pointed out after the banks can do anything about it."

Murdoch said that while security researchers were restricted from viewing the protocol, people with malicious intent would be able to view it.  "I'm sure crooks will have a copy of the spec," said Murdoch. "People can get hold of a copy if they sign a contract saying they will not make any reports [about the protocol]. Any criminals could get hold of a copy of the specification, but academics are at a disadvantage."

A Barclays spokesperson told ZDNet UK on Monday that there had been extensive third party testing of the contactless system, and said that security risks around contactless payments had been mitigated.

Editor's Note:  Yeah, by limiting transactions to 10 pounds.  The money that hackers could steal is only 1% of what they could get by hacking into a system where they could steal 1000 pounds.  So I suppose, in a bend it like Beckham way...that statement could be "bent" into somehow being being defended as true.

"Contactless is designed for small transactions, while users will periodically be asked for a PIN," said the spokesperson. "The card uses dynamic data authentication, in which a unique secret code is generated to authenticate each transaction, while the chip contains different information than the magnetic strip, to prevent cloning."

The Barclays spokesperson added that testers had concluded that it would not be economically viable for criminals to subvert the system.  "The cost of intercepting the information doesn't justify how much could be made out of the information," said the spokesperson.

(Translation:  Sure...we know it's not secure, but we limit the purchases that can be made with this insecure non-solution to 10 pounds, so that shouldn't interest the hackers.  They can  make more by concentrated on bigger payouts.  Who needs prevention"...we've got 10 pounds of cure!)

Cambridge University researchers have said they have serious security concerns about chip and pin payments systems. Researchers Saar Drimer, Ross Anderson, and Murdoch published a paper on Thursday detailing security flaws in the Chip Authentication Programme (CAP) used for UK payments cards. The main problem for the researchers was that the some UK online cards payments systems using readers had been optimized for usability, to the extent of sacrificing security
Editor's Note:  You simply cannot sacrifice "convenience" for security.  No way, no how.  Security needs to be first and foremost on the minds of payment industry professionals.   HomeATM understands that, which is why we implore online shoppers to "swipe" their own card information in our tamper-proof, PCI 2.0* PED providing a "dually authenticated," "3DES end-to-end encrypted" online debit solution. (with DUKPT)   Don't call us alternative...the "alternative" is entering your card information "manually"...and having it get intercepted and "swiped" by the bad guys. Swipe...don't Type. 

*HomeATM's personal SwipePIN device has been rigorously tested by Witham Laborities (1 of 8 certification outfits in the world) and found to meet or exceed PCI 2.0 requirements.  Our device and the Witham Lab's report has been forwarded through the proper channels for PCI. 2.0 certification. 

Reblog this post [with Zemanta]

CBN Orders Banks to Stop Issuing Magstripe Payment Cards

The Central Bank of Nigeria (CBN) has ordered banks to Stop issuing magnetic stripe payment cards by April 1st 2009.A magnetic stripe payment card is a type of card capable of storing data by modifying the magnetism of tiny iron-based magnetic particles on a band of magnetic material on the card. The magnetic stripe, sometimes called a magstripe, is read by physical contact and swiping past a reading head.

On the other hand is the Smart (or chip) card which is the latest in payment card technology. This is a plastic card containing a computer chip and enabling the holder to purchase goods and services, enter restricted areas, access medical, financial, or other records, or performs other operations requiring data stored on the chip.

It has a built-in microprocessor and memory used for identification or financial transactions. When inserted into a reader, it transfers data to and from a central computer. It is more secure than a magnetic stripe card and can be programmed to self-destruct if the wrong password is entered too many times. As a financial transaction card, it can be loaded with digital money and used like a travelers check, except that variable amounts of money can be spent until the balance is zero.

In a circular to all banks titled, “Extension of Timeline for Migration from Magnetic stripe to Chip plus PIN/EMV, signed by the Acting director, banking supervision department, Mr. James Olekah, the CBN stated that, “Recall that section l,4.2c of the e-banking guidelines issued in 2003 by the CBN stipulates that “in view of the demonstrated weaknesses in the magnetic strip technology banks should adopt the chip( smart card) as the standard, within five years”. The implication of this is that the timeline given to card issuers in the guidelines had expired as at the end of August, 2008. However, after due considerations of the concerns from the market and other stakeholders,

The National Payments System Committee agree to extend the deadline for the migration to Chip+PIN technology to April 1, 2009. You are by this circular required to cease the issuance of new magnetic strip cards with effect from April 1, 2009. However, previously issued magnetic should be withdrawn on expiration of the cards and not as at April 1, 2009. Please note that no new extension of the time would be granted, while failure to comply with this directive will attract severe sanctions which would include imposition of financial penalty and withdrawal of approvals.”

It would be recalled that recently, in anticipation of the directive of the CBN on Chip Cards, InterSwitch,Nigeria’s premier payment transactions switching company, introduced Verve card, a pan-African innovative chip and PIN (Personal Identification Number), EMV compliant payment card.

According to Mr. Mitchell Elegbe, Managing Director/CEO of InterSwitch, who spoke to journalists at the media launch of Verve card, the expected change from magnetic strip cards to chip & PIN platform, is what necessitated the release of Verve card into the financial market.

Elegbe said CBN’s directive was made in the best interest of banks, merchants and cardholders because existing magnetic stripe cards have minimal storage space, cannot store applications, offer little flexibility for new product development, are easy to duplicate and offer minimal security features.
With the release of Verve card, which can be used on mobile,

ATMs, PoS, Web and the Internet, Nigerian banks are expected to begin the conversion of 28 million cards in circulation to the chip & PIN platform since major payment card schemes in Europe, Middle East, South America and Africa have converted their cards to the secured smartcard platform.

However, Verve card on other hand is secured with integrated circuit chip (ICC) and can carry enhanced data. The ‘chip’ part refers to the
smart card-a plastic payment card with an embedded microp pocessor, which contains the same information as a magnetic stripe but it has additional processing capabilities and a secure memory. In developing the Verve card, Mastercard MChip 4 technology was adopted. The card has bigger storage capacity, offline PIN verification and can perform cryptographic calculations.

”The microprocessor can hold multiple applications where an application may be a specific brand of credit card, loyalty card, gift card, staff discount card, etc; so a cardholder could have credit and debit applications, loyalty applications and electronic ticketing on a single physical card”, Elegbe explained.

Specifically, Elegbe informed that Verve cards can hold information securely and is difficult to copy or alter. The security and EMV features in Verve card guarantees a higher level of security for payment transactions than magnetic stripe cards. Interswitch has also initiated eight other security initiatives; MoneyGuard (which allows cardholders send an sms from their phones to block their cards should they suspect any unusual activities), Fraud Watch (a portal and email for fraud reporting and information management, Fraud Guard ( a fraud management and transaction security system), Fraud Insure (card fraud Insurance), Fraud Team (Risk Management team), Identity Guard (Token based strong authentication), Fraud Aware (Cardholder Awareness Campaign) and Data Guard (EMV Mchip 4).



Reblog this post [with Zemanta]

TrialPay Review


Review: TrialPay can help you get freebies online
By RACHEL METZ  AP

NEW YORK (AP) — With the economy in the dumps, you might hesitate before buying discretionary goodies like video games or pizza. But what if you could get those things for free by doing something you might already be inclined to do — like signing up for a trial of Netflix or buying coffee from Starbucks.com?

Mountain View, Calif.-based TrialPay offers just that kind of a deal, which it bills as a win-win-win for consumers, merchants and advertisers. It probably won't change your buying habits dramatically, but it could help you get a (sort of) free lunch.

Here's how it works: Let's say you're perusing a movie ticket Web site. If that site is working with TrialPay, you might be presented with the option to get tickets not by paying for them directly, but simply by completing a purchase or trial offer with another company. If you're game, you can click to see a list of participating companies, such as Starbucks or Netflix. And if you agree you'll receive e-mailed instructions on how to get your free movie tickets.

As TrialPay's 27-year-old co-founder, Alex Rampell, describes it, the service is "kind of like PayPal for people who don't pay."

Rampell began building his own business in high school and college by selling shareware — software that you can generally download and try for free but are later prompted to pay for. He came up with the idea for TrialPay in 2004 as a way to get more consumers to "pay" for his software, after talking with a marketer friend who helped him realize how much companies are willing to shell out to acquire customers.

People might not be willing to pay for software, but they might be willing to pay for cat food, he mused. And if a cat food seller is willing to pay the software seller for sending it a customer, then the software seller could ostensibly give its product to the customer for free.

Most of the free items you can get through TrialPay retail for about $30 or less. And except for some deals, like one with pizza-delivery chain Papa John's, most are not physical goods.

Still, the model appears to be working. Since the company started in the summer of 2006, it has grown to include more than 7,500 merchants and about 2,000 advertisers. TrialPay makes its money by taking a cut of what the advertiser pays the merchant.

Continue Reading


Reblog this post [with Zemanta]

iPhone = Two-Thirds of All Mobile Web Traffic

Apple's iPhone now represents 66.61 percent of all mobile web traffic according to a new study issued by web solutions provider NetApplications.

Click Chart to Enlarge


The Java ME platform follows a distant second at 9.06 percent, trailed by Windows Mobile at 6.91 percent. NetApplications notes that despite the iPhone's commanding lead in mobile browsing share, both Android (6.15 percent, tied with Symbian) and BlackBerry (2.24 percent) are rapidly gaining market share--however, the report notes increases by Apple's rivals does not mean that iPhone web browsing is shrinking, as the overall market continues to grow rapidly. In all, mobile web browsing as a percentage of all web browsing is on the upswing and currently stands at 0.72 percent, up from 0.69 percent in January 2009.

Source: Fierce Telecom





Reblog this post [with Zemanta]

ID Theft Top Consumer Complaint - FTC


FTC Releases List of Top Consumer Complaints in 2008

The Federal Trade Commission on Friday released the list of top consumer complaints received by the agency in 2008. The list, contained in the publication “Consumer Sentinel Network Data Book for January-December 2008,” showed that...
  • for the ninth year in a row, identity theft was the number one consumer complaint category.
  • Of 1,223,370 complaints received in 2008, 313,982 – or 26 percent – were related to identity theft.
In December, the FTC called on the US Government to "extend two-factor authentication" (such as the application provided by HomeATM) standards deployed by banks to all private sector organizations that maintain consumer accounts, in a bid to combat rising levels of ID fraud.  (See: Dual Authentication for ALL Consumer Accounts - FTC

This report breaks out complaint data on a state-by-state basis and also contains data about the 50 metropolitan areas reporting the highest per capita incidence of fraud and other complaints. In addition, the report sets forth the 50 metropolitan areas reporting the highest incidence of identity theft.

The report states that credit card fraud was the most common form of reported identity theft at 20 percent, followed by government documents/benefits fraud at 15 percent, employment fraud at 15 percent, phone or utilities fraud at 13 percent, bank fraud at 11 percent and loan fraud at four percent.

Reblog this post [with Zemanta]

Saturday, February 28, 2009

Hacked! Is Visa Next?



In an article scheduled for  next months Bank Technology News, Rebecca Sausner talks about the call and the need for systematic reform in the payments industry.  The main theme of the article is to adopt an End (Beginning) to End Encryption standard. 

One of the more eye-opening quotes comes from Avivah Litan, distinguished analyst from Gartner, who asks "How much worse can it get than a top 10 processor being breached? Visa's next."

Let me remind you Avivah Litan predicted that hackers would target the payment acquirers/processors months ago.  I believe it was shortly after the Hannaford breach. 

Now, with 3 processor/acquirer breaches in 3 months, it appears she's the Nostradamus of the financial transaction world.  So when one of her "quatrains" predict that "Visa's next"...I, for one, wouldn't write that off as being overly cautious (or pessimistic).  HomeATM CEO, Ken Mages, (who's also a "see-er) saw the same writing on the wall years ago.  Difference is, he's was in a position to, (and has already done) something about it.  Ms. Litan states that Visa needs to start seeing the same thing...or they're next. 

One of the reason's HomeATM employed End to End Encryption back in January 2007, is because Ken Mages understood that without beginning to end encryption, data is ripe for the picking. 

That's why HomeATM is the "only" (to our knowledge) processor who instantaneously encrypts the data at the point of sale (during the swipe) while it's inside our personal swiping device.  Amusingly, ironically and paradoxically, it's was his "outside the box" thinking that made him realize that encryption needs to be done "inside the box."

One of the biggest challenges HomeATM faces is overcoming the "hurdles" involved with trying to convince industry "insiders" that in order to truly secure a transaction, a hardware device is not optional,  it's necessary.  These latest breaches should make "overcoming those hurdles" a lot easier.  New Information always = New Decision(s).

One of the things we do have going for us in this "perfect storm," is that as unfortunate as these 3 processing/acquirer breaches in 3 months were, they are helping us in driving our message home. Articles like the one below don't hurt either.
These breaches should actually assist HomeATM in overcoming these hurdles... in fact, our technique(s) to securing transactions can hurdle HomeATM towards becoming an "Edwin Moses" like talent  

Speaking of Moses...they (the breaches) may even help part the read/see and get HomeATM to the promised land sooner. (Editor's Note: Edwin Moses overcame hurdles {for 122 straight wins} during a 9 year, 9 month and 9 day "run." 

I find it heartening that HomeATM's approach to securing/encrypting data for transaction's (since 1/2007) also involved a 9/9/9...99.9 Sigma. 

Like Edwin Moses, we WILL win. (with PIN)  The hackers don't hurt by "running" right through a processor's so-called security protocols.Here's an excerpt from the article:

Heartland's Lonely Quest For Reform
Bank Technology News | March 2009

By Rebecca Sausner

Heartland Payment Systems CEO Robert Carr has likened his company's massive data breach to the Tylenol moment when product contamination led to an overhaul in packaging safety. It's likely Carr has had a few Tylenol moments himself in the past couple of months as he dealt with perhaps the largest data breach ever, though the actual number of cards compromised is undisclosed.

Now Carr is using his standing in the industry - he founded Heartland and enjoys healthy respect among processors - to call for industry-wide reform of payments technology and information sharing about exploits to prevent criminals from successfully deploying the same hack on multiple targets.

Lots of industry players agree with his stance, but there's been scant input thus far from the industry's most influential parties: including titans such as MasterCard, Discover and Visa, which are mostly mum on the subject.

"Our concern is that an underlying principal of PCI compliance is that data can be held in its native form - unencrypted - as long as it is properly protected within a corporate firewall," says Bob Baldwin, CFO of Heartland.  Corporate firewalls are only as strong as their weakest link. "What we're trying to do in end-to-end encryption is have the data always remain in its encrypted form from the moment of the swipe to the moment it gets to the association."  (Editor's Note: that's going to be the biggest challenge as that will require the ecosystem of the payments landscape to be rebuilt)
It's easy to make a case that the Heartland breach should be a louder call for industrywide action than Hannaford or TJX.  The company is one of the leading processors, moving 11 million transactions each day, and was known to have invested heavily in its security. And, it had passed its latest PCI audit.


"I think it's more serious, how much worse can it get than a top 10 processor?" says Avivah Litan, Gartner vp. "Plus, it's a much bigger target. Visa's next."

Litan's in agreement with Carr that now's the time for the industry to pony up for end-to-end encryption. Some POS terminals can already encrypt data,

(Editor's Encryption Note 1
: Our PIN Entry Device was manufactured from "beginning to end" to do so)
processors can encrypt data while it's in their environment, (Editor's Encryption Note 2:  HomeATM not only "can" but DOES) and issuers could "theoretically" accept encrypted data and decrypt it in their environment.

Editor's Encryption Note 3:  That's the beauty of our PIN approach...it's not theoretical, it's reality.  PIN's remain encrypted all the way through the process...and not only is a KEY required by the processor to un-encrypt it, but HomeATM uses DUKPT (DuckPut)  which creates a "UNIQUE" key for every transaction.  In the extremely unlikely event "one key" is somehow obtained, only one transaction is put at risk because there's a new key for the next one.

For those interested, here's a quickie lesson.  Others, scroll down, my rant continues...


In cryptography, Derived Unique Key Per Transaction (DUKPT) is a key management scheme in which for every transaction, a unique key is used which is derivedfrom a fixed key. Therefore, if a derived key is compromised, futureand past transaction data are still protected since the next or priorkeys cannot be determined easily. DUKPT is specified in ANSI X9.24 part 1.

DUKPT allows the processing of the encryption to be moved away fromthe devices that hold the shared secret. The encryption is done with a derivedkey, which is not re-used after the transaction. DUKPT is used toencrypt electronic commerce transactions. While it can be used toprotect information between two companies or banks, it is typicallyused to encrypt PIN information acquired by Point-Of-Sale (POS) devices.

DUKPT is not itself an encryption standard; rather it is a key management technique. The features of the DUKPT scheme are:
  • enable both originating and receiving parties to be in agreement as to the key being used for a given transaction,
  • each transaction will have a distinct key from all other transactions, except by coincidence,
  • if a present key is compromised, past and future keys (and thus thetransactional data encrypted under them) remain uncompromised,
  • each device generates a different key sequence,
  • originators and receivers of encrypted messages do not have to perform an interactive key-agreement protocol beforehand.
The problem is without an agreed-upon standard - though triple DES would likely work - (Editor's Encryption Note 4:  HomeATM uses triple 3DES) there are "air gaps" between each of the players that even PCI doesn't address.


Still, it'd likely be worth the trouble.

Editor's Encryption Note 5:  It WAS worth the trouble, in fact that isn't what troubled us...what's  troubling is that it seems like it's taking forever getting other's (payment industry pro's) to understand what it written in this article...(maybe because it's written in "clear text.")

What we we need is an Edwin Moses approach to overcoming the hurdles involved with "parting that read/see" and getting industry insiders to "read" further into the risks mitigated by PIN and "see" what Avivah Litan see's...)


"I would say the cost of putting end-to-end encryption in place would be lower than the all the PCI security costs and the breaches," Litan says.

Editor's Encryption Note 6:  Ya think?  Now if we can only get "DUH!" so-called industry experts/insiders to see it that way...)  About the only thing HomeATM puts out there in "clear text" is that a "PIN Based 3DES DUKPT Encryption is the most secure way to process a transaction.  Beginning to End Encryption. 

Want to learn more about our Tales from Encrypt?  Contact us.
and we'll tell you all about it...from Beginning to End!


Continue Reading at Bank Technology News



Reblog this post [with Zemanta]

Visa: New Payment Processor Breach Not New

The new processor breach that has had everyone speculating over the past 2 weeks... is "not new" according to Visa. 

Everyone else's (100,000,000 plus cards) card information has not been kept a secret, yet the "identity" of the processor who let the hacking world into theirs HAS been.   Visa has already publicly stated that  this "new" breach was "unrelated to the Heartland breach," so that leaves only one processor in the running.  RBS Worldpay.  Developing...

Here's the story from ComputerWorld.com

Visa: New payment-processor data breach not so new after all
February 27, 2009 (Computerworld) Days after Visa Inc. seemingly confirmed that a data breach had taken place at a third payment processor, following on the recent breach disclosures by Heartland Payment Systems Inc. and RBS WorldPay Inc., the credit card company is now saying that there was no new security incident after all.

In actuality, Visa said in a statement issued today, alerts that it recently sent to banks and credit unions warning them about a compromise at a payment processor were related to the ongoing investigation of a previously known breach. However, Visa still didn't disclose the identity of the breached company, nor did it say why it is continuing to keep the name under wraps.

Visa said that it had sent lists of credit and debit card numbers found to have been compromised to financial institutions "so they can take steps to protect consumers." The company added that it currently "is risk-scoring all transactions in real time, helping card issuers better distinguish fraudulent transactions from legitimate ones."

Visa's latest statement follows ones that both it and MasterCard International Inc. issued earlier this week in response to questions about breach notices that had been posted by several credit unions and banking associations. The notices made it clear that they weren't referring to the system intrusion disclosed by Heartland on Jan. 20 and suggested that a new breach had occurred.

Visa's initial statement and the one from MasterCard were both carefully worded; neither said specifically that the breach being referred to was a new one, but they also didn't say that it was a previously disclosed incident. Visa said it was "aware that a processor has experienced a compromise of payment card account information from its systems," while MasterCard said it had notified card issuers of a "potential security breach" affecting a payment processor in the U.S.

MasterCard officials didn't respond today to requests seeking clarification on whether its statement referred to a previous breach or a new one.

Benson Bolling, vice president of lending at the Alabama Credit Union in Tuscaloosa, said today that officials there had understood the breach to be a new one based on the alerts sent out by Visa — but couldn't say that for sure. According to Bolling, the credit union, which posted an advisory on Feb. 17 and updated it two days later, was informed by Visa of a "big breach" shortly after getting the word about the intrusion at Heartland.

The identifying number that was used in the so-called Compromised Account Management System alert issued by Visa appeared to suggest a new breach, because it was different from those used in previous CAMS notices, Bolling said. It was his understanding, he added, that CAMS alerts related to a previous breach would use the same identifier as the original notifications...

continue reading at ComputerWorld.com


Friday, February 27, 2009

Finovate Startup09 Company Descriptions

Finovate Startup Conference Company Descriptions (NetBanker)
By Jim Bruene

To give you an idea of the types of innovations being funded in financial services these days, here's a capsule description of the first 48 companies demoing at FinovateStartup April 28 in San Francisco

Attention attendees: You have just one day left to register (here) at the discounted price of $795.

Finovate Startup 2009 Participants


Acculynk
Acculynk is a payments solutions provider with a suite of software-only services that secure online transactions by utilizing a graphical, scrambling PIN-pad for the secure entry of sensitive cardholder information.

AlphaClone
AlphaClone is a web-based investment research service that lets users explore the investing ideas of top hedge fund and institutional money managers.

Aradiom
Aradiom is a mobile solutions provider and designer of Java mobile applications and platform development technology including turn-key applications, embedded soft-token security solutions and BlackBerry® enterprise applications.

BillShrink
BillShrink is a personalized savings advisor that helps consumers make smart, money-saving decisions by providing continuously updated, personalized, usage-based recommendations on everyday services like credit cards and cell phone plans

BudgetTracker
BudgetTracker is a personal finance manager that allows users to manage their finances and keep track of their budget, bills, and transactions online without having to install software.

CalendarBudget
CalendarBudget is a free online personal budgeting tool that helps users organize and track their finances, plan future spending and save money.

Centrro
Centrro is a financial search engine that allows consumers to anonymously shop for personal financial products that best fit their specific credit profile.

CircleUp
CircleUp provides group communications services, which enable actionable and efficient interactions across diverse social, email, mobile, messaging and private web networks.

Cooler Inc.
Cooler Inc. enables users to know, decrease, and offset the global warming impact of their everyday purchases and activities by using the country's only peer-reviewed carbon calculator to calculate impact and then providing reductions targets and strategies, and offering recommendations on high quality carbon offsets.

CreditArray
CreditArray is a vault of proprietary information to allow consumers to better apply for and manage their credit portfolios.

Credit Karma
Credit Karma provides consumers free access to their credit score and offers credit simulators, advice, and credit score comparison tools in order to allow them to more actively manage their credit and financial health.

GoalSpring
GoalSpring's product, DebtGoal, makes paying down debt as easy and efficient as possible by taking into account all of a customer's debt and helping them organize, optimize and pay it down.

Expensify
Expensify simplifies keeping track of business expenses by combining an electronic payment card and a web-based expense manager to automate expense report preparation, approval, and reimbursement.

Green Sherpa
Green Sherpa offers personal cash flow management software that lets users conveniently download, manage and update all their financial accounts via a single online resource.

Home-Account
Home-Account is in stealth mode at this time.


HomeATM

HomeATM provides a secure PIN debit and PIN credit card transaction method via the Internet that utilizes the HomeATM swipe pad technology to allow users to conduct secure PIN-based transactions from home, ensuring virtually zero fraud and lower merchant processing fee costs.




iBearSoft
iBearSoft is the creator of iBearMoney, a personal finance application for the iPhone that allows users to input and categorize their transactions, run financial reports, analyze payments, and keep track of expenses.

iThryv
iThryv is a financial literacy platform that combines a content delivery system and an incentive system in order to create an immersive learning environment which provides a powerful tool when used in partnership with online banking and core providers.

Jwaala
Jwaala provides software for banks and credit unions that improves their online banking services. Their MoneyTracker application offers a personal financial management solution that can be added to any bank or credit union's existing online banking solution.

kaChing
kaChing is a social investment community that applies an open source and social-networking strategy to offer every investor the opportunity to find outstanding investors, emulate their portfolios, and access the returns, insights, transparency and talent previously only available to wealthy individuals.

Kapitall
Kapitall is a rich web application that aims to make investing easy for everyone. Inspired by game design, Kapitall combines an graphical user interface with tools that make it easier than ever to research companies, build portfolios, share ideas and get smarter about the market.

Lending Club
Lending Club is an online social lending network where people can borrow and invest money at attractive rates.

LendingKarma
LendingKarma is a person-to-person lending site that makes it easy for parties that know each other to create loans and provides borrowers and lenders with tools to help service the loan and see it through to repayment.

Looniesdesk.com
Looniesdesk.com enables people to manage their finances online using an open source financial platform that allows developers to build sophisticated applications which will help users enhance their experience and increase the efficiency of the service.

Mint
Mint is an online personal finance service that securely downloads users' financial transactions, allows them to categorize their transactions, provides a unified view of all account activity and relevant account alerts, and offers personalized suggestions for significant savings opportunities.

Moneta
Moneta provides a secure, quick and easy form of online payment that directly debits users' checking or money market account allowing users to only enter a secure username and password when making online purchases.

NCore
NCore provides enterprise class delivery channel solutions to financial institutions within the Asia Pacific and Middle East regions fusing applications, innovative security and middleware technology into a single integrated platform.

OurCashFlow
OurCashFlow offers personal finance management tools for financial institutions that can turn their website into a place where customers can create a budget, save money and achieve their savings goals.

Pennyminder
Pennyminder helps individuals and small groups manage their shared and personal finances by tracking deposits and withdrawals allowing them to see what's happening with their money

People Capital
People Capital is a peer-to-peer private student loan service that utilizes a unique scoring system to predict a student's potential and provide a true, unbiased measure of the economic value of an education that empowers students to make better educational decisions and offers multiple advantages for both borrowers and lenders.

Pertuity Direct
Pertuity Direct offers social lending for personal loans by bringing together the advantages of capital markets, social networks and traditional banking.

Portfolio Monkey
Portfolio Monkey provides free online portfolio management tools to help average investors optimize their portfolios and find customized investment ideas so they can create more efficient portfolios with higher expected return and less risk.

Prosper
Prosper is a person-to-person lending marketplace where people list and bid on loans using Prosper's online auction platform.

The Receivables Exchange
The Receivables Exchange is a real-time online market for trading accounts receivable that gives businesses access to working capital at a competitive cost by connecting a global network of accredited investors to the nation's small and mid-sized businesses.

Rudder
Rudder is a free personal finance software designed to minimize the effort required in managing money by helping users to manage their budget, track their bills and analyze their expected income and projected expenses.

Silver Tail Systems
Silver Tail Systems provides fraud prevention to defend users' websites against business logic abuse through the use of behavior detection, efficient investigation and real-time mitigation to track suspicious behavior and divert the bad actors, leaving legitimate users unaffected.

SimpliFi
SimpliFi provides independent financial advice online. Users can complete a profile and receive a personal financial plan with specific actionable steps.

SmartHippo
SmartHippo uses the power of the community to find users the best rates on financial products and services.

SmartyPig
SmartyPig is a social saving service that helps users save for a specific goal by allowing them to invite others to contribute to their account, providing incentive boosts from top retailers, and offering a competitive interest rate.

Strands
moneyStrands is a money management service that helps users get information on anything from practical savings tips to getting help tracking expenses down

Syphr
Syphr is a technology and marketing credit union service organization that created RateMatch, a service that matches participating credit unions with the thousands of credit report purchasers per month.

ThreatMetrix
ThreatMetrix helps companies control online fraud and abuse in real time by profiling the device used in an online transaction so companies can determine whether the users are fraudsters or customers.

Transparent Financial Services
Transparent Financial Services is online comparison-shopping service for small businesses that uses technology to help users compare and purchase financial services like payroll processing, credit card processing and business loans.

Victrio
Victrio offers a credit risk management system that uses voiceprint recognition technology to fight credit card fraud and identity theft.

Wesabe
Wesabe is an online personal finance management tool that provides members with information about where they spend and links them with a community dedicated to helping each other make smart financial decisions.

WeSeed
WeSeed seeks to demystify the stock market by helping real people share what they know and make smart investing decisions based on the collective wisdom of the community.

ZimpleMoney
ZimpleMoney is a web-based financial services platform enabling people and organizations to manage and administer financial agreements including loans, leases, rentals, tithing, trusts and settlements.


Reblog this post [with Zemanta]

Visa Survey Reveals Many SME's Believe They Are too Small to Attract Fraudsters


Fraud Prevention Month activities highlight importance of data security for small businesses in Canada

TORONTO, Feb. 27 /CNW/ - A survey of Canadian small businesses released today by Visa reveals that 41 per cent of respondents believe that 'data thieves and hackers' are not interested in targeting their businesses because of their size.  

As part of its annual Fraud Prevention Month activities, Visa is hosting free fraud prevention seminars in Toronto, Ottawa, Winnipeg and Calgary that will emphasize the importance of data security for small businesses.

"Regardless of the size of the enterprise, it's important for business owners to appreciate the importance of data security and what steps they should take to protect their customers and business," says Gord Jamieson, Head of Payment System Risk, Visa Canada. "The information sessions will provide a great deal of information and an opportunity for small business owners and managers to ask questions."

The Ipsos Reid survey, which was commissioned by Visa Canada, surveyed 885 small business owners about their data storage and security practices.

39% of respondents describe securing customer information as a vital part of their business and 94% believe that securing data is important to their customers. Of the 60 per cent of respondents that do keep electronic files with customer information, 86 per cent noted that they either encrypt the data (8%), ensure that it is password protected (39%) or ensure that the information is both encrypted and password protected (39%).

While the majority of respondents claim to appreciate the importance of data security to their business and customers, more than half (52%) have never sought information about how to properly secure electronic information and 24 per cent do not know where to get information about how to better secure information for their business.


"Preventing fraud is a shared responsibility," says Jamieson. "By offering information to small businesses during Fraud Prevention Month, we can help them better protect themselves against data thieves."

The Visa Canada workshops will help educate small businesses about how to better protect themselves from fraudsters. Sessions will include information on how to properly process a credit card transaction, tips on how to protect credit card information and to ensure that their payment application is secure, chip and PIN technology, and an overview of the Visa Account

Information program. More information and free registration is available online at www.visa.ca/fpm. In addition, through its participation in the Fraud Prevention Forum, Visa works closely with government and law enforcement to provide educational materials to all Canadians to help them "recognize, report and stop" fraud. Educational materials for consumers and merchants on fraud prevention can be found on www.visa.ca/securewithvisa.

About the Survey

The online survey was conducted between February 2 and 9, 2009, by Ipsos Reid. A total of 885 small and medium sized business owners who employ 1-250 employees and accept credit or debit cards were surveyed. An unweighted probability sample of this size, with 100 per cent response rate, would have an estimated margin of error of plus or minus 3.3 percentage points, 19 times out of 20. Margin of error for subgroups will be larger.

About Visa

Visa Inc. operates the world's largest retail electronic payments network providing processing services and payment product platforms. This includes consumer credit, debit, prepaid and commercial payments, which are offered
under the Visa, Visa Electron, Interlink and PLUS brands. Visa enjoys unsurpassed acceptance around the world, and Visa/PLUS is one of the world's largest global ATM networks, offering cash access in local currency in more
than 170 countries. For more information, visit www.corporate.visa.com.

For further information: Sarah Van Lange, Fleishman Hillard, (416) 645-8173, sarah.vanlange@fleishman.ca; Carla Morin, Visa Canada, (416) 860-8850, camorin@visa.com


Source: VISA INC.



Reblog this post [with Zemanta]

Banks File Class Action Against Heartland

Bank Info Security, which has been covering the Heartland Breach better than most any other site I have found is now reporting that a class action lawsuit has been filed against the company on behalf of the banking institutions. 

Saw this coming from a mile away...(see: Banks Not HPY with Heartland)  This is just the beginning folks.  If I owned shares in Heartland, I wouldn't be HPY.

One lawsuit,the Lone Star National Bank is asking for $50 million in damages.  Damages will most likely be trebled.  This has got to be giving Heartland a bad ticker...speaking of which I haven't had an opportunity to check their stock price yet today...hold on..let me grab it for you...


In the meantime, you can click on the graphic to enlarge if you can't read it...







Here ya go..it's a little off from it's 52 week high...yes?  Heartland says it will meritoriously defend itself against any lawsuit, which I take to mean that it will file a counter-suit against the brands (V/MC) claiming the breach was their fault because they don't provide end-to-end encryption. 

IMHO, if Visa and MasterCard would simply take the reduced Interchange Fees hit and get rid of (completely eliminate) signature debit...and completely replace it with the more secure PIN Debit debit platform, this dog wouldn't be barking. 


Here's the report from Bank Info Security:

Heartland Data Breach: Class Action Suit Filed on Behalf of Banking Institutions

Complaint Seeks to Recover Costs, Damages from Fraud
February 27, 2009 - Linda McGlasson, Managing Editor


One month after the Heartland Payment Systems (HPY)data breach was revealed, a Philadelphia law firm filed a class actionlawsuit against the processor on behalf of two banks and three creditunions. The complaint was filed by Chimicles & Tikellis in U.S. District Court in Trenton, NJ on February 20.  (Click the graphic below to enlarge and read the treble damages request)

The five institutions named in the complaint are AmalgamatedBank, New York, NY; Matadors Community Credit Union, Chatsworth, CA;GECU, El Paso, TX; MidFlorida Federal Credit Union, Lakeland, FL ;andFarmers State Bank, Marcus, IA. All the institutions say they have hadto re-issue "substantial" numbers of credit and debit cards because ofthe Heartland breach.

Joseph Sauder, the (soon to rich) attorney leading the case, says while onlyfive institutions were named in the complaint, "We talked with numerousbanks. These five were the ones we selected to present in thecomplaint."

Although no one has estimated officially how many institutions, cards and consumers might be affected by the breach, more than 500 institutions have stepped forward to tell Information Security Media Group that they have been impacted.

Chimicles & Tikellis also has a consumer class action lawsuit filed against Heartland, filed in the same U.S. District Court in Trenton on January 27.


Seeking to Recover Costs

In the new class action suit, Sauder says the institutions "seekto recover money for the cost of reissuing cards and also for thefraudulent activity that banks and credit unions are ultimatelyresponsible for as a result of this breach, among other things."

Heartland announced on January 20 that its computer systems hadbeen breached by outside hackers sometime in 2008. The processorhandled on average 100 million transactions per month for about 175,000merchants and retail establishments. Heartland only became aware of thebreach after it was notified by Visa and MasterCard of "patterns offraudulent credit card activity," the lawsuit states.

The breach compromised information including debit and creditcard numbers, expiration dates and internal bank codes. Many of theinstitutions that had cards compromised in the breach were forced tore-issue new credit and debit cards to their customers. "Given thelarge size of the data breach, the expenses associated with doing soare substantial," the complaint says, "and include costs for purchasingnew plastic debit and credit cards, postage and other mailing expenses,time spent by employees address this issue and harm to reputation andgoodwill."|


Many institutions have also reported incidents of fraud, thecomplaint states. It says Heartland's actions "constitute violations ofthe consumer protection statute of New Jersey," and amounts to a breachof implied contract, negligence, negligent misrepresentation, andcommon law negligence.

Sauder says he cannot estimate how soon the case may begin orhow long it may last. "It's hard to tell at this time, since the casewas just filed, as to what Heartland's position is going to be," hesays. He adds that more institutions are expected to join the classaction suit.

Other Suits


There are at least three consumer class action lawsuitsfiled against Heartland and three other lawsuits filed in other courtsby institutions seeking to recoup their losses and expenses related tothe breach:
  • The Lone Star National Bank, Pharr, TX has filed a lawsuit seeking $50 million in damages against Heartland. The Lone Star case was filed in Texas Southern District Court on February 16.

  • TriCentury Bank, Simpson, KS filed a lawsuit in New Jersey District Court on February 13 seeking a judgment against the payments processor for breach of contract.

  • Lone Summit Bank, Lake Lotawana, MO filed a lawsuit in the Fraud or Truth-In-Lending office of the New Jersey District Court on February 6.

The lawsuits against Heartland aren't the only issues the paymentsprocessor is confronting. During a conference call reportingHeartland's 2008 fourth quarter earnings on February 24, HeartlandPresident and CFO Bob Baldwin said, "Today, we have had severallawsuits filed against us and we expect that additional lawsuits willbe filed. We are also the subject to several governmentalinvestigations and enquiry, including an informal enquiry by the SECand a related investigation by the Department of Justice, an inquiry bythe OCC, and an inquiry by the FTC, and we may, in the future, besubject to other governmental enquiries and investigation."


Reblog this post [with Zemanta]

Experts Publish 20 Guidelines to Halt Data Breaches

NOTICE to readers of this draft document: Criticisms and suggestionsare strongly encouraged. If you are actively engaged in cyberforensics, red teams, blue teams, technical incident response,vulnerability research, or cyber attack research or operations, pleasehelp make sure this document is as good as it can be. Sendcriticism/comments/sugges tions to John Gilligan as well as to cag@sans.org byMarch 25, 2009Twenty Most Important Controls and Metrics for Effective Cyber Defense and Continuous FISMA Compliance

                                                                                                                                                     

    Publish at Scribd or explore others:            Academic Work                  cyberdefense              fisma          

Reblog this post [with Zemanta]

Mobile Banking to Top $5.5 Billion in 2013


By Jason Ankeny

Consumers will conduct almost 300 billion mobile payment and banking transactions worth more than $860 billion in 2013, a twelve-fold increase in gross global transaction values in five years, according to a new forecast published by market research firm Informa Telecoms & Media. Informa contends that if key players collaborate effectively, the mobile payments and banking market offers a shared annual revenue opportunity of more than $10 billion in 2013, galvanized by m-banking services, which are expected to contribute $5.5 billion of that amount. Informa predicts that in four years' time, more than 445 million mobile subscribers worldwide will regularly use their mobile phone to purchase physical goods and services remotely--the report estimates that while the value of mobile payments and transactions in 2008 totaled around $71 billion, a third of which was spent on mobile digital content like ringtones, games and full-track downloads, physical goods and services will represent about 95 percent of mobile transactions by 2013.

Informa forecasts there will be 977 million worldwide users of mobile banking services by 2013, up from about 67 million at the end of 2008. In addition, almost 424 million consumers will transmit more than $157 billion of personal funds via mobile domestically by 2013, with another 73 million sending $48 billion internationally. However, Informa anticipates near-field communications payment models will be held back by the lack of availability of NFC-enabled handsets and related uncertainties concerning the overall business case for mobile NFC. Even so, Informa believes approximately 11 percent of all mobile handsets shipped in 2013 will be NFC enabled, with more than 178 million mobile subscribers regularly using mobile NFC phones to acquire physical goods and services, such as tickets, at the point of sale.

Informa credits the growth of mobile payments to drivers and enablers including more sophisticated handsets and network technologies, a more enlightened regulatory perspective on mobile banking, consumer familiarity and increased investment across the ecosystem. The report concedes that uncertainties remain, in particular the global financial meltdown as well as a crisis in consumer confidence triggered by widespread turmoil throughout the banking industry.

For more on the Informa forecast: read this release

Related articles:
Bill Gates pledges $12.5 million for mobile banking
MMA publishes Mobile Banking Overview
Reblog this post [with Zemanta]

Whitepaper - Mobile Banking in the United States

Blackberry Whitepaper: Mobile Banking in the United States – The Evolution of Anywhere Banking
Technological, economic and market factors have enabled a new breed of customers. Find out how the banking industry can leverage this new channel.

* Download Now (PDF)

or...to only see their conclusion, click the image below and it will enlarge enough to read















Reblog this post [with Zemanta]

Moneris Awards Verifone $10M EMV Terminal Contract


CANADA'S MONERIS AWARDS VERIFONE $10M EMV TERMINAL CONTRACT

Bank-backed Canadian card payments processor Moneris is gearing up for the country's migration to EMV by awarding eftpos vendor Verifone a $10 million contract for the supply of terminals.

More on this story: http://www.finextra.com/fullstory.asp?id=19695

Pago Retail Report 2008 Press Release


(In Europe) Credit card increases lead over other payment methods in online retailing

Latest Pago Retail Report by Deutsche Card Services shows significant differences in payment behaviour between online retailing and e-commerce as a whole

COLOGNE, 27 February 2009 - As in overall e-commerce, credit cards are clearly the preferred payment method in European retailing. Their share rose almost 6 pp year-on-year, to now 81.57%. In other words: Consumers use credit cards to pay for more than eight out of ten purchases in European online retailing. This is one of the results explained in the Pago Retail Report 2008, which was recently published by Deutsche Card Services, a subsidiary of Deutsche Bank

(Editor's Note: These numbers are skewed because PIN Debit is not ubiquitous on the web.  For "across the board" numbers, visit "Debit is King, Cash Overthrone")

Offline payment methods and direct debiting lose importance in favour of credit cards

Despite the predominance of credit cards offline payment methods such as invoice purchases, COD and prepayment as well as direct debiting still play a more important role in online retailing than in overall e-commerce (payment behaviour in overall e-commerce is described in detail in the Pago Report 2008).

Just like the sector-specific Pago Retail Report 2008, the Pago Report 2008 is based on real-life transactions, not on surveys. That is what makes the Pago Reports different from other e-commerce studies. The report highlights that 5.04% of all retail transactions were paid for by offline methods and 11.97% by direct debiting.

The shares of these payment methods in overall e-commerce are only 0.77% and 8.34%, respectively. However, offline payment and direct debiting lose ground to credit cards in online retailing; in fact, the latter increased their lead, largely due to the success of Visa, whose share rose by more than 4%, whereas competing credit card brand MasterCard lost more than 2%.

Consumers from the UK and from outside Europe pay almost exclusively by credit card

The predominance of credit cards as most important payment method in retailing is even more visible among consumers from the UK and outside Europe than among German customers. Traditional payment methods such as invoice purchasing or direct debiting are almost non-existent for this consumer group. UK consumers use their credit cards even more often in retailing than in overall e-commerce. The share in overall e-commerce is already very high, at 91.50%, and it rises to 94.90% in retailing. Maestro, the leading international debit payment method, which is gaining ground in e-commerce in comparison to credit cards, is the only other payment method which seems acceptable to British consumers, with a share of 5.10%. Shops which also target customers outside Europe do well to offer credit card payment, which has a share of almost 100% among these consumers.Upward potential for new payment methods Maestro and giropay in European retailingIn general, retail consumers are still reluctant to adopt newer payment methods such as Maestro and giropay (which is based on the well-established PIN/TAN electronic banking method) - at least more reluctant than e-commerce customers as a whole. giropay meets with even less approval than Maestro. Maestro has a share of 0.77%, but giropay undershoots even this low mark with a share of only 0.65%. This is probably due to the fact that, using this new payment method, it is still difficult to process retail good returns and the crediting procedure for returned purchases is complicated.

Visa increases its lead over MasterCard as top credit card brand

Visa, which is the leading credit card brand in overall e-commerce, was able to confirm and even improve its leadership position in retailing, too. While the gap between Visa and MasterCard was just above 19pp in the preceding year, it is now more than 25pp. Visa has increased its lead again at the expense of the other credit card brands, whose share dropped from 7.35% to 5.48%. In the meantime Visa has overtaken its rival MasterCard in retailing with German consumers, too: While MasterCard was ahead of Visa in the preceding year with a share of 41.69% (vs 33.95%), Visa is now in front of MasterCard (44.40% vs 35.40%). In other consumer countries such as the UK, where the lead is an impressive 36.20 pp, Visa is even more predominant than in Germany.

Source: Press Release

Reblog this post [with Zemanta]

Visa in one Helluva SMS



HOLLYWOOD, Fla., Feb. 26 /PRNewswire/ --

Charge Notification Services Corporation (C.N.S.C.) has filed a lawsuit against VISA, Inc. for patent infringement. C.N.S.C. is a relatively young company in Miami, Florida, that offers information processing services to credit card issuing banks. The C.N.S.C. patent covers charge card transaction authorization and/or notification in real-time via SMS to the cardholder's cellular phone. VISA and some of their bank partners have recently been offering this service.

"We are very sorry that it had to come to filing this suit," says Ivan Ochoa, the C.E.O. of C.N.S.C. "For months we've tried exhaustively to work with VISA with no results. We're a young company but we have experience with this product and the credit card business as a whole. We have the knowledge and infrastructure to handle even the most extreme transaction volume. We've expended considerable resources on patent registration and product development."

Editor's note:  Apparently Visa didn't get the SMSage

Daniel Davila, COO of C.N.S.C., adds: "In these economically troubled times people want to use their cards (debit, pre-paid, credit card and charge) and receive real-time information about charges to their account. If cardholders have to wait until they receive their statement to discover possible merchant errors or duplications, it's already too late to avoid the complex and time-consuming process of 'charge-back' that costs cardholders and businesses time, resources and aggravation. Of course what cardholders want most of all is to be confident that their card account will not be used fraudulently. All indicators show that card fraud activity is expected to increase even further. We have the line of products that will significantly decrease card fraud and give confidence to all cardholders that in the event their card or account information is ever stolen and used fraudulently our SMS service will send them notification within a matter of seconds from the moment it occurs. We are in the business of stopping the fraudsters and providing tremendous savings and other benefits to our card issuing clients. As VISA continues to infringe on our patent, we really must take this legal action against them to protect our business. In the meantime, of course, we continue to actively offer our services to all card issuing financial institutions."

Ochoa and Davila have a combined five decades of experience in the financial services industry. Mr. Davila's background includes 16 years at American Express where he was a Senior Director within the Global Network Services (GNS/Franchise) division and more recently, two years as Vice President and Chief Risk Officer of the credit card division at Russian Standard Bank (RSB) in Moscow. While at RSB, Mr. Davila launched a similar SMS credit card fraud protection service with great success, resulting in an overall significant reduction of fraudulent transactions. Mr. Ochoa's 25 years in the financial services industry include executive positions within American Express and MasterCard International, where he was Chief of Staff for Latin American countries. His areas of expertise include managing operations for multi-markets, re-engineering, quality control and technology. Mr. Ochoa has lead major innovative developments in products and systems.
SOURCE Charge Notification Services Corporation


Disqus for ePayment News