Tuesday, March 3, 2009

Annual E-Commerce Fraud Survey Results

Merchant Risk Council Announces Annual E-Commerce Fraud Survey Results

MRC Platinum Members Show Best Overall Online Fraud Control Management

Editor's Note:  HomeATM's Chief Operating Officer, Mitch Cobrin will be in attendance at this years
Merchant Risk Council’s 7th Annual e-Commerce Payments and RiskConference March 10–12, 2009at the Wynn Las Vegas.  If you know of any attendees you feel would be a good fit with HomeATM, let me know and I'll forward.

(Seattle, WAMarch 3, 2009) The Merchant Risk Council (MRC), a merchant-led trade associationfocused on electronic commerce risk and payments globally, todayannounced the results of its Annual Merchant Fraud Survey.  This year’s survey was sponsored byCyberSource Corporation as part of its broader annual survey of onlinefraud.  The results of this survey showMRC Platinum members setting the pace for e-Commerce merchants in both thecontrol of online fraud and the protection of legitimate customer orders.  MRC Platinum members are 150 of the largestonline retailers in the world.
This year’s survey shows that MRC Platinum members areutilizing the highest number of fraud detection tools, have the lowest manualorder review rates, and lead all merchants in reviewer productivity.
 
Key Survey Findings:
  • MRC Platinum members reported an average of just 1.1% of their totalrevenue lost to online fraud, compared to 1.4% for the overall sample, and 1.3%for other large non-member merchants with greater than $25 million in onlinesales
  • MRC Platinum members rejected 2.4% of domestic orders on suspicion offraud compared to 2.9% for the overall sample, and 2.6% for other largenon-member merchants
  • MRC Platinum members rejected just 6% of international orders compared to11% for the overall sample, and 12% for other large non-member merchants
  • MRC Platinum members reported a fraudulent international order rate ofjust 3.2%, compared to 4.0% for the overall sample and 3.4% for other largenon-member merchants
  • MRC Platinum members had a 70%higher review order productivity level compared to other large non-membermerchants, and were more than twice as productive as the overall sample

“This survey shows that even though MRC members are allowinga much greater rate of online orders to be processed, they are actuallyexperiencing a lower rate of overall fraud for both domestic and overseasorders,” said Tom Sullivan, Chairman of the MRC, and Sr. Director of GlobalPayments & Risk for Expedia, Inc.  “Asmerchants continue to look for ways to maximize revenues during tough economictimes, accepting more valid international orders can be a great source ofgrowth.”
The survey also revealed that MRC Platinum members use anaverage of 7.8 automated fraud screening detection tools. This compares to just4.7 tools utilized by the overall sample and 5 tools used by other largenon-member merchants.
“Today’s online criminals are getting more sophisticated andrelentless in searching for merchant vulnerabilities,” said MRCExecutive Director Tom Donlea. “The MRC allows a wide range of e-Commerce and multi-channel retailersto combine forces and strengthen their defenses.  These survey results validate ourcollaborative efforts in both fighting fraud and increasing merchantprofitability.”

Full survey results will be presented by CyberSourceas part of the Merchant Risk Council’s 7th Annual e-Commerce Payments and RiskConference March 10–12, 2009at the Wynn Las Vegas.  The conferencewill be uniting over 500 representatives from the world’s top Internetmerchants, credit card companies, risk management providers, law enforcementagencies and various consultants and educators – all with the mission of makinge-Commerce safer and more efficient for consumers. 
Conference keynote speakers include:
  • Tom Ridge, the firstUSSecretary of Homeland Security, addressing the growing cyber security issuesthat affect both USsecurity and the global economy.
  • Terry Jones, Travelocity.com founder, focusing on the business ofinnovation.
  • Chris Hansen, Dateline NBC correspondent, sharing his findings on thegrowing cybercrime community.

Forfull conference schedule, registration and exhibition information, please visitthe MRC website at www.merchantriskcouncil.org. Forjournalists wanting more information on this survey, please contact MRCCommunications Manager, Jordan Rubin (206.364.2789; jordan@merchantriskcouncil.org).

About the Survey
The MRC Platinum Fraud Survey was included as part of theEighth Annual CyberSource Fraud Survey, sponsored by CyberSource Corporationand conducted by Mindwave Research.  Thesurvey was fielded October 21 through November 11, 2008 and yielded 400 qualified and complete responses, of which74 were MRC Platinum merchants.  Thesample was drawn from a database of companies involved in electronic commerceactivities.  Incentive to respondentsincluded a summary of the research. 

Aboutthe Merchant Risk Council
The Merchant Risk Council (MRC) is a merchant-ledtrade association focused on electronic commerce risk and paymentsglobally.  The MRC leads industry networking, education and advocacyprograms to make electronic commerce more efficient, safe and profitable.   Today, with the power of its member-base, the MRC is the leading trade association for managing payments,preventing online fraud and promoting secure e-Commerce.  The MRC is dedicated to working withe-Commerce and multi-channel merchants, payment processors, credit cardissuers, credit card companies, alternative payment providers, risk managementexperts, and law enforcement to make the Internet a safer and more profitableplace to do business.
The MRC Board of Directors and Advisors includes:Expedia, Inc., Adobe Systems, Inc., Neiman Marcus Direct, 41stParameter, Apple, BestBuy.com, Bill Me Later, Blizzard Entertainment, ChasePaymentech, CyberSource Corporation, Dell, Inc., Discover Network, Gap, Inc.Direct, iovation, Microsoft, Trustwave, Visa, Inc. and Wal-Mart. The MRC is headquartered in
Seattle, Washington
.



Reblog this post [with Zemanta]

March is Fraud Prevention Month

Interac Association Encourages Canadians To Put Their Fraud Prevention Smarts to the Test
March is Fraud Prevention Month


TORONTO, March 3 /CNW/ - March is Fraud Prevention Month, and as Canada's leading payment network, Interac Association is encouraging Canadians to put their debit card fraud prevention smarts to the test.
  • Can I share my PIN with a friend or family member?
  • Is it safe to enter my PIN without shielding it, if no one is watching me?
  • Do fraudsters have to physically have my card to steal money from my bank account?
If you answered "yes" to any of the above questions - you may want to take a refresher on how to use your debit card more safely. "INTERAC is among the safest networks in the world, however debit card fraud can occur and that's why we're involved in raising awareness about debit card fraud and educating Canadians about what they can do to help keep their money safe," said Caroline Hubberstey, Director, Public and Government Relations, Interac Association.

Interac Association and its industry partners have a number of initiatives in place to protect Canadians, including the transition to chip card technology, a new generation of payment cards that will significantly reduce debit card skimming and the production of counterfeit cards.

Cardholders can also play a role in the fight against fraud by practicing safe debit card use. Following are some key safety tips for cardholders and retailers:

Cardholder Safety Tips

1. Use your hand or body to shield your PIN during every transaction conducted at an Automated Banking Machine (ABM) or at the checkout;
2. Keep your debit card in sight when conducting transactions at the checkout;
3. Check your banking statements regularly and contact your financial institution immediately if you detect any unusual activity, for example purchases you did not make or missing charges;
4. Notify your financial institution immediately, if your debit card is lost, stolen or retained by an ABM;
5. Memorize your PIN - only you should know it. If you suspect that someone knows your PIN, even a friend or family member, change it immediately;
6. Select a unique PIN. Never use obvious information, such as your telephone number, date of birth, address or Social Insurance Number. These numbers are often stored in the same place as your debit card enabling criminals to easily guess your PIN.

Retailer Tips

1. Treat your PIN pads like cash. Keep PIN pads out-of-sight when not in use;
2. Check your PIN pads and Automated Banking Machines (ABMs) regularly for anything unusual;
3. Lock-up PIN pads at closing;
4. Include log-in sheets for accountability of PIN pad in cash open and close procedures;
5. Consider adding surveillance cameras;
6. Know your employees - exercise due diligence when hiring and check references;
7. Remind your customers to protect their PIN when entering it at every opportunity;
8. Talk to your payment service provider about other steps you can take to prevent fraud from happening at your location.

"In the instance of debit card fraud, cardholders are protected by the Canadian Code of Practice for Consumer Debit Card Services, under which victims will be reimbursed," said Hubberstey.

Chip cards to make safe system even more secure

Chip cards and terminals have already begun to roll out across Canada and the majority of Canadians will be able to fully benefit from this new technology by 2010. Throughout the transition chip terminals will recognize both chip and magnetic stripe cards, so customers will be able to continue to use their magnetic stripe card where chip terminals are not yet available.

For more information about debit card fraud and chip or to test your fraud prevention smarts, please visit www.interac.ca.

About Fraud Prevention Month

Fraud Prevention Month is coordinated by the Fraud Prevention Forum (FPF), a group of private sector firms, consumer and volunteer groups, government agencies and law enforcement organizations committed to fighting
fraud targeted to consumers and businesses. Chaired by the Competition Bureau, the FPF aims to prevent Canadians from becoming victims of fraud.

About Interac Association

A recognized world leader in debit card services, Interac Association is responsible for the development and operations of the INTERAC network, a national payment network that allows Canadians to access their money through Automated Banking Machines and point-of-sale terminals across Canada.  Interac Association was founded in 1984 and is composed of a diverse membership which includes banks, trust companies, credit unions, caisses populaires, merchants, and technology and payment related companies. Other INTERAC-branded and related services include: INTERAC Online, for secure online payments directly from a bank account, INTERAC Email Money Transfer, for the transfer of money from a bank account to anyone with an email address, and Cross Border Debit, for point-of-sale access at more than 1.5 million U.S. retailers.  For further information: Media contacts: Tina Romano, Interac Association, (416) 869-5062, tromano@interac.ca; David Weinstein, Strategic Objectives, (416) 366-7735 ext. 231, davidw@strategicobjectives.com


Banks Must Wake up to Payments Challenge

Finextra: Banks must wake up to payments challenge - BCG
Banks must wake up to payments challenge - Boston Consulting Group
Banks around the world must take forceful steps to protect their payments businesses or risk a further dent in their profits as the financial crisis continues, according to a new report by the Boston Consulting Group.

The report, 'Weathering the Storm: Global Payments 2009', says that although payments businesses have proved to be reliable revenue generators - global payments revenues hit $805.1 billion in 2008, up from $654.3 billion in 2006, and are forecast to reach $1.4 trillion by 2016 - their momentum is slowing. The darkest cloud over the industry is the steady decline in average revenues per transaction. For banks, BCG estimates that these revenues will fall from $0.94 to $0.88 for domestic payments and from $9.33 to $7.50 for cross-border payments from 2008 through 2016.

According to the report, a variety of factors are contributing to price erosion and margin pressure, including regulatory pressure, intensifying competition, and infrastructure investments. The net result is higher costs, but not necessarily higher revenues.

Niclas Storz, a BCG partner and coauthor of the report, says banks chould address the business models for retail and corporate payments separately.

"On the retail payments side, the key to success will be a lean, end-to-end business model aimed at achieving the highest possible level of efficiency," he says. "On the corporate side, the key will be end-to-end service excellence rather than focusing solely on efficiency."

According to the report, banks in Europe should continue to avoid massive Sepa-related investments and policymakers should stop driving payments providers into unnecessary expenditures and focus instead on other initiatives - such as setting industry standards for electronic and mobile payment instruments and improving payments inefficiencies within specific countries through incentives.

Large automated clearing-houses (ACHs) in Europe are also advised to wait until it is apparent whether full Sepa will actually be achieved before consolidating volumes onto one platform. ACHs should make strategic acquisitions in order to secure volume, says BCG, but should take a wait-and-see approach before carrying out full migration.

In North America, the imminent challenge for payments providers is maintaining growth amid the credit crunch. The winners, the report says, will be those banks that capture a greater share of consumers' balance sheets through loyalty strategies that offer flexible rewards tied to overall relationships. In Latin America, the main challenges are migrating consumer payment preferences from cash to cards and encouraging the adoption of cards by both unbanked and underbanked consumers.

The payments opportunity in the Asia-Pacific region, as in Latin America, begins with the large number of financially excluded consumers - those who do not have bank accounts. Mobile phones can thus play a game-changing role in emerging Asia-Pacific markets for distributing financial services in general - and payments specifically, says BCG.


Reblog this post [with Zemanta]

Contactless and "Clueless" How Convenient...


Yesterday I did a post: "Who Needs an Ounce of Prevention...We've Got 10 pounds of Cure!  where I weighed in on some backwards thinking.  Sacrificing security in the name of convenience is just plain dumb.

Today, in the Times Online, they talk about some backlash,  taking the form of fear, over contactless cards.  Of course, as you'll read, there's really nothing to fear and  there's no new risk.  A Barclay's spokeswoman explains why to the best of her ability... (hope not)

From Times Online
Fraud fears over contactless cards
Barclays' customers could be liable for up to £50 of any losses on their debit cards

Ali Hussain

A CASHLESS society came a step closer this week with the launch of Barclays “contactless” debit cards which allow customers to pay for items costing less than £10 by simply waving their cards over a reader.

However, concerns have been raised that customers will be exposed to more card fraud as stolen or lost cards will not require a pin to make payments.
In some cases, customers could find they are liable for up to £50 of any losses.

The cards are being sent to all customers when their existing cards expire. Barclays is the first bank in the UK to roll out the technology to all current account customers as "a standard feature of most new and replacement debit cards".

Up to three million customers are expected to be using contactless debit cards by the end of the year and the majority of Barclays debit card customers will have one by 2011. However, there are concerns that the cards are more likely to expose the owner to any losses incurred before they report the card stolen.

Anyone finding a wallet containing a contactless card could immediately use it to make a number of small purchases while the card remains active.  Apacs, the UK payments authority, said consumers are liable for the first £50 if their debit card is used by thieves before they cancel it.  Editor's Note: Okay, so the new cards can be used immediately, and consumers are  liable for the extra 50 pounds put on their cards.  Understood.  The next part is a little more confusing..

A spokeswoman for Barclays "denied" it was exposing its customers to a new risk
, she said: "A lost and "reported" card will be immediately cancelled, and no longer useable.
A card that has been lost but unreported for whatever reason can only be used four or five times before a PIN number is demanded.   If the card was used fraudulently before it was reported missing we would look at the refund circumstances on an individual basis."

Editor's Note:  So let me get this straight...a Barclay's spokeswoman "denied" it was exposing customers to a new risk...and the reasoning was that although consumers are "liable" for the first 50 pounds if their cards are used by thieves, (and a lost or stolen card can be immediately used)...the safety valve is that contactless cards can only be used 5 times (for 10 pound purchases) before a PIN number is demanded,  thereby alleviating the new 50 pound risk that the new cards are not exposing it's customers to on a case-by-case basis.  How convincing is that?  Talk about Barclay up the Wrong Tree

I'm dumbphoneded.  Oh, and one last thing.  A PIN Number?  As in a Personal Identification Number-Number?  Is that like dumb and dumber, but with a numb and number?  Give me security over convenience. 




Reblog this post [with Zemanta]

$440m Investment Fund for AltPay, eCom and Mobile Raised

New $440 Million Investment Fund

Snapping its fingers under the nose of the "Great Recession," Index Ventures has closed a 350 million euro investment fund, a little pile worth upwards of $440 million, that it means to trickle into high-tech start-ups that need seed money and early stage capital.

It's thinking ventures in the cloud, alternative payments, mobile and e-commerce as well as virtualization and clean technology that are located in the US, Israeli and Europe - and its map of Europe jumps the Urals and goes into Russia.

A European operation in business since 1996, Index backed Skype - before it went to eBay - MySQL - before Sun bought it for a billion dollars cash - and Last.fm - before CBS bought the social music platform.

This new fund is its fifth in the last 10 years.  It currently has money in Criteo (France), DimDim (India), Lehigh Technologies (US), MyHeritage (Israel), NormOxys (France), OpTier (Israel), Playfish (UK), WooMe (UK/US) and RightScale (US). And it frequently ties up with VC outfits such as Sequoia, Accel and NEA as well as angel investors such as Mark Andreessen.

David RimerDavid Rimer

David is a co-founder of Index Ventures and has been responsible for all aspects of the operations of Index since he joined in 1995. Prior to joining Index, David spent five years at The Capital Group Companies in Geneva, Los Angeles and New York. During his career at Capital, David worked in both the Fund Management and MSCI Index departments. He has a BA in Anthropology from Stanford University.





Contact details


Email:
Skype:
davidrimer
Location:
Switzerland
Assistant:
Manuela Cesarani -




Reblog this post [with Zemanta]

Monday, March 2, 2009

E-Pay's Sticking a PIN in Paper

E-Pay’s Sticking a PIN in Paper
Bank Technology News | March 2009 - By John Adams

It’s too early to dig a grave for paper money, but new research from BAI and Hitachi Consulting suggest cash is increasingly loosing out to automated payment modes like PIN and SIG debit.


The joint “2008 Study of Consumer Payment Preferences” shows PIN and SIG debit account for 37 percent of consumer payments, with cash coming in at 29 percent.

And
PIN debit wins out over SIG debit by a 45 percent to 35 percent count.

Continue Reading at BTN

For more information on the "2008 Study of Consumer Payment Preference and how not only debit, but specifically PIN Debit rules the land, read the PIN Payments Blog coverage at:

Debit is King...Replaces Cash on Throne


Reblog this post [with Zemanta]

PIN the Blame on the Dynamic Duo(poly)


Consumers, merchants take aim at high rates and fees - Steve Arnold - The Hamilton Spectator

Canadians have always had a love-hate relationship with their credit cards, but in recent months there has been a lot more hate than love as consumers and businesses bristle at the way they feel abused by credit card issuers.

At the top of that list are sudden and drastic increases in interest rates and service charges, especially "hidden fees" paid by merchants who accept cards -- fees that end up being figured into the cost of a restaurant meal, CD or new suit.  Reaction to those moves has sparked an Internet campaign led by the Retail Council of Canada called StopStickingItToUs.com .

Consumer anger about high interest rates -- up to 28.8 per cent in some cases -- and fees for everything from cash advances to foreign currency transactions has been well publicized. Less known are the "back office" fees that drain billions from hard-pressed merchants.

Peter Woolford, vice-president for policy development and research at the Retail Council, says that's allowed to go on because two massive companies dominate the market and use that bulk to gouge their customers.

"Credit cards remain an effective and efficient way of paying for goods, but there are problems," he said. "In Canada we have a duopoly in place that's taking advantage of its dominance to gouge us.

"We've been hit with a whole series of measures that have quite substantially increased the fees merchants have to pay," he added. "They very clearly are not listening to us."

The credit card market in Canada is utterly dominated by Visa and MasterCard
. Between them they control 80 per cent of the business -- 68.2 million credit cards used to purchase $267 billion of goods and services in 2008. In 2007 there were 64.1 million cards in use.

It's a profitable business. Very profitable. For 2008, Visa International reported global earnings of $1.7 billion US from processing payments of $2.7 trillion. In its earnings news release, the company stated its profit growth was "driven by strong contributions from service fees, data processing fees, and international transaction fees."  In the fourth quarter alone those fees amounted to $788 million, up 8 per cent over the prior year. Data processing fees rose 18 per cent, to $548 million, and international transaction fees were up 45 per cent.  For 2008, MasterCard International reported a net profit of almost $1.1 billion on revenue of $4.06 billion.

Those fees are the focus of the Retail Council's campaign demonizing "big credit card companies" that bled $4.5 billion from consumers in 2007 to cover "lavish incentive programs and corporate credit card benefits, even if you don't have one."

In industry jargon it's called the interchange fee, a levy of up to 3 per cent of the sale that's supposed to cover the cost of processing the transaction. Trouble is, according to the StopStickingItToUs campaign, only 13 per cent of what's collected actually goes to cover processing costs. More than 40 per cent goes to the cost of credit card reward programs such as Air Miles.

Restaurateurs Ron and Leanne Ciancone, of the Ancaster Old Mill and Spencer's in Burlington, figure 90 per cent of the business in their dining rooms is paid with credit cards. The fees for these transactions take as much as $170,000 a year off their profit statements.

"The credit card companies can do that to you. It's all about how much power they have," he said. "Nobody seems too interested in doing anything about it."  "In some of these cases the credit card company is making more on a purchase than the merchant, and for no added value other than a way to pay," she said.

Editor's Note: HATM can help online retailers cut their Interchange Fees by up to 100 basis points while providing an exponentially more secure payment environment for your online shoppers.  Contact us to find out how to bring online debit to online shopping.

Related Stories from the PIN Payments Blog
PIN Debit Payments Blog: Use PIN to "Start Sticking It To Them"  Sep 12, 2008
If retailers, specifically Internet Retailers, truly want V/MC to "stop sticking it to them," they should be organizing a push for PIN debit and the lower fees and higher security it brings to the table. ...

Editor's Note: This is the third time I've posted about Retail Council of Canada's "Stop Sticking itTo Us" campaign. They certainly are an incessant group getting a lot ofpublicity for their cause. Here's the latest attack on V/MC as ...

Credit-card companies 'sticking itto' Canadians with high fees, retailers say; EU to Allow DebitInterchange For Now - ETA; Canada Keeps Fighting to Change Interchange;Use a PIN to "Stop Sticking It To Us"... Update on HR 5546 ...

In it, I mentioned that if all these organizations made the same effort to have their customers use PIN Debit, they would stop sticking it to themselves. Maybe HomeATM can start a coalition with Internet Retailers and their associations ...
Reblog this post [with Zemanta]

Who Needs an Ounce of Prevention...We Have 10 pounds of Cure!

Barclays bank has rolled out a contactless Visa debit card - ZDNet.com.uk

From Monday, Barclays customers will receive new or replacement cards containing RFID technology that will allow contactless transactions of up to ten pounds, without entering a PIN. (Editor's Note:  Limiting transactions to 10 pounds ($14.10 US) is not a testament to the security of the methodology is it?)

Cards will continue to be used for chip and PIN transactions and bank machine withdrawals.  (Editor's Note:  HomeATM uses the same bank rails used for bank machine withdrawals)

The protocol behind the contactless technology has not been made available to academic security researchers, according Cambridge University researcher Steven Murdoch, who expressed concerns that any security holes in the technology won't be found until after it has been rolled out.

"The problem with the UK contactless system is that it's secret, which means we have to reverse engineer it to point out vulnerabilities," Murdoch told ZDNet UK on Monday. "Contactless payment has been rolled out, but any security vulnerabilities will be pointed out after the banks can do anything about it."

Murdoch said that while security researchers were restricted from viewing the protocol, people with malicious intent would be able to view it.  "I'm sure crooks will have a copy of the spec," said Murdoch. "People can get hold of a copy if they sign a contract saying they will not make any reports [about the protocol]. Any criminals could get hold of a copy of the specification, but academics are at a disadvantage."

A Barclays spokesperson told ZDNet UK on Monday that there had been extensive third party testing of the contactless system, and said that security risks around contactless payments had been mitigated.

Editor's Note:  Yeah, by limiting transactions to 10 pounds.  The money that hackers could steal is only 1% of what they could get by hacking into a system where they could steal 1000 pounds.  So I suppose, in a bend it like Beckham way...that statement could be "bent" into somehow being being defended as true.

"Contactless is designed for small transactions, while users will periodically be asked for a PIN," said the spokesperson. "The card uses dynamic data authentication, in which a unique secret code is generated to authenticate each transaction, while the chip contains different information than the magnetic strip, to prevent cloning."

The Barclays spokesperson added that testers had concluded that it would not be economically viable for criminals to subvert the system.  "The cost of intercepting the information doesn't justify how much could be made out of the information," said the spokesperson.

(Translation:  Sure...we know it's not secure, but we limit the purchases that can be made with this insecure non-solution to 10 pounds, so that shouldn't interest the hackers.  They can  make more by concentrated on bigger payouts.  Who needs prevention"...we've got 10 pounds of cure!)

Cambridge University researchers have said they have serious security concerns about chip and pin payments systems. Researchers Saar Drimer, Ross Anderson, and Murdoch published a paper on Thursday detailing security flaws in the Chip Authentication Programme (CAP) used for UK payments cards. The main problem for the researchers was that the some UK online cards payments systems using readers had been optimized for usability, to the extent of sacrificing security
Editor's Note:  You simply cannot sacrifice "convenience" for security.  No way, no how.  Security needs to be first and foremost on the minds of payment industry professionals.   HomeATM understands that, which is why we implore online shoppers to "swipe" their own card information in our tamper-proof, PCI 2.0* PED providing a "dually authenticated," "3DES end-to-end encrypted" online debit solution. (with DUKPT)   Don't call us alternative...the "alternative" is entering your card information "manually"...and having it get intercepted and "swiped" by the bad guys. Swipe...don't Type. 

*HomeATM's personal SwipePIN device has been rigorously tested by Witham Laborities (1 of 8 certification outfits in the world) and found to meet or exceed PCI 2.0 requirements.  Our device and the Witham Lab's report has been forwarded through the proper channels for PCI. 2.0 certification. 

Reblog this post [with Zemanta]

CBN Orders Banks to Stop Issuing Magstripe Payment Cards

The Central Bank of Nigeria (CBN) has ordered banks to Stop issuing magnetic stripe payment cards by April 1st 2009.A magnetic stripe payment card is a type of card capable of storing data by modifying the magnetism of tiny iron-based magnetic particles on a band of magnetic material on the card. The magnetic stripe, sometimes called a magstripe, is read by physical contact and swiping past a reading head.

On the other hand is the Smart (or chip) card which is the latest in payment card technology. This is a plastic card containing a computer chip and enabling the holder to purchase goods and services, enter restricted areas, access medical, financial, or other records, or performs other operations requiring data stored on the chip.

It has a built-in microprocessor and memory used for identification or financial transactions. When inserted into a reader, it transfers data to and from a central computer. It is more secure than a magnetic stripe card and can be programmed to self-destruct if the wrong password is entered too many times. As a financial transaction card, it can be loaded with digital money and used like a travelers check, except that variable amounts of money can be spent until the balance is zero.

In a circular to all banks titled, “Extension of Timeline for Migration from Magnetic stripe to Chip plus PIN/EMV, signed by the Acting director, banking supervision department, Mr. James Olekah, the CBN stated that, “Recall that section l,4.2c of the e-banking guidelines issued in 2003 by the CBN stipulates that “in view of the demonstrated weaknesses in the magnetic strip technology banks should adopt the chip( smart card) as the standard, within five years”. The implication of this is that the timeline given to card issuers in the guidelines had expired as at the end of August, 2008. However, after due considerations of the concerns from the market and other stakeholders,

The National Payments System Committee agree to extend the deadline for the migration to Chip+PIN technology to April 1, 2009. You are by this circular required to cease the issuance of new magnetic strip cards with effect from April 1, 2009. However, previously issued magnetic should be withdrawn on expiration of the cards and not as at April 1, 2009. Please note that no new extension of the time would be granted, while failure to comply with this directive will attract severe sanctions which would include imposition of financial penalty and withdrawal of approvals.”

It would be recalled that recently, in anticipation of the directive of the CBN on Chip Cards, InterSwitch,Nigeria’s premier payment transactions switching company, introduced Verve card, a pan-African innovative chip and PIN (Personal Identification Number), EMV compliant payment card.

According to Mr. Mitchell Elegbe, Managing Director/CEO of InterSwitch, who spoke to journalists at the media launch of Verve card, the expected change from magnetic strip cards to chip & PIN platform, is what necessitated the release of Verve card into the financial market.

Elegbe said CBN’s directive was made in the best interest of banks, merchants and cardholders because existing magnetic stripe cards have minimal storage space, cannot store applications, offer little flexibility for new product development, are easy to duplicate and offer minimal security features.
With the release of Verve card, which can be used on mobile,

ATMs, PoS, Web and the Internet, Nigerian banks are expected to begin the conversion of 28 million cards in circulation to the chip & PIN platform since major payment card schemes in Europe, Middle East, South America and Africa have converted their cards to the secured smartcard platform.

However, Verve card on other hand is secured with integrated circuit chip (ICC) and can carry enhanced data. The ‘chip’ part refers to the
smart card-a plastic payment card with an embedded microp pocessor, which contains the same information as a magnetic stripe but it has additional processing capabilities and a secure memory. In developing the Verve card, Mastercard MChip 4 technology was adopted. The card has bigger storage capacity, offline PIN verification and can perform cryptographic calculations.

”The microprocessor can hold multiple applications where an application may be a specific brand of credit card, loyalty card, gift card, staff discount card, etc; so a cardholder could have credit and debit applications, loyalty applications and electronic ticketing on a single physical card”, Elegbe explained.

Specifically, Elegbe informed that Verve cards can hold information securely and is difficult to copy or alter. The security and EMV features in Verve card guarantees a higher level of security for payment transactions than magnetic stripe cards. Interswitch has also initiated eight other security initiatives; MoneyGuard (which allows cardholders send an sms from their phones to block their cards should they suspect any unusual activities), Fraud Watch (a portal and email for fraud reporting and information management, Fraud Guard ( a fraud management and transaction security system), Fraud Insure (card fraud Insurance), Fraud Team (Risk Management team), Identity Guard (Token based strong authentication), Fraud Aware (Cardholder Awareness Campaign) and Data Guard (EMV Mchip 4).



Reblog this post [with Zemanta]

TrialPay Review


Review: TrialPay can help you get freebies online
By RACHEL METZ  AP

NEW YORK (AP) — With the economy in the dumps, you might hesitate before buying discretionary goodies like video games or pizza. But what if you could get those things for free by doing something you might already be inclined to do — like signing up for a trial of Netflix or buying coffee from Starbucks.com?

Mountain View, Calif.-based TrialPay offers just that kind of a deal, which it bills as a win-win-win for consumers, merchants and advertisers. It probably won't change your buying habits dramatically, but it could help you get a (sort of) free lunch.

Here's how it works: Let's say you're perusing a movie ticket Web site. If that site is working with TrialPay, you might be presented with the option to get tickets not by paying for them directly, but simply by completing a purchase or trial offer with another company. If you're game, you can click to see a list of participating companies, such as Starbucks or Netflix. And if you agree you'll receive e-mailed instructions on how to get your free movie tickets.

As TrialPay's 27-year-old co-founder, Alex Rampell, describes it, the service is "kind of like PayPal for people who don't pay."

Rampell began building his own business in high school and college by selling shareware — software that you can generally download and try for free but are later prompted to pay for. He came up with the idea for TrialPay in 2004 as a way to get more consumers to "pay" for his software, after talking with a marketer friend who helped him realize how much companies are willing to shell out to acquire customers.

People might not be willing to pay for software, but they might be willing to pay for cat food, he mused. And if a cat food seller is willing to pay the software seller for sending it a customer, then the software seller could ostensibly give its product to the customer for free.

Most of the free items you can get through TrialPay retail for about $30 or less. And except for some deals, like one with pizza-delivery chain Papa John's, most are not physical goods.

Still, the model appears to be working. Since the company started in the summer of 2006, it has grown to include more than 7,500 merchants and about 2,000 advertisers. TrialPay makes its money by taking a cut of what the advertiser pays the merchant.

Continue Reading


Reblog this post [with Zemanta]

iPhone = Two-Thirds of All Mobile Web Traffic

Apple's iPhone now represents 66.61 percent of all mobile web traffic according to a new study issued by web solutions provider NetApplications.

Click Chart to Enlarge


The Java ME platform follows a distant second at 9.06 percent, trailed by Windows Mobile at 6.91 percent. NetApplications notes that despite the iPhone's commanding lead in mobile browsing share, both Android (6.15 percent, tied with Symbian) and BlackBerry (2.24 percent) are rapidly gaining market share--however, the report notes increases by Apple's rivals does not mean that iPhone web browsing is shrinking, as the overall market continues to grow rapidly. In all, mobile web browsing as a percentage of all web browsing is on the upswing and currently stands at 0.72 percent, up from 0.69 percent in January 2009.

Source: Fierce Telecom





Reblog this post [with Zemanta]

ID Theft Top Consumer Complaint - FTC


FTC Releases List of Top Consumer Complaints in 2008

The Federal Trade Commission on Friday released the list of top consumer complaints received by the agency in 2008. The list, contained in the publication “Consumer Sentinel Network Data Book for January-December 2008,” showed that...
  • for the ninth year in a row, identity theft was the number one consumer complaint category.
  • Of 1,223,370 complaints received in 2008, 313,982 – or 26 percent – were related to identity theft.
In December, the FTC called on the US Government to "extend two-factor authentication" (such as the application provided by HomeATM) standards deployed by banks to all private sector organizations that maintain consumer accounts, in a bid to combat rising levels of ID fraud.  (See: Dual Authentication for ALL Consumer Accounts - FTC

This report breaks out complaint data on a state-by-state basis and also contains data about the 50 metropolitan areas reporting the highest per capita incidence of fraud and other complaints. In addition, the report sets forth the 50 metropolitan areas reporting the highest incidence of identity theft.

The report states that credit card fraud was the most common form of reported identity theft at 20 percent, followed by government documents/benefits fraud at 15 percent, employment fraud at 15 percent, phone or utilities fraud at 13 percent, bank fraud at 11 percent and loan fraud at four percent.

Reblog this post [with Zemanta]

Saturday, February 28, 2009

Hacked! Is Visa Next?



In an article scheduled for  next months Bank Technology News, Rebecca Sausner talks about the call and the need for systematic reform in the payments industry.  The main theme of the article is to adopt an End (Beginning) to End Encryption standard. 

One of the more eye-opening quotes comes from Avivah Litan, distinguished analyst from Gartner, who asks "How much worse can it get than a top 10 processor being breached? Visa's next."

Let me remind you Avivah Litan predicted that hackers would target the payment acquirers/processors months ago.  I believe it was shortly after the Hannaford breach. 

Now, with 3 processor/acquirer breaches in 3 months, it appears she's the Nostradamus of the financial transaction world.  So when one of her "quatrains" predict that "Visa's next"...I, for one, wouldn't write that off as being overly cautious (or pessimistic).  HomeATM CEO, Ken Mages, (who's also a "see-er) saw the same writing on the wall years ago.  Difference is, he's was in a position to, (and has already done) something about it.  Ms. Litan states that Visa needs to start seeing the same thing...or they're next. 

One of the reason's HomeATM employed End to End Encryption back in January 2007, is because Ken Mages understood that without beginning to end encryption, data is ripe for the picking. 

That's why HomeATM is the "only" (to our knowledge) processor who instantaneously encrypts the data at the point of sale (during the swipe) while it's inside our personal swiping device.  Amusingly, ironically and paradoxically, it's was his "outside the box" thinking that made him realize that encryption needs to be done "inside the box."

One of the biggest challenges HomeATM faces is overcoming the "hurdles" involved with trying to convince industry "insiders" that in order to truly secure a transaction, a hardware device is not optional,  it's necessary.  These latest breaches should make "overcoming those hurdles" a lot easier.  New Information always = New Decision(s).

One of the things we do have going for us in this "perfect storm," is that as unfortunate as these 3 processing/acquirer breaches in 3 months were, they are helping us in driving our message home. Articles like the one below don't hurt either.
These breaches should actually assist HomeATM in overcoming these hurdles... in fact, our technique(s) to securing transactions can hurdle HomeATM towards becoming an "Edwin Moses" like talent  

Speaking of Moses...they (the breaches) may even help part the read/see and get HomeATM to the promised land sooner. (Editor's Note: Edwin Moses overcame hurdles {for 122 straight wins} during a 9 year, 9 month and 9 day "run." 

I find it heartening that HomeATM's approach to securing/encrypting data for transaction's (since 1/2007) also involved a 9/9/9...99.9 Sigma. 

Like Edwin Moses, we WILL win. (with PIN)  The hackers don't hurt by "running" right through a processor's so-called security protocols.Here's an excerpt from the article:

Heartland's Lonely Quest For Reform
Bank Technology News | March 2009

By Rebecca Sausner

Heartland Payment Systems CEO Robert Carr has likened his company's massive data breach to the Tylenol moment when product contamination led to an overhaul in packaging safety. It's likely Carr has had a few Tylenol moments himself in the past couple of months as he dealt with perhaps the largest data breach ever, though the actual number of cards compromised is undisclosed.

Now Carr is using his standing in the industry - he founded Heartland and enjoys healthy respect among processors - to call for industry-wide reform of payments technology and information sharing about exploits to prevent criminals from successfully deploying the same hack on multiple targets.

Lots of industry players agree with his stance, but there's been scant input thus far from the industry's most influential parties: including titans such as MasterCard, Discover and Visa, which are mostly mum on the subject.

"Our concern is that an underlying principal of PCI compliance is that data can be held in its native form - unencrypted - as long as it is properly protected within a corporate firewall," says Bob Baldwin, CFO of Heartland.  Corporate firewalls are only as strong as their weakest link. "What we're trying to do in end-to-end encryption is have the data always remain in its encrypted form from the moment of the swipe to the moment it gets to the association."  (Editor's Note: that's going to be the biggest challenge as that will require the ecosystem of the payments landscape to be rebuilt)
It's easy to make a case that the Heartland breach should be a louder call for industrywide action than Hannaford or TJX.  The company is one of the leading processors, moving 11 million transactions each day, and was known to have invested heavily in its security. And, it had passed its latest PCI audit.


"I think it's more serious, how much worse can it get than a top 10 processor?" says Avivah Litan, Gartner vp. "Plus, it's a much bigger target. Visa's next."

Litan's in agreement with Carr that now's the time for the industry to pony up for end-to-end encryption. Some POS terminals can already encrypt data,

(Editor's Encryption Note 1
: Our PIN Entry Device was manufactured from "beginning to end" to do so)
processors can encrypt data while it's in their environment, (Editor's Encryption Note 2:  HomeATM not only "can" but DOES) and issuers could "theoretically" accept encrypted data and decrypt it in their environment.

Editor's Encryption Note 3:  That's the beauty of our PIN approach...it's not theoretical, it's reality.  PIN's remain encrypted all the way through the process...and not only is a KEY required by the processor to un-encrypt it, but HomeATM uses DUKPT (DuckPut)  which creates a "UNIQUE" key for every transaction.  In the extremely unlikely event "one key" is somehow obtained, only one transaction is put at risk because there's a new key for the next one.

For those interested, here's a quickie lesson.  Others, scroll down, my rant continues...


In cryptography, Derived Unique Key Per Transaction (DUKPT) is a key management scheme in which for every transaction, a unique key is used which is derivedfrom a fixed key. Therefore, if a derived key is compromised, futureand past transaction data are still protected since the next or priorkeys cannot be determined easily. DUKPT is specified in ANSI X9.24 part 1.

DUKPT allows the processing of the encryption to be moved away fromthe devices that hold the shared secret. The encryption is done with a derivedkey, which is not re-used after the transaction. DUKPT is used toencrypt electronic commerce transactions. While it can be used toprotect information between two companies or banks, it is typicallyused to encrypt PIN information acquired by Point-Of-Sale (POS) devices.

DUKPT is not itself an encryption standard; rather it is a key management technique. The features of the DUKPT scheme are:
  • enable both originating and receiving parties to be in agreement as to the key being used for a given transaction,
  • each transaction will have a distinct key from all other transactions, except by coincidence,
  • if a present key is compromised, past and future keys (and thus thetransactional data encrypted under them) remain uncompromised,
  • each device generates a different key sequence,
  • originators and receivers of encrypted messages do not have to perform an interactive key-agreement protocol beforehand.
The problem is without an agreed-upon standard - though triple DES would likely work - (Editor's Encryption Note 4:  HomeATM uses triple 3DES) there are "air gaps" between each of the players that even PCI doesn't address.


Still, it'd likely be worth the trouble.

Editor's Encryption Note 5:  It WAS worth the trouble, in fact that isn't what troubled us...what's  troubling is that it seems like it's taking forever getting other's (payment industry pro's) to understand what it written in this article...(maybe because it's written in "clear text.")

What we we need is an Edwin Moses approach to overcoming the hurdles involved with "parting that read/see" and getting industry insiders to "read" further into the risks mitigated by PIN and "see" what Avivah Litan see's...)


"I would say the cost of putting end-to-end encryption in place would be lower than the all the PCI security costs and the breaches," Litan says.

Editor's Encryption Note 6:  Ya think?  Now if we can only get "DUH!" so-called industry experts/insiders to see it that way...)  About the only thing HomeATM puts out there in "clear text" is that a "PIN Based 3DES DUKPT Encryption is the most secure way to process a transaction.  Beginning to End Encryption. 

Want to learn more about our Tales from Encrypt?  Contact us.
and we'll tell you all about it...from Beginning to End!


Continue Reading at Bank Technology News



Reblog this post [with Zemanta]

Visa: New Payment Processor Breach Not New

The new processor breach that has had everyone speculating over the past 2 weeks... is "not new" according to Visa. 

Everyone else's (100,000,000 plus cards) card information has not been kept a secret, yet the "identity" of the processor who let the hacking world into theirs HAS been.   Visa has already publicly stated that  this "new" breach was "unrelated to the Heartland breach," so that leaves only one processor in the running.  RBS Worldpay.  Developing...

Here's the story from ComputerWorld.com

Visa: New payment-processor data breach not so new after all
February 27, 2009 (Computerworld) Days after Visa Inc. seemingly confirmed that a data breach had taken place at a third payment processor, following on the recent breach disclosures by Heartland Payment Systems Inc. and RBS WorldPay Inc., the credit card company is now saying that there was no new security incident after all.

In actuality, Visa said in a statement issued today, alerts that it recently sent to banks and credit unions warning them about a compromise at a payment processor were related to the ongoing investigation of a previously known breach. However, Visa still didn't disclose the identity of the breached company, nor did it say why it is continuing to keep the name under wraps.

Visa said that it had sent lists of credit and debit card numbers found to have been compromised to financial institutions "so they can take steps to protect consumers." The company added that it currently "is risk-scoring all transactions in real time, helping card issuers better distinguish fraudulent transactions from legitimate ones."

Visa's latest statement follows ones that both it and MasterCard International Inc. issued earlier this week in response to questions about breach notices that had been posted by several credit unions and banking associations. The notices made it clear that they weren't referring to the system intrusion disclosed by Heartland on Jan. 20 and suggested that a new breach had occurred.

Visa's initial statement and the one from MasterCard were both carefully worded; neither said specifically that the breach being referred to was a new one, but they also didn't say that it was a previously disclosed incident. Visa said it was "aware that a processor has experienced a compromise of payment card account information from its systems," while MasterCard said it had notified card issuers of a "potential security breach" affecting a payment processor in the U.S.

MasterCard officials didn't respond today to requests seeking clarification on whether its statement referred to a previous breach or a new one.

Benson Bolling, vice president of lending at the Alabama Credit Union in Tuscaloosa, said today that officials there had understood the breach to be a new one based on the alerts sent out by Visa — but couldn't say that for sure. According to Bolling, the credit union, which posted an advisory on Feb. 17 and updated it two days later, was informed by Visa of a "big breach" shortly after getting the word about the intrusion at Heartland.

The identifying number that was used in the so-called Compromised Account Management System alert issued by Visa appeared to suggest a new breach, because it was different from those used in previous CAMS notices, Bolling said. It was his understanding, he added, that CAMS alerts related to a previous breach would use the same identifier as the original notifications...

continue reading at ComputerWorld.com


Disqus for ePayment News