OTTAWA — A leading business organization is calling on Finance Minister Jim Flaherty to use "moral suasion" to block credit card companies from entering the debit market so shoppers are shielded from higher price tags.
And if public pressure doesn't work, the Retail Council of Canada says Flaherty should exercise his power to regulate the payment system to protect retailers from seeing a "very substantial increase" in merchant costs, which would be passed on to consumers.
Interac has already applied to the Competition Bureau to restructure from a low-cost non-profit organization to a for-profit operation in anticipation of Visa Canada and MasterCard's move into the debit market.
"If government were to indicate that it was concerned about this, it was concerned about the cost this would impose on small businesses and on customers, I think the large banks would think very long and very hard before they bought in to the Visa and MasterCard model," said Peter Woolford, the retail council's vice-president of policy and research.
"Moral suasion has a role, so Visa and MasterCard might continue to try and sell their product, but the banks might look at it and say, 'Do we really want to infuriate all of our customers in order to make some money when we're already making money on the product we use today?'
"They might think twice before they say, 'We've got this great new product where we get to gouge you.'"
The retail council estimates merchant fees could more than triple if banks sign up with the debit systems of Visa or MasterCard. Currently, Interac fees for retailers range from about three to seven cents per transaction, depending on the size of the retailer. The fee does not change if the total bill for the transaction is higher, as is the case with credit-card transaction fees set by credit-card companies and paid to the issuing banks. Continue Reading
Revenue loss from ecommerce fraud rose 8 percent in 2008 to $4 billion, matching the overall growth in online sales, according to a new study.
Although ecommerce fraud as a percentage of total sales was flat at1.4 percent in 2008, total online sales actually grew so that theabsolute revenue lost increased from $3.7 billion in 2007 to theaforementioned $4 billion in 2008, according to the Mindwave Research study conducted for the Merchant Risk Council, a merchant-led trade association focused on electronic commerce risk and payments globally, and sponsored by CyberSource.
The survey also sought to compare Merchant Risk Council members'rates of fraud loss and transaction acceptance to the rates fornon-members.
Things going from bad to worse for Bob Carr as now he's been forced to sell almost 700,000 shares of his stock. That constitutes more than one-sixth of his holdings and the reason was to meet loan obligations for which the stock was pledged as security.
The balance of his shares continues to be subject to pledges under the loan and although it's likely he'll have to sell more shares to meet those pledges, this is the last time we're going to hear anything about it.
Last week, a class-action lawsuit was filed against Heartland on behalf of banks who were forced to issue new cards. (see related stories below)
A breach can be a messy thing. Hope the EFT networks are taking notice when they decide to go with either a hardware or software approach to bringing PIN Debit to the web. In the Heartland breach, although 100 MILLION Personal Account Numbers (PAN's) were obtained...the total number of PIN's lifted was ZERO. Let's keep it that way.
Here's the press release:
Click to Enlarge
Princeton, NJ – March 2, 2009 – Heartland Payment Systems, Inc. (NYSE: HPY) announced today that Robert O. Carr, chief executive officer, and his wife, Jill A. Carr, were subject to the forced sale of an aggregate of 692,412 shares of the company’s common stock to meet obligations under a loan for which the shares were pledged as security. The proceeds of the loan were used to refinance prior loans, a portion of the proceeds of which were expended by Carr in connection with the acquisition of approximately 1.75 million additional shares of Heartland Payment Systems stock by the exercise in 2006 of options granted by two large institutional stockholders. The balance of the common stock of the company owned by the Carrs, approximately 4.3 million shares, continues to be subject to pledges under the loan, and it is likely that additional shares will be sold.
Carr commented, “I am extremely disappointed about this involuntary sale of my stock. This forced sale is precipitated by the mix of extraordinary circumstances confronting Heartland and the recent drop in its stock price. Unfortunately, I had no ability to stop the sales by my lender. Together, with my wife, I have been one of the company’s largest shareholders since its inception, and I acquired additional shares of stock in 2006 as an expression of my confidence in the company’s potential. This sale initiated by my lender does not in any way reflect my view of the company’s value and future performance potential. My confidence in Heartland remains strong, and I am enthusiastic about reestablishing my ownership position in the company over the months and years to come.”
The company has also been advised that Sanford C. Brown, chief sales officer, is expected to be subject to a forced sale of shares of the company’s common stock to meet obligations under a loan for which the shares were pledged as security.
The company does not undertake to provide further updates concerning future forced sales of shares owned by the Carrs or Brown.
If you're interested in learning how to protect your business against card-not-present fraud, Quova's new white paper, "Geolocation - Knowing Your Enemy," may be of interest.
This paper addresses how Quova's customers are using IP geolocation technology to minimize fraudulent online orders, limit manual reviews and reduce false positives by:
Recognizing mismatches between credit card billing locations and IP locations
Blocking orders from specific "high risk" countries
Flagging orders with problematic domain name extensions
Identifying and declining or reviewing orders forwarded by anonymous proxy servers
Detecting uncharacteristic behavior from analysis of user profiles
Establishing unlikely time patterns for location or frequency of shopping activity
Ukash brings vouchers on the French market via partnership with Central Telecom
UK voucher-based prepaid online payments provider Ukash has partnered French telecom operator Central Telecom to make the Ukash vouchers available through Central Telecom's Tonéo prepaid card.
According to the agreement between the two parties, French online shoppers can buy a Tonéo card at over 15,000 locations across the country and exchange it for a Ukash voucher on the internet or via SMS through Tonéo's call centre, virtualgoodsnews.com reports. Online buyers can use the vouchers to make purchases on social networks, virtual worlds and online games.
Tonéo enables customers to make IDD calls, pay online or top up a mobile abroad (airtime transfer). In order to pay with a prepaid Tonéo card which can be bought from a store or on the internet, customers must convert credit into a payment code with one of Tonéo partners: Ukash, Wallie or French online payment services provider Ticket surf.
The Ukash, Wallie or Ticket surf payment orders allow customers to purchase virtual services within online games, pay for top-ups for VoIP and settle subscriptions on social networking websites.
Leading Biometric Check Cashing Company Changes Name to AllTrust Networks
Trusted Data Network and New Service Offerings, Prepaid Card and Bill Payment, Drive Name Change
HERNDON, VA – (March, 2009 (AllPayNews.com) – The leader in biometric check cashing, formerly know as BioPay Paycheck Secure, announced its new company name, AllTrust Networks. Still under the same ownership and management, the name change is part of the company’s overall strategy to position itself as the leading provider of “decisioning” data in the alternate financial service market. Its customers, retailers who are part of the AllTrust network, benefit from this “trusted” data source, receiving valuable check recommendations based on transaction history – from both the check issuer and the check casher. Transactions that begin with a biometric identification are faster and more secure than traditional check authorization systems. AllTrust leverages its network of over 5-million enrolled consumers and thousands of retail locations to dramatically reduce the fraud risks of payroll check cashing.
The name change also reflects the expansion of the company’s service offerings and the added value created for both retail clients and consumers. Prepaid card issuance and bill payment services complement the base check cashing system, and enable retailers to more efficiently fulfill their customers’ needs by using one system to perform multiple financial services. In addition AllTrust Networks has enhanced existing features of the check cashing product including electronic deposits and check maker research, to improve the overall retailer experience.
“Our client base, comprised of grocery, c-store and financial service centers, uses our check cashing system to drive in-store traffic, reduce losses from bad checks and grow their businesses by efficiently serving underbanked individuals,” said Jon Dorsey, CEO of AllTrust Networks. “We are proud of our ability to service this market through our trusted data network, and strongly believe that the name change more clearly defines our commitment to both retailers and consumers.”
About AllTrust Networks
With more than five million registered consumers, AllTrust Networks, formerly BioPay Paycheck Secure, is the most widely used biometric check cashing system in the nation. Thousands of retail locations across 46-states are using the Paycheck Secure system to quickly, safely, and easily identify customers and process financial transactions. Designed to stop fraud and speed check cashing transactions, the payroll check cashing solution, now offers retailers and banks full MSB compliance, embedded Check 21 processing, prepaid card and bill payment services. For more information on AllTrust Networks, visit www.alltrustnetworks.com
Editor's Note: First off, let me be perfectly clear. This is good news in terms of bringing PIN Debit to the web and I don't want to appear biased in any way when I publish my analysis of this announcement tomorrow.
For the record, I've spoken with Acculynk's co-founder and President, Nandan Sheth, several times over the past year and frankly, I've got nothing but good things to say about him. He's an excellent marketer and an excellent sales professional. He has taken a company (ATMDirect) which started in Dallas several years ago, (and was subsequently acquired by Pay By Touch, with whom I was a founding shareholder) and has done more with it, in a very short time, than either Pay By Touch or it's founder, Mr Zeiglar had done over the last decade. A magnificent job on Mr. Sheth's part. I look forward to meeting with him at FinovateStartup'09 in April where both HomeATM and Acculynk will be demonstrating their wares...our's hard...his soft...er simple I think it says on the graphic to your left.
With that said, tomorrow I shall Type, Not (take a) Swipe at my understanding of why the methodology behind Acculynk's software based solution could put users at risk. I will use recently published examples, and ask questions as to whether those same recent exploits could apply to any software-based (I'm not picking on Acculynk) Internet PIN Debit solution. And I'm not alone...Avivah Litan, Gartner's Distinguished Analyst predicted that processors would be next to be hacked.She's even recently implied she thinks Visa's Next. I think she presents her opinion in very simple terms. In a recent ATM&Debit News article entitled "HomeATM Wants to Change the E-Commerce Experience (click here to download article in PDF) she says:
"I would highly recommend (to any consumer) not entering their PIN anywhere on the Internet unless it were hardware-based - Avivah Litan
Talk about a transmitting in clear text! That's about as clear as it gets. Any questions? Do ask.
As regular readers of this blog are most certainly aware, I have pointed out many times that in today's fraud-ridden payments space, it is clear there is a distinct need for end-to-end encryption. E2EE has been getting a lot of coverage lately on the heels of the "massive" Heartland Payment Systems (HPY) breach. Whereas, HPY co-founder and CEO Robert (Bob) O. Carr is calling for it to position his company's defense in impending class-action lawsuits, HomeATM has incorporated it into it payment schemata since January 2007, well before any processor had been breached. Note: I have my opinion that it's the Heartland call for E2EE is a legal maneuver designed to PIN the blame on V/MC...otherwise he'd have called for it prior to the breach. It's part of their strategy to "meritoriously defend" themselves. V/MC leaves a window open when they receive the unencrypted data, and that window may be the only window of opportunity Bob O. Carr has to keep his company alive. But that's a post for another day...getting back to true end-to-end-encryption, security and how it relates to Acculynk...
I understand that with Acculynk's approach, the keyboard is locked (preventing keylogging) when the floating PIN Pad comes up, but if a consumer/user can see the Graphical User Interface, (GUI) then so can the hackers. That's not only my contention but one that is shared by many respected authorities in the payments industry.
Keylogging is but only one method of attack. Screen scraping is another oldie, but goodie. The floating PIN Pad can float all it wants and it can scramble and shuffle the numbers all it wants, but at the end of the day...if a hacker has control over the user's PC, via malware, bots, etc, they can watch the consumer move the mouse arrow as it approaches the GUI (and screen save) each entry of each number of the PIN. Holy Grail Batman!
I understand that there's encryption, I'm not quite sure how this method would lower interchange fees, since the transaction would still technically be a "card not present" (CNP) transaction" because it requires the consumer to "type" in their Personal Account Number {PAN} and therefore, it's a CNP transaction. I've never seen published Interchange rates on a CNP PIN transaction. Of course, that's the least of the worries that many people I've talked to have.
Their concerns are more or less (pun intended) security related. "Simple and Secure" are not usually two words that go hand in hand. One of my biggest worries is that some journalists will read thepress release issued today by Acculynk think it's the greatest thingsince sliced bread. Maybe it is...maybe it isn't, but that determination should be made by doing research. So, I implore anyone who reads this blog that may bein the field of journalism to do some common sense research in order todetermine how safe you think this process really is. If E2EE, 3DES or DUKPT seems to technical, call AvivahLitan and ask her yourself. She's usually pretty good about taking thetime to speak with journalists in layman's terms...and whereas my rants could be mistakenfor competitive jealously (I assure you they're not)...her take is both authoritative and legit.
That said...I want to be sure to take the time to extend kind regards and "Kudos" to both Mr. Sheth and Acculynk for providing PIN Debit on the Web with some major momentum! Online Debit for Online Shoppers is long overdue and there's no doubt he is a pioneer. By the way...Acculynk also has a demo of their application in Flash, which can be viewed by clicking the following link: Acculynk Flash Demo of PaySecure(TM)
Here's Acculynk's press release...
Acculynk Announces Issuer Participation in Pin Debit Pilot Program Wednesday March 4th Estimated Card Base of Several Million to Be Enabled During the Pilot
ATLANTA--(BUSINESS WIRE)--Acculynk’s Internet PIN debit pilot program is scheduled to go live in early March with several issuers that will bring several million cards to the pilot. The first pilot issuers to participate are from the ACCEL/ExchangeEFT network, owned by Fiserv, Inc., the leading global provider of financial services technology solutions. A second EFT network will be announced in a few weeks.
“We’ve had very strong interest from our issuing community, including some of our council members, because this is a value-add service that provides greater security for a consumer’s online transaction,” said Michael Kelly, (pictured on left) general manager of the ACCEL/Exchange Network, from Fiserv. “We are very excited that some of the first transactions for this payment type will be driven through ACCEL/Exchange issuers.”
PaySecureTM utilizes a consumer’s debit card and the PIN for online payments, requires no redirection or enrollment, and offers consumers a simple and familiar checkout experience.
“With security a top priority for all consumers, we strongly feel that adding a second factor of authentication for online payments will increase the security of our customer’s data. Many of our cardholders prefer to use PIN debit at the point of sale. We are excited to give them this payment choice online with a service that adds an extra layer of fraud protection,” said Jeff Gegen, Vice President of Bank Operations at Baker Boyer Bank, an ACCEL/Exchange issuer. “This is a historic pilot program where the promise of PIN debit on the Internet is finally being realized, and we are thrilled to be one of the initial issuers participating.”
As one of North America’s premier ATM/POS networks, ACCEL/Exchange from Fiserv provides financial institutions with the infrastructure for cardholders to access their funds anytime, anywhere. The network is currently enabled at more than 200,000 ATMS in North America and most major merchant locations throughout the United States.
Acculynk is the first company in the U.S. to bring PIN debit to the Internet with a software-only service that has been certified by several major EFT networks. PaySecureTM provides an extra layer of security for online card transactions and reduces fraud and charge-backs by as much as 75% for issuers, while offering attractive margins and no-cost adoption.
“Our value proposition to issuers is very strong, and we’ve managed to secure an impressive line-up of institutions for this pilot,” said Ashish Bahl, CEO of Acculynk. “But what’s most exciting is the enormous merchant demand for this product. Such demand will benefit all of our issuers with increased volume and brand awareness.”
Acculynk brings the strength of PIN-based authentication to a domestic online market that has recently been impacted by increased fraud associated with data breaches.
About Acculynk
Acculynk is a leading technology provider with a suite of software-only services that secure online transactions. Backed by a powerful encryption and authentication framework protected by a family of issued and pending patents, Acculynk’s services provide greater security, reliability, convenience and return on investment for consumers, merchants, networks, issuers and acquirers. For more information, visit www.acculynk.com.
About Fiserv
Fiserv, Inc. (NASDAQ: FISV - News) is the leading global provider of information management and electronic commerce systems for the financial services industry, driving innovation that transforms experiences for financial institutions and their customers. Ranked No. 1 on the FinTech 100 survey of top technology partners to the financial services industry, Fiserv celebrates its 25th year in 2009. For more information, visit www.fiserv.com.
Contact:
Acculynk Corporate Contact: Danielle Duclos, Director of Marketing, 678-894-7013 dduclos@acculynk.com
Remember when Visa and MasterCard were credit card companies? Well they've quietly "shifted" their focus. With 314 million debit cards, 53% of Visa's card volume is debit.
Meanwhile, MasterCard has seen their 126 million debit cards be responsible for 40% of their business. And don't think it will stop there. They saw the writing on the wall years ago.
The people behind Visa and MasterCard have been called many things, but stupid isn't one of them. Here's some proof of that...
MasterCard Grows Debit Business with KeyBank Deal By Juan Lagorio
NEW YORK (Reuters) - MasterCard Inc., the world's second-largest credit-card network, will launch a debit card with U.S. regional bank KeyBank on Wednesday, in MasterCard's latest bid to tap demand for payment systems that do not involve borrowing.
"Debit remains a priority for us," Patricia Preston, senior vice president of U.S. debit product management and development of MasterCard Worldwide, told Reuters in an interview. The World Debit MasterCard will offer rewards, discounts, and savings in an effort to attract customers. Cleveland-based KeyBank, a unit of KeyCorp (KEY.N), will be the first of many partners the credit card network expects to adopt the new debit card.
KeyBank plans to issue 25,000 of the cards by the end of March, and 60,000 by the end of the first year, said Carl Stauffeneger, senior consumer product manager of KeyBank. He added the bank, with almost 1,000 branches in 14 states, was targeting clients with an annual debit spend of around $7,500.
MasterCard said it expected to promote the new debit card in the United States before exporting it to other countries, but declined to give further details.
The company prospered in recent years as fast-spending consumers used their credit cards more. But with many Americans trying to curb their borrowing, the use of debit cards is likely to increase as consumers stick to stricter budgets.
In the United States, credit transactions represent 60 percent of the gross dollar volume of MasterCard, while debit cards make up the rest. In contrast, rival Visa has a bigger presence in the debit business in the United States, with 53 percent of Visa's total volume in debit cards, and 47 percent in credit cards. (Editor's Paradigm Shift Note:: Just as Macy's "net profit" surged 29% (net as Internet, not gross vs. net) and their bricks and mortar shrunk 7.7.%, Debit Card volume grew 13 percent while credit cards shrank 2% MasterCard has 126 million debit cards in use in the United States, while Visa has 314 million debit cards.
Calls for widespread EV (Extended Valuation) SSL implementation are on the rise as SSL threats increase
By Kelly Jackson Higgins - DarkReading
Two years after its rollout, the more secure Extended Validation Secure Sockets Layer (EV SSL) digital certificate for authenticating Websites and securing Web sessions is used on more than 11,000 Websites worldwide. But that's only 1 percent of the 1.03 million sites currently secured with SSL certificates, according to Netcraft.
Editor Translation: 99% of "SSL Secure" websites are "SOL" when it comes to security.
Meanwhile, calls for EV SSL adoption have intensified amid concerns of new man-in-the-middle (MITM) attacks targeting newly discovered weaknesses in SSL, namely the MD5 encryption algorithm hack that allows the creation of forged CA and X.509 digital certificates, and the MITM attack demonstrated at Black Hat DC that basically makes users think they are visiting a secure Website when they are not.
Facebook has been targeted by malicious hackers seeking to steal valuable data from members. The social network site has been hit by five separate security problems in the last seven days, say security experts.
By creating fake messages padded with details of Facebook members the thieves are capitalising on the trust and social links that drive the network. Security firms warn that the popularity of social networking sites makes them a tempting target for hi-tech thieves. Trust network
"It's been a pretty bad week for social networking in general," said Rik Ferguson, senior security advisor at Trend Micro.
In the last week, said Mr Ferguson, Facebook had been hit by four malicious applications as well as a new variant of the Koobface virus that first targeted members of the social site in December 2008. The rogue applications on Facebook all try to steal saleable information from the profiles of those who open it up, said Mr Ferguson.
One malicious application tried to trick people into adding it by claiming that their friends were having trouble looking at their profile. If the application is added it spams itself to every Facebook friend that a member of the site has. Even as Facebook stamps out one malignant application, it can pop up in another place." Once installed the malicious program hunts for cookies on a victim's computer and uses the details it finds in the small text files to log into other social sites that person may be a member of. Editor's Note: I have to wonder out loud why they wouldn't be able to log into Twitter as "anyone they want" and wipe out "anyone they want's" prepaid "Twitpay" account.
Watch for the headline of that particular breach by the end of the year....
About 7.5 percent of U.S. adults lost money as a result of financial fraud last year, mostly due to data breaches, according to a new Gartner study released on last night.
In the survey of nearly 5,000 consumers, 70 percent said they had never been a victim of identity theft fraud. Meanwhile 14 percent said they had had their credit card information used to charge purchases or get money, 7 percent said their debit card was used, 6 percent said a new account had been opened in their name, 5 percent had money transferred out of their account, and 4 percent had had checks forged.
The study also looked at why people switch banks and concluded that security and financial health of a bank were of about equal importance to consumers, said Gartner analyst Avivah Litan.
From the Twitpay Blog: Twitpay taken out of Beta...
First, an overview.
In order to use this service you must first sign up, secondly Transfer (PUT SOME CASH) money into your Twitpay account which is administered by Amazon, and third, use Amazon Payments to move your cash to and fro. This isn't a true money transfer service...it's a prepaid service. Otherwise you would not have to "fund" a third party first in order to fund a first party second...
According to Twitpay’s FAQ page, the app was created “because Silicon Alley Insider said it was a billion dollar business (and) a billion dollar business sounded good to us.” It is a good idea. But...as you'll read below, Twitter themselves admit that "we’ve faced some challenges, mostly because doing money transfer is a pretty complicated thing to do. There are a lot more regulations to comply with than we guessed over that weekend in November". Well guess what. Hackers can (and will) make it even more complicated in the future. The idea of taking your cash out of your checking or savings account and placing it into another account before it can be transferred seems to be to "middlemanish." Why go through that extra step when instead you could completely eliminate the middle man? It seems to me that with no middleman, you would eliminate "man-in-the-middle" attacks. That's how HomeATM's P2P money transfer service is designed. You enter the email of the recipient, swipe your card, enter your PIN, hit Send. They receive the email, swipe "their" card, enter "their" PIN and hit Receive. Simple yes? Dually authenticated on BOTH ends, with beginning to end encryption. And it's done in "REAL-TIME".
This from the Twitpay Blog:
Today, we’re taking Twitpay out of beta and putting it out there for everyone to use. (If you don’t like to read long blog posts: we’re turning on “real money” powered by Amazon Payments. We’re excited. Twitpay is awesome.)
Since our unusual inception at Atlanta Startup Weekend 2 we’ve had an interesting few months. As a company, we’ve faced some challenges, mostly because doing money transfer is a pretty complicated thing to do. There are a lot more regulations to comply with than we guessed over that weekend in November. We’ve also seen some competition, and some copycats. We welcome the former, and are annoyed by the latter, although the job post for “build a clone of Twitpay” was really appealing. Maybe we should have applied for it…
Mostly what we’ve seen is that you want to use Twitpay, just like we do. In fact, the most frequent question (maybe the only question) we get asked is “When can I do real money?”
We’re exceedingly happy to say that the answer is “right now.”
As we’ve thought about what’s important about social payments, a few things stayed in the front of our minds: they have to be really easy, and they have to be secure. We got the easy part down on Day 1: just tweet the money and it goes! If you haven’t used Twitpay yet, here’s how it works:
1. Post a tweet like ”@ev twitpay $1 because Twitter is awesome” 2. There’s no Step 2!
Our apologies to Jeff Goldblum.
If you’re sending money to someone who will probably send you some back later (settling up your coffee shop tab every day) you may be happy with just keeping track. For most of us, though, there are times when you want to send “real money.”
The standard way to solve this is to say “Well, you give some money to Twitpay, and then later we’ll give it to the person you sent money to.” In fact, that’s what we started to do at first. Something didn’t sit right with us, though. Why should you trust Twitpay with your money? You don’t know us. Even more importantly, in the above scenario, Twitpay effectively becomes a bank. And while the allure of TARP funds is seductive, we’ve heard some rumblings lately that maybe being a bank isn’t the greatest idea right now.
So we decided not to ask you to trust us. Working with Amazon Payments, we’ve built a new version of Twitpay that means we don’t have to be the middle-man for your cash. That’s good for you as a user because you don’t have to trust us with your money, you just have to trust Amazon. It’s good for us as a service because it allows us to focus on adding new features and focus on the core of our business.
So as of 12:01 AM, March 3, 2009, Twitpay is live with real money. And we are also the most secure and trustworthy social payment platform out there. If you have any ideas or suggestions, please visit us twitpay.me and click on the Support link. We look forward to hearing from you.
IBM's Zurich research laboratory has developed a USB stick that the company says can ensure safe banking transactions even if a PC is riddled with malware.
A prototype of the device, called ZTIC (Zone Trusted Information Channel), is on display for the first time at the Cebit trade show this week. IBM hopes to entice banks into buying it for online banking, which saves banks money on personnel costs but is constantly under siege by hackers.
When plugged into a computer, ZTIC is configured to open a secure SSL (Secure Sockets Layer) connection with a bank's servers, said Michael Baentsch, product manager for BlueZ Business Computing at the Zurich lab.
ZTIC is also a smart-card reader and can accept a person's bank card for verification. Once a PIN (personal identification number) is verified, a transaction can be initiated through a Web browser.
Web browsers, however, are a point of weakness for online banking because of so-called man-in-the-middle attacks.
Hackers have created malicious software programs than can modify data as it is sent to a bank's Web server but then display the information the consumer intended in the browser. As a result, a person's bank account could be emptied. Man-in-the-middle attacks are also effective even if the bank's customer is using a one-time password generator.
The ZTIC, however, bypasses the browser and goes directly to the bank. It ensures that the data exchanged is accurate.
Editor's Note: Sounds like IBM agrees with Avivah Litan, who agrees with HomeATM. Hardware is not an option...it's a necessity.
For example, say a bank customer wants to transfer money. The customer will input US$100 into a form in the browser. The bank's servers will then try to confirm the amount. During a man-in-the-middle attack, the attacker is capable of transferring $1,000 but can modify the confirmation message to still show $100.
Since it has a direct secure connection with the bank's servers, the ZTIC will show the amount that actually has been requested to be sent. So even if the browser shows a confirmation for $100, the ZTIC will show $1,000, indicating a man-in-the-middle attack in progress, Baentsch said. The user would know to reject the transaction and press the red "x" button on the ZTIC.
"If malware is attacking your online banking transaction, it will show you something strange has happened," Baentsch said.
IBM expended a lot of effort to figure how to initiate an SSL session within a USB stick, Baentsch said. It takes some processing muscle, and since the USB runs independent of the PC, it does not have access to the computer's processor.
ZTIC uses a chip from microprocessor designer ARM, and the software has been designed so it can quickly establish a SSL session, Baentsch said. Although it is a memory stick, no data can be stored on it, which also prevents malicious software from infecting it.
Using ZTIC would also prevent phishing attacks, where a fraudulent Web site tries to elicit sensitive details from a user, and pharming attacks, where DNS (Domain Name System) settings have been tampered with, Baentsch said. ZTIC checks to ensure that the Web site has a valid security certificate.
IBM has internal figures on how much the ZTIC might cost for banks, but Baentsch wouldn't reveal them, saying that it would depend on the final design specifications of the ZTIC and other factors.
Web sales at Macy’s grow 29% in 2008 while total sales sink 7.7%
The full-year story on 2008 is in for Macys Inc., the department store chain, and final numbers confirm what the chain experienced as the year progressed: Online sales had blow-out growth while the stores continued to sink.
Macy’s online sales grew 29% in 2008 while total sales were down 7.7% and comp-store sales were down 7%.
Macy’s, No. 28 in the Internet Retailer Top 500 Guide, didn’t break out dollar numbers for online sales in its earnings report this week, but the Internet Retailer Top 500 Guide estimated Macy’s 2007 web sales at $812.2 million. Growth of 29% would put Macys.com’s 2008 sales at $1.04 billion, an increase of about $230 million.
By that measure, the web accounted for 4.2% of Macy’s sales in 2008 vs. 3.1% the year before. Total sales in 2008 equaled $24.89 billion versus $26.31 billion in 2007. Macy’s includes web site sales in its same-store sales calculations.
Macy’s bottom line was in positive territory, with net earnings of $280 million versus $893 million a year earlier.
Macy’s executives were unable to explain the cause of the growth in web sales in a call with stock analysts this week. When an analyst asked why online sales had grown so strongly, Karen M. Hoguet, Macy’s CFO, said, “I don’t know, honestly. We’re very pleased with it, I think the team working on Macys.com has done a terrific job of integrating it more and more with the store experience, so I think that’s a piece of it. I think that the site looks better than ever, the assortments are sharp and were in stock. I have to believe that helps. But I’m surprised.”
According to two surveys of USmobile phone users that were conducted by ABI Research, most consumers’preferences and choices when using their mobile phones for shoppinghave remained largely unchanged between late 2007 and late 2008,indicating the barriers to mobile money services remain strong.
Howeveron a more positive note more than half of all the respondents havepurchased at least one ringtone, suggesting that low-value transactionsare less threatening to consumers. Respondents also showed somewillingness to have mobile purchases added to their wireless phone bill.
“Consistentfrom year to year, a little over one-half of all respondents are notinterested in using their mobile phones to make purchases,” says ABIResearch senior analyst Jeff Orr.
“Transaction security was cited by71% of mobile phone users as a major concern preventing wider uptake.
As consumers become more comfortable with transaction security byestablishing trust with transaction vendors, more emphasis will beplaced on the speed of the transaction.”
Textmarketing messages remain unpopular with consumers, although someindicated that they were open to inducements such as free content aimedat converting a message to a sale.Senior analyst Mark Beccueadds, “As smartphone penetration increases, more merchants willintroduce mobile shopping, spurring growth. Smart merchants will focuson the advantages of mobile, such as impulse shopping and real-timeauctions.“
The surveys, each of which sampled more than 1000 mobile phone users in the United Statesaged 14-59 and across a wide range of demographic profiles, wereconducted in November 2007 and December 2008. They queried users’preferences with regard to a variety of mobile phone and content usagequestions.
“US Mobile Phone Purchase Trends”compares results of the two surveys, and includes survey methodology,responses laid out in charts with additional summaries and analysis,and respondent classification/demographics.Itis one of a series of Research Briefs comparing the results of ABIResearch’s 2007 and 2008 consumer mobile content surveys across anumber of topics. They are all included in two of the firm’s Research Services, “The Mobile Consumer” and Mobile Money.
ABIResearch provides in-depth analysis and quantitative forecasting ofemerging trends in global connectivity. From offices in North America,Europe and Asia, ABI Research’sworldwide team of experts advise thousands of decision makers throughresearch and advisory services in seven key practice areas. Est. 1990.For more information visit www.abiresearch.com, or call +1.516.624.2500.
BEVERLY HILLS, Calif.--(BUSINESS WIRE)--Verifi Inc., the leading provider of transaction risk management services for card-not-present merchants, today announced that the company has signed a preferred partner agreement with Chase Paymentech.
Chase Paymentech is a global leader in payment processing and merchant acquiring, processing more than half of all Internet transactions.
Verifi will recommend Chase Paymentech as a preferred merchant account provider to its merchant customers, and will provide its transaction risk management services, including chargeback prevention and management, to Chase Paymentech's card-not-present merchants.
"Verifi has already had success in working with our merchants to help them identify transaction risk, and has put effective measures in place that not only allow them to control chargebacks, but also help them operate more efficient and profitable businesses," said Rob Lyons, Vice President, Technology Alliances, for Chase Paymentech.
"We are very pleased to be partnering with Chase Paymentech, the recognized leader in card-not-present transaction processing, and we look forward to working jointly with them to help our mutual clients identify and manage their transaction risk," said Jennifer Schulz, chief operating officer of Verifi.
About Chase Paymentech
Chase Paymentech, a business unit of JPMorgan Chase, is a global leader in payment processing and merchant acquiring, capable of authorizing transactions in more than 130 currencies. The company's state-of-the-art platforms provide access to a wide variety of payment methods, such as credit cards, debit cards, prepaid stored value cards and electronic check processing.
With a legacy of innovation and vision in electronic payments, Chase Paymentech has promoted the growth of e-commerce worldwide. The company continues to fuel the success of the Internet's largest brands, currently processing more than 50 percent of all Internet transactions. Offering secure payment solutions, improving cash-flow management, mitigating risk and accelerating funding, Chase Paymentech's consultative approach helps today's small and emerging businesses become tomorrow's industry leaders. On the Internet or at the point of sale, Chase Paymentech's unique combination of outstanding service, innovative solutions and financial strength offers solid benefits to companies both large and small. More information can be found at www.chasepaymentech.com.
About Verifi
Verifi is a leading provider of electronic payment and risk management solutions for card-not-present merchants. Verifi’s highly customizable payment gateway serves as a foundation for its suite of risk management services. Verifi has a proven track record of reducing risk and increasing profitability for its clients by offering transaction risk management and mitigation, business optimization strategies, cardholder authentication, and chargeback representment for all major card brands.
Verifi also advises and supports its clients with a full compliment of alternative payment services. Verifi is a PCI Level1 compliant transaction processor, and is certified to process transactions with all major U.S. payment processors. Verifi continually works with its partners within the payment industry to drive innovative services and solutions that will help its merchant clients to better manage risk and operate their business more efficiently.
The company is headquartered in Los Angeles, California with a satellite office in Redwood Shores, California. For more information on Verifi, please visit www.Verifi.com.
eMarketer reports on comScore's 2008 E-Commerce Sales..
Unlike in preceding years, business-to-consumer (B2C) e-commerce growth got sluggish in 2008. Looking specifically at retail e-commerce, comScore found that sales grew by only 6% in 2008, the lowest rate since the dot-com crash in 2003.
Of the total $221 billion in B2C online sales last year, $130 billion were retail e-commerce sales. The rest were travel sales.
Other sources reported numbers similar to comScore’s, with Citi Investment Research, Collins Stewart and eMarketer all within $10 million of their retail projection.
The online retail categories that were hardest hit by theslowdown were computer software, digital entertainment and officesupplies, while fitness equipment, books and furniture continuedstrong.
So how can companies thrive under tough economic conditions? GianFulgoni of comScore suggests savvy marketers ask themselves thefollowing questions:
Am I appropriately allocating my marketing/advertising budgets?
How am I measuring my online advertising performance?
What is my current coupon/promotion strategy?
Am I using the down economy as a time to build relationships with customers that will pay off in the future?
Am I optimizing my search strategy in today’s economy?
Am I being creative, or am I doing what I have always done?
If you have the right answers, then the downturn might not be so bad.
Shoebuy and Moneta Offer Online Shoppers Secure, Convenient, Responsible Payments
ATLANTA--(BUSINESS WIRE)--Shoebuy.com, one of the largest Internet retailers of footwear and apparel, will offer Moneta as its newest payment option. Moneta offers consumers a secure, free online payment method which enables them to safely pay from their bank account without leaving the merchant site or disclosing sensitive information.
Consumers setup their free Moneta account conveniently through a single enrollment process at www.monetacorp.com; setting a username, password and designating a bank account for online payments. When shopping online, the consumer simply logs in, and completes the transaction within seconds, without leaving the merchant site or revealing sensitive information.
Moneta’s method of securely transferring payments from the consumer’s checking account is growing in popularity. Financial analysts predict that consumer credit use may decline by 40 percent within a year accelerating debit-based payment acceptance, like Moneta, as consumers pay down credit balances.
“Shoebuy customers appreciate the range of choice we provide in product selection and in payment options,” said Jim Keller, SVP Marketing at Shoebuy.com. “Moneta is well suited for our customers who prefer to pay directly from a bank account and avoid running up credit balances and interest charges. In addition to providing value to our existing customers, we believe that Moneta’s bank payment approach will attract new customers to Shoebuy.com through unique marketing programs with trusted consumer organizations such as financial institutions and non-profits.”
“We are pleased to have Moneta added as a payment option on Shoebuy.com, one of the largest online retailers,” said Guido Sacchi, CEO of Moneta. “Shoebuy’s commitment to a positive customer experience reflects our focus on increasing consumer confidence through a secure, easy online transaction that promotes responsible spending. Using Moneta, Shoebuy customers now have a safe, easy-to-use option to pay directly from their bank account.”
About Shoebuy.com
Shoebuy.com is the largest retailer on the Internet focused on all categories of footwear and related apparel. Shoebuy.com has partnerships with more than 750 manufacturers and represents more than 700,000 products from top brands including adidas, Aerosoles, Allen-Edmonds, Born, Bostonian, Brooks, Charles by Charles David, Clarks, Crocs, Dockers, Donald J Pliner, Dr. Martens, Easy Spirit, Fila, Florsheim, Franco Sarto, Hush Puppies, Jessica Simpson, Johnston & Murphy, K-Swiss, Keds, Mephisto, Merrell, Mezlan, Naturalizer, New Balance, Reebok, Rockport, Sebago, Skechers, Softspots, Sperry Top-Sider, Stride Rite, Timberland, Tommy Hilfiger, and many more. Shoebuy.com also operates Bagsbuy.com, which represents all categories of bags including handbags, backpacks, luggage, baby gear, briefcases and laptop bags. Shoebuy.com is an operating business of IAC.
About Moneta Corporation
Moneta Corporation offers secure, convenient methods for consumers to pay online merchants directly from their checking or money market accounts. Moneta partners with online merchants, nonprofits and financial institutions to process payments, while providing banks online branding opportunities. Merchants offering Moneta payments benefit from increased online traffic through marketing programs with trusted financial institutions and non-profits. Moneta is a privately-held company headquartered in Atlanta, Ga. Visit www.monetacorp.com.