Friday, March 13, 2009

On to the Next Breach...

Anthony Freed, Financial Editor for Information-Security-Resources.com,  wrote an exclusive on Visa having put Heartland on "double secret probation" over it's recent breach.  It's already been picked up by Seeking Alpha.

Anthony is a researcher, analyst and freelance writer whoworked as a consultant to senior members of product development,secondary, and capital markets from the largest financial institutionsin the country during the height of the credit bubble. Anthony’s workis featured by leading Internet publishers including Reuters, TheChicago Sun-Times, Business Week’s Business Exchange, Seeking Alpha,and ML-Implode.

He also is the official live blogger for the upcoming 2009 Sarbanes-Oxley Conference.  For more information visit: ISR

Visa Puts Heartland on Probation Over Breach

By Anthony M. Freed, Information-Security-Resources.com Financial Editor


Heartland Payment Systems (HPY),one of the largest credit card processors in North America, is finallybeing called to the carpet for the apparent lapses in Payment CardIndustry Data Security Standards (PCI DSS) that contributed to the largest data breach of 2008, perhaps even the largest breach ever considering the full extent of the exposure has yet to be determined.

Called to the carpet sort of, anyway; the sanctions and guidance laid out by Visa (V) seem a little lackluster when weighed against the severity and duration of the breach.

Given that Visa is now considered themost likely of several candidates for inclusion in the Dow IndustrialAverage, taking up slack from soon to be sidelined Citigroup (C) and Bank of America, (BAC) it is not surprising that they do not want to call too much attention to the situation:
On January 20th of this year,Heartland Payment Systems (HPS) publicly disclosed a large-scalecompromise involving account data from all card brands. In light ofthis event, Visa has taken the following actions to help protect theVisa system:

CAMS Alerts - Between January 18thand February 4th Visa issued a series of Compromised Account ManagementSystem (CAMS) alerts (US-2009-046-IC) to financial institutions relatedto this compromise event. Providing this information can help financialinstitutions act quickly to minimize fraud on exposed card accounts.
It is worth noting here that Visa and MasterCard (MC) reported anomalies to Heartland in late October, about two and a half months before the CAMS alert was issued.

Data breaches in the financial industry always reignite the debate between those who want full and immediate disclosure, and those who would prefer to subdue the news. A lot seems to depend on your preferred usage of words like “quick” and “help”.

As for the sanctions Visa hasprescribed for Heartland, I believe it’s something akin to when DeanWormer put the Delta House on Double Secret Probation, or at leastthat’s how it reads:
Removal from Visa’s List ofCompliant Service Providers - Visa has removed Heartland from itsonline list of Payment Card Industry Data Security Standard (PCI DSS)compliant service providers. HPS has advised, however, that it isaggressively working on remediation and re-validation of its systems tocomply with PCI DSS standards. The company will be relisted once itrevalidates its PCI DSS compliance using a Qualified Security Assessorand meets other related compliance conditions.

System Participation - HPS is now in a probationary period,during which it is subject to a number of risk conditions includingmore stringent security assessments, monitoring and reporting. Subjectto these conditions, Heartland will continue to serve as a processor inthe Visa system.
So Heartland is off of Visa’s Christmas card list for 2009, but they still get a fruitcake.

A breach of unknown scope and impact toconsumers, participating banks, their shareholders, merchants, theeconomy in general, the source of multiple class action lawsuits anduntold losses for years to come, and the big smack down is thatHeartland has to sit in the back of the bus?

Profits over protocols; some actuarymust have crunched the numbers, the underwriters drew the bottom line,and the executives decided to mush on.  Damn the torpedo (holes).

And Heartland may not be the whole story.

There are multiple access points in thedata chain.  Heartland may be where the malware disease did its worstdamage, but that does not guarantee that Heartland is also the point ofinfection.

And as far as being PCI DSS compliant, there has been some confusion as to what that exactly means for security assurance.

PCI DSS compliance is only a momentarymeasure. Think of it along the lines of a kitchen inspector who gives arestaurant the highest rating after inspection, that is no guaranteethe cook will wash his hands well next week, or that the mayonnaisewill never get left out.

That is why you will hear a CEO of a breached credit card processor plead “But we were PCI DSS compliant“  and simultaneously you will hear the PCI council (made up of the major payment card brands American Express (AXP), Discover Financial Services (DFS), JCB International, MasterCard Worldwide and Visa) exclaim that “No PCI compliant processor has ever been breached.”

Both of these statements can not be correct.

Also included in Visa’s belatedresponse to the Heartland breach is a fine to be levied against theparticipating banks - most of whom rightly consider themselves to bevictims of the breach as much as their customers are.  This must be like when the mean DrillSergeant makes everyone march in the rain because one jerk made agoof.  I guess the client banks are supposed to exert peer pressure onHeartland to mend their ways, or something:
Fines - In accordance with VisaOperating Regulations, fines will be assessed to Heartland’s sponsoringbanks. Such fines are part of the program Visa uses to assurecompliance with system rules. Ongoing compliance with PCI DSS helpskeep the system more secure for all participants.
I fail to see the purpose of penalizingbanks that send their processing business to Heartland unless it can beshown that the bank somehow contributed to the breach in a materialmanner, otherwise this is just more fodder for the lawyers in the formof damages to recover through litigation.

Another mystery contained in Visa’sannouncement is the requirement that all fraud related to the Heartlandbreach has to be reported by May 19th.  This is ridiculous, as it couldbe a year or two before all fraud cases can be identified and thensubstantiated; requiring this to happen in the next two months isunrealistic, if not unreasonable:
Account Data Compromise Recovery -Visa has determined that this event qualifies for the Account DataCompromise Recovery (ADCR) program. Subject to its terms, this programprovides issuers the ability to recover a portion of their lossesrelated to accounts that are determined to be the subject of a breach,by assessing acquirers for the ADCR financial liability. An acquirer’sADCR financial liability is determined based on a percentage ofmagnetic stripe-read counterfeit fraud and specified operating expenseliability amounts. Issuers will have until May 19th to report fraudlosses related to this event to Visa. Until this reporting windowcloses, specific recovery amounts cannot be determined. Visa willprovide clients with additional information as it becomes available.
Finally we get to that last paragraph,and I can say there is something there that I actually agree with:  ThePCI DSS is a decent start.  What really needs to be fixed is how PCIDSS is implemented and maintained throughout the data access chain:
This recent compromise underscoresthe importance of all parties maintaining ongoing compliance with thePayment Card Industry Data Security Standard. These standards continueto serve as a robust and critical foundation to protect cardholder dataand, when implemented properly, have proven to be highly effective inpreventing and mitigating the impact of data compromises. Compromiseevents are a reminder of the importance for all parties in the paymentsystem to maintain ongoing vigilance when it comes to protectingcardholder data. Each stakeholder in the Visa system has a criticalrole in our collective fight against the criminals that perpetuate cardfraud.
So in summation, Heartland (and others)may be full of holes, and Visa belatedly recommends business as usualuntil such time as the holes can be found and filled.
On to the next breach.

Anthony is a researcher,analyst and freelance writer who worked as a consultant to seniormembers of product development, secondary, and capital markets from thelargest financial institutions in the country during the height of thecredit bubble. Anthony’s work is featured by leading Internetpublishers including Reuters, The Chicago Sun-Times, Business Week’sBusiness Exchange, Seeking Alpha, and ML-Implode.

The Author gives permission to link, post, distribute,or reference this article for any lawful purpose, provided attributionis made to the author and to Information-Security-Resources.com





Related Articles by Anthony Freeman:




Zemanta Pixie

Contactless M-Commerce Failing?

Finextra: Contactless m-commerce fails to take off
The development of contactless mobile payments has failed to live up to expectations and the technology will account for just a fraction of the value of commerce transacted over cell phones this year, according to data from ABI Research.

The firm says the value of mobile commerce transacted via non-NFC methods - SMS, Internet and applications - will total $1.6 billion in 2009. In contrast contactless mobile commerce will be "minimal".

Dan Shey, practice director, ABI Research, says: "NFC is the 'holy grail' that provides the easiest user experience. Other methods require more work and expertise from the consumer."

Continue Reading at Finextra





, , , , ,

Thursday, March 12, 2009

PIN on PED vs. PIN on the Web

Editor's Note:  Both Ken Mages, HomeATM CEO, and Mitch Cobrin, COO were at the Merchant Risk Council Annual Conference over the past two days.  At the conference, a "cautious" Chase Paymentech, announced that they will "pilot" PIN Debit on the Web, first with Acculynk, with others to possibly follow. 

See Digital Transaction News
: A Cautious Chase Paymentech Signs Up for Online PIN Debit


The developments at the MRC are definitely raising awareness for the desire to incorporate PIN Debit into the webosphere.  That is good.  In fact, Mike Strada, manager for debit card product at the Dallas-based processing giant predicted that PIN Debit would become the most widely used payment mechanism on the web by 2012.  I've been predicting that the potential for PIN Debit on the web cannot be ignored since early 2006, back when I started the Pay By Touch Blog.  (HomeATM has been doing the same since 2000)

I know enough about a PIN Based Application to be dangerous, speaking of which, (dangerous) I received an email from our CEO regarding these recent announcements.  I asked if I could post it and he gave me the go ahead, so here it is:

John, I appreciate that your blog is truly YOUR blog. You and I both have issues with the old ATMDirect so those topics are naturally covered frequently.

I don't editorialize nor do I influence the content. Having said this, and having just attended the MRC, I can't help but say that Acculynk does indeed deserve kudos for raising the awareness of PIN for the Internet.

What I would say is that HomeATM does NOT do PIN on the web.  We use the web to connect a buyer to a seller and then we do a safer than standard (the track2 data is encrypted also), traditional, unhackable, unbreachable, impregnable where the Internet is merely the conduit for our encrypted packets (as it is for 99% of all PIN transactions).


I won't belabor the point but if Acculynk (or ANY software only) PIN on the web solution goes live, I promise, just as I promised music and movie executives fifteen years ago that their digital business would die on a PC (and entertainment has, check out Virgin).  Not to mention any software solution using a browser for PIN entry likely violates our core patent.

This isn't meant as a threat nor as a contentious point, I just want PIN experts to weigh in on the real issues of "software vs. hardware"  
POS transactions.


Finally I'll make this last promise or take a lunch bet with anyone...that once software PIN goes live, within a month an FTP site will arise with user's PAN and PIN numbers.

I One-Hundred-Percent (100%) guarantee it.

Thanks,

kgm
Chairman/CEO
HomeATM ePayment Solutions



Editor's Note:  At $1000 per PIN (see illustration above, click to enlarge)  I wouldn't bet lunch against him.  Speaking of the illustration above...let me remind you of a direct quote from Acculynk Chairman and CEO, Ashish Bahl... (from Digital Transactions:) 


Without going into details, Acculynk’s CEO Ashish Bahl counters that each click is encrypted in ways intended to frustrate hackers.

At the same time, he adds, the resources necessary to predict when to start and stop screen scraping with each click
would be cost-prohibitive even for determined fraudsters. 

Editor's Note: "Cost prohibitive" is relative to the potential return. (again, see graphic above) Personal Identification Numbers are the "holy grail" for hackers. If you have the PINs then you have the capability to empty bank accounts. So, in my humble opinion, there is simply no such thing as a "cost prohibitive" barrier when it comes to PIN's. Especially, if the hackers are "determined."  It's something hackers would want to get their hands on "at all costs."



Technorati Tags:







Reblog this post [with Zemanta]

Barney Frank and Internet Gambling


Internet Gambling Back on the Table?

MARCH 11, 2009 - eMarketer


Rolling the virtual dice…


Smart money is betting that Congress will repeal the 2006 Unlawful Internet Gambling Enforcement Act (UIGEA) this year, or at least soon.


Barney Frank (D-MA), chairman of the House of Representatives Financial Services Committee, plans to bring back legislation to repeal the UIGEA this month. Rep. Frank maintains that online gambling is a fundamental freedom, and that attempts to make it illegal smack of Prohibition in the 1920s and 1930s.

In addition, much of the political momentum for repeal of the act is coming from online poker players who are fighting back.


“There is a dramatic need to have a regulated system that protects American consumers,” Jeffrey Sandman, a spokesman for the Safe and Secure Internet Gambling Initiative, told Reuters. “Right now, it's the Wild West.”
PricewaterhouseCoopers (PwC) estimates that the amount the US could raise from regulating and taxing Internet gambling is about 22% higher than it was in 2007—because US online gambling has grown despite the ban.
In fact, comScore Media Metrix found that as of last November, online gambling was the ninth-fastest-growing category online.

Making it illegal for businesses to knowingly transfer payments to Internet gambling operations, including payments by credit card, wire transfer or check, the 2006 ban was approved when Republicans still controlled both houses of Congress and President Bush was in the White House—and before the economy collapsed.

Continue Reading at eMarketer







Reblog this post [with Zemanta]

IBM Internet Security Systems Introduces Endpoint Security Offering



SOURCE: IBM


IBM Introduces First-of-a-Kind Endpoint Security Offering

New Offering From IBM Strives to Free Clients From Vendor Lock-In, Simplify Security Management, Reduce Costs and Promote Industry Innovation

ARMONK, NY--(Marketwire - March 11, 2009) - Today, IBM (NYSE: IBM) announced a first-of-a-kind endpoint security offering, IBM Proventia Endpoint Secure Control (ESC), that is designed to enable enterprises to escape from the constraints of vendor lock-in and to enhance endpoint security, compliance and operations at a lower cost. This new endpoint security offering is delivered by IBM Internet Security Systems (IBM ISS) leveraging IBM's depth in security experience and technology from BigFix, Inc. for endpoint security management.

The IBM ISS solution delivers endpoint security management designed to address two major problems in the industry today: the escalating cost of security and the growing complexity of endpoint security management.

Continue Reading



Reblog this post [with Zemanta]

Norm Coleman Donors Credit Cards Hacked


kare11.com | Twin Cities, MN | Coleman urges donors to cancel credit cards after purported data breach

ST. PAUL, Minn. -- If you donated online to Norm Coleman's 2008 Senate campaign, or his recount efforts, you should call and cancel the credit card you used to make that donation.

That was the simple advice from the Coleman campaign on Wednesday, which hurried to notify donors of an apparent security breach in the computer server where the private information of online contributors is stored.

That breach, which most likely occurred January 28th of this year, became more obvious Wednesday afternoon when lists of those donors and partial credit card numbers popped up on the Internet.

"I can't tell you how it pains us to have to tell people that," Coleman recount attorney Fritz Knaak told KARE, "But obviously that's the whole idea, that kind of infliction of harm on our relationship with contributors and supporters is exactly what's intended by this."

Coleman's campaign manager Cullen Sheehan said the Secret Service is investigating the incursion into the data server, which housed a database 4,700 donors. He said it had been compromised most likely by hackers stealing the information via the Internet.

The stolen information included credit card numbers and purchase security codes, in addition to the names, phone numbers, addresses, e-mail addresses and occupations of the givers.

On the web already

By Wednesday afternoon the list had been posted on a political website known as WikiLeaks, which is run by a nonprofit group with the stated goal of creating a "uncensorable Wikipedia for untraceable mass document leaking and analysis."  (Click here to visit the WikiLeaks web page where you can download the list)

The downloadable spreadsheets listed the donors' credit card types, but only 12 of the 16 digits in the credit card number. It wasn't enough by itself to commit fraud, but it was offered as proof that the information is quite possibly in the wrong hands.

The Internet thieves also took a database of 51,000 others identified as supporters, which included even journalists who subscribed to the campaign's electronic newsletters. That list was also posted as a downloadable document on the site.

WikiLeaks did not explain how it came to possess the data, but apparently used the donors' information to tip them off about the breach.

Dozens of Coleman faithful on Tuesday night received e-mails from WikiLeaks informing them,"Your name, address and other details appear on a membership list leaked to us from the Norm Coleman Senate campaign."

Political attack alleged

The document leaking site claims to have a "primary interest is in exposing oppressive regimes" around the world, but the Coleman campaign sees it as a blatant attack on the former Senator's ability to raise money for the current election contest trial in Saint Paul.

"We believe this is a politically motivated attack," Knaak remarked, "We believe it's a basically an assault on the whole political system essentially."

The Senator himself, in a brief statement to reporters after Wednesday's court session, echoed that sentiment.

"I think it will have a very debilitating effect," he told reporters, "I find it to be frightening, I find it to be scary and I'm obviously disappointed."

Coleman said he's confident the Secret Service will solve the case and punish those who are behind it. That agency, part of the U.S. Department of Treasury, was already investigating an attempted invasion of Coleman's servers.

Continue Reading at kare11.com



Reblog this post [with Zemanta]

There Will Be Blood


SOURCE: MarketResearch.com

Financial Services Technology Spending Will Decline 3.7% in 2009

ROCKVILLE, MD--(Marketwire - March 11, 2009) -

MarketResearch.com has announced the addition of TowerGroup's new report "There Will Be Blood: US Financial Services Trends and IT Spending in 2009 and Beyond," to their collection of Banking & Financial Services market reports. For more information, visit http://www.marketresearch.com/redirect.asp?progid=67618&productid=2063442

TowerGroup estimates overall US financial services technology spending will decline 3.7% between 2008 and 2009 as firms scrap ineffectual projects and delay new investments until 2010.

Cost cutting born of desperation may permanently cripple IT structures, while smarter actions to rationalize IT and discard decaying assets offer better short-term returns and long-term strategic benefits.

TowerGroup expects a growing polarization between leaders and laggards as visionary financial institutions rise to the challenge of calamity and move ahead of their weaker competitors.

Replacement IT spending will rise 20% in 2009 as IT transformation -- either forced or chosen -- tops FSI priority scales and opens doors of opportunity for technology vendors.

Three critical trends will reshape the US financial services industry: regulatory pressure, shifting consumer demographics, and accelerating globalization.

FSIs are challenged from two sides to embrace IT transformation in support of new business models: from customers who will demand it and competitors who will provide it

Report Coverage:
Background
Banking and Payments
Insurance
Securities and Investments
The IT Spending Ripple Effect
Exhibit 1
Exhibit 2
Operational Efficiency
Risk Management
New Customer Segments
Exhibit 3
Banking
Securities and Investments
Insurance
Exhibit 4
Call to Action for FSIs: Survival of the Fittest
Shifting Customer Demographics and Imagination
Disruptive Globalization
Heightened Regulatory Pressure
Summary

For more information visit http://www.marketresearch.com/redirect.asp?progid=67618&productid=2063442


Reblog this post [with Zemanta]

Wednesday, March 11, 2009

Top 10 Most and Least Admired Companies - Fortune







Rank        Company                      Industry Rank


1 Apple 2
2 Walt Disney 1
3 Google 1
4 Nike 1
5 Medco Health Solutions 1
6 Herman Miller 1
7 Amazon.com 2
8 Goldman Sachs Group 1
9 Integrys Energy Group 1
10 Graybar Electric 1


WORST (Least Admired)


1 Dillard's 10
2 Sears Holdings 9
3 Circuit City Stores 11
4 Family Dollar Stores 8
5 PEMEX 14
6 McClatchy 7
7 National City 12
8 Surgutneftegas 14
9 ONEX (Celestica) 10
10 US Airways Group 12


From the March 16, 2009 issue

363 Top Rated Companies






High-Tech Criminals Target ATMs to Steal Vital Personal Financial Information From Customers

ADT Offers New ATM Security Technology to Combat 'Skimming,' Which Results in Millions of Dollars of ATM Fraud Losses


BOCA RATON, Fla., March 11 /PRNewswire/ -- Skimming - a way criminals use high-tech electronic tools to capture personal financial information and steal money from automated teller machine (ATM) customers - is one of the financial industry's fastest-growing crimes, according to the U.S. Secret Service.

Also, the worldwide ATM Industry Association (ATMIA) reports over $1 billion in annual global losses from credit card fraud and electronic crime associated with ATMs.

"But perhaps the most significant skimming cost to financial institutions is the damage to their reputation and the loss of customer confidence that accompanies the theft of personal financial information," said Hank Monaco, vice president for ADT Security Services.

ADT is introducing to North American financial institutions its Anti-Skim(TM) ATM Security Solution that helps prevent skimming attempts and detects skimming devices on all major ATM makes and models.

In a matter of seconds, criminals can place a skimming device on an ATM card reader that blends in with the machine's appearance and does not interfere with its operation. A small wireless camera, concealed near the ATM fascia, is also used to capture the user's personal identification number (PIN) as it is entered. Information from the device and camera is sent wirelessly to the criminal's laptop computer. The ATM user typically has no idea that his or her information has been compromised.

Criminals use the stolen data to "cash out" debit card accounts, clone duplicate credit-debit cards or sell personal financial information to worldwide crime syndicates. Several high-volume transaction ATMs in an area can be targeted in just one day.

Boca Raton Police Chief Dan Alexander said identity theft and related offenses such as ATM skimming are a serious concern in the community. Boca Raton Police will begin a campaign through its Viper program to help raise awareness among residents. Tips will include how to protect your identity from criminals.

"The Strike Out Identity Theft campaign is a perfect example of how community partners such as ADT can work in conjunction with law enforcement to help protect the public," Alexander said.

To help reduce ATM skimming, the ADT solution is installed inside an ATM near the card reader, making it invisible from the outside. The technology helps prevent card-skimming attempts by interrupting the operation of the illegal card reader. The solution also detects the presence of foreign devices placed over or near an ATM card entry slot, without disrupting the customer transaction or operation of most ATMs. For effective, layered ATM security, the ADT solution can trigger a silent alarm for command center response and can coordinate video surveillance of all skimming activities.

The ADT Anti-Skim ATM Security Solution:

* Helps protect the integrity of cardholders' personal financial information during ATM transactions.
* Can trigger a silent alarm for command center response and coordinate video surveillance of all skimming activities.
* Requires no software adjustments to the ATM.
* Does not connect to or affect the ATM communications network.
* Has more than 40,000 successful ATM applications worldwide.

ATM operators should take advantage of anti-skimming solutions, according to Lana Harmelink, ATMIA's chief executive officer, the Americas.

"Skimming is a problem that will continue to grow until available technology is employed to bring it under control," she said. "The technology exists today to help defeat the problem."

Monaco said a recent study by Harris Interactive reported that 67 percent of U.S. adults who use financial institutions with ATMs would likely switch after experiencing ATM fraud or a data breach.

"This survey highlights the important role that the ADT Anti-Skim ATM Security Solution can play in helping secure consumer confidence in ATM transactions," he said. "ADT already helps to protect tens of thousands of retail banking facilities, operations centers and ATM operations with a variety of intrusion, access control and video surveillance systems. Our new anti-skim solution adds another layer of protection for financial institutions."

About ADT Security Services




ADT Security Services is a unit of Tyco International and part of ADT Worldwide, the world's largest security provider. In North America, ADT provides electronic security services to nearly five million commercial, government and residential customers. ADT's total security solutions include intrusion, fire protection, video systems, access control, critical condition monitoring, home health services, electronic article surveillance, radio frequency identification (RFID) and integrated systems. ADT's government and commercial customers include a majority of the nation's Fortune 500 companies, all U.S. federal courthouses and over 70 mid to large airports. Headquartered in Boca Raton, Florida, ADT has more than 24,000 employees at approximately 240 locations in the U.S. and Canada. More ADT information is at http://www.adt.com


SOURCE ADT Security Services







Reblog this post [with Zemanta]

New Wave of Internet Acquisitions May Be Ahead


New Wave of Internet Acquisitions May Be Ahead
Large companies will buy smaller firms for their technologies instead of investing in R&D.   by Alex Goldman:

A new report from J.P. Morgan suggests that the future of Internet business starts with consolidation in 2009, as the biggest companies buy the best of the small.

With the economy approaching zero or even negative growth, Internet companies are still under pressure to grow -- and the only way to do so is through acquisitions, J.P. Morgan Analyst and Managing Director Imran Khan wrote in a report.

Large companies have every reason to put money into mergers, he added.

For one reason, the stock price of smaller companies (those with market capitalizations under $1 billion) is getting cheaper, while the stock of larger companies (those with market caps over $5 billion) is not. While large companies' stock prices remains close in value now to their value at the start of the year, the stock of small companies has fallen in value by 23 percent, on average -- potentially making them a steal.

At the same time, acquisitions would give large companies access to the fruits of smaller companies' research and development, which is becoming increasingly critical as they trim their own research budgets. According to Khan, large companies have decreased the rate of growth of investment in R&D from 25 percent a year ago to a projected 9 percent this year...

Continue Reading at Internet News.com

Reblog this post [with Zemanta]

Chase Paymentech Predicts: PIN Debit Ubiquitous on Web by 2012

Merchant Risk Councils Platinum Day - Afternoon Sessions
by Allen Weinberg - Glenbrook Partners Payments Views

Allen Weinburg, from Glenbrook Partners, who is blogging about the Merchant Risk Council's Las Vegas conference, wrote an article in Payment Views entitled: "Is Now the Time For Online PIN Debit?"

Mike Strada, from Chase Paymentech predicts that PIN Debit on the Internet will be the most widely used payment mechanism on the web by 2012.  I agree
.

Allen also talks about 4 solutions, and whether 3D Secure might be just as good, if not a better solution. I took a moment out of my morning to leave a comment ascertaining that the answer is probably yes...for all but one.

Allen WeinbergIs Now the Time for Online PIN Debit?

This session was presented by MikeStrada from Chase Paymentech. Mike is a fan of online PIN debit,especially the notion of giving merchants more choices. His discussionfocused on the different options the 12 North American debit networksare exploring.

Several of the debit networks are exploring PIN debit, some aren’t.ACCEL, NYCE, PULSE and STAR are doing PINless debit for utility andother low risk payments. Mike explained that these are the 4 networksthat are exploring PIN debit on the Internet. Three of these four (allexcept STAR) have recently announced PIN debit pilots.


Mike maintains that PIN debit forecommerce transactions could provide some incremental sales lift formerchants, especially since 14% of debit cards are “ATM only” – i.e.,they don’t have a MasterCard or Visa logo on them and thus can’t beused for general ecommerce transactions.
Mike explored the pros and cons of the four alternatives:
  • Acculynk (formerly ATM Direct, previously owned bynow-defunct Pay By Touch). ACCEL, NYCE and PULSE have all signed LOIsto do pilots with Acculynk. Mike thinks two more debit networks willannounce pilots within the next 90 days.
  • Safe-Debit (the same name of the program NYCE wentto market years ago using a CD ROM token). This iteration is usingVerient’s platform to redirect the user to the customer’s home bankingsite for authentication. In this case, the cardholder is sent a onetime PAN for use at the merchant site. Hoping to do a pilot in firsthalf of 2009. This, of course, requires a redirect which scares a lotof merchants due to the increased risk of abandoned shopping carts.
  • Claerity – technology allows consumer to registercell phone number with their DDA FI. The bank, via the network, sendsone time password back to cell phone which the shopper enters onmerchant checkout page. Network compares the onetime password sent tocell phone with the one issued to the consumer. Not clear who will bearthe cost of the SMS message. Hoping for a 2009 pilot, but unclear if ontrack.
  • Home ATM – Canadian firm distributes USB PIN padthat has a mag-stripe card reader and encrypts data. Has a distributionagreement with Microsoft, but no announced pilots.
Mike acknowledged one of the big issues that Glenbrook encounterswith our merchant clients – critical mass and the challenge of gettingonline merchants adopting two or three (forget four or more) differentprocesses. Our clients tell us they’ll consider it when the networksadopting a particular approach/technology bring critical mass ofcardholders in aggregate. My sense is that STAR has critical mass untoitself. The next 3 largest networks (assuming Interlink and Maestrowon’t play) would need to converge on a solution to bring critical massto market. Just my opinion, but Mike doesn’t think standardization willhappen in the foreseeable future, and Paymentech has decided to moveforward anyway.

Mike/Chase Paymentech is predicting that be the end of 2010, most ofthe major networks will implement online debit products (excluding, ofcourse, Interlink and Maestro), with transaction pricing somewhere inbetween physical POS interchange and online Visa/MasterCardinterchange.

Mike also predicted that by 2012, online PIN debit could be the mostwidely used payment mechanism on the Internet.


The operating rules forhandling online PIN debit transactions haven’t been worked out, butthey’re working on it. He acknowledges that the rules really should be,and probably will be standardized across networks.

ChasePaymentech has agreed to do a pilot with Acculynk (and is looking for merchants to participate).

Of course there’s the fraud risk associated with these new products(Mike acknowledged it, but didn’t spend much time on this area).


Mike feels the consumer proposition is one of safety, security, and identity theft protection.

One question I have is whether 3D Secure technology could do just aswell as the above four products/technologies mentioned above. Mikethought that it probably could, but he wasn’t aware that any of thedebit networks had considered that path (could mitigate merchantadoption problem).

The merchants in the audience were somewhat skeptical on a number offronts. For example, how to deal with split shipments that span theauthorization time frames. They worried about consumer valueproposition and recalled all the issues they encountered with 3DSecure, particularly how the banks/issuers didn’t do as good a job asthey needed to educating their cardholders.

{ 1 comment… read it below or add one }


John B. Frank 03.11.09 at 5:50 am

Your comment is awaiting moderation.

You questioned whether 3D Secure Technology could do just as well asthe four products/technologies mentioned above. You pose an interestingquestion, but I want to point out that you cannot lump those fourtogether, as there is one key distinction. 1 uses a hardware device.The other 3 are software-based.

Which leads me to ask a pertinent question… How is it even“possible” to “securely” process a PIN Debit transaction WITHOUTHardware? (a magnetic stripe reader and PED) If a software applicationis utilized, then, by definition, it is a Card Not Present transaction.Thus a software based approach “cannot ” be a pure PIN Debit play…asthe card “must” be present in order to process the track data locatedon the magnetic stripe.

Remember…all PIN-based transactions “require” the submission ofvalid track data in order for the PIN to be properly decrypted. Withouttrack data, PIN submission becomes unnecessary and the transaction isbetter submitted as a manually-entered credit card transaction (withouta PIN), therefore 3D Secure would be just, if not more, effective.

For a true PIN Debit transaction to occur, a developer mustimplement PIN support as part of the submission process. Without trackdata, it becomes impossible to encrypt or decrypt PIN numbers (becausethe magnetic stripe data is used as part of PIN encryption/decryption).If track data is not submitted, a debit card transaction becomesimpossible and the transaction becomes a manually-entered credit cardtransaction.

That said, I would have to agree with Allen when he says there’s afraud risk associated with these new products (the lone exception beingthe one who utilizes a hardware “SwipePIN” device capable of not onlyproviding: E2EE, 3DES DUKPT, but also encrypting the Track 2 data aswell.) Track2 = PAN+Separator+Expiry Date+ServiceCode +Pvk Index+ PVV +CVV

Is it a coincidence that the event is called “The Merchant RiskCouncil” and although Mike Strada “acknowledged the risk of fraud… “hedidn’t spend much time on it?”

PN Debit card transactions require the availability of two (unlessyou combine them into one) hardware device(s): a PIN pad and a magneticstripe reader. Unless both a PIN pad (which is configurable with aworking key) and a magnetic stripe reader are both available andoperational, these debit card transaction examples cannot be applied asa PIN Debit card transaction requires both track data and an encryptedPIN to proceed.

Therefore, the only logical conclusion is that a Hardware device isrequired, not optional. What’s the big deal with a hardware deviceanyway? Did you ever have to charge your cell-phone…sometimes ahardware accessory is necessary to protect the Holy Grail. (PIN’s)

Otherwise the Heartland Breach will pale in comparison to what willhappen if people start putting their PIN’s into a software-basedapplication. The writing has never so clearly been written on any wall.

Where am I wrong here? Where is Avivah Litan wrong? Where are theSociety of Payment Security Professionals wrong? I’m dying to know,because I was a founding shareholder in Pay By Touch and could havebought ATMDirect out of the PBT bankruptcy “cheap.”.

You mean to tellme that PayPal will fork out nearly $1 BILLION for Bill Me Later butsaid “later” when it came to forking out $600K for ATMDirect?  If so,and PIN Debit is the most widely used payment mechanism on the internetby 2012, (as Mike Strada/ChasePaymentech predicts) then not evenbidding on ATMDirect will go down as one of the biggest mistakes inPayPal/Ebay history. (and mine)  But I think we're both fine...

TAGS: , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , ,







Reblog this post [with Zemanta]

Tuesday, March 10, 2009

Cardinal and CyberSource Team Up

MENTOR, Ohio, March 10, 2009 (GLOBE NEWSWIRE) -- CardinalCommerce Corporation, the worldwide-leading payment brand enabler, today announced a new strategic partnership with CyberSource Corporation (Nasdaq:CYBS), a leading provider of electronic payment and risk management solutions. CardinalCommerce has integrated its Cardinal Centinel(r) Platform with CyberSource's payment management services to provide CyberSource merchants with continued, strengthened support for Verified by Visa (VbV) and MasterCard(r) SecureCode(tm) (MCSC).

Through the partnership, CyberSource is able to leverage Cardinal's team, which provides active monitoring and quality assurance so participating merchants receive the maximum benefits of VbV and MCSC -- including the potential for fraudulent chargeback protection and interchange savings. By utilizing Cardinal's hosted platform, CyberSource customers will also have the benefit of improved reliability and speed for VbV and MCSC transactions. Enhanced transaction performance and Cardinal quality assurance review are designed to create an optimized authentication experience for both merchants and their customers.

"To be entrusted by one of the world's premier online fraud prevention companies is a great achievement for Cardinal," said Tim Sherwin, EVP/CMO, CardinalCommerce. "We are proud of the incredible growth, adoption, and evolution of our Cardinal Centinel platform that has brought us to this very important partnership. Clearly, we are excited to bring our enhanced payer authentication offering together with CyberSource's well-known payment services to grow our business."
Story continues below ↓advertisement | your ad here

About CyberSource

CyberSource Corporation is a leading provider of electronic payment and risk management solutions. CyberSource solutions enable electronic payment processing for Web, call center, and POS environments. CyberSource also offers industry leading risk management solutions for merchants accepting card-not-present transactions. CyberSource Professional Services designs, integrates, and optimizes commerce transaction processing systems. Approximately 253,000 businesses use CyberSource solutions, including half the companies comprising the Dow Jones Industrial Average. The company is headquartered in Mountain View, California, and has sales and service offices in Japan, the United Kingdom, and other locations in the United States including Bellevue, Washington and American Fork, Utah. For more information on CyberSource please visit www.cybersource.com or email info@cybersource.com. For more information on Authorize.Net small business solutions, please visit www.authorize.net or email sales@authorize.net.

About CardinalCommerce

CardinalCommerce Corporation is the global leader in enabling authenticated payments, secure transactions and alternative payment brands for both eCommerce and mobile commerce. Cardinal Centinel(r)* enables payment brands such as Verified by Visa, MasterCard(r) SecureCode(tm), Amazon Payments(tm), Bill Me Later(r), Clickandbuy(tm), Ebates(tm), eBillme(tm), eLayaway(tm), Google(tm) Checkout, Green Dot(r) MoneyPak(r), Mazooma(tm), MyECheck, NACHA(r) Secure Vault Payments (SVP), PayPal(tm), RevolutionCard(tm), Western Union(r), Ukash(tm), and more to a network of thousands of merchants and merchant service providers. Our mobile commerce platform, Cardinal MAX(tm), makes it simple for retailers to sell and market products through the mobile channel. Cardinal's proprietary and easily deployable technology provides consumers, merchants, credit/debit card issuers, and processors the ability to conduct authenticated Internet, wireless and mobile transactions safely and securely. Headquartered in Cleveland, Ohio, with facilities in the United States, Europe, and Africa, Cardinal services a worldwide customer base.

For more information, visit www.cardinalcommerce.com


Shoppers Choice Runs Acculynk PaySecure (tm) PIN Debit Transaction

Editor's Note:  Once, again...two questions.  Where's the PVV, and the PIN offset?  HomeATM has a lot of knowledgeable and respected card industry authorities on our side (scroll down to the next post) but what's disconcerting, is that the Top 500 Internet Retailers are eager to save money on Interchange Fees. 

Acculynk is smart.  They are being very generous with their how they slice their transaction fee pie. They are enticing the EFT Networks with some potentially major cabbage, and since they (the EFT networks) are currently making absolutely $0.00 on the Internet, it's alluring,  because they're anxious to penetrate this lucrative market.  I hope the lure of the cabbage hasn't clouded their judgment, because almost everyone I am talking to sees some major risks to a serious breach.  Speaking of breaches...I have ONE BIG QUESTION.  When there is a breach, because it's not iffy, it's whenny, who has the liability? Who will they PIN the Blame on?   It it the Internet Retailer?  Is it the EFT Network?  Or did Acculynk get a $500 million Lloyds of London insurance policy? Somebody's got to pay.  Who will it be?

What's good about all this, is the fact that PIN Debit for the Internet is getting some well deserved exposure.  What's potentially bad is that PIN's may get some exposure too.  "I told you so" won't feel good.  I'd rather provide exposure to the risks, than have PIN's exposed to the risk.

It is easy to overlook the online payment platformas a simple link in the e-commerce chain. However, choosing the rightpayment system could make the difference between a successful businessthat is trusted by its customers, and one that is burdened/destroyed by fraud.Asking the right questions of prospective providers and looking closelyat the technical, security, and particularly the anti-fraudcredentials, will help build a solid platform for success online. 

Here's the latest press release from Acculynk: 



PRESS RELEASE ShoppersChoice.com Runs First PaySecure(TM) PIN Debit Transaction


Acculynk delivers "real" debit card processing via the Internet

ATLANTA, Mar 10, 2009 (BUSINESS WIRE) -- ShoppersChoice.com, a luxury cooking and outdoor living retailer, is processing purchases made with PaySecure(TM), the first and only software service for PIN debit on the Internet.

PaySecure(TM) meets consumer demands for increased security and convenience, while providing merchants lower interchange fees, reduced fraud and charge-backs, guaranteed funds and simple implementation with the online checkout.

"We are very excited to bring PaySecure(TM) to our website because we are constantly seeking new, innovative payment methods that are convenient, safe and easy for our customers to use," said Corey Tisdale, COO, ShoppersChoice.com. "What we especially like about PaySecure(TM) is that our customers don't need to enroll in a program or download an interface to use it, which keeps customers on our site." 

Over the past five years, various attempts have been made to bring PIN debit online, but no solution has succeeded in gaining traction with merchants, consumers, EFT networks and issuers. PIN debit is an ideal online payment method because it provides an extra layer of security for consumers and cost savings for merchants, while offering attractive margins to issuers and a new revenue source for EFT networks.

PaySecure(TM) is the first product to gain approval by four EFT networks, including ACCEL/Exchange from Fiserv and NYCE, to run Internet PIN debit transactions.

"The industry has waited a long time for a PIN debit solution that meets the security requirements of the EFT networks but could also be accepted by merchants, consumers and issuers and become a 'standard' for PIN debit online," said Mike Kelly, General Manager of ACCEL/Exchange EFT network, owned by Fiserv, the leading global provider of financial services technology solutions. "We feel Acculynk's product could become this standard."

ShoppersChoice.com represents the first of four pilot merchants that will trial the service. Pending the results of the pilot, over 20% of the Internet 500 retailers have expressed interest in launching the solution as part of their consumer checkout options.

PaySecure(TM) has the potential for widespread adoption because it provides a simple checkout experience and can be used with a consumer's existing debit card and PIN. "PaySecure(TM) leverages a familiar payment method - PIN debit - that is already preferred at the retail point of sale but has never been offered online in a software-only service," said Ashish Bahl, CEO of Acculynk. "We have designed our service to mimic the brick and mortar PIN debit payment experience so it is completely intuitive for customers to understand and use, which will help ensure consumer adoption."

About ShoppersChoice.com
ShoppersChoice.com is a luxury cooking and outdoor living retailer. ShoppersChoice.com offers the best service, the best selection, the best trained staff, and the fastest ship times available on- or off-line at a price point that meets or beats all other online retailers. ShoppersChoice.com is one of the Top 500 Internet retailers and is headquartered in Baton Rouge, LA. For more information, visit www.shopperschoice.com.

About Acculynk

Acculynk is a leading technology provider with a suite of software-only services that secure online transactions. Backed by a powerful encryption and authentication framework protected by a family of issued and pending patents, Acculynk's services provide greater security, reliability, convenience and return on investment for consumers, merchants, networks, issuers and acquirers. For more information, visit www.acculynk.com.
SOURCE: Acculynk

Acculynk
Corporate Contact:
Danielle Duclos, 678-894-7013
Director of Marketing
dduclos@acculynk.com

Copyright Business Wire 2009 End of Story



TAGS:









Reblog this post [with Zemanta]

Disqus for ePayment News