Friday, July 17, 2009

Interac Teams with Inside Contactless




Interac Connects With Contactless Debit Payments


According to Digital Transaction News, Canada’s Interac Association debit network is teaming with France-based semiconductor manufacturer Inside Contactless in a partnership that will include a test next year that will pair PIN-based debit cards with contactless payments. But to keep transactions moving quickly, cardholders will not need to enter a PIN.

The test will be yet another as card networks, processors, banks and vendors try to find a winning formula for the much-ballyhooed contactless card that uses radio technology to pass data between the card and payment terminal at close range. Issuers have pumped out millions of contactless cards, but there are fewer than 200,000 locations worldwide that accept them.

Thursday, July 16, 2009

Top 10 PIN Debit Networks


Rhetorical Question of the Day: Are Web Applications a Security Concern?


Are Web Applications a Security Concern?

Editor's Note:  Here's an excerpt from an excellent article in today's New York Law Journal.  I think it adequately explains "todays" risks inherent with transacting on the web.  That said, I'm more worried about tomorrow than I am today.  After all, yesterday "https:// was safe, SSL was safer and EV SSL was safest.  Not today.  Click any graph to enlarge...JBF

by Richard Raysman and Peter Brown
New York Law Journal - July 16, 2009


...Several high-profile computer hackers have recently been indicted or face prison time as a result of their unlawful activities. For example, a hacker named "Max Vision," who stole almost 2 million credit card numbers from financial institutions, merchants and other hackers, recently pleaded guilty to federal wire fraud charges and is awaiting sentencing. In another matter, a 19-year-old blind hacker was sentenced to 135 months in prison for unauthorized access to telecommunication company information, among other crimes.[FOOTNOTE 1]

Also, in ongoing proceedings, an accused British hacker, who allegedly accessed data on NASA computers, is seeking judicial review of a prior order permitting his extradition to the United States, arguing he should not be held criminally responsible because he is a sufferer of Asperger's syndrome.[FOOTNOTE 2]

Facing similar concerns to operators of government networks, private companies with external Web sites can be susceptible to attackers looking to commit defacement or infiltrate computer networks to steal sensitive information. The increased corporate reliance on complex applications and technologies contribute to the potential for security vulnerabilities and an increased need for computer security.

A growing concern, legitimate Web sites continue to be targeted by hackers, with a reported 30,000 pages affected every day by malware attacks.[FOOTNOTE 3] Successful attacks can compromise confidential resources or consumer data and harm an organization's image. Further, an improperly configured Web server can be attacked directly to obtain unauthorized access to an organization's internal resources.

This article will discuss Web application security concerns, common Web application attacks and some of the enforcement actions taken by the Federal Trade Commission against companies that have suffered security breaches allegedly due to inadequate security practices.

SECURITY CONCERNS

Business sites have become an indispensable means to communicate with prospective customers and conduct transactions. Sites have become more dynamic, giving users new capabilities to run applications, query databases and access personal and financial content.

Highly interactive sites boast multiple ways to reach out to users, namely through login and informational fields, electronic shopping carts and data uploading systems that collect, process and electronically transmit potentially sensitive consumer information.

Such interactions are performed by Web applications, which are programs that act as the intermediary between a site's servers and its database servers such that data submitted or requested by users can be transmitted from a company's database to users' browsers.

For example, a database might maintain information related to login credentials, financial information, statistics, pricing or inventory information, or other sensitive data that, when accessed legitimately, gives a site its functionality for users and customers.

When a user's submission requires additions to or retrieval from a company's database, whether it be a simple search, account information request or e-commerce transaction, the application accesses the database servers to run the particular request, with the information displayed on users' screens.

However, as hackers and identity thieves have become more adept at exploiting programming vulnerabilities to gain access to a company's Web and database servers, the use of Web applications raises cybersecurity concerns.
 

The intruders seek unauthorized access for several reasons, such as to deface a site (i.e., changing information on the server or redirect traffic to embarrass a company or make a political statement); steal sensitive data for illicit gains; plant malicious code to further a phishing scheme or other online scam; or create a distribution point for attack tools, spam, pornography or pirated software.[FOOTNOTE 4]

In addition, sensitive information transmitted unencrypted between the server and a user's browser may be intercepted or malicious entities may attempt to gain unauthorized access to resources elsewhere in the organization's network via a successful attack on the server.

Such attacks are consistent with a trend in malicious user behavior, which focuses on attacking applications accessible via the Internet, as opposed to attacking the operating system of the host platform.[FOOTNOTE 5] 

Indeed, the growth of attacks has been fueled by the easy availability of automated programs or "rootkits" that can perform a sweep across the Web to detect which sites have known vulnerabilities. Thus, if a site's applications are not secure, then sensitive consumer information could be at risk from one of many common exploits.

COMMON ATTACKS

In recent years, as the security of networks and server installations have improved, poorly written software applications and scripts that inadvertently allow attackers to compromise the security of a Web server or collect data from backend databases are the routine targets of attacks.

Common attacks include "structured query language" injection, where an hacker is able to input commands to a database, and "cross-site scripting," where an attacker manipulates the application to store malicious scripting language commands that are activated when a subsequent user opens the Web page.[FOOTNOTE 6]

Generally speaking, XSS refers to the act of injecting a malicious code into a Web page, which is then executed in the user's browser, in order to perform some sort of manipulation. XSS exploits the browser's (as well as the user's) trust that the page they are viewing is safe for downloading information and/or clicking on links presented.

XSS often takes advantage of Web servers that return dynamically generated pages. A successful attack potentially allows the hacker to redirect the page to a malicious location, hijack a user's browser, engage in computer network reconnaissance or plant backdoor programs, all while being completely transparent to the end users.[FOOTNOTE 7] As a result, a hacker can typically gain access to a company's database servers, deface Web pages, spread worms or execute malicious computer script.[FOOTNOTE 8]

Another common attack, SQL injection, allows commands to be executed directly against the database, thereby permitting disclosure and modification of the data within.

SQL is a computer language for querying and modifying data and the management of databases. The most common pathway for an SQL injection attack occurs when a hacker is permitted to enter SQL commands into a certain Web feature (e.g., login form, search query boxes, feedback forms) or directly into the browser address bar and query the database without authorization.

SQL injection usually involves a combination of inappropriate security permissions, unfiltered user input, and software code errors or omissions. Since SQL injection is possible even when no traditional software vulnerabilities exist, mitigation is often more complicated than simply applying a security patch.[FOOTNOTE 9]

With more and more Web servers comprising a front end for a database server, there is an ongoing risk that an intruder can compromise the database unless adequate security precautions are taken.

Read the Article in Full


Richard Raysman, a partner at Holland & Knight, and Peter Brown, a partner at Baker & Hostetler, are co-authors of "Computer Law: Drafting and Negotiating Forms and Agreements" (Law Journal Press).


:::FOOTNOTES::::






Reblog this post [with Zemanta]

AirTran Airways is 3rd Merchant to Accept Acculynk PIN Debit Transactions

AirTran Airways To Accept Pin-Debit Transactions Online

July 16, 2009
Source: CardLine


AirTran Airways, an Orlando, Fla.-based low-fare airline, has become the third merchant to agree to pilot Acculynk Inc.'s PaySecure Internet PIN-debit product. Acculynk enables PIN-debit purchases online by integrating its PaySecure software into a merchant's online-checkout system. Atlanta-based Acculynk plans to announce PaySecure partnerships with three other merchants by September, Nandan Sheth, Acculynk president, told CardLine sister publication ATM&Debit News last month. AirTran customers can choose the PaySecure option during online checkout. The airline tells customers debit cards can be used for a PIN-based purchase. Cardholders use their computer's mouse to enter their four-digit PINs into an Acculynk virtual PIN pad that appears on the computer's monitor. Acculynk also is conducting PaySecure tests with Metavante Technologies Inc.'s NYCE, Fiserv Inc.'s Accel/Exchange and Discover Financial Services' Pulse networks (CardLine, 3/24). Two online retailers are accepting PIN-debit cards online using PaySecure: ShoppersChoice.com, a luxury-cooking retailer, and 2Checkout.com, an authorized reseller for online retailers. Elavon Inc., which processes transactions for AirTran and ShoppersChoice.com, was the first processor to support PaySecure, according to Acculynk. Elavon did not respond to a request for comment by CardLine's deadline. Merchant e-Solutions Inc. processes transactions for 2Checkout.com.
 
Reblog this post [with Zemanta]

Visa Releases Registered ISO List (PDF 44 pages)

Visa Releases List Of Registered ISOs; Industry Gives Overall Positive Response

Source: ISO & Agent Weekly

This article appears in the July 2, 2009, edition of ISO&Agent Weekly.

Industryprofessionals have guessed 300, 5,000 and even 10,000 ISOs when askedhow many registered ISOs exist in the United States.

Visa Inc.put the question to rest in recent weeks when it made its lists ofregistered ISOs publicly available on its Web site. The total,according to Visa, is on the lower end of many observers' estimates.

The44-page document contains more than 1,900 entries, however some entriesare duplicates because some companies registered to accept Visa credit and registered again to accept Interlink, Visa's PIN-based point-of-sale debit brand. The list also contains the names of organizations that offer Visa prepaid products.

Visa'slist is available at www.visa.com/isolisting. Details of each entry aresparse, with only a few containing company Web sites.

"I'vebeen asking for this since as far back as 1995," says Joyce Cook,president and CEO of International CyberTrans, a Brentwood, Tenn.-basedISO.   Cook at that time was president of the ElectronicTransaction Association, a Washington, D.C.-based trade grouprepresenting ISOs and acquirers.

MasterCard Worldwide says itdoes not intend to release its list of registered ISOs because thesponsoring banks actually hold the information and ISOs may not wantMasterCard to disclose it.

List Release A 'Good Thing'
Cook welcomes Visa'srelease of the list. "It's a good thing because there are a lot ofpeople who are not registered and shouldn't be allowed to represent thebrands," she tells ISO&Agent Weekly.

That appears to be part of the reason why Visa released the list.

Continue Reading

CyberSource and Debenhams Direct Connect


Debenhams Direct using CyberSource for online payment, fraud management

Reading, England and Mountain View, Calif., July 16 /PRNewswire-FirstCall/ -- CyberSource Ltd., the U.K.-based CyberSource (Nasdaq: CYBS - News) subsidiary, today announced that it is working with Debenhams Direct to assist that company with the secure processing and management of its online transactions. Debenhams Direct is the eCommerce arm of one of the leading retail groups in the U.K. and Ireland, visited by over 3 million online customers each month. The site processes over 2,500 orders on an average day and offers products and services that are available in Debenhams' stores.

CyberSource's payment management services allow Debenhams to securely and reliably process multiple payment types through a global payment processing network that has been certified as compliant with the Payment Card Industry Data Security Standard. Through a single connection to CyberSource, Debenhams can also utilise additional cardholder verification programs such as Verified by Visa and MasterCard SecureCode, providing Debenhams' customers with greater protection from fraud and reducing chargeback risk for Debenhams.

Debenhams turned to CyberSource's flexible risk management solutions as part of the retailer's overall eCommerce focus. CyberSource's Decision Manager accesses over 150 global validation tests to screen for fraud, enabling Debenhams to determine in real-time whether transactions should be accepted, rejected, or marked for further review. This has allowed Debenhams greater flexibility in the management of its fraud screening rules, allowing it to evolve and develop, in real-time, the strategies it deploys against fraudsters.

Anthony Leach, Senior Operations Manager, Debenhams Direct, said: "We are keen to stay ahead of the curve and selected CyberSource based on its functionality and the partnership we have already developed. The intelligence to which we have access will help us identify and manage higher risk orders appropriately whilst supporting legitimate customers within our secure website. Our continued focus is on providing a secure platform for our online customers whilst managing commercial risks and having clear and flexible processes."

Simon Stokes, Managing Director, CyberSource Ltd., commented: "Debenhams is a great example of a traditional high street retailer that has embraced the online environment and increased its investment in this area. By consolidating and streamlining its multi-channel operations, Debenhams is better able to provide its customers with a secure and convenient online shopping experience."

For more information on CyberSource risk management solutions, see: http://www.cybersource.co.uk/products_services/risk_management/ .

About CyberSource

CyberSource Ltd. is the U.K.-based wholly-owned subsidiary of CyberSource Corporation (NASDAQ: CYBS - News). CyberSource solutions enable electronic payment processing for web, call centre, and POS environments. CyberSource also offers industry leading risk management solutions for merchants accepting card-not-present transactions. CyberSource Professional Services designs, integrates, and optimizes commerce transaction processing systems. Approximately 262,000 businesses use CyberSource solutions, including half the companies comprising the Dow Jones Industrial Average. The company is headquartered in Mountain View, California, and has sales and service offices in Japan, the United Kingdom, and other locations in the United States including Bellevue, Washington and American Fork, Utah. For more information on CyberSource Ltd. please visit www.cybersource.co.uk or email uk@cybersource.com.

About Debenhams

Debenhams is a leading department store group with a strong presence in key product categories, including womenswear, menswear, childrenswear, homeware and health and beauty. The group trades through over 150 department stores in the U.K. and the Republic of Ireland and www.debenhams.com .

Source: Company press release. 


Reblog this post [with Zemanta]

Canadians' Call for Regulation of Interchange Fees Rejected - GreenSheet

Canadians' call for regulation rejected

In June 2009, the Canadian Senate Standing Committee on Banking, Tradeand Commerce rejected its own merchant lobbyists' call for priceregulation on fees charged to merchants for credit card transactions.MasterCard Canada officials welcomed the decision and said theyappreciated the opportunity provided by the committee to participate ina comprehensive examination of Canada's payment systems.

"TheSenate Committee clearly recognized that price controls areinappropriate and would harm consumers," said Kevin Stanton, President,MasterCard Canada, in a press release. "Australia continues to providean excellent example of how such price controls reduce credit cardprogram benefits and result in no appreciable decrease in the price ofgoods and services."

New York Times - Card Fees Pit Retailers vs. Banks


Merchants across the nation, from powerhouses like Wal-Mart and Home Depot, to gas stations, mom-and-pop restaurants and 7-Eleven, have spent years unsuccessfully fighting the biggest of these costs, known as an interchange fee, which generates an estimated $40 billion to $50 billion in income annually for banks that issue credit cards.

But after Congress passed a law last month to protect consumers from excessive fees and interest on credit cards, merchants are mounting a fresh offensive.

This time, they believe the momentum in Washington has turned in their favor. Legislation is winding its way through Congress, a government audit has been ordered and petitions are surfacing in hundreds of convenience stores, including Ms. Orzano’s 7-Eleven, encouraging customers to voice their opposition to the fees. “Congress sort of already illustrated the willingness to take on the credit card companies and the big banks,” said Keith Jones, a lobbyist for 7-Eleven. “We just feel like the job is half done.”

And while large and small banks often clash on political agendas, they have formed a united front, joined by payment networks like Visa and MasterCard, to prepare for a furious battle on Capitol Hill. With profit from credit cards likely to diminish because of the new laws, they are determined not to absorb another major hit.

“It’s a big deal to them, and they would be fully engaged in it,” said Kenneth J. Clayton, senior vice president for card policy at the American Bankers Association.

Every time a consumer uses plastic, about 2 percent to 3 percent of the charge goes to banks and payment networks, which price the fee differently in different countries. Of that, the interchange fee is paid to the cardholder’s bank, and at roughly 1.8 percent of each purchase in the United States, according to June report by J.P. Morgan, it is the largest and most controversial of these costs.

But retailers may have a tough time convincing Congress that consumers would benefit if the effective interchange rate, which has increased slightly in recent years, is dialed back. Many other countries, including Israel and Australia, have required banks that issue cards to reduce the fee. Yet there is little evidence that the savings were passed along.

Continue Reading



Reblog this post [with Zemanta]

Paradigm Shifting - Web Sales Trump Store Sales at Macy's

The Paradigm Shift is occurring as I type this.

1. MasterCard has "shifted" it's focus to debit cards

2. Two months ago, for the first time in the history, debit card "volume" surpassed credit card volume, and

3. Macy's web sales have trumped it's store sales. (see story below)


It now looks more and more like a certainty eCommerce will one-day take over the brick and mortar space, But it is wrought with fraud. Therefore PIN Debit (with it's built-in two factor authentication True Zone 1-5 End-to-End-Encryption ) is the obvious payment method for this space. Did it ever occur to you that there is a reason signature debit is called off-line debit" and PIN Debit is referred to as "online debit?" I ask you...which one makes the most sense for "online" shopping? See: Chase Paymentech Predits PIN Debit Ubiquitous on Web by 2012

Here's why HomeATM is uniquely positioned:

1. There is "only one" PCI 2.0 certified PIN Debit solution for the Internet, and that one and only is HomeATM.

2. HomeATM also owns the "global" patent for any Debit or Credit Card Payment transaction conducted via the Internet, be it hardware or software based. (US Patent and Trademark Office has issued patent No. 6,834,271 (see related articles below) to HomeATM's wholly owned subsidiary Kryptosima/Patent for Internet ATM/Debit and Credit Card Transactions Granted In Europe -HomeATM announced that it hasreceived notification that the European Patent Office isgranting Kryptosima's patent application No. 00957801.4 for "ApparatusFor and Method of Secure ATM Debit Card and Credit Card PaymentTransactions Via The Internet."...)

3. HomeATM also recently went through a CTGA ANSI TG-3 Audit (The
American National Standards Institute(ANSI) has developed a set of best practice security standards known asTechnical Guide 3 (TG-3) to govern Personal Identification Number (PIN)Security. Interbank networks that route Automated Teller Machine (ATM)and Point of Sale (POS) transactions such as STAR, Pulse, and NYCErequire their members to achieve compliance with TG-3 standards.Organizations held to these control standards are subject to periodicaudits by CTGA (Certified TG-3 Auditor) licensed professionals) and based on what we've heard certification is imminent. To our knowledge, we would be the "first and only" company in the world with a eCommerce PIN solution to be TG-3 certified. We know were' the only one who is PCI 2.x certified.

4. Based on the aforementioned, specifically 1 & 3, HomeATM is the most secure (tested and documented) online payment in two hemispheres...


As such, we are uniquely positioned as the next step of the Paradigm Shift takes place... thanks to the perfect storm we know as "the economy," "the debit card," "cybercrime" and the "world wide web."

At mid-year, web sales trump store sales at Macy’s


For the sixth month in a row, web sales outpaced store sales at Macy’s Inc.


In its June sales numbers, Macy’s, No. 23 in the Internet Retailer Top 500 Guide, reported a gain in web sales of 8.2% while comparable-store sales declined 8.9% and total sales decreased 8.9% to $2.04 billion from $2.24 billion in June 2008.

For the first six months of the year, e-commerce sales also easily outpaced comparable-store sales.

From January through June, Macy’s, which doesn’t break out specific numbers for its e-commerce business, posted a gain in online sales of 13.6%. Comparable-store sales for the same period declined 9% and total sales decreased 9.4% to $8.99 billion from $9.92 billion in January through June of 2008.

While store sales languish, one retail analyst says Macy’s web sales are growing because the retailer is making an effort to build up a sales channel that its customers clearly prefer shopping.

Continue Reading at InternetRetailer.com












Reblog this post [with Zemanta]

Wednesday, July 15, 2009

Ingenico Introduces Chip and PIN Kiosks for Airports


Ingenico_logo-140px.jpgIngenico has announced a three-year partnership with Ryanair to develop the world’s first self-service passenger kiosks with chip and pin technology to allow passengers to purchase optional services such as priority boarding when they arrive at the airport.

Ingenico and Ryanair will initially install the Chip and PIN payment system in all its London (Stansted) based kiosks and roll out the development across its Barcelona (Girona), Belfast, Frankfurt (Hahn) and Marseille bases. As part of a three-year contract with Ryanair, Ingenico has provided a complete transaction management system for the inital rollout of 250 unmanned kiosks, with plans to grow to 450 kiosks. It comprises the AXIS electronic payment system, centralised hosting of the transaction management system and PIN pads. The solution enables the kiosks to be fully compatible with PCI-DSS guidelines, as well as those set by Visa and Mastercard for secure payments. This ensures that passengers can pay for any optional services whilst checking in, negating the need to go to the ticket desk.

“Ingenico’s unique partnership with Ryanair demonstrates Ingenico’s commitment to being at the forefront of innovation and the technological advances in the sector,” said Philippe Lazare, CEO, Ingenico. “We continue to expand our international footprint, and are dedicated to ensuring that customers and retailers have access to the highest levels of convenience, security and simplicity in their transactions.”

“Ryanair has already begun the move to 100% online check-in which will remove all check-in desks from our 146 airports by October when all passengers will check-in online and use baggage drop points to deposit their hold baggage,” said Ryanair’s Stephen McNamara, Head of Communications. “We are upgrading and installing self service kiosks to ensure passengers can still purchase the services they require when they arrive at the airport. Our partnership with Ingenico will help us to provide a secure and convenient payment method for passengers who want to purchase services such as priority boarding or hold baggage before they board their low fares Ryanair flight.”

“The Ryanair kiosks are unique in the airline field, as they have integrated payment mechanisms, which enable both Chip and PIN as well as magnetic stripe payments to be made at the terminals, in a fully PCI (PCI-PED, PCI-DSS) compliant payment solution,” said Cillian Wright, Business Development Director, Ingenico. “This gives customers the peace of mind that transactions will be processed to the highest security standards. The provision of managed payment services provides Ryanair with a convenient and safe end-to-end transaction solution, giving them a significant advantage against other airlines.”

Source: Press Release 

AFP Says More Info with Wire Transfers Would be Helpful


Study shows remittance info in wire transfer benefits firms

Bethesda, Md., July 15, 2009 -- U.S. corporations overwhelmingly confirmed the importance of receiving remittance information in wire transfers -- and banks would benefit as well, according to a new survey by the Association for Financial Professionals (AFP). Ninety-five percent of the 331 respondents said remittance information would be valuable to their organizations if it were made available in the wire transfer message. Organizations of all revenue sizes and wire volumes shared this view, especially larger companies and those with larger wire volumes.

While nearly all respondents expect the wire transfer enhancements to be valuable, a portion of respondents expect their wire volume to increase with the addition of remittance information.

Organizations today do not receive sufficient information with their wire transfers to post the payments to the correct accounts without manual intervention. AFP has been working the Federal Reserve Banks and The Clearing House, operators of the Fedwire(R) Funds Service and CHIPS(R), to develop a solution to this problem. The two organizations have agreed to expand their formats to provide remittance information with wire transfers by late 2010.

While 91% of wire transfer recipients -- the main beneficiaries of remittance information -- indicated they would use the new data to receive and post incoming wires, nearly two-thirds (61%) said they would include remittance information in outgoing wires, perhaps to reduce the number of inquiries from the receiver of the wire transfer.

"The results of this study are a ringing endorsement of this initiative," said Arlene Chapman, CTP, consultant to AFP. "It shows how valuable it will be to corporate customers -- and banks."

Bank cash management systems are the primary channel used by organizations to send and receive wires. When banks and software providers make this new format available, businesses will be able to accurately identify incoming payments and post them to the correct accounts without manual intervention and research.

Remittance resources:

Study: Providing Remittance Information with Wire Transfers: http://www.afponline.org/wiresurvey .

Background: http://www.afponline.org/wirebackground .

Video: http://www.afponline.org/wirevideo .

Payments Newsletter: http://www.afponline.org/paymentsnewsletter .

Contact: Ira Apfel at 301.961.8881 or iapfel@afponline.org

Source: Association for Financial Professionals (http://www.afponline.org/about )

About the Survey

In May 2009, the Association for Financial Professionals conducted a survey on the value to organizations of receiving remittance information with wire transfers and the systems and software they use to send and receive wire transfers. AFP sent surveys to over 3,000 corporate practitioner members and received 331 responses. After adjusting for misdelivered email, the response rate was nine percent. The 331 responses are the basis of this report. The survey questionnaire and report were produced by the Research Department of the Association for Financial Professionals, which is solely responsible for the content.

About AFP(R)

The Association for Financial Professionals (AFP) serves a network of more than 16,000 treasury and finance professionals. Headquartered in Bethesda, MD, AFP provides members with breaking news, economic research and data on the evolving world of treasury and finance, as well as world-class treasury certification programs, networking events, financial analytical tools, training, and public policy representation to legislators and regulators. AFP is the daily resource for treasury and finance professionals.

AFP's global reach extends to over 150,000 treasury and financial professionals worldwide, including AFP of Canada, AFP's gtnews, an on-line resource for the treasury and finance community, and the London-based bobsguide, a financial IT solutions network.

Source: Company press release.
Reblog this post [with Zemanta]

Closer Look at Western Union


A closer look at Western Union

Money-transfer giant Western Union is a lot like Visa (NYSE: V) and MasterCard (NYSE: MA) -- more of a technology company than a financial company, but often lumped in with the latter. Its real value lies within the massive global network of processing locations that gives it a large moat against competition. In an industry where scale is the single most important factor, it's very difficult to compete with someone like Western Union.

When most people think of this company, remittances to Mexico come to mind. This exposure scares them silly because the jobless rate in the U.S. discourages immigration from Mexico, which should, logically, stifle business.  

But Mexico makes up just 7% of total revenue. For consumer-to-consumer transactions, which make up 85% of total revenue, business is fairly diverse:



Geographic diversity is a big plus in this economy. Having more robust areas such as India and China to fall back on as growth in the U.S. wanes is a lifesaver. Furthermore, more remote areas of the world don't have nearly the type of banking infrastructure that the U.S. does, making Western Union essential to their economies.
Reblog this post [with Zemanta]

Visa Steps up to the Security Plate...Kinda

New Merchants must use PA-DSS Compliant Applications by this time next year but "Existing Merchants" still have 2 more years to put your cardholder data at risk!

Visa has announced global requirements for financial institutions to ensure their merchant customers and agents use secure payment applications, that do not store prohibited data elements and adhere to the Payment Card Industry (PCI) Payment Application Data Security Standard (PA-DSS).


As per the deadlines, in addition to the US and Canada financial institutions, in Asia Pacific, Central and Eastern Europe, Middle East and Africa (CEMEA) and Latin America and the Caribbean (LAC), Visa acquirers must ensure that newly signed merchants use PA-DSS compliant applications by July 2010.

By July 2012, those acquirers must ensure that existing merchants and agents in the Visa network use PA-DSS compliant applications.


Eduardo Perez, head of global data security, Visa, commented: "Criminals are targeting certain versions of software known to have security vulnerabilities. It's essential that every business that handles payment card information adhere to the highest data protection standards to protect the security and privacy of their customers' financial information.”

The PA-DSS is a global set of security requirements for software vendors who develop payment applications. PA-DSS compliant applications do not store prohibited data such as track data, sensitive authentication data, or PIN data, helping merchants and agents mitigate compromises and support overall compliance with the Payment Card Industry Data Security Standard (PCI DSS).
Reblog this post [with Zemanta]

Visa & MasterCard Certify Gemalto's Optelio in Gulf Region


Gemalto gets Visa, MasterCard certification for global banking card in Saudi Arabia

• 15 Jul 2009

AMSTERDAM, Netherlands — Gemalto has announced that its Optelio banking card has been certified to the Saudi Arabian Monetary Agency requirements.

According to a news release, Optelio is suited for the local market, as it hosts the Saudi Payments Network application, the debit card functionality deployed in Saudi Arabia. The Gemalto product also is compatible with the GlobalPlatform specifications (the standard for smart card infrastructure), the Visa Electron and the Debit MasterCard and Maestro Card requirements, making it usable worldwide.

Those certifications enable Gemalto to complete its existing Multos offer for the Saudi Arabian banking market, the largest in the Gulf Region with more than 10 million debit cards in use, and to support local financial institutions in their EMV migrations.  Optelio lets dual-issuer banks deliver either Visa's VSDC or MasterCard's M/Chip applications on the same product.

"We are proud to offer this innovative and secure payment solution to Saudi Arabia," said Philippe Cambriel, executive vice president of Gemalto’s secure transactions business unit. "These certifications confirm that Gemalto has the widest portfolio in the industry, covering all applications and technology platforms."


Reblog this post [with Zemanta]

Capital One PINs DeFault on the Economy

What's In Your Wallet?

Capital One: US Credit Card Defaults Rise in June...

* U.S. credit card charge-off rate rises to 9.73 pct
* U.S. credit card delinquencies fall to 4.77 pct
* International cards charge-off rate falls to 9.26 pct
* Shares rise 3.2 percent in premarket trading


NEW YORK, July 15 (Reuters) - Capital One Financial Corp's (COF.N) U.S. credit card defaults rose in June as unemployment increased and Americans struggled to pay their debts, but the figures were better than expected and the company's shares rose 3.2 percent.

In a regulatory filing on Wednesday, Capital One said the annualized net charge-off rate for U.S. credit cards -- debts the company believes it will never collect -- rose to 9.73 percent in June from 9.41 percent in May.

Capital One, one of the largest issuers of Visa and MasterCard credit cards, said accounts at least 30 days delinquent -- an indicator of future loan losses -- fell for fourth straight month, to 4.77 percent from 4.90 percent.

Continue Reading




iPay, My CU Services Partner on Bill Payments


iPay Technologies, My CU Services bring bill payment to CUs

Elizabethtown, Ky., July 14, 2009 -- iPay Technologies, the leading independent online bill pay provider for financial institutions, today announced that it has partnered with MY CUÃ’ Services, a subsidiary of Mid-Atlantic Corporate Federal Credit Union, to provide its bill payment product to all of the credit unions that use MY CU bill payment services. The partnership will combine the great service that members are accustomed to receiving from MY CU with iPay’s superior bill pay product.

“iPay's innovative products and exceptional customer service make them a great partner for our online bill payment service," stated Drew Kishbaugh, president and CEO, MY CU Services.

The partnership further advances iPay’s position as the market leader in bill payment service to community financial institutions. iPay currently provides bill payment services to over 2,800 financial institutions. An additional 800 financial institutions are under contract to begin service later this year, bringing the total number of financial institutions using iPay’s bill pay service to over 3,600. Of these 3,600, more than 1,600 of them are credit unions, putting iPay’s market share amongst credit unions with bill pay at over 51%.

“iPay has been dedicated to providing outstanding bill payment services to community financial institutions since its inception,” said Dana Bowers, founder and managing partner, iPay Technologies. “We are extremely pleased that MY CU Services, a leader among service providers in the credit union industry, has selected iPay as the best bill payment product for its members.”

“We continue to execute on our mission of providing best-in-class bill payment products to community financial institutions through our network of financial services partners. We are proud to now include MY CU Services amongst our network of over 50 financial services partners,” said Bill Ready, president, iPay Technologies.

About iPay Technologies

iPay Technologies is the leading independent provider of Internet bill payment services. Founded in 2001, iPay develops and fully supports consumer and small business online bill pay solutions for more than 2,800 financial institutions nationwide and in Puerto Rico. iPay offers exceptional customer service with a U.S. based customer service center of bill pay experts who resolve 9.5 of every 10 calls within the first five minutes. iPay offers a 99.93% payment success rate with more than 1,200,000 bill pay customers, and over 4,000,000 payments processed each month. The company is owned by Spectrum Equity Investors, Bain Capital Ventures, and management. More information about iPay is available at www.ipaytechnologies.com .

Source: Company press release.

Quddit: $23 Quadrillion for a Pack of Smokes?

NH man charged $23 quadrillion dollars, plus fee

Editor's Note:  How big $23 quadrillion dollars?  Take the picture on the left and multiply that by 2300

MANCHESTER, N.H.—JoshMuszynski (Mu 'SIN' ski) swiped his debit card at a gas station to buya pack of cigarettes. His bank account showed he spent over 23quadrillion dollars.  (Editor's Note:  New tax on cigarettes perhaps?)
Hechecked his account online a few hours later, expecting to see a couplehundred dollars -- but the 17-digit number that rivals even thenational debt confronted him. 

Muszynski called Bank of Americaabout the string of numbers and a $15 overdraft fee the bank tacked on(while I have ya on the phone, there's also the issue of the $15 bucks) to his mysterious debt. 

After two hours on the phone, Muszynski said,the representative on the line had no idea what to say, WMUR-TVreported.  (Editor's Note:  Why would anyone spend 2 hours on the phone with anyone to learn they have no idea what to say?  What did they say for two hours?  Maybe that was the time it took to take the $15 bucks off...)

The bank corrected his statement the next day.   (wonder if he got the smokes free?)

Editor's Note:  Speaking of statments, Bank of America told WMUR the card issuer, Visa, could only answer questions. Visa, in turn, referred questions to the bank.

Cisco Midyear Security Report is Out...and so it seems is security

An Update on Global Security Threats and Trends

The Cisco 2009 Midyear Security Reportpresents an overview of Cisco security intelligence, highlightingthreat information and trends from the first half of 2009. The reportalso includes recommendations from Cisco security experts andpredictions of how identified trends will evolve.

As predicted in the Cisco 2008 Annual Security Report,attacks are only becoming more sophisticated and targeted as we movethrough 2009—and the global recession. However, while cybercrime ismore pervasive, there are encouraging signs that increasedcollaboration among the "good guys" is not only making it moredifficult for attacks to take root and grow, but also helping to bringcriminals to justice.

Report Highlights

  • Criminals are exploiting "old-school"vulnerabilities because they believe security experts and individualcomputer users are paying little attention to these types of threats.
  • Compromising legitimate websites for the purpose of propagating malware remains a highly effective technique for criminals.
  • Web 2.0 applications, prized for their ease of use and flexibility, have become lures for criminals.
  • Criminalsare targeting people who use online banking with well-designed,localized text message scams—and they're leaving virtually no trail.
  • TheObama administration has made strengthening U.S. cybersecurity a highpriority, and looks to leverage technology innovation and partner withthe private sector. Other countries are also stepping up efforts toenhance cybersecurity and prevent cybercrime.
In addition, the number of vulnerabilitiesand discrete threats has been off to a slower start this year comparedto 2008, according to research by Cisco-a sign the security communityis succeeding in making it more difficult for attacks to take root andgrow.

ATMs Fitted with Pepper Spray - Finextra

Finextra is reporting that ATM's are being fitted with pepper spray, so do NOT check the ATM for skimming devices, or camera's...as it may mistake you for someone trying to install them. 

For complete details on how to be peppered, er, prepared, you'll have to wait for my forthcoming book..."Be Prepared or be Peppered" due out in 2060.

SOUTH AFRICA'S ABSA FITS ATMS WITH PEPPER SPRAY

A plan by South African bank Absa to deter criminals from bombing its ATMs by fitting them with pepper spray backfired last week when a rogue machine attacked maintenance workers.  (bet he wasn't peppered for that)


According to local news site Independent Online, the bank, inconjunction with police, has fitted 11 cash machines across the CapePeninsula with cameras and spray canisters.

When the cameras detect that someone is tampering with card slots -either to install a bomb or skimming machine - the pepper spray isejected, disorientating the culprit, giving police time to reach thesite.

However, last week a machine in Fish Hoek accidentally sprayed threepeople during a routine maintenance inspection, leaving them requiringtreatment from paramedics.

According to the Guardian, the number of cash machines blown up inSouth Africa has risen from 54 in 2006 to 387 in 2007 and nearly 500last year.

Source:  http://www.finextra.com/fullstory.asp?id=20271

PCI Council Publishes Wireless Security Guidlines for Payment Cards

Editor's Note:  HomeATM CEO, Ken Mages, a noted security expert, has worked on and put forth his recommendations regarding "web security guidelines" for payment cards. 

Call it  "wPCI."  

Considering today's announcement that PCI is publishing "wireless" security guidelines, I don't see any reason why the council wouldn't be 100% behind putting together a Web Special Interest Group (SIG) and begin this much needed process as well.  In fact, I would humbly suggest that there is a huge void until they publish web security guidelines.  Would it take a year and a half?  Well, let's just say they could derive a huge head start by giving Ken a call...

Any business accepting credit and debit cards -- and using or considering wireless LANs -- should carefully review the recommendations for use of 802.11 wireless access points that are detailed in the guidelines issued Wednesday by the Payment Card Industry Security Standards Council.

In the past, the council has issued standards that have become required by Visa, MasterCard, banks and others for secure processing of payment and debit cards. Troy Leach, the council's technical director, emphasized that the recommendations in the "PCI Data Security Standard (DSS) Wireless Guideline" are not mandatory for businesses handling payment cards and using WLANs. But he adds, "This is probably the way wireless should have been deployed all along."

And though not officially mandatory, the PCI guideline for WLAN deployments, which expands on the existing 12-part standard PCI DSS that is required, do point merchants in the direction the council thinks is optimum for protecting cardholder data.

The guideline was crafted by the council's Wireless Special Interest Group (SIG), chaired by Doug Manchester, director of product security at VeriFone Holdings, in a process that took more than half a year with 50 SIG participants.

Manchester, who notes the guideline is specifically for WLANs and doesn't include technologies such as BlueTooth (more wireless-technology guidelines can be expected in the future), says the goal was to clear up questions and establish a "common vocabulary."

Continue Reading






, , , ,

O2: Mobile Oyster Card Kickoff Entirely Ready Y'all (Acronym=MOCKERY)


O2: Oyster cards in mobiles ready to roll

Your phone could buy you dinner and take you home (Editor's Note: Or take you to the cleaners)



O2 has told reporters it is confident consumers will see 'substantial progress' in bringing a mobile phone able to make contactless payments in the very near future.

Ronan Dunne, O2's UK Chief Executive, said O2's move into the financial space with O2 Money was the "first step" on the journey towards a contactless future.  "As you know O2 led trials [of Near Field Communication (NFC) technology in mobile phones] last year, and we engaged with a number of commercial organisations in that area," said Dunne.

"Customers loved it, and the challenges now are with electronic point of sale capability, and deployment across mass retail.  "We'll be talking to large retailers, grocers for instance, also people in the transport industry [about bringing the technology to market]." 

O2 used around 500 people in the trial, which saw them using their mobile phone to make smaller payments, similar to Visa's Paywave system, and swapping an Oyster card for a phone in London too.

Not a foregone conclusion

However, Dunne pointed out while NFC might be coming to fruition, the next stage of deployment is far from a foregone conclusion:  "It's one of those situations where the technology is ready to go, but we need more deployment to get critical mass. We're confident you'll see substantial progress in that space, under the O2 brand, in the not too distant future.

Continue Reading at Tech Radar




Brazil's Congress Targets VisaNet and Redecard


Brazil seeks credit card regulation, competition

Wed Jul 15, 2009 8:12am EDT

* Proposals seek to end dominance of VisaNet, Redecard
* Legislators want more oversight by central bank
* Credit card industry association warns of over-regulation


By Natuza Nery and Fernando Exman

BRASILIA, July 15 (Reuters) - Brazil's Congress is moving to heighten competition in the $190 billion credit card industry, where customers and merchants complain about exorbitant costs and a dearth of options.

Last week the Senate approved a bill intended to force a reduction in the fees charged on credit card purchases. At an average of 4 percent of the sales price, the fees are roughly 70 percent higher than what is charged in Europe and the United States, according to a study by Senator Adelmir Santa.

The bill would allow retailers to offer discounts for cash sales, thereby putting pressure on credit card operators, including VisaNet (VNET3.SA) and Redecard (RDCD3.SA), to cut fees.

The Chamber of Deputies, the lower house of Congress, could vote on the bill as soon as today (Wednesday).

Other proposals are in the making. One, supported by both government and opposition parties, is to end the market dominance by Redecard and VisaNet and attract more players to the field. The measures could reduce the merchant fees, but would also undermine profit margins for card operators.

VisaNet and Redecard, which have exclusive contracts with Visa (V.N) and Mastercard (MA.N), respectively, have a combined market share of more than 90 percent. Both companies authorize merchants, issuers and transactions and act as a clearinghouse.

A proposal from the opposition Democratas party proposes to end such exclusivity, allowing a credit card brand to be managed by several operators. The ruling Workers' Party, or PT, backs the proposal, making its approval in Congress likely, analysts say.

"We want to stimulate competition and break this duopoly," said PT Senator Ideli Salvatti.

Continue Reading

Editor's Note:  I have 3 questions:  They (Chamber of Deputies) might want to take other factors into account...
1.   Didn't VisaNet just raise more than 7 billion reais last month in the biggest-ever IPO inBrazil?  
2.   Therefore, wouldn't it potentially be the shareholders who were hurt most by this legislation?  
3.   If they are considering it now, why didn't they consider it before the IPO?  



Firm that Settles Credit Card Disputes is Accused of Fraud

Disqus for ePayment News