Tuesday, September 1, 2009

Online Banking "Dangerous" - Gartner



Gartner States that Online Banking is "Dangerous" in newest analysis:



Event
On 24 August 2009, the Washington Post's Security Fix blog reported that the Financial Services Information Sharing and Analysis Center (FS ISAC) — an industry group created by a U.S. presidential order to share data about critical threats to the financial sector — had issued a confidential alert to its members, which include the Federal Reserve, the New York Stock Exchange, Citigroup, Morgan Stanley and Goldman Sachs. The FS ISAC alert urged business bank customers to "carry out all online banking activity from a stand-alone, hardened, and locked-down computer from which e-mail and Web browsing is not possible."



Editor's Note:  Why dedicate a stand-alone, hardened and locked-down computer from which e-mail and Web browsing is not possible, when it would be safer, more cost-effective and more useful to utilize a PCI 2.x Certified "stand-alone" device which not only provides multi-factor authentication, but also provides "real-time" money transfer, B2B payments and more? 



The FS ISAC issued its alert in response to reports from financial institutions, security companies, the media and law enforcement agencies of "a significant increase in funds transfer fraud involving the exploitation of valid banking credentials belonging to small and medium sized businesses."




Editor's Note:  Again, exploitation is relative to how you conduct funds transfers.  Agreed, you cannot use a PC from which web browsing is possible, but you can utilize a device which doesn't use the web in the first place.



Analysis
The FS-ISAC warning calls into question the safety of online banking...and confirms that criminals are winning the cyber war against financial institution account holders....



Criminals raid these accounts for millions of dollars (no estimates are available for the total amount of money stolen, (but Gartner believes it could be very large) by planting trojans on user desktops to steal account credentials and transfer money to criminals' accounts. Especially problematic aspects of these incidents include:
  • Lack of disclosure by banks to shareholders and account holders, who must learn about these incidents from media reports

  • Criminals' practice of targeting business accounts, which are typically larger but enjoy less protection under the law than consumer accounts.

  • Lack of protection afforded by current antivirus and anti-malware software running on users' PCs, and users' failure to keep their protection software updated.

  • Criminals' ability to circumvent strong user authentication, which includes using dedicated one-time password tokens issued by the bank to business users.

  • The new level of sophistication in reconnaissance, asset acquisition and exploitation demonstrated by these attacks, raising the possibility that ex-intelligence, paramilitary and military personnel are working with traditional organized crime groups.

These multistage attacks do more harm to customers than large, well-publicized credit card breaches. When cards are stolen, regulations typically require reimbursement of customers for unauthorized charges. In money transfer attacks, business users are unlikely to recover the bulk of their stolen funds.








  • Don't rely solely on the strength of user authentication if the authentication is communicated through a PC browser.

Editor's Note:  Which is why HomeATM doesn't use the web browser for authentication, but instead utilizes the only PCI 2.x Certified PED in the world to instantaneously encrypt the authentication credentials and transmit the encrypted data using the Internet (not the web) as a conduit. Is it safer this way?  You can bank on it!











Reblog this post [with Zemanta]

Boku Press Release

Sep 01, 2009 08:00 ET


BOKU Sets the Standard in Mobile Payments, Announces Arsenal of Online Games, Social Networking and Facebook Application Customers





Publishers Choose BOKU for High Conversion Rates, Sophisticated Technology and Coverage in 55 Countrie
s
SAN FRANCISCO, CA--(Marketwire - September 1, 2009) - BOKU, Inc., the standard for online mobile payments, today announced an extensive group of merchants and publishers who have selected BOKU for its convenient, bank-grade payment solution. Spanning the social and casual gaming, social networking and application spaces, these companies use the BOKU™ service to sell digital goods and services to their global customers. The service allows over 1.8 billion potential consumers to shop online and purchase virtual goods and digital content easily and securely using their mobile phone.



In addition, BOKU announces it is going live in the next week with its payment service in Indonesia, New Zealand, Slovenia and Taiwan, bringing the company's global reach to 55 countries.



Continuing on its recent success, BOKU has attracted an impressive set of customers, including Aeria Games, Badoo, fatfoogoo, Gambit, Games-Masters (Cabal Online), HitGrab (MouseHunt), Hive7 (Knighthood), Hi5, IceBreaker, IGG, Jambool, K2Networks/GamersFirst, Meez, Offerpal, PageFad (Premier Football), Playfish, Slide, Sometrics, Super Rewards, TheBroth (BarnBuddy), Three Rings, TrialPay and WeeWorld with more going live soon.



These publishers have chosen BOKU as a complete, online payments solution that offers analytics reporting, flexible billing and pricing, fraud and security management and greater revenue opportunities to partners in the USA and worldwide. Additionally, the company's global reach, leading technology platform, seasoned executive team and tier one investors set it apart from all other players. Today, the company has over 1000 customers that use BOKU as their mobile payments provider of choice.



"After switching to BOKU for mobile payments on Meez, we saw a dramatic increase in revenue," said John Cahill, CEO of Meez. "BOKU is leading the charge in alternative payments methods and we're extremely satisfied with their offerings -- not only to Meez as a company, but to our customers, as well."



"We chose to add BOKU for mobile payments for our 6 million gamers to pay for virtual goods," said Vu Hoang, co-founder of Aeria Games. "BOKU is an important and growing part of our business worldwide. They have great conversion rates and customers are quick to choose it as a payment method because of its ease and simplicity."



"Mobile payments for digital goods is one of the fastest growing segments of mobility," said J. Gerry Purdy, Ph.D., VP & Chief Analyst, Mobile & Wireless at Frost & Sullivan. "BOKU is clearly one of the early winners in this fast growing market with impressive customer wins and millions of transactions per month. We see billions of digital assets being purchase via mobile phone in the next few years."



"Since our launch this summer, BOKU has seen a tremendously positive response from the publisher community worldwide," said Ron Hirson, Co-founder and Senior Vice President of Product Marketing for BOKU. "In addition to seeing impressive revenue growth for our customers, BOKU itself has seen strong growth as it continues to set the new standard in mobile payments and further expand its international reach."



Watch a demonstration of how easy and safe it is to pay using BOKU.



About BOKU:



BOKU is creating the standard for online payments using your mobile phone, making it easy to pay for digital goods and social experiences across the web. With a strong focus on reliability and security, BOKU's goal is to bring bank-grade payments technology and mobile users together on the web, creating a trusted, viable and accessible market for consumers, publishers and carriers alike. Based in San Francisco with offices in Europe, Asia and Latin America, BOKU reaches over 1.8 billion consumers worldwide, and is funded by leading Silicon Valley entrepreneurs and venture capitalists Benchmark Capital, Index Ventures and Khosla Ventures. For more information, please visit boku.com.



BOKU and Pay by Mobile are registered trademarks or trademarks of BOKU, Inc., and/or its subsidiaries. All other brand names, product names, or trademarks belong to their respective holders. BOKU reserves the right to alter product offerings and specifications at any time without notice.

In Case You Missed It...Web/Online Banking Not Safe!

In the last two weeks, it should have become clear to everyone that Web Security is shot and online banking authentication, including One-Time Passwords (OTC's) and Transaction Authorization Numbers (TANs) needs to be.

40% more consumers are afraid to enter their personal details into web sites than last year, phishing has graduated to Trojans, no website is safe and we're still typing. Meanwhile, Hackers have created "real-time" Keylogging...meaning that even if we "create temporary numeric passwords that get changed each minute, the probelm is that the hacker/attacker now gets the same password immediately." Nice!

Below are links which review some of the posts that cover recent "uncoverings."
If he you have the time, read them and you'll be as convinced as I am that we need to stop typing and start swiping.


Older to Newer: Recent PIN Payments News posts Regarding Web and Online Banking Insecurity


Web Insecurity Part Deaux (Don't...Trust It)

MasterCard vs. Visa: Dueling Compliance Philosphies

Malware Aimed at Stealing Bank Log-In Credentials Growing

ONO! Huge Security Hole on the Web

Bi-Annual Web Hacking Report Released by Breach.com

Credit Card Scam Raises New Web Security Fears

What Causes Financial Fraud? (It's the Stupid Typing!)

Card Fraud Expected to Increase in US...Yet We're Still Typing and Hackers are Still Swiping!

HomeATM's Weapon of "Phish Destruction"...

Did You See the HomeATM Finovate Startup '09 Live Demo?

Attempted Card Not Present Fraud in China up 60%

Experts: More Heartland Style Breaches Expected: This is Probably Just the Start!

Hacker Costs Keep Growing

Hackers Exploit Evolving Web

The HomeATM Solution

Real Time Keylogging Makes OTP Log-In Obsolete (If you Type it...They will Come!)

Online Banking Fraud Worse Than We Think (and we think it's BAD!)

Browsers are to Hacking what Fuel is to Race Cars

As Predicted, It's Getting Worse...Not Better!

Skimming Prevention: Best Practices for Merchantsl

Top 11 eCommerce Paradigm Shifters Put HomeATM in Gear

IBM: Unprecedented State of Web Insecurity - No Such Thing as Safe Browsing

Online Banking Insecure...Only 1 Bank Rated Excellent

FDIC: Online Banking Flawed

HomeATM Provides the "Inevitable" Solution Now

Not the "Type" of Two Factor Authentication we Need...





Wait Just One Minute Mr. Wi-Fi!

From the "wait a minute, are you sure that's safe?" department: 



It took Japanese researchers only 60 seconds but it appears as if  the replacement to the extremely vulnerable WEP needs replacing. 



The WPA encryption system used for wireless security can hacked in about 60 seconds.  That's scary since the WPA protocol and related TKIP were created due to weaknesses discovered in Wired Equivalent Privacy (WEP).



According to CBR, "The security attack they have formulated for the Wi-Fi Protected Access or WPA protocol is similar to one known as the Beck-Tews attack which appeared last year as a means of recovering plain text from an encrypted short packet, and from there falsifying it.  That took anything up to 15 minutes. But with this latest message falsification attack, which is good for pretty much any WPA implementation, the execution time is cut to about one minute in the best case."



Can't say I'm surprised...the writing was on the wall...(see previous posts on wireless insecurity below) Remember, our boy Albert Gonzalez,.a.k.a. "SoupNazi" got his start thanks to WEP by Wardriving. 





PIN Debit Payments Blog: Wireless Security Does Not Have Any...

Mar 15, 2009


The group accused of stealing the TJX data was believed to have hacked into several stores' weakly encrypted wireless
networks. Last year, supermarket company Hannaford Bros. reported a data breach, saying customer accounts at stores in ...
May 14, 2009
AirTight Networks published a study of wireless access points and found that the majority still use WEP and the WEP cracking time is less than five minutes. Interesting study. The URL to the PDF is at the end of this post. ...
Aug 17, 2009
DENVER - August 17, 2009 - First Data, a global leader in electronic commerce and payment processing services, announced today that it is launching the FD400, the first low-cost, battery-powered, wireless point-of-sale terminal for
Jul 15, 2009
Considering today's announcement that PCI is publishing "wireless" security guidelines, I don't see any reason why the council wouldn't be 100% behind putting together a Web Special Interest Group (SIG) and begin this much needed ...
 
Aug 19, 2008
Despite serving as an informant, the Justice Department claims, Gonzalez also began "wardriving" in the areas around US Highway 1 in Miami, according to this month's indictments. The term refers to the tactic of cruising in a vehicle 



PIN Debit Payments Blog: Wireless Identity Theft - More on Hackers 11

24 Nov 2008 


In an article published on IBLS (Internet Business Law Services) the author talks about wireless hacking (See WarDriving 101), Hackers 11 and possible changes in laws relating to cybercriminal behavior. ...




Reblog this post [with Zemanta]

Monday, August 31, 2009

Not the "Type" of Two Factor Authentication we Need...



An article written two years ago (August 17th, 2007) blasted online banking log-in procedures and still, nothing has changed...even though they mention using true two-factor authentication as a solution way before it got as bad (fraud) as it is today...



Banks are still using the "type" of authentication that hackers love.  What type is that?  You know what the Hellvetica I'm talking about.  The kind you use when you don't swipe!



I thought it might be interesting to "revisit" what was said two years ago in order to demonstrate that online banking has not progressed, while hackers unarguably have.

"A new financial services requirement calling for two-factor authentication should make online banking secure, but one researcher says it's actually making things worse.  At this year's DefCon gathering in Las Vegas, security researcher Brendan O'Connor outlined several scenarios in which online banking has gotten worse, rather than better. Under Federal Financial Institutions Examination Council (FFIEC) guidelines that went into effect at the end of last year, banks are required to provide some form of multifactor authentication of their customers.


That typically means asking the user to provide , something you have (an ATM card), something you know (a PIN) (Editor's Note:  where did "typically" go when  it comes to online banking/online shopping?  Sounds like a "swipe" vs. "type" argument to me...or something you are (a fingerprint scan). (Editor's Note: Been there,  done that


However, O'Connor,found that the new authentication implementations were no better than the traditional user-name and password that were required prior to last year.  (which, BTW is why I always utilize "username" "password" in my rants against typing. 


O'Connor also shared some insight into why, with all these new protections in place, so many phishing sites are still operational today.



FFIEC--what?




Nearly two years ago, the Federal Financial Institutions Examination Council (FFIEC) recommended guidance on authentication for online banking. According to their Web site "The Council is a formal interagency body empowered to prescribe uniform principles, standards, and report forms for the federal examination of financial institutions by the Board of Governors of the Federal Reserve System (FRB), the Federal Deposit Insurance Corporation (FDIC), the National Credit Union Administration (NCUA), the Office of the Comptroller of the Currency (OCC), and the Office of Thrift Supervision (OTS), and to make recommendations to promote uniformity in the supervision of financial institutions." O'Connor, who isn't an expert on compliance, said that failure to pass an FFEIC audit could make it hard for banks to acquire smaller banks or institutions.
"The guidance specifically says that transaction fraud and identity theft are a problem, and it places the blame squarely on authentication," said O'Connor. ." He pointed to the "three strikes--you're out" rule with most Web applications. Guess the wrong password and you're locked out until you get on the phone to someone. "Attackers aren't getting in by guessing, they're getting in by stealing the credentials or tricking the end-user into giving away the credentials." So adding more credentials won't make sites more secure.  (Editor's Note:  EXACTLY!  A user can "type" in 20 credentials and if a keylogger gets a hold of it, or they have malicious code on their computer, or if they type it into a counterfeit bank website, they are screwed.  So authentication isn't the problem.   Typing is!)







The [FFIEC] guidance specifically says that transaction fraud and identity theft are a problem, and it places the blame squarely on authentication I disagree with entire premise 



Editor's Note:  Here Here.  It's the "type" of  "authentication" that creates the  problem.  More specifically...Consumer's "typing" authentication instead of "swiping" to authenticate their online banking session!. 
The trouble with credentials

Choosing the answer to a security question isn't two-factor authentication; it's one factor--it's choosing something that only you know. But is it? O'Connor said it depends on the question. If it's public record data, then an attacker might also know the value of your mortgage or the year you graduated from college. If it's personal information, then pick a good question to answer. O'Connor mentioned Paris Hilton's choice of "What is the name of your pet?" Everyone knows that.



Then there are the oblivious choices, such as "What's your favorite city?" "If your user ID is CubsFan123," said O'Connor, "it's probably Chicago." Likewise, he said if your user ID is NYCgal576 then the answer to "Where did you go to high school?" is probably New York City. 



Editor's Note: Duh!  Ya think?  So, what can we do?  How about encrypting the data so that hackers just find random gobbledygook. "If they were properly encrypted, it would take until the sun burns out for anyone to decode it."





Read "two year old" article in full at CNET





Reblog this post [with Zemanta]

Over 70% Concerned About Mobile Security

Security still a concern for e-commerce in RP



Smart beefs up security in payment service
By Alexander Villafania - INQUIRER.net



MANILA, Philippines – Buying items online or through mobile phones is still a relatively low activity in the Philippines, even when there is gradual growth in Internet and mobile users.



At present, according to Nielsen Philippines, there are about 20 million Internet Users in the Philippines, mostly in urban areas. Another 70 million are mobile phone users.



While there is huge potential in both the online and mobile world,  fraud and identity theft remain to be barriers to growth of both e-commerce and m-commerce.



Even in countries such as the US, many people are still apprehensive to buy online much less use their mobile phones to make purchases.



A report by US-based ABI Research showed that over 70 percent of those interviewed about mobile transactions are still concerned about security



Continue Reading





From ABI Research:  Mobile Money Security

Challenges and Solutions The security of the mobile channel is perhaps the greatest impediment to the exponential growth of mobile money services worldwide. Consumer perception is that mobile is not safe for personal financial services.



All three mobile delivery options -- SMS, mobile Internet, and downloadable applications -- pose security risks. For mobile money services to fulfil their potential, mobile money service providers must find the proper balance of security and convenience for consumers. What are mobile money vendors and mobile money service providers doing to ensure security? This Brief details specific actions being taken today by leading mobile money service providers and vendors, and makes recommendations for specific actions that need to be taken to ensure security.

UAL's Interchange Pass Thru in For a Fight

Travel agents fighting United Air fee plan

Bloomberg News



Aug. 31 -- U.S. travel agents are asking Congress to prevent United Airlines from forcing some to pay credit-card processing fees on ticket purchases, saying it may raise costs for travel businesses and millions of customers.



United said in June it was making the change because of transaction expenses that have risen to several hundred million dollars annually. United had planned to begin levying the fees last month, and extended the start date by 60 days.



Some agents will have to absorb the costs when customers buy with Visa Inc., MasterCard Inc., American Express Co. and other cards. Ten states including California and New York bar agents from passing along to consumers the card surcharges, which are usually 2 percent to 3.5 percent of the purchase price, said Paul Ruden of the American Society of Travel Agents.



ASTA wrote to the Congressional sponsors of pending legislation to reauthorize the Federal Aviation Administration on the subject of so-called "back-to-gate" time limits for delayed passenger flights. In the letter, ASTA requested that Congress establish a clearly-defined time limit beyond which passengers who have been subjected to lengthy on-board tarmac delays must be permitted to return to the gate and exit the delayed aircraft. The legislation was reported out of a key Senate Committee last week, and is slated for a vote in both chambers of Congress later this fall.



ASTA wrote to the Congressional sponsors of pending legislation to reauthorize the Federal Aviation Administration on the subject of so-called "back-to-gate" time limits for delayed passenger flights. In the letter, ASTA requested that Congress establish a clearly-defined time limit beyond which passengers who have been subjected to lengthy on-board tarmac delays must be permitted to return to the gate and exit the delayed aircraft. The legislation was reported out of a key Senate Committee last week, and is slated for a vote in both chambers of Congress later this fall.



In the letter, ASTA said:



In the face of continuing delays and the evident lack of concrete efforts on the part of the airlines to create a meaningful solution thereto, and absent a robust reporting mechanism that would compel airlines and airports to report back to the Department of Transportation on their actual progress in implementing the recommendations in the Task Force's [National Task Force to Develop Model Contingency Plans to Deal with Lengthy Airline On-Board Ground Delays (Tarmac Delay Task Force)] final report, we see little hope for real progress in this area without further action from Congress. 


Therefore, we respectfully ask that you establish a clear standard for the airlines to follow. A Congressionally-defined standard will not in itself solve the inexorable problem of chronic flight delays, but it will surely represent an improvement over the current system, in which people are trapped on planes without adequate supplies for hours on end. 




On Nov. 12, 2008, the Tarmac Delay Task Force, on which ASTA held a seat, concluded nearly a year of debate about how to deal with inevitable major flight delays that strand passengers on aircraft for periods up to eight or even 10 hours. Among the Task Force's recommendations was that each airline be permitted to establish its own time limit at each airport for deplaning passengers who have been subjected to lengthy delays. In addition, the Task Force recommended that delayed passengers be provided with "regular and timely information" concerning the reason for such delays.


See full Letter to U.S. Congress

See full Letter to the U.S.Senate



ABOUT ASTA


ASTA's (American Society of Travel Agents) mission is to facilitate the business of selling travel through effective representation, shared knowledge and the enhancement of professionalism. ASTA seeks a retail travel marketplace that is profitable, growing and a rewarding place to work, invest and do business.















Reblog this post [with Zemanta]

44% Less Likely to Trust eCommerce Than Last Year

The shifting of consumer behavioral attitude towards a "more secure transaction" such as the one's provided by HomeATM's 2FA 3DES DUKPT E2EE  solution is gaining momentum.  In fact, 44% of consumers are less likely to trust a Web Merchant with their personal data than just one-year ago.  It's only a matter of time before "everyone" realizes that financial transactions must be conducted "outside the browser space." 



Here's a snippet from Network World:



Network World - Consumers are increasingly interested in doing business with companies they know and trust while avoiding the criminal elements that stalk the Internet.



In fact, 60% of online shoppers abandon their carts at some point during their shopping experience, mostly due to fear of identity theft (Sherpa Marketing Study, 2006), and almost half (44%) say they're less likely than they were just a year ago to trust a Web merchant with personal data (Yankee Group Study, 2008). As the climate of trust erodes, consumers are more sensitive than ever.


Continue Reading (Don't Be Insecure)







Reblog this post [with Zemanta]

Backlink Test

  1. Make Money Online | Money Blogging Tips

  2. HowHero


  3. Find Torrent Search Engine

  4. Indo Contest

  5. Mga Kwentong Ma Alamat

  6. Contest Love

  7. It Blood

  8. I Heart Contest

  9. Nurse Jen Doll

  10. Your Web and Graphics Design

  11. My Blog Contest

  12. Prize King Contest Blog

  13. Computer Collections

  14. Medan Blogger

  15. Eiffel Tower


  16. Programming the Life

  17. John Doro Dot Com

  18. Paco Contest

  19. Couch Surfing Host

  20. Erick's Blog

  21. My Life 4 Hire

  22. The Spirit of Blogging

  23. EmTNester

  24. Amori, poesi, arte, chat

  25. Great Wall of China

  26. The Painted Veil

  27. FeeFiFoto Blog

  28. I am Harriet

  29. Phoenix2Life

  30. Anurag Bhateja

  31. Online Treasure

  32. Gorilla Sushi

  33. London Eater

  34. News n' Tech Palace

  35. Sherry Rambling

  36. Blogging Tips and Tools

  37. Selbst Management

  38. Skip Ratt

  39. Eljon

  40. Heart Net

  41. Just 4 You


  42. Widgets For Free Blogger Widgets

  43. Bubble Crush


  44. GoGalavanting

  45. Mesothelioma Cancer Help

  46. How Things Do

  47. Hardware Rig

  48. Reality View

  49. Utah Web Design

  50. Hero Help Tutorials


  51. Nub Lag Teh Server

  52. Jobs Human Resources

  53. Naeem's Blog

  54. Facts For History

  55. Prasdikatama

  56. McPhee-Env

  57. PeriPheryPoem

  58. Writings of RYU

  59. Heart Net

  60. Cater Hater

  61. Tech Recipe

  62. Tech Boy UK

  63. Internet Leashed

  64. Tha Good Life Reviews

  65. Solaris Photography

  66. bSaves - Saving Energy Search Engine - Black Google

  67. Sitfu

  68. The All Rounder

  69. The Science of Getting Richer

  70. University Results

  71. Surigao Digital Services

  72. Senior BabyBoomers

  73. Gazlo

  74. Jessi & Ray Dream Life

  75. Life Around Raymond


  76. Susan Boyle

  77. Get Any Thing

  78. Exclusive Arena

  79. The Star Girl

  80. Tem Bolog

  81. Trash XP

  82. How Hero - How to Tutorials - Video Tutorials

  83. Blog Darma

  84. Money Central Online

  85. Watch Free Online Movies

  86. Zoom Your View

  87. Hey I Want a Job

  88. Dog Pet Grooming Supplies

  89. Aqualux Carpet Cleaning

  90. All about the Beautiful Game

  91. Communicate Your Emotions

  92. Vemma Kuantan

  93. Online Global Biz

  94. Home Affiliate

  95. News to Me

  96. Google Gadget Games

  97. High Point of the Day

  98. The Biggish

  99. Tech Feast

  100. Cake and Bread

  101. Home Cleaning Tips

  102. Fitness Excercise

  103. Funny N Cool Pix

  104. D Bucks

  105. Fow Furniture

  106. Dubious Ma

  107. Mami Bizi

  108. Fundo Geek

  109. Nijan Translator

  110. Core Worlds

  111. Dance Music Ireland

  112. A Blog for All

  113. Golf Swing Pro

  114. AFpaintball.com

  115. Top Money Making Websites

  116. Bunny Exclamation

  117. V2 Tricks

  118. Make Money Online - Comple Exercise

  119. Kits Kingdom

  120. Daily Blog

  121. Financial Planning with Chris Pua

  122. Work At Home

  123. Awesome Tech – A blog dedicated to Tech-News

  124. RohitComputers

  125. Superplaystationstore

  126. Joeedmund

  127. Yooray's Blog


  128. Feisublog - Anime blogs and Forums

  129. LUMIXiOUS

  130. imanes27.blogspot.com

  131. Best on Tube

  132. Dubai Moves

  133. ViJeshKirodian

  134. Demystifying the East

  135. MyFundoo Blog

  136. Jobconstruction

  137. http://yatabe84.blogspot.com/

  138. Cash Crate

  139. Bucks N Blogs

  140. OMG LaGigel

  141. Vintage Shirt | Vintage Jeans

  142. http://chickylounge.blogspot.com

  143. Hack A File

  144. PIN Payments Blog


See the original post where you can sign up at MoneyBush.blogspot.com





Don’t forget to promote this article via social networking and word of mouth.. It only means better results for yourself and everyone on the list.

HomeATM Provides the "Inevitable" Solution Now






HomeATM: "Inevitably For Our Own Good"







Here's an excerpt from an article written by Rhodi Mardsen which unequivocally states the reality of what it takes to secure online banking and credit/debit card transactions conducted online.  It's the economy typing stupid! Don't Type: Swipe!



HomeATM encrypts the card details so that hackers only find "random gobblygook" and manufactures the "only device" designed for eCommerce to be PCI 2.x Certified.   We did it because "it's for your own good."  The shift towards everyone using a HomeATM to conduct secure transactions and online banking continues...




There is a worldwide standard (the PCI-DSS) that any companies dealing with cardholder information are obliged to sign up to, but many security experts have pointed out that it's possible to tick all the PCI's boxes and still be insecure. The offence allegedly committed by Gonzalez is as vivid an illustration of that as one can imagine.



For once, this lapse in online security has nothing to do with us, the general public. We're guilty of all manner of stupidity when it comes to our personal financial security – writing down PIN numbers on Post-it notes, using the word "password" as our password (or typing "anything" into online banking sites or merchant checkout) just because we are "instructed to.")  – but in this case there's nothing we could have done, save for withdrawing entirely from the 21st century and using cash instead.
So what should these companies be doing to protect us? Graham Cluley, (sounds like he has one...Clu that is) from internet security firm Sophos, has expressed his disbelief that our card details aren't encrypted when they're stored, so that hackers just find random gobbledygook. "If they were properly encrypted," he says, "it would take until the sun burns out for anyone to decode it."

Editor's Note:  HomeATM believes that they shouldn't even be stored.  This is why HomeATM instantaneously encrypts the card details (including the Track2 data).  By doing so the Internet Retailers (IR) never store it, in fact never even handle it. This provides three distinct benefits.  1.  It  keeps the data safe, 2.  instantaneously places the IR within the realm of  PCI compliance and 3. protects the IR from significant fines which would be levied against them by V/MC in the event of a breach.  Those are three pretty significant benefits...but first, we have to eliminate typing. 


But it's not just the companies storing our details that need to shape up. The 130 million stolen credit card numbers would be of no use to anyone if they couldn't be used to buy stuff. Any masterminds wouldn't have been the ones picking a card number and using it to buy soft furnishings on eBay; they'd sell the numbers on to other criminals in blocks of a few thousand. But eventually, someone would pretend to be you and use your money, because it's still disconcertingly easy to do.



Online shopping is a click-happy cinch, but with that convenience comes risk; if you can tap out your 16-digit number, expiry date and a supposed "secret" three-digit number on the back of your card to book a flight to the South of France, so can anyone else.
"We may balk at the idea of carrying around an additional device (of the kind Barclays customers now have to use for online banking) to enter our PIN every time we make a credit card purchase online, but when these kind of measures are inevitably introduced, we'll have to grin and bear it. It's for our own good, after all.
As for the likes of Alberto Gonzalez, they're talented individuals capable of writing sophisticated software that can detect weaknesses in even the strongest computer defences. Indeed, such characters frequently find themselves with job offers in the industry following their release from prison. But after a 35-year stretch, technology is likely to have marched on a bit too far for anyone to catch up. Marched on so far, one would hope, that our money would finally be safe from marauding cybercriminals. Fingers crossed.
Source: Independent

Reblog this post [with Zemanta]

Fraud Necessitates the Need to Track Consumer Credit Card Purchases

<p/> Credit-card companies track your purchases to make sure you and they aren't scammed


Sunday,  August 30, 2009 3:42 AM
THE COLUMBUS DISPATCH
Pat Kastner | Dispatch illustration



At noon, you use your credit card to pay for gas at a station in Columbus. An hour later, your card has been used to buy a $1,500 computer -- at a store in Moscow.



Before the charge is approved, a sophisticated computer-monitoring system thousands of miles away raises a red flag, denies the charge and keeps you from becoming the victim of a crime -- all in a matter of seconds.



Such technology used behind the scenes to thwart criminals has become the norm in the ever-evolving, techno-savvy and secretive world of credit- and debit-card security.  It's a world filled with sophisticated and well-organized bad guys determined to steal your identity and card information -- and equally determined card issuers and networks bent on stopping them.



The card industry includes financial institutions such as Huntington and JPMorgan Chase, which issue credit and debit cards that are serviced by electronic payment networks. The two biggest are Visa and MasterCard.  Discover and American Express also issue and service credit cards.



At stake in their combined fight against criminals is billions of dollars. Identity theft netted crooks about $48 billion in 2008 in the United States, a 16 percent increase over 2007, according to Javelin Stategy & Research.





Of this total, about $22 billion was realized from fraud connected to existing cards.



Most cardholders have zero liability for fraudulent activity, so the fraud is likely to cost them mainly time and inconvenience.   Editor's Note: So that balance between security and convenience is what again?...and whose convenience?  It seems to me that if $22 billion worth of fraud creates "monetary loss" and "time and inconvenience" for consumers, that we need to re-evaluate that balance.  Yes?  That's without considering the fact that consumer privacy is past-tense now that every purchase is "tracked."  Why not process (E2EE) transactions the "right" way instead?





Instead, the card industry and merchants are on the hook for all those billions, which is quite an incentive to limit their losses. The card industry doesn't like to discuss the details of how fraudulent card activity is monitored and detected.  "If they became public, they wouldn't be effective. It would only aid the fraudsters," said American Express spokeswoman Lisa Gonzalez.



Continue Reading at Columbus Dispatch

Disqus for ePayment News