Wednesday, September 9, 2009

One-Third of Web Users Fearful of Shopping Online

A Third of Web Users are Too Scared To Shop Online

by Craig Buckler



Editor's note:  It's going to get worse before it gets better.  Until card holder data is instantaneously "encrypted" hackers will use zombies, malware, SQL injection, key logging and yet to be invented pervasive attacks to obtain our financial details.  Here's some snippets from a post on SitePoint...



Almost a third of website visitors consider online shopping to be insecure and unsafe. A recent report published by the UK’s Office of Fair Trading found that 30% of internet users would not hand over their credit card details. The report concluded that consumer confidence is growing, but it’s occurring at a slow rate. Online trading could be held back for many years, especially when UK online sales are twice as high as the European average.



The issue of trust is not helped when large-scale security problems are covered in the press.  Embarrassingly for the shops concerned, the credit card details were accessed using a SQL injection attack. Although the Department of Justice states this is a “sophisticated hacking technique,” developers have been aware about these attacks for many years. Whilst no system can ever be 100% secure, SQL injections can normally be thwarted with rudimentary data sanitization and securely-formed SQL commands.



Hacking “success” stories have an immediate impact. 7-Eleven’s online sales have certainly been affected, but the case will have a domino effect throughout the web.



The fact remains that a large proportion of users do not trust the web. Online shopping will never reach its full potential unless we tackle that problem effectively.




Reblog this post [with Zemanta]

ATM Network Offers Zero Down 0% Interest for 6 Months



Minnetonka, Minn, -- ATM Network is offering prospective customers a new atm program that gives them six months to pay for all new atm machines (www.atmnetwork.net / atmgallery.php ). Under this program, ATM Network ships and installs the atm, and also provides signage, toll-free customer support, and real-time internet monitoring. Customers can either pay for the atm machine in full after the six month period or have it converted to a traditional lease with monthly payments.



According to ATM Network's General Manager, Kurt Duhn, the program has become very popular. "Our new customers really love this program because it's very flexible. Customers have the option of paying the atm machine off after the six months with no interest, or letting it roll into a lease. It's nice to be able to offer two different options that the customer doesn't have to decide on for six months."



The owner of an atm machine collects revenue in the form of a transaction fee or surcharge that is assessed on each cash withdrawal. With ATM Network's zero down program, the atm owner receives a check for the surcharge revenue every month, even during the six month, no-payment period. "We've had a number of customers tell us that the revenue checks they received during the six months more than covered the cost of the machine when they paid it off," remarked Duhn.



Established in 1996, ATM Network is a nationwide atm company that specializes in atm sales, service, and customer support. For more information, visit atmnetwork.net . (www.atmnetwork.net )



Source: Company press release.

NY Times on Debit Cards and "Overdraft Protection" Fees

Now that debit has surpassed credit in terms of both the number of transactions AND volume, we are starting to see more media reports on the subject of debit.  One of focal points are "overdraft protection"  fees attached to "signature debit" transactions.  These fees earned banks $38 Billion dollars in 2008.  Unless you are a  Wells Fargo or a Bank of America customer, you can request the stoppage of what they euphemistically call "overdraft protection."  (WF and BoA won't let you switch that cash cow off)  Anyway...



The New York Times recently ran a couple stories on debit cards   Here's an excerpt from one, followed by an excerpt from the other:



When Peter Means returned to graduate school after a career as a civil servant, he turned to a debit card to help him spend his money more carefully.


So he was stunned when his bank charged him seven $34 fees to cover seven purchases when there was not enough cash in his account, notifying him only afterward. He paid $4.14 for a coffee at Starbucks
and a $34 fee. He got the $6.50 student discount at the movie theater — but no discount on the $34 fee. He paid $6.76 at Lowe’s for screws — and yet another $34 fee.
All told, he owed $238 in extra charges for just a day’s worth of activity



Mr. Means, who is 59 and lives in Colorado, figured employees at his bank,
Wells Fargo, would show some mercy since each purchase was less than $12. In addition, a deposit from a few days earlier would have covered everything had it not taken days to clear.

But they would not budge.

Editor's Note:  Has anyone else noticed that a check's "float" has been all but eliminated when "paying" with a check (thank you check imaging) but when "depositing" a check, the clearing time has increased.  Does anyone have an explanation as to why that might be?  (other than setting up the consumer for $238  worth of "overdraft protection" fees)  Has anyone else noticed that banks reshuffle (see graphic on left) the order of the checks "in order" to reap the highest amount of "overdraft protection" fees?  (i.e. $300 in account.  5 debit purchases.   1-4 are $25.  5 = $275.  The $275 is paid leaving $25  resulting in 3 overdraft protection charges of $35.  ($105) as opposed to paying the 1 for the $275.)



Banks and credit unions have long pitched debit cards as a convenient and prudent way to buy. But a growing number are now allowing consumers to exceed their balances — for a price.


Continue Reading "Overspending on Debit Cards a Boon for Banks" at NYT





So what can consumers do about it? 



"Many consumers don’t realize their bank may automatically let a debit card transaction go through even if there is not enough money in the checking account. A fee then accompanies the purchase, no matter how small, that exceeds your balance. Some banks, like Bank of America and Wells Fargo, generally won’t let you switch off overdraft coverage.

Stop by the branch or call on the phone and ask to turn off the overdraft protection. Many banks will do this if you ask. But make sure you understand what will happen if it says yes. In addition to cutting your debit card off when you’re at the store and low on funds, will it also refuse to allow bounced checks to go through?"



Read "Preventing Fee's From Piling Up" at the New York Times







Reblog this post [with Zemanta]

Data Breach Cost Analysis Podcast



















Data Breach Cost Analysis

The average cost of data breaches is rising as companies struggle to contain data leakage, explains Larry Ponemon of the Ponemon Institute. Also, Henry Helgeson, CEO of payment processor Merchant Warehouse, talks about PCI and encryption in the wake of the Heartland breach.  sponsored by Palisade Systems, Inc.


Play now:

    

Download for later:



Data Breach Cost Analysis

• Internet Explorer: Right Click > Save Target As

• Firefox: Right Click > Save Link As


Browse Related Resources:

Data Encryption  |  Data Security  |  Encryption Standards  |  Endpoint Security  |  Hackers  |  Information Security  |  Intrusion Detection  |  Intrusion Prevention  |  Payment Card Industry  |  PCI Bus  |  Risk Assessment

View all Resources by Palisade Systems, Inc.

JJ Buckley Offers Acculynk PaySecure for Internet PIN Debit

 AcculynkJJ Buckley Offers PaySecure for Internet PIN Debit



Major Online Wine Seller Latest Merchant to Add PaySecure to Its Payment Options




ATLANTA--(PIN Payments Blog)--Acculynk announced today that JJ Buckley Fine Wines, a premier provider of high quality wines, has enabled PaySecureTM on its Ecommerce website. PaySecure allows JJ Buckley customers to pay with their debit card and PIN right at the merchant checkout, adding an extra layer of security and convenience to their online transaction.



“PaySecure makes sense for us because we have a good volume of debit transactions on our website, and this payment method gives our customers another choice of how they use their debit card,” said Michael Stajer, CEO and co-founder of WineCommune, the parent company of JJ Buckley. “With PaySecure, we benefit from the lower price point of Internet PIN debit plus we expect it will bring new transactions from customers who prefer to pay with PaySecure.”



PaySecure’s graphical PIN-pad appears at the merchant checkout when it is determined that a consumer’s debit card can be used with a PIN and is in Acculynk’s network of participating issuers. Consumers are given the choice to enter their PIN on the PaySecure PIN-pad or run the transaction as signature debit. If they choose to use PaySecure, they enter each digit of their PIN using their mouse, hit “Submit PIN” and receive payment confirmation from the merchant.



“PaySecure provides a seamless payment experience using a debit card that the consumer already has and a PIN only they know – and it brings merchants a pre-enrolled base of consumers ready to shop,” said Ashish Bahl, CEO of Acculynk. “JJ Buckley is an incredibly unique merchant with a great value proposition to online shoppers, and we are pleased that out of all of the available alternatives on the market today, they have chosen to offer PaySecure.”



PaySecure is the first software-only service in the U.S. that provides consumers the option to pay for online purchases with PIN debit. JJ Buckley is a Top 500 Internet Retailer and joins a growing list of merchants that have adopted PaySecure, including AirTran, ShoppersChoice.com, 2Checkout.com and Ace Hardware Outlet. Acculynk recently released data on consumer usage of PaySecure in a white paper entitled “PaySecure: Tracking to Become a Leading Online Payment Method.” The white paper is available for download at http://acculynk.com/.



About JJ Buckley



JJ Buckley Wines was founded as the retail arm of WineCommune, LLC. Since 1999, it has been helping wine lovers find the best wines at excellent prices. JJ Buckley uses the Internet and today’s technology to streamline the entire wine retail process - from interacting with distributors to fulfilling orders. For more information, visit http://www.jjbuckley.com/.



About Acculynk



Acculynk is a leading technology provider with a suite of software-only services that secure online transactions. Backed by a powerful encryption and authentication framework protected by a family of issued and pending patents, Acculynk’s services provide greater security, reliability, convenience and return on investment for consumers, merchants, networks, issuers and acquirers. For more information, visit Hhttp://acculynk.com/.



Contacts



Acculynk

Danielle Duclos, 678-894-7013

Director of Marketing

dduclos@acculynk.com



Permalink: http://www.businesswire.com/news/google/20090909005719/en


Reblog this post [with Zemanta]

A Day in the Life: 09/09/09

The calendrical anomaly arrives tomorrow...any special plans? 



9/9/09 represents the last set of repeating, single-digit dates that we'll see for almost a century (until January 1, 2101), or a millennium (mark your calendars for January 1, 3001), depending on how you want to count it. Here's how I count it: in 13 months we'll have a perfect 10/10/10, so it's really not as big of a deal as some make it.



As part of his obsession with numbers both mathematically and divine, and like many mathematicians before and since, Pythagoras noted that nine in particular had many unique properties.



Any grade-schooler could tell you, for example, that the sum of the two-digits resulting from nine multiplied by any other single-digit number will equal nine. So 9x3=27, and 2+7=9.



Multiply nine by any two, three or four-digit number and the sums of those will also break down to nine. For example: 9x62 = 558; 5+5+8=18; 1+8=9.



Sept. 9 also happens to be the 252nd day of the year (2 + 5 +2)...



But, when it comes to the past mixing into the present, 09/09/09 signifies The Beatles Rock Band Nine...Number Nine, Number Nine, Number Nine



Oh, and for those who are into Rock Band (I personally prefer blues harmonica) 09/09/09 represents The Beatles Rock Band Release: Please visit thebeatlesrockband.com.

























Reblog this post [with Zemanta]

Tuesday, September 8, 2009

Smart Card Alliance Executive Direct Unhappy with Online Banking Security

In today's Smart Card Newsletter, issued by the Smart Card Alliance,  Randy Vanderhoof, Executive Director of the Smart Card Alliance, had the following to say about online banking fraud:  





Payment fraud resulting from massive data breaches was in the news again this month and one specific type of payment fraud–online banking fraud–got a little too close to home for me personally...



The Smart Card Alliance fell victim to such fraud this month. Our online banking account was breached by someone who created a valid account relationship with the Alliance’s business checking account and began making large, unauthorized ACH withdrawals from our account.



What was most shocking was how inept the bank’s (I won’t mention any names, but it is one of the BIG ones) internal business processes were in responding to the fraud, locking down the account, and putting on additional controls after the fraud was reported. What I was told was that I could set up manual controls to limit ACH deposits and withdrawals to only authorized accounts, but that I needed to upgrade our account to a “stronger” type of account.  It took 10 business days just to have an ACH blocking feature turned on!


I was also told that the bank can provide me with a smart card–not to securely log in and authenticate myself to my account in place of my current user name and password , but rather to have the chip generate a dynamic one-time password (OTP) each time I authorize a transaction.



For authentication,
I would still have to type the password into my desktop computer , which just might be infected with a key logger connected to Twitter-like instant messaging that can capture my account information "and the OTP" as I type and log in as me without me even knowing it. (Such a “man-in-the-middle” attack was recently revealed in this NY Times article).


I am on a mission now: to find out how our bank account got hacked, why all online personal and business checking accounts are vulnerable–at least in this bank–and why no one is doing anything about it.


An Open Letter to Mr. Vanderhoof:   Randy,  HomeATM agrees that typing your password into your desktop computer is a futile way to prevent hackers from obtaining your sensitive data and HomeATM IS  trying to do something about it.  We are in the midst of speaking with several national banks in order to demonstrate that consumers need to authenticate themselves the same way they do at an ATM machine.  I am aware, that as Executive Director of the Smart Card Alliance you would probably be more interested in our EMV version (which we have, should you know anyone in Europe who might be interested) , but until EMV is prevalent in the United States, we are offering banks the opportunity to offer their customers our PCI 2.x Certified PIN Entry Device, the only one of its kind.  One which would provide users with the security and protection of a two-factor (what you have/card and what you know/PIN) 3DES DUKPT TRUE "End to End Encrypted" Log-In.   (Most are End-to-Almost-End Encrypted)  HomeATM provides true Zone 1 through Zone 5 encryption for the PIN.  (The track2 data is encrypted through Zones 1-4)



Our device would also provide consumers with the means to conduct "card present" transactions in a "card not present" fraud infested world (wide web) and enable the bank to offer a real time (not ACH) P2P Money Transfer option as well as " real time" online bill payments.  



Maybe the Citizen's Bank lawsuit, which I blogged about earlier today will open their eyes to the risk they are not only exposing their customers to, but the risks they are exposing themselves to as well!   F
eel free to drop me a line anytime if you'd like to discuss further!   


John B. Frank





















Reblog this post [with Zemanta]

Online Fraud Shows No Signs of Letting Up

Card Not Present Fraud is the biggest culprit. 



HomeATM provides a low cost, 2FA 3DES E2EE PCI 2.x Certified Solution which allows Internet Retailers and Consumers to level the playing field by eliminating the "card not present" environment. 





If an online consumer was instructed to  "Swipe their Card thereby capturing the data on the magnetic stripe, it would be, by definition, a "card present" transaction. 



Therefore, our device would eliminate "card not present" fraud by "morphing" the "card not present" environment into a "card present" environment.  Yes? 



You might say that HomeATM changes the way card information is swiped. 



The way it is done now, the card details are "swiped by the fraudsters."   Does it not make more sense for the online shopper to "swipe" their own card details? Then again, we could ignore all the red flags and just keep on typing!





No let up by fraudsters as online card spend soars | Response Source

Fraud prevention specialists reveal Britain’s top UK card fraud hotspots



Many of Britain’s high street shops may have been affected by the economic downturn, but millions of consumers have been more than happy to spend their money online and through mail order with their favorite retailers. However, once again the dark side of card usage is revealed as fraud specialists, the 3rd Man, unveil the extent of criminal card activity and in particular the worst places in Britain for attempted card fraud.
An analysis of the 3rd Man’s comprehensive and detailed records shows that between August 2008 and August 2009, shoppers spent an estimated £46 billion using their cards in ‘card not present’ transactions, the term used to describe purchasing when, for example, a customer is buying online or by phone. Of this figure, fraudsters have tried their best to relieve retailers of more than half a billion pounds worth of goods.


“Although Britain has been in a serious recession, it appears that many consumers have been happy to spend their money over the Internet, which is good news,” says Andrew Goodwill, fraud specialist with the 3rd Man.



“However, fraudsters show no signs of giving up. They know that online shopping has become big business and they try every scam imaginable to dupe retailers. More and more honest people are using their cards to buy over the Internet, but unfortunately more and more fraudsters are also upping their game.” 





Editor's Note:  Time to "up OUR game" or these "jokers" will continue to steal our identities, cash, and peace of mind.  Eliminate Typing, Start Swiping and "Card Not Present" fraud will be eliminated. It's really not that difficult to grasp the concept...is it?  






Reblog this post [with Zemanta]

Metavante Shareholders Approve FIS Merger

On Friday, I posted a press release announcinig that the Department of Justice cleared the way for an FIS/Metavante merger: See: FIS and Metavante Receive DoJ Clearance to Proceed with Merger



Last July, I posted that Fidelity National Information Services was holding a special shareholder meeting See: Fidelity and Metavante to Hold Special Shareholder Meetings   to vote on the merger.  Apparently, Metavante was waiting on the DoJ clearance to hold and announce the results of their shareholders votes:  RTTNews reports the vote was overwhelmingly "for"...



(RTTNews) - Banking and payment solutions provider Metavante Technologies, Inc., said Friday that its shareholders overwhelmingly approved the proposed merger with Fidelity National Information Services, Inc., FIS at a special shareholder meeting.



Earlier on April 1, Fidelity, also a banking and payment technologies provider. had agreed to acquire rival Metavante in an all stock deal valued at about $2.95 billion. The deal had the approval of the board of both the companies. The Milwaukee, Wisconsin - based company and FIS are targeting an October 1, 2009, completion date for the merger, subject to customary closing conditions. The transaction is expected to be accretive to adjusted earnings per share in fiscal 2010.



The combination is expected to create a company with a pro forma enterprise value of $10 billion and the world's largest provider of comprehensive integrated payment and financial core processing services. The deal is expected to achieve cost synergies of about $260 million and increased long-term organic revenue growth for Fidelity.



Metavante Technologies, spun-off from Marshall & Ilsley Corp. (MI) in November 2007, has been offering processing services to about 8,000 financial institutions of all sizes for more than 40 years. Services include outsourced deposit, loan, and trust account processing, check processing, electronic funds transfer, commercial treasury services, and health care payment services.



Related:

Jul 27, 2009
FIS will hold a special meeting of its shareholders to vote on the issuance of FIS common stock in connection with the merger of Metavante into a wholly owned subsidiary of FIS, and to vote on the issuance of approximately 16 million ...


Friday, September 4, 2009

FIS and Metavante Receive DoJ Clearance to Proceed with Merger



Fidelity National Information Services, Inc. and Metavante Technologies, Inc., Receive Department of Justice Clearance to Proceed with Planned Merger








Reblog this post [with Zemanta]

Biometrics Firm Partners with InterSwitch in Nigeria



LUND, Sweden - (September 8, 2009 PIN Payments Blog) Precise Biometrics has entered into a strategic partnership with Interswitch -- one of the leading African financial solution providers based in Nigeria. The aim is to supply fingerprint recognition with Precise Match-on-Card(TM) to bank applications. The partnership is already engaged in a first project, which will provide license sales at a minimum of EUR200,000 in 2009.



The partnership between Precise Biometrics and Interswitch aims at building and promoting biometric Match-on-Card solutions for the bank segment in Africa. The solutions will initially target Nigeria, which is the largest populated country on the continent with more than 150 million inhabitants.



Nigeria recently decided to replace magstripe bank cards with more secure chip cards, so called smart cards, in order to gradually eliminate fraud related to less secure magstripe cards. The new cards comply with the EMV (Europay, Mastercard, VISA) standard used in the bank industry and the government deadline to replace all magstripe cards with chip-based smart cards is December 31, 2009.



To enable banks to migrate faster, Interswitch has introduced the Verve card into the market. The Verve card has both international and local security features, and through Interswitch's partnership with Precise Biometrics, it also includes fingerprint recognition and Match-on-Card features. These features are used to control a cardholder's physical presence at the moment of a transaction. With fingerprint recognition and Match-on-Card, banks, governments and organizations increase security internally as well as for customers through personal verification and KYE (Know Your Employee).



Mitchell Elegbe, Managing Director and Chief Executive Officer of Interswitch states: "We are pleased to enter into this partnership, as Precise Biometrics is the leading provider of biometric Match-on-Card solutions. We believe that our joint efforts and technological know-how will have great commercial potential in the West African region. The capabilities, security and reliability of the Match-on-Card solution gives us a positive differentiation from biometric solutions that are relying on databases or external servers."



Thomas Marschall, CEO at Precise Biometrics comments: "We are very pleased to have come to an agreement with Interswitch, which will place Precise Biometrics in a prime position to capture the rising biometric opportunities within the financial sector of West Africa. While the strength of the partnership is documented by already being engaged in a project which will provide income for 2009, we have substantial commercial expectations for the partnership in 2010 and onwards."



Precise Biometrics is a market-leading provider of solutions for fingerprint recognition to prove people's identities. With top-of-the-line expertise in fingerprint verification, Precise Biometrics offers fast, accurate and secure authentication of a person.



Its core product, Precise Match-on-Card(TM), adds value to ID, SIM, enterprise and bank cards as well as systems for access control to buildings, computers and networks. Precise Biometrics serves business and government organizations throughout the world and its technology is licensed to close to 100 million users.



For more information, please visit www.precisebiometrics.com or see a presentation



www.precisebiometrics.com/movie.aspx.



For the full version of the press release please click on the link below http://hugin.info/131387/R/1337790/318917.pdf



For more information, contact:



Precise Biometrics AB

Thomas Marschall, CEO

+46 46 31 11 10

+46 734 35 11 10

Email: thomas.marschall@precisebiometrics.com

Don't Say I Didn't Warn You on Dangers of Online Banking!



I've been blogging about the dangers of online banking for quite a while now.  So as more an more people fall victim to phishing attacks, keylogging, DNS Hijacking, SQL Injections, Cloned Bank Websites, etc. you can't say I didn't warn you...



Today I found a "mainstream" article (The Telegraph UK) that sums up my beliefs...specifically..."Don't Type...Swipe!  



Here are some excerpts:



Viruses, spyware, key loggers – the James Bond style vocabulary of the computer hacker is enough to make us paranoid about losing all the money in our bank accounts when we log on to online banking to pay the gas bill.


And it's not just an irrational fear. Take one acquaintance of mine. She's hardly computer illiterate – a web designer with programming skills, she keeps her antivirus and other security software up to date religiously. Yet this didn't stop someone hacking into her account and sending himself most of the money she had at the time. A quick look at the online forums confirms that she's by no means the only one to fall for this particular scam.



So is online banking secure? I've spoken to a couple of experts in computer security. Both were happy to bank online themselves, they told me, although they take rigorous precautions to keep the hackers out. But they're experts: what about the rest of us? We don't want to spend our lives keeping up with the latest online threats.

After all, the criminals have economies of scale on their side – they can put a lot of effort into perfecting their malicious software because, once it's ready, they can use the internet to get it onto the PCs of hundreds of thousands of people. So there's a huge underworld industry out there, all busily working out new ways to bypass our firewalls and get at our passwords.



My experts told me that the man in the street can bank safely online, but only if certain conditions are met.
Firstly, if your bank has given you a card reader – a gadget you connect to your computer and insert your bank card into – you are safe.



If you don't have a card reader, look at how you enter your password.



Do you just type it in?
That's a gift to the scammers – a simple piece of spyware software called a key logger can record the password and send it off to the fraudsters over the internet.





Fortunately, the banks are getting wise to this. Many have developed websites that make you enter your details using mouse clicks. Although in principle it's possible to write malicious software that tracks this too, it's a lot more work than a simple key logger. Editor's Note:  A little more work won't stop them, besides, as more banks go to this method, more hackers will dedicate their time to developing a mouse click logging program...especially when people start mouse clicking their PINs, as PINs are the "holy grail" for hackers.



If you don't have a card reader and you use the keyboard to enter your whole password, you are depending entirely on your security software – and the hackers only have to be lucky once.



Personally, after seeing what happened to my friend the web designer, I wouldn't take this risk. She got her money back in the end, but only after days of worry and frantic phone calls. And the banks are becoming more and more reluctant to bail out those who have failed to take online security seriously.



When it comes to internet banking, a little paranoia is no bad thing.


Reblog this post [with Zemanta]

Online Banking Fraud Doubled in 2008

How safe is your internet banking? | Dan Hyde, This is Money

Banks love to promote their internet banking's security, but just how safe is it? Find out why Halifax and Abbey customers are most at risk



How safe is your internet banking? Online banking fraud nearly doubled in 2008.




A worrying £52.5m was stolen by sinister hackers tracking the movements of their prey, affecting one in four of all those banking online.  Some customers are still falling foul of 'phishing' schemes – emails that pretend to be from a bank and then direct customers to bogus websites where their passwords are stolen.  But more careful online bank customers are also suffering at the hands of underground hacking technology.





'Keylogging' – whereby a virus tracks every stroke of a password as it is entered – can breach the best of defences on personal computers, and is largely held responsible for the rise in online fraud.
For the ordinary web user, extra-thick internet firewalls and up-to-date anti-virus software is about as much as can be done to fend off this aggressive software.  But improving technology has helped the hackers past these barriers and, to make matters worse, many users still forget or disregard important steps like regular computer checks.



That means the onus falls on the banks to protect their vulnerable customers from internet keylogging rogues – and some are better at it than others.  Expert-led research at Which? Computing magazine showed that Halifax and Abbey internet customers are exposed to the greatest risk of having money stolen from their accounts, while Barclays led the way with its anti-fraud password controls.



Security loopholes - including password entry methods that are dangerously exposed to keyloggers, and unprotected money transfers once a user is logged in - had Abbey and Halifax firmly at bottom of the online security pile.



Barclays, meanwhile, excelled by using both its PINsentry device to generate a random password every time a user logs on, and by asking for more login information than other banks.



Some banks have also begun to use apparatus such as drop-down menus, making keylogging impossible, but this has not yet found its way onto either Abbey or Halifax's sites.



Of course, the flipside is that the once ultra-convenient days of internet banking with just a password are gone for many, replaced by carrying a card machine with keypad round and having to fill in a run of details for each transaction.








Reblog this post [with Zemanta]

Court Allows Suit Against Bank Based on Poor Online Banking Log-In



I was working on a post I decided to entitle "Don't Say I Didn't Warn You" (upcoming) when this came across the wires.  The PIN Payments Blog will follow this case closely as the ruling will set a precedent, as all rulings do.  This could be a game-changing ruling when it comes to how banks provide authentication.  As I've stated for the past 18 months, Don't Type...Swipe!  This case could result in banks being subjected to the risk, as opposed to their customers which might provide more motivation for them to take the extra steps necessary to securely authenticate their online banking customers with a 2FA 3DES DUKPT E2EE PCI 2.x Certified approach.  





This was first reported by David Johnson's Digital Media Lawyer Blog which spoke a little about the the largest precedential impact. 





"The aspect of the case that may have the largest precedential impact was its decision on the plaintiffs' negligence cause of action. (Fn1) A major basis for their negligence claim was the theory that financial institutions have a common law duty to protect their members' or customers' confidential information against identity theft. While the Court could not find controlling State precedent on point (Indiana law applied), it noted that Indiana courts have held that a bank has a duty not to disclose information concerning one of its customers unless it is to someone who has a legitimate public interest. The Court then stated, "If this duty not to disclose customer information is to have any weight in the age of online banking, then banks must certainly employ sufficient security measures to protect their customers' online accounts."
Editor's Note:  If Citizens loses this case..."citizens everywhere win".... as banks will be forced to increase the security of online banking.  There is no safer way to authenticate the user than to utilize the same trusted security banks use to dispense cash at ATM's.  HomeATM provides the only 2FA 3DES DUKPT E2EE PCI 2.x Certified Solution  in two hemispheres.  The average phishing attack is $352 and that hasn't yet got the banks moving.  Maybe the threat of losing $100k+ every time one of their online customers fall victim to fraud caused by weak authentication will motivate them to invest $12.00 or so, and protect themselves AND their customers.   We'll keep ya posted!





Finextra: Court allows suit against bank for poor online security







The plaintiffs claim that by only requiring user names and passwords to authenticate customers at log in, Citizens failed to maintain state-of-the-art security standards.  


A US couple who had thousands of dollars stolen from their online account have been given the go-ahead by a court to sue their bank for failing to provide adequate security.





In 2007 Marsha and Michael Shames-Yeakel fell victim to an ID thief who gained access to their Citizens Financial Bank online account and stole $26,500 from a home equity credit line.  The money was transferred, via a bank in Hawaii, to a financial institution in Austria. The Austrian bank refused to return the funds, prompting Citizens to inform the couple that they would be liable for the loss.



The Shames-Yeakel's refused to pay, leading the bank to report their account as delinquent to the national credit bureaus and threaten to foreclose on their residence. In response, the couple sued the bank on several grounds, claiming violations of the Electronic Funds Transfer Act and the Fair Credit Reporting Act, in the northern district of Illinois.   They also accused the bank of negligence under state law for failing to adequately protect their online accounts.

"In light of Citizens' apparent delay in complying with FFIEC security standards, a reasonable finder of fact could conclude that the bank breached its duty to protect Plaintiffs' account against fraudulent access." - US District Judge Rebecca Pallmeyer





The Judge also states: "If this duty not to disclose customer information is to have any weight in the age of online banking, then banks must certainly employ sufficient security measures to protect their customers' online accounts."












Reblog this post [with Zemanta]

Does Western Union Limitation Apply to B2B Payments?

Western Union to compete in the international B2B payments space
Commerical Payments International is reporting that Western Union is getting ready to compete in the B2B payments space.  I'm wondering out loud if the same P2P limitations outlined in the previous post, applies to B2B transfer? 

Western Union to compete in the international B2B payments space

With its acquisition of international B2B (business-to-business) payments provider Custom House, Western Union has placed itself firmly as a competitor in the international B2B payments space. Custom House processes payments originating in seven countries for payout in 120 countries.

This acquisition introduces Western Union to a new market – cross-border payments for small- to medium-sized enterprises (SMEs). The SME segment has become an increasingly important focus for payments providers in recent times as they develop products designed to serve the needs of this previously underserved market.

Western Union estimates that the SME cross-border payments market generates global revenue at least as great as the consumer-to-consumer money transfer market.

Currently, Custom House enables more than 40,000 clients to make payments in over 150 currencies. Its clients range from businesses with a need to pay international staff to firms that want to pay vendors and merchants.


, , ,

Western Union Limitation Causing Big Problems



US Meltdown Crippling Western Union Money Transfers



7News in Belize is reporting on a little known Western Union limitation.  Namely, what goes out, had to have come in the day before.  This is causing a big problem for people wanting to send money transfers.  In fact, reports say if you don't get there and put in your send request by 8:15 AM, you are out of luck for that particular day....



Have you tried to send money via Western Union recently
? If you have, then you’ll know that unless you start lining up, like an hour before the office opens,
it’s almost impossible to send money  But why is this? Is it an oppressive monetary policy, low reserves or could it be what the growth economist like to call, “exogenous shocks?” Well, according to the Governor of the Central Bank Glenford Ysaguirre it’s the third: outside factors.

You see, in any one day, Western Union can only send out as much money as it got the day before – and since the US financial meltdown, remittances, meaning money sent from the states, has declined sharply. So, in any one day, all the Western Union agencies across the country only receive something in the range of one hundred thousand US dollars. So that becomes the quota for the following day, meaning the limit of what they can wire out. Spread that $100,000 across 37 agencies countrywide, and it’s not much, meaning that if you get to a Western Union office by 8:15, you’re probably already too late!


It’s a big change; in the past no one had ever heard of a cap on the amount of money that can be sent out; you could visit the office anytime during regular working hours and breezily send the money. But things have changed and it’s been the roughest on those depend on the service for its convenience and speed. But the Governor of the Central Bank told Jacqueline Godwin today that there’s nothing the bank can do.



Glenford Ysaguirre, Governor - Central Bank of Belize

“There is some misinformation out there that the Central Bank has something to do with it because we are restricting Western Union. But no, those are conditions on their licenses from the time the license were issued. So it is not some new condition that has gone into place; it has always been there. It is just that in the past the remittances were sufficient to cover the outgoing demand.  A condition of their license is that they can only sell foreign exchange to the extent that they receive. So their outgoing remittances cannot be more than their incoming. That is to protect and preserve the reserve position of the country.



Jacqueline Godwin, “So for example if they receive twenty thousand dollars for that day, they cannot give out more than twenty thousand dollars?



Glenford Ysaguirre, “Yes that is the condition. So I guess with the economic downturn remittances coming from the States actually is on a decline and so they are restricted or limited by that and have to adjusts the outgoing remittances to the same magnitude.



The Central Bank is not here to source US dollars for Western Union remittances. The commercial banks source their own US dollars and they source that through investments coming in from customers or from proceeds from export earnings that goes into the commercial banks and that is also available to the public through the commercial banks. So if Western Union do not have, people have the option of going to a commercial bank and purchasing US dollars based on availability.”  Anecdotal reports are that things have gotten so bad in the states that in some cases Belizean are subsidizing their Belizean American relatives. Ysaguirre says that retired Belizeans living in the States are also drawing down on their savings in Belize. In the meantime, he’d urge those frustrated with the Western Union cash flow constriction to try using the banks since they have greater sources of foreign exchange.







Reblog this post [with Zemanta]

Web Browsers Exploited by XSS Attacks

Tech Insight: XSS Exposed

Pervasive Web application vulnerability is often misunderstood -- with dangerous consequences
By John Sawyer DarkReading - A Special Analysis for Dark Reading

SQL injection has been getting most of the attention lately, but the average SQL injection attack isn't nearly as sophisticated and difficult to pull off as a well-crafted cross-site scripting (XSS) attack:

XSS affects all victims of a vulnerable Website, stealing their credentials, exploiting their Web browsers, and taking action on behalf of them without their knowledge.



XSS has been the reigning champion of Web application vulnerabilities in the sheer number of applications that house this vulnerability. Like SQL injection, XSS is a flaw caused by a lack of validation of user input. But instead of attacking the Web application or database server directly, the XSS attack hits the Web app's victims and executes malicious code in the victims' Web browsers.



Continue Dark Reading













Reblog this post [with Zemanta]

Monday, September 7, 2009

11 Charged in Minnesota Cloned Card Scheme





Nearly a Dozen Charged in Counterfeit Credit Card Scheme in Minnesota



KSTP TV - Minneapolis, Minnesota



Prosecutors have charged eleven people in an elaborate, counterfeit credit card scheme. Eight of them are in custody. Federal investigators are still looking for the other three defendants.



According to the criminal complaint, between July 2008 and April 2009 the group is accused of purchasing the personal information of Capitol One Bank customers from an online source in the Ukraine, who illegally profited from the sale.



It says the group then used the information to create counterfeit credit card accounts, withdrawing more than $652,205.49 from more than 170 ATMs throughout the Twin Cities.



Investigators says in some instances, the stolen money was converted into cashier checks and used to purchase vehicle parts or vehicles with salvaged titles. Those vehicles were then shipped to Nigeria, where un-named co-conspirators sold them at an inflated price.



Investigators say the defendants recruited Nigerian residents living in Minneapolis to buy pre-determined cars at auto auctions. They were given money to buy the cars and allowed to keep whatever was left over.  They are also accused of getting some of the same people to create bank accounts so they could deposit high-dollar fraudulent checks and then withdraw the cash the following day.



The defendants are each charged with one count of bank fraud and one count of access device fraud.  If convicted, the defendants face up to 30 years in prison on the bank fraud count and 10 years on each access device fraud count.



In related news, Finextra is reporting that European security agency Enisa is calling on banks and law enforcement agencies in EU member states to raise awareness of cash machine safety issues following an alarming 149% rise in ATM attacks in 2008.



More on this story: http://www.finextra.com/fullstory.asp?id=20448

Nigeria's InterSwiitch Selects Gemalto





Nigeria’s InterSwitch Selects Gemalto’s Complete Strong Authentication Solution to Secure their e-Payment Services



Scalable solution offers security and convenience to all banking customers

Amsterdam, The Netherlands, September 7, 2009 – Gemalto, the world leader in digital security, today announced that InterSwitch is deploying its complete Ezio strong authentication solution to secure their e-payment services in Nigeria. InterSwitch is a leading provider of secure electronic payment solutions in Nigeria and comprises 25 member banks. Gemalto supplied its Ezio Strong Authentication Server and acted as server integration partner. The company also delivers EMV card readers and unconnected tokens, all customized with InterSwitch’s visual corporate identity. With Gemalto’s scalable solution, InterSwitch enables banking customers to perform secure e-transactions either using their EMV card and reader or a token.
Ezio enables InterSwitch member banks to enhance security for e-commerce by replacing static passwords with strong authentication. Users can pay their bills and taxes or buy airline tickets in a more secure and convenient manner, by authenticating themselves with a One-Time-Password using the device. They can also access online banking services, such as fund transfer, with increased security.
“We launched our EMV migration program with Gemalto and the company has proven a reliable partner,” commented Mitchell Elegbe, Managing Director, InterSwitch. “This success contributed to creating a strong business relationship and this is why we selected Gemalto for our strong authentication program”.
“Gemalto is proud to supply InterSwitch with an easy-to-use, end-to-end solution that enables users to buy and sell over the Internet, confident that their personal details are private and protected,” added Jacques Seneca, executive vice president of the Security Business Unit for Gemalto. “With our scalable solution, users get the device that is perfectly tailored to their needs.”

About Gemalto

Gemalto (Euronext NL 0000400653 GTO) is the world leader in digital security with 2008 annual revenues of €1.68 billion, and 10,000 employees operating out of 75 offices, research and service centers in 40 countries.
Gemalto is at the heart of our evolving digital society. The freedom to communicate, travel, shop, bank, entertain, and work—anytime, anywhere—has become an integral part of what people want and expect, in ways that are convenient, enjoyable and secure.
Gemalto delivers on the growing demands of billions of people worldwide for mobile connectivity, identity and data protection, credit card safety, health and transportation services, e-government and national security. We do this by supplying to governments, wireless operators, banks and enterprises a wide range of secure personal devices, such as subscriber identification modules (SIM) in mobile phones, smart banking cards, smart card access badges, electronic passports, and USB tokens for online identity protection. To complete the solution we also provide software, systems and services to help our customers achieve their goals.
As the use of Gemalto’s software and secure devices increases with the number of people interacting in the digital and wireless world, the company is poised to thrive over the coming years.


For more information please visit www.gemalto.com.
Reblog this post [with Zemanta]

Disqus for ePayment News