Monday, September 21, 2009

Device Fingerprinting Worse than Passwords?



Are we going backwards instead of forwards in our fight against cybercrime?  Passwords are bad enough, but a study shows that people falsely believe that device fingerprinting will protect them.



I've been lamenting about the inherent weaknesses in "password" protection for well over 18 months.  Consumers know it is not safe.  But what they don't know, is that a possible replacement for passwords, something called "device fingerprinting" is just as lame. 



So I will LAMEnet some more...



Prior to bringing you the following article/study, let me provide you with  two quotes...one from Symantec and another from Avivah Litan, distinguished analyst at  Gartner Research. 







Then ask yourself.  If the problem is the browser, why introduce a so-called solution which relies on the browser?  Are we taking two steps backwards when it comes to online security?  Sure seems that way.   I think it's been proven that you don't plug a hole in a dyke by sticking your finger in it. 



Again, in order to provide a secure environment, financial transactions MUST be conducted outside the browser space.  It is NOT a recommendation.  It is FACT.  Read these two quotes, read the story and then take two steps backwards and see the forest through the trees...






"The truth is that 'fingerprint' security technology is no longer effective," said Rowan Trollope, senior vice president of product development at Symantec.   "The bad guys figured out how to get around our technology."





Speaking of device fingerprinting, Avivah Litan, a Gartner VP and analyst who focuses on financial fraud...said "the technology has limits...it's not foolproof at all," "If a cyber criminal takes over

your browser, it won't work." 







Editor's Note:  Got it?  Okay...here's the latest word on how we can secure online transactions!





Users Prefer Device Fingerprinting to Passwords





Study finds 70 percent of respondents say they'd be willing to have their PCs and mobile devices authenticated by an online merchant before completing a transaction.





The latest data protection and information security survey conducted by the independent Ponemon Institute suggests that consumers would be willing to let Big Brother encroach a bit on their individual computing devices in exchange for more online security and lot less memorization of pesky user names and passwords.



Of the 551 participants who responded the Traverse City, Mich.-based researcher's online survey, 70 percent said they'd be willing to have their computers authenticated by an online merchant before purchases are completed and 75 percent of those surveyed said that computer authentication is preferred because it's more convenient than remembering passwords or answering pre-selected questions.



According to a 2007 password study by Microsoft, the average person has 6.5 Web passwords, each of which is shared across almost four different Web site. The study also found that each user has about 25 accounts that require passwords and he or she types an average of eight passwords a day.





If this particular study and it's relatively small sample size is indicative of how the majority of consumers feel, so-called device fingerprinting software and technology developed by the likes of Los Altos, Calif.-based ThreatMetrix will soon find a much larger market with e-tailers, online payment processors and even social networking and e-dating sites.



Editor's Note:  Take a step backwards here...look up...see the forest?





"Actually, I did find the responses a little surprising," said Larry Ponemon, chairman and founder of the Ponemon Institute. "The responses were overwhelmingly positive and it's clear people are becoming more comfortable with technology that can authenticate their machines."

The idea of allowing a third-party Web site to use a software that would then report back the IP address, browser and physical location of a PC or mobile device still strikes some as an invasion of privacy.  However, the notion of divulging personal information such as a mother's maiden name or the last four numbers of a social security number apparently bothers Internet users even more.

"The thing I've learned over a number of years is that timing is everything," said Tom Grubb, vice president of marketing at ThreatMetrix. "I really feel like it's the right time for this technology.



The timing is right?  The only thing I see good timing for is to review Symantec's take on device fingerprinting one-more-time...

"The truth is that 'fingerprint' security technology is no longer effective," said Rowan Trollope, senior vice president of product development at Symantec.  "The bad guys figured out how to get around our technology."











Reblog this post [with Zemanta]

Typhone Awarded Electronic Transaction Card Patent



PORTLAND, Ore.--PIN Payments Blog-- Tyfone (www.tyfone.com), a global provider 
of mobile financial services infrastructure and fully integrated mobile NFC payments
/secure transaction capabilities, today announced the company was awarded a second
patent for its innovations in smart card-based electronic wallet technology.

This newest patent, US 7,581,678, is entitled "Electronic Transaction Card."

Using time-varying magnetic fields, Tyfone`s patented technology enables the use of a memory card as an electronic wallet and/or the
ability to use that memory card for the secure transmission of financial information. This groundbreaking technology is used in the
company`s u4ia® (euphoria) Mobile Financial Services platform, which completed successful beta testing in June of this year.

In the growing contactless payment marketplace, Tyfone`s patented technologies and u4ia secure memory card platform enable a
Trusted Service Manager (TSM) to bring scale to the ecosystem by enabling existing market-deployed handsets to
become NFC ready. This leads to significant benefits to consumers and the key stakeholders such as banks, transportation
companies, mobile operators and merchants, without change to the current ecosystem and without incurring significant cost to enable it.

Unlike other software-only technologies that refer to their application as an electronic wallet, Tyfone`s platform includes a neutral secure
element -- thereby making it a true electronic container or "wallet." This solution allows a TSM to securely manage different consumer credit,
debit, transportation and pre-paid accounts for use in a wide range of payment and other secure transactions.

A key application for Tyfone`s newly patented technology is using SideTapTM to conduct a contactless payment transaction. Using SideTap,
consumers purchase goods at point of sale simply by tapping their mobile device at point of sale.

"To Tyfone, this patent is the culmination of tireless work developing a neutral solution not only as a viable implementation of NFC that
can be broadly used today, but also as a truly game-changing technology," said Dr. Siva Narendra, chief technology officer at Tyfone.
"As was demonstrated when initial testing was completed with the key stakeholders in the NFC value chain, Tyfone`s newly patented
technology brings us one step closer to a ubiquitous contactless payment reality. Tyfone`s secure memory card technology is out of the
R&D lab, has been tried and tested and is ready for the next stage in evolving the stakeholders` existing business models into new
revenue opportunities."

"Enabling near field communications without requiring design changes to the handset is the fastest way to proliferate contactless
applications," said Patrick Gauthier, who launched Visa Paywave and is now CEO of SMC Advisors, a management consulting firm focused
on emerging payments, mobile and e-commerce businesses. "Tyfone`s technology is critical to jump start NFC by providing a packaging that
is familiar to the consumers, delivering a neutral secure element that is appropriate for banks and service providers, and enabling a new class
of use cases that can drive revenue for operators."

About Tyfone:

Tyfone connects money and mobility via a highly secure, scalable and flexible Mobile Financial Services (MFS) infrastructure thaTt is tailored
to meet the evolving needs of mobile network operators, transportation agencies, retailers and financial institutions. With its complete
MFS platform and global alliance partners, Tyfone is uniquely qualified to deliver issuer-centric turnkey solutions with fully integrated
contactless payments capabilities. To discover why Tyfone is becoming the partner of choice for MFS technologies to many of the
world`s leading organizations, please visit www.tyfone.com.

Tyfone
Carol Grunberg, +1 503-546-9364
carol.grunberg@tyfone.com
Reblog this post [with Zemanta]

Community Banks Focusing on Secure Payments



Washington, D.C., -PIN Payments News Blog- Community banks are continuing to invest in payments-related products, according to a nationwide community bank payments survey released today by the Independent Community Bankers of America (ICBA).



The 2009 ICBA Community Bank Payments Survey (www.icba.org ), conducted every two years, revealed that 52 percent of community banks increased payments-related spending, while only 11 percent decreased spending.



The survey also revealed that 62 percent of community banks offer merchant remote deposit capture (RDC), up 41 percent since 2007; debit cards continue to be the dominant consumer-payments vehicle for community banks; and debit card and check fraud are of great to concern to community banks.



"The 2009 ICBA Community Bank Payments Survey shows that, even during these challenging economic times, community banks (www.icba.org ) are increasing their investment in payments products and services that enable customers to execute secure banking transactions anywhere at any time," said Viveca Ware, ICBA senior vice president of payments and technology policy.



"It's evident that most community banks now understand the benefits their investments in payment technology bring to operational efficiency for both the bank and the customer."



The number of community banks that offer merchant remote deposit capture is expected to increase to 78 percent by 2011. RDC adoption rates are strongest among the largest community banks, with 97 percent of those with more than $500 million in assets offering merchant RDC versus 32 percent of community banks with assets less than $100 million.



While debit cards ranked as the most important payments vehicle, and checks were the second most important, the outside fraud associated with both has been a challenge for community banks, the survey showed.



Debit cards have been hit particularly hard, with 91 percent of survey respondents citing the need to reissue cards due to fraud, while 78 percent said they experienced a monetary fraud loss. Check fraud continues to be a problem as well, with 56 percent of community banks experiencing monetary fraud losses last year.





"While community banks such as mine are heavily committed to protecting our customers and our bottom lines, fraudsters continue to be just as committed to exploiting banking customers," said John Buhrmaster, chairman of the ICBA Payments and Technology Committee and president of 1st National Bank of Scotia, N.Y. "Payments fraud risk can be mitigated, but not without effort or expense."



Other key findings from the 2009 ICBA Community Bank Payments Survey include:

  • Online bill payment is becoming more prevalent across the community banking sector. All banks over $250 million in assets (99 percent) offer this service, while smaller community banks offering the service (74 percent) are rapidly closing the gap.

  • Community banks still consider checks the most important business payments product, followed by ACH origination, cash management, bill payment and payment-card merchant processing.

  • Six percent of community banks offer mobile banking services today, with 27 percent planning to increase their technology spending in this area by 2011.

  • Community banks are close to implementing all-image check processing. While 82 percent of community banks currently receive their cash letters electronically, an additional 9 percent plan to do so next year.


The survey was conducted from June 1-26, 2009, and included 43 questions with responses from 909 community banks with asset sizes from under $100 million to more than $500 million. For more information, visit www.icba.org .



About ICBA



The Independent Community Bankers of America (www.icba.org ), the nation's voice for community banks, represents nearly 5,000 community banks of all sizes and charter types throughout the United States and is dedicated exclusively to representing the interests of the community banking industry and the communities and customers we serve. For more information, visit www.icba.org .



Source: Company press release.


Reblog this post [with Zemanta]

NAB: "Mobile Payments Not in the Cards"



In an article written by Suzanne Tindal, for ZDnet Australia, she reports that National Australian Bank will deploy over 2500 Contactless Terminals to merchants by Christmas, but has pulled the plug on a mobile payments platform that relied on a software download to the phones SIM.



NAB rolls out contactless terminals




Suzanne Tindal, ZDNet.com.au
- September 21 2009



National Australia Bank has announced that it will roll out systems to over 500 Melbourne merchants this month, which will enable them to take customers' payment when they hold their cards up to a reader, but has stopped developing technology for payments via mobile phone.






"The bank had also been trialling contactless payments via mobile phone, made possible by downloading a software application to a phone SIM. However, despite positive results from a three-month trial of this technology which found that 90 per cent of participants were happy making payments using the mobile technology, the bank said mobile payments weren't on the cards.









"Mobile payments rely upon card issuing companies and telcos positioning product together," a spokesperson for the bank said. "We are not pursuing development of this at this point in time."



Editor's Note:  Sounds like they read Javelin's Report (see previous post) on contactless/mobile payments where they stated:



"The contactless payments ecosystem is presently a series of “islands” with little-to-no mutual realization of value among the various constituents. The report indicated that the success of contactless solutions depends on some disruptive factor or wide-scale deployment that bridges the gaps and allows for value creation among all constituents that connects the islands. 













Reblog this post [with Zemanta]

Javelin: Contactless Payments Have Little-to-No-Mutual Realization of Value





San Francisco, -PIN Payments News Blog– Javelin Strategy & Research (www.javelinstrategy.com ) today released a report revealing that the contactless payments ecosystem is presently a series of “islands” with little-to-no mutual realization of value among the various constituents. The report indicates that the success of contactless solutions depends on some disruptive factor or wide-scale deployment that bridges the gaps and allows for value creation among all constituents that connects the islands.



The Javelin report, Contactless/Mobile Payments Ecosystem: Solutions Must Bridge Islands of Value to End Market Stagnation, also reveals that until this bridging occurs, Near Field Communication (NFC) and the evolution of mobile payments will flounder in the U.S. market.



“Efforts to deploy contactless and mobile payments solutions have suffered from conflicting value propositions among various constituents, specifically merchants, payment networks, card-issuing financial institutions, and wireless carriers,” said James Van Dyke, President & Founder. “But companies such as Vivotech and newcomer Zenius are seeking to build solutions that bridge the gaps in value among the constituents. Consumer awareness and behavior changes are also necessary.”



Key Findings of the Javelin Strategy & Research Report:
  • Smartphone ownership will be a key driver in consumer adoption of more robust mobile activity, including mobile payments. (For more on smartphone and iPhone usage, please refer to our 2009 Mobile-Banking and Smartphone Forecast Report.)


  • Current smartphone owners show a much higher propensity to use contactless cards and are more likely to extend this into mobile payments usage.


  • The tipping point for wide-scale mobile payment deployments will sync with the growth of selected smartphones and the congruence of value for each ecosystem player.


  • As ecosystem players realize the value of NFC beyond the payments, the path to value from large-scale deployments of NFC solutions will become clearer.


  • Wireless offers with higher uptakes will lead to a greater likelihood that customers will engage in mobile payment activities






“Finding the right base of consumers that will drive contactless usage and make the leap to early adoption of mobile payments is an integral part of widespread deployment,” said Mary Monahan, Research Director & Managing Partner. “Several population segments show propensity to use contactless and mobile payments – including mobile bankers, smartphone owners and tech-savvy consumers. In-depth information on these segments will enable all industry players to better understand their individual value proposition and their position in the ecosystem.”



To arrange an interview with Mr. Van Dyke or Ms. Monahan and/or view research on this topic or a similar topic (available to qualified members of the press), please contact Crystal Mendoza at +1.925.225.9100 ext. 35 or cmendoza@javelinstrategy.com .



About Javelin Strategy & Research



Javelin provides superior direction on key facts and forces that materially determine the success of customer-facing financial services, payments and security initiatives. Our advantages are rigorous process, independent position, and expert people. For more information about this or other Javelin reports, please visit www.javelinstrategy.com/research or contact Elizabeth Travers at (925) 225-9100 ext. 31 or etravers@javelinstrategy.com .


Source: Company press release.


$3 Million Raise for Mocapay





Denver, -PIN Payments News Blog- Mocapay, a leader in mobile gift, loyalty, and marketing, is proud to announce today that they have closed $3.0 million in funding from Spartan Mobile, Lacuna and other investors.



“We are very excited to have Spartan Mobile as the lead investor in this round and we look forward to their active role in helping to guide the Company,” said Kevin Grieve, CEO of Mocapay. “To close a funding round in this economic environment is a testament to the momentum of our business and the viability of our business strategy. We continue to see market interest in our mobile commerce services and our ability to support a new-to-market mobile payments and marketing product.”



Currently, Mocapay provides merchants’ the capability to mobile-enable their gift and loyalty programs which allows consumers to transact at the point-of-sale, access their account balance and transaction history, find the nearest merchant location accepting mobile gift and loyalty, and reload their gift account, all from their mobile phone.



In addition, Mocapay customers can take advantage of the Gift-A-Friend application, which enables consumers to send mobile gift accounts to their friends and family directly to their mobile phone from the Mocapay website (www.mocapay.com ).



Proceeds from the funding will go towards supporting new customer implementations, expanding business development efforts, and developing additional enhancements to the mobile commerce platform, for both payments and marketing services.



“We look forward to the opportunity to help Mocapay grow and establish themselves as the leader in the mobile payments and marketing space,” says Chris Martin, investment manager of Spartan Mobile. “We see the tremendous value and potential of Mocapay, as they continue to expand their footprint among merchants’ gift, loyalty, and marketing programs.”



About Mocapay (www.mocapay.com )



Mocapay provides the only mobile commerce platform that supports integrated mobile payments, marketing and distribution at point-of-sale. Mocapay delivers unequaled direct marketing opportunities and customer loyalty to merchants while providing consumers with the unprecedented ability to transact simply and securely with their mobile device and receive real-time promotions from their favorite retailers.



About Spartan Mobile



Spartan Mobile is an investment fund out of Dallas, TX that has invested in the mobile space since 2005, specializing in mobile marketing, information and promotions. Spartan, backed by the Headington Group, provides capital, manpower, and takes an active role in helping to guide its companies to continued success.



About Lacuna (www.lacuna.com )



The Lacuna Venture Fund is a pioneer in the concept of Gap Capital, which helps early-stage companies negotiate the gap between product innovation and marketplace adoption. The company provides financial capital and go-to-market expertise to accelerate the success of promising entrepreneurial companies.



Source: Company press release.

Sunday, September 20, 2009

CNN on Cybercrime





CNN Money.com had a great article on Cybercrime last Thursday. Did you know that the number of NEW Web Security Threats Tripled this year?



Yup...we are now looking at a mere 1.7 Million Threats. Let me put that in perspective for you...



If I were to do a unique post on each threat...assuming each post took 30 minutes...and assuming I worked 12 hours a day...7 days a week for 365 days a year...it would take me a mere 194 years before I was done. (that would be me...pictured on the right...years before completion)



Put another way, if I actually had started this project on September 17th, 1815, I still would not be finished. (What's that? Oh...you are correct...I would've been done on September 17th 1815...considering the number of Web threats I would have needed to post about back then, but you get my drift)



So don't be looking for me to even start...not gonna duet..not even one. After all, it''s a hellava lot easier to surmise all 1.7 million threats with just one post, in "three simple words"...

"Don't Type...Swipe!



Here are a couple of excerpts...starting with a basic warning. By the way, I wish the media would start calling "Enter" "Type"! Don't Enter...Swipe! doesn't rhyme...



"Cybercriminals can see what you enter (type) on your screen
and steal your credit card information or bank account information."



Cybercrime: A (not so) secret underground economy

Cybercriminals are making a killing off of stolen identities, creating their own market for  buying and selling credit card and bank account information on the cheap.
Cybercrime has become a rapidly growing underground business built by savvy criminals, who buy and sell valuable stolen financial information from millions of unsuspecting Internet users every year in an on online black market.



"Most cybercriminals are very, very interested in financial gain by compromising customer accounts," said FBI special agent Austin Berglas, who supervises the Bureau's New York Internet crimes squad. "Believe it or not, there are people who fall victim to their scams, and we see it every day."



Because cybercriminals are so skilled at hacking into thousands of computers every day, the crime is potentially a billion-dollar business. If every stolen credit card and bank account had been wiped clean last year, that would have netted cybercriminals some $8 billion, according to data from Symantec, maker of the Norton antivirus software.

As a result of the lucrative payout, more and more online criminals are entering the game. In fact, the number of new Internet security threats rose nearly three-fold last year to 1.7 million.



Those cyber attacks mostly come from malware, or malicious software, that hands control of your computer, and anything on it or entered into it, over to the bad guys without you even knowing it. The most common forms of malware
include keystroke logging, spyware, viruses, worms and Trojan horses.



"Credit cards and bank account information made up 51% of the goods advertised on the underground economy last year, up from 38% in 2007. Credit cards are most popular because they're the cheapest stolen commodity."



Security software also helps, but it far from solves the problem. To avoid detection, many cybercriminals will send out just a handful of viruses before modifying the code and sending it out again.



"The truth is that 'fingerprint' security technology is no longer effective," said Rowan Trollope, senior vice president of product development at Symantec. "The bad guys figured out how to get around our technology."


Editor's Side Note: Speaking of device fingerprinting, Avivah Litan, a Gartner VP and analyst who focuses on financial fraud...said "the technology has limits...it's not foolproof at all," "If a cyber criminal takes over your browser, it won't work." 



And for those of you who may believe that I've been blowing this out of proportion (the fact that the web is not safe for financial transactions unless done "outside the browser space" and "instantaneously encrypted) " I've got three things to say to you.  "Don't Type"...Swipe.  (or if you are a member of the media) "Do Not Enter!" 

I assure you I'm not blowing this out of proportion.  I'm coming from help here.  In fact, I'd give the "shirt off my back" to help people comprehend just how unsafe it is to enter/type card numbers into a box on a merchant's checkout...  






What size would you like?













Reblog this post [with Zemanta]

Saturday, September 19, 2009

Winnipeg Party Animals Spend $900k in Credit Card Scams

They "Party Too Hard"... Now They are a "Party To HardTime"



This is not your everyday credit card scamming gang.  Out of the seven people arrested, four were women (girls) under 25.  They used the money to paint the town red (
they jetted their friends into town, rented limo's, splurged on fine dining, drugs, alcohol, four star hotels, big screen TV's, electronics, etc.) and their spending spree (frenzy) lasted less than a month. 



The amount of money they spent in 28 days totaled nearly $900,000 or almost $33k per day in partying.



Now the party's over and they are going to have a hard time with this particular hangover. 



I'm sure it will be an experience they will never forget.  I've heard of partying too hard, but now it's "party to hard-time"...hope they had fun. 
Wonder if their lawyer said "Take two of these and call me in the morning?" 



From the Winnipeg Sun







Winnipeg police have identified four more suspects in a massive credit card scam that fleeced credit card companies of nearly $900,000 in a spending frenzy.  A total of seven people are facing 152 fraud-related charges in connection with a high-living crime spree that took place between June 18 and July 16.



On Friday, police announced the arrests of Jeremy Pete, 27, and Lauren Brooks, 24, both of British Columbia, and Winnipeg residents Bethany Granholm, 25, and Kayla Munroe, 22.  In July, police arrested accused ringleader Anthony White, 33, of Richmond B.C., Kaitlin Sadie Caissie, 24, of Burnaby, B.C., and Vancouver resident Jerry Allan Byron Grimson, 31.



The Winnipeg Police Service said the group used stolen and forged credit cards to pay for a lavish spending spree that included stays in high-end downtown hotels, limousines, fine dining and electronics purchases. Police said the suspects also bought airline tickets to fly friends in and out of Winnipeg for a night on the town.







Reblog this post [with Zemanta]

Friday, September 18, 2009

"Chat in the Middle" Phishing Attack





Online Banking just became even more dangerous than it already was with new phishing attack...

"Chat-in-the-Middle" Phishing Attack Attempts to Steal Consumers' Data via Bogus Live-Chat Support





A new, unique type of phishing attack targeted against online banking customers was recently discovered by the RSA FraudAction Research Lab. RSA has coined this as a "Chat-in-the-Middle" phishing attack and it is first executed through routine means but then presents a more advanced layer of perpetrating online fraud. The phishing attack may dupe bank customers into entering their usernames and passwords into an ordinary phishing site but the addition of a bogus live chat support window can obtain even more credentials via a live chat session initiated by fraudsters.



During the live chat session, the fraudster behind the attack presents himself as a representative of the bank's fraud department and attempts to dupe customers who are online into divulging sensitive information - such as answers to secret questions that are used for online customer authentication. This attack is currently targeting a single U.S.-based financial institution.





Upon detecting the attack RSA immediately informed the affected financial institution and commenced a standard phishing attack shut-down procedure through the RSA Anti-Fraud Command Center and its RSA FraudAction service. (RSA cannot identify this bank in order to protect its security and privacy.) The attack is hosted on a well-known fast flux network for "hire" from fraudster to fraudster, which hosts a wealth of malicious websites such as phishing attacks,

Trojans infection points, mule recruitment websites, and more.



The Design of the Attack


The phishing attack starts out as a normal phishing website that prompts customers for their usernames and passwords. Usually at this point, after providing access credentials, phishing victims are redirected either to the next page (or pages) of the phishing website or to the genuine bank website. However, this attack proceeds with a new, advanced technique for obtaining additional information on victims – instead of being redirected to the next page of the phishing kit or the genuine site, a fake live-chat support window appears launched by the fraudster as part of the attack .





Continue Reading 







Reblog this post [with Zemanta]

53% of German Companies Victim of Breach over Last 12 Months



PGP Corporation announced the results from The Ponemon Institute's third annual study on encryption usage in the enterprise - The 2009 Annual Study: German Enterprise Encryption Trends.



This year's study surveyed 490 IT and security practitioners, 27 percent of whom hold positions at managerial level or higher, and identifies the trends in enterprise encryption planning strategies, budgeting and spending, deployment methodologies and impact on data breach incidents.



The fundamental conclusion on the basis of study participants' responses is that data protection is a significant problem in Germany.





Fifty-three percent of all companies and organisations suffered at least one instance of data loss during the past twelve months, representing an increase of over 55 percent on the figure for 2008 (click graphic on left to enlarge)



Continue Reading at Help Net Security



Click Here to Download the Report



Reblog this post [with Zemanta]


Ebay Pushes EU to Change Competition Laws

ecommerce and shopping cart newsSeptember 17, 2009

By the ZippyCart Shopping Carts Content Team



Ebay wants to grow their market share in the European Union and, in an effort to help improve the laws to help them sell online, they had 750,000 Ebay users sign a petition. The petition handed to the European Parliament urges the government to reform the laws to prevent companies from blocking online sales.



Companies like Ebay and Amazon really want to expand their business operations into the European market, but these laws are preventing them from selling many brands via their online ecommerce stores.

The law in question, which Ebay feels is unjust, allows luxury goods manufacturers to decide who they want to sell their products online. The petition Ebay submitted says manufacturers should not be able to "insist that Internet retailers must have an offline retail store before they can sell online".



Continue Reading


Reblog this post [with Zemanta]

Splash and MoreMagic Solutions Offer Mobile Money Transfer in Sierra Leone











Available for Zain and Africell Mobile Phones; First Mobile Money Service in Sierra Leone



Freetown, Sierra Leone; Newton, MA, US, September 18, 2009 - PIN Payments News Blog: Splash Mobile Money Limited ("Splash"), a leading mobile payment system provider, and MoreMagic Solutions, a leading mobile transactions provider, announced today the availability of Sierra Leone’s first mobile money transfer system, enabled by MoreMagic Solutions industry-leading MWallet platform. Splash customers in Sierra Leone can now send money using just the mobile phone, quickly, easily, cheaply and without any requirement to have a bank account.



Splash customers use the service by visiting a Splash agent location, including branches of GT Bank. Customers transfer money by completing a free registration, purchasing SplashCash™ and sending it by text to any Zain or Africell mobile phone. The recipient then exchanges the SplashCash™ for cash at any agent location. Agents are currently concentrated in Freetown, Bo, and Makeni, with many more locations due to open throughout Sierra Leone before the end of the year.



"Splash promises to provide access to basic financial services to many Sierra Leoneans for the first time," said Ben Farren, Director of Splash. "Unbanked customers can now send money across the Country at the touch of a button."

"In Sierra Leone, mobile phone customers often travel far from home to support their families, and managing salaries in a secure way can be a challenge," said Pankaj Gulati, chairman and CEO, MoreMagic Solutions. "MoreMagic Solutions is pleased to support Splash in delivering SplashCash™, a truly innovative way for customers to manage their household money using the mobile phone."



Splash

Launched in early 2008, Splash Mobile Money Limited, designs and delivers mobile payment solutions in West Africa. www.splash-cash.com



MoreMagic Solutions

With deployments in more than 50 countries worldwide, MoreMagic Solutions offers transaction platforms for mobile operators, financial institutions, content providers, and distributors, enabling consumers to purchase goods and services on demand using a mobile phone, POS, or web.  The MoreMagic Solutions high-throughput payment engine and pre-packaged applications enable revenue-generating services, including mobile recharge and mobile money transfer, both domestic and international; mobile banking; bill payment; and mobile commerce; with integration into diverse network environments, languages, and currencies. Through MoreMagic Solutions worldwide distribution, MNO-branded services are available for out-of-country customers, enabling communications with relatives back home, and increased usage on mobile networks worldwide.



Contacts

Ben Farron

Splash

benfarren@mac.com

www.splash-cash.com

Carol J. Meier

MoreMagic Solutions

cjmeier@moremagic.com

www.moremagic.com



$32 Million Transcript of Heartland CEO Testimony





Heartland spends $32 million during first half on breach-related activities

Heartland Payment Systems Inc. spent about $32 million in the first six months of this year on forensics, legal work and other activities related to the December 2007 database breach that resulted in the theft of millions of credit and debit card numbers, CEO Robert Carr told the U.S. Senate Committee on Homeland Security and Government affairs this week.



Here's the entire transcript: 

Complete Testimony of Robert O. Carr Before Senate Committee

One in Eight Brits Hit by Online Fraud - Survey





Finextra - According to a survey commissioned by Internet security outfit VeriSign, one in eight of the UK's adult population have fallen victim to online ID fraud in the last year.



The YouGov survey of over 2000 Brits found that these fraud victims have had on average £463 stolen, with a quarter claiming to still be in dispute over compensation for the money taken. In total, £2.65 billion was stolen online from UK consumers in the last 12 months.



Despite the high proportion of victims, VeriSign says British Web users are conscientious when it comes to online shopping. Over three quarters (82%) of respondents claim to buy only from sites with enhanced security settings.



Young people are less likely to be hit by criminals, with only five per cent of 18 to 25 year olds stating that they have been online ID fraud victims, compared to 14% of people aged 45 to 54.



Continue Reading

eCrime Researchers Summit October 19th-21st



Cambridge, Mass., Sept. 17, 2009 -- The Anti-Phishing Working Group (http://apwg.org/ ) (APWG) announced it has opened registration for its eCrime Congress | Tacoma 2009 (http://apwg.org/events/2009_gm.html ), a three-day program beginning October 19, 2009.



The eCrime Congress program interrogates the current electronic crime threatscape that menaces online commerce today and tomorrow, and posits resources, tactics, and techniques to constructively engage them. APWG is the world's leading pan-industrial and law enforcement association focused on eliminating fraud and identity theft (http://apwg.org/events/events.html ).



No event combines the topical richness in exploring the electronic crime phenomenon and delegate heterogeneity like the fall APWG eCrime conferences, drawing thought leadership from technologists from many disciplines as well as from the financial services, retail and communications industries, law enforcement, and university research centers in the US, Europe and Australasia.



"No single sector holds the solution to electronic crime. At the APWG's conferences, all stakeholders can stand face-to-face and shoulder-to-shoulder to engage the eCrime phenomenon comprehensively, in ways that create dialog across affected constituencies - and inspire concerted action," said APWG Secretary General Peter Cassidy.



eCrime Congress | Tacoma 2009 will include a one-day, General Members (members-only) meeting on Oct. 19, followed by two days of open sessions on Oct. 20 and 21, examining such subjects as: crimeware's evolution, botnets' evolution, malvertising, Website vulnerabilities, business process logic abuse, telephony-based phishing, eCriminal tracking, counter-eCrime consumer safety instruction and the abuse of the Domain Name System by eCrime gangs.





The AWPG eCrime Researchers Summit (eCRS) on Oct. 20 and 21, held contiguously with the APWG General Members' meeting, will be presenting papers on counter-forensics, wireless network vulnerabilities,improvement of phishing-attack countermeasures, identification of vulnerable websites, phishing detection techniques, mechanisms for tracing the provenance of phishing attacks and much more. The eCRS, the world's only peer-reviewed technical conference dedicated exclusively to electronic crime research, is held every year with IEEE Standards Association (IEEE-SA) serving as the conference's Technical Sponsor.



The conference agenda and registration links are here:





http://www.antiphishing.org/events/2009_gm.html

Reblog this post [with Zemanta]

Finovate 2009 Reminder





Finovate 2009 is almost here and with it your chance to see the future of finance and banking before anyone else. In today's hyper-competitive market, finding and implementing the next great innovative idea (before your competition does) is critical.



Finovate will return to Manhattan on September 29, 2009 to once again showcase the best new financial and banking technology innovations from established leading companies and hot young startups. Finovate 2009 will showcase 32 of the most innovative ideas in financial technology (ideas you need to know about). Because of it's unique fast-paced format that is packed with value, the event is on pace to attract even more attendees than last year.



Handpicked from hundreds, the companies get a mere 7 minutes on stage to demo (no powerpoint allowed) their latest and greatest. Last year, almost 400 executives, entrepreneurs and industry experts attended the event’s action-packed day. Overwhelmingly, they said they’d come back. Will you join them?



Attendees from companies like American Express, Discover, Citi, Bank of America, ING Direct, Forrester, Wall Street Journal, NY Times, Fidelity, the Economist, RBC Venture Partners, Intuit, Microsoft, HSBC, Bloomberg Ventures, Visa, Lincoln Financial, CNNMoney, Money Magazine, PayPal, Ally, Canaan Partners, Yahoo!, Federal Reserve Bank, American Banker, The Hartford, USAA, AARP and many more.



Plus, don't forget to use your special offer code fan2009 to save an additional $100 on the ticket price. If you register before next Tuesday you can save a total of $200 off the last-minute ticket price! Register now.

Consumers Will Be Hurt By Interchange Regulation: 5 Articles of Proof



Yesterday I posted about the battle between the retailers and the banks over interchange fees. The Battle Has Needlessly Begun and Congress is Ready to Screw it Up.  Earlier today I posted the National Association of Convenience Stores Press Release on Interchange Fees.



Now I bring you the press release from the Electronic Payments Coalition...a release which dispels the theory put forth by the Merchant Payments Colation that they would pass the "swipe fee" savings on to the consumer. (common sense dictates that the merchants would pocket the savings) As I said in yesterday's post:
The study found that if American merchants paid the same swipe fees as those in Australia the past four years, the net savings would total $125 billion. Editor's Question: In whose pocket did that $125 billion go? I don't need a study to tell you it "wasn't the consumers"...



Here's the Press Release:



WASHINGTON, Sept. 17 /PRNewswire/ -- The Electronic Payments Coalition issued the following statement:



Today, the Electronic Payments Coalition released key evidence from several sources, demonstrating conclusively that consumers would be hurt by interchange regulation in the form of higher fees, fewer benefits, and zero savings at the cash register.



Despite the misleading claims of giant retailers who want to shift this cost, merchants themselves have confirmed that they would not pass savings on to their customers.



Representatives of the U.S. government, international economic experts, the Reserve Bank of Australia, and merchants themselves have acknowledged that consumers would see no savings from any interchange regulation.

It's simple: merchants don't want to pay their fair share, and they want consumers to foot the bill. And that's not fair.



CRA International




However, "there is no evidence that losses to consumers have been offset by reductions in retail prices." (pp. 1, 4, 13, 58) Neither merchants nor the RBA has presented any empirical evidence showing the extent to which the benefits of interchange fee reductions were passed onto consumers. Rather, "[o]ne of the main effects of the RBA's interventions has been a redistribution of wealth in favour of merchants." (pp. 1, 4, 13, 20, 58) In fact, the CRA study showed that since 2003, when that regulation was implemented, cardholder fees have risen by 22% for standard cards, between 47%-77% for rewards cards, and cardholders now pay AU$480 more in credit card fees each year. The value of rewards also fell 23% during that period.



Robert Stillman, William Bishop, Kyla Malcolm, and Nicole Hildebrandt, "Regulatory intervention in the payment card industry by the Reserve Bank of Australia: Analysis of the Evidence" (28 April 2008), available at
http://www.crai.com/ecp/assets/Regulatory_Intervention.pdf.



GAO Study




(p. 2) "Since Australia's regulators acted in 2003, total merchant discount fees paid by merchants have declined, but no conclusive evidence exists that lower interchange fees led merchants to reduce retail prices for goods; further, some costs for card users, such as annual and other fees, have increased. Few data exist on the impact of the actions taken in Mexico (beginning in 2004) and Israel (beginning in the late 1990s). Because of the limited data on effects, and because the structure and regulation of credit and debit card markets in these countries differ from those in the United States, estimating the impact of taking similar actions in the United States is difficult."

CREDIT AND DEBIT CARDS Federal Entities Are Taking Actions to Limit Their Interchange Fees, but Additional Revenue Collection Cost Savings May Exist (GAO-08-558)



Tom Robinson
, owner of Rotten Robbie's convenience stores, in testimony before the House Judiciary Committee



Mr. Keller
: Let me just be crystal-clear. Let's say you are paying 2-percent interchange fees now, and the Conyers bill passes, and you go to the arbitrator, and the arbitrator says 'I agree 100 percent with Rotten Robbie, and it is going to be 1 percent,' will Rotten Robbie customers get a discount when they go to buy donuts or gasoline or Coca-Cola as a result of that taking interchange fees from 2 percent to 1 percent?

Mr. Robinson: Well, I don't think the marketplace works exactly like that.

Mr. Keller: But your whole argument -

Mr. Robinson: But, ultimately, ultimately, the answer to your question, the consumer will benefit.

Mr. Keller: Okay. That is the $64,000 question, because your whole argument is you want lower interchange fees because it is better for consumers. And so that is why I want to give you the chance. He is saying it is not going to benefit consumers. Is it going to benefit consumers or not?

Mr. Robinson: There is not a businessman that does not attempt to keep the margin.



May 15, 2008




Credit Union Times,
May 15, 2009, reporting on a panel discussion at the Chicago Federal Reserve:



"A banking regulator from Australia acknowledged that there was no evidence [prices had been lowered as a result of regulation] in his country, which has dramatically lowered credit card interchange. 'That is a very hard question to answer,' said John Simon, chief manager for the Payments Policy Department of the Reserve Bank of Australia, responding to a question from an attendee at the Federal Reserve Bank of Chicago's 2009 Payments Conference. 'There are so many different things that might go into a price change of 98-cent can of Coke to a 96-cent can of Coke that it's impossible to say whether or not that reflected the lowered interchange rate or something else, a global economic downturn, for example.'"



"Review of the Reserve Bank of Australia and Payments System Board" for the Standing Committee on Economics, Finance, and Public Administration, June 2006




"The committee was concerned by evidence which suggested that some merchants are profiteering from the ability to surcharge. While the committee notes proposals for surcharges to be capped at a merchant's costs, it does not believe a cap would be entirely effective. Surcharging - and in particular excessive surcharging - occurs in markets not subject to high levels of competition. If merchants in these markets want to charge excessively, they could simply do so through the prices of goods and services. If surcharges were to be capped, it is possible that other prices would rise to compensate for the lost revenue."



For more information on this and other issues in the interchange debate, contact Trish Wexler of the Electronic Payments Coalition at trish@electronicpaymentscoalition.com.





SOURCE Electronic Payments Coalition


Banking Salaries Require Fed Approval



Fed plans to approve banking salaries: report

Want to read something really scary?  Here ya go...



Fri Sep 18, 5:04 AM  NEW YORK (AFP) - The Federal Reserve would be required to approve salaries for tens of thousands of US bank workers, as part of a plan to curb risk-taking at financial institutions, The Wall Street Journal reported Friday.



"The Fed's plan would, for the first time, inject government regulators deep into compensation decisions traditionally reserved for the banks' corporate boards and executives," the report said.  The proposal would see the Fed empowered to ban any compensation policies it believes encourage bank employees -- from chief executives, to traders, to loan officers -- to take too much risk.



"The US' largest banks, about 25 in number, would get especially close scrutiny.




A final proposal "is still a few weeks from completion and could be revised along the way," the report said citing unnamed persons familiar with the matter. The move requires a vote by the Fed board, but not a Congressional green light.



How scary is that?  The last line in the story states: France and Germany, Europe's leading economies, are lobbying for strict limits on executive's compensation.



Reblog this post [with Zemanta]

Brits Ditch Checks

BRITS DITCH CHEQUES AS FAST PAYMENTS GATHERS MOMENTUM



The total value of cheques cleared in the UK in the second quarter fell a massive 20% compared to the same period in 2008, as Brits continued to turn to debit cards and the Faster Payments Service.



According to the UK Payments Administration, the value of all cheques cleared, including those issued by companies, fell by 20.9% to £219.23 during the quarter. The actual number of cheques cleared was also down 13.7% on Q2 2008.

Cheques - which are set to be phased out in the UK by 2018 - accounted for just 7.8% of all non-cash payment volumes in the quarter, declining from 19.7% in Q2 2003....



More on this story: http://www.finextra.com/fullstory.asp?id=20516.   Editor's Note:  According to the Drudge Report, the Brits are not alone as Obama has also ditched czechs...



Reblog this post [with Zemanta]

Study: U.S. Pays More for Interchange Fees






More on the Merchant Payments Coalition and their New Study...





A new study by the Merchants Payments Coalition finds that Americans pay a much higher percentage for interchange charges than the rest of the industrialized world.









WASHINGTON, DC – A new study by the Merchants Payments Coalition (MPC) www.unfaircreditcardfees.com found that if U.S. consumers paid the same low credit and debit card swipe fees as consumers in Australia pay, then the net benefit would have totaled $125 billion over the last four years.



Interchange fees, or “swipe fees,” cost Americans an average of $2 on every $100 they spend with credit cards — a higher percentage than anywhere else in the industrialized world. Why? Because other countries and their governments have been able to negotiate with the big banks and credit card companies for fair rates and transparency, the MPC notes.



NACS is one of the founding members of the MPC
.





But, in the United States merchants and their customers are still forced to pay sky-high interchange fees.

Interchange fees started out in the 1960s as a way for banks to cover the cost of processing credit card transactions. But even as technology has dropped that cost dramatically, the banks and credit card companies have pushed swipe fees higher and higher, turning it into a cash cow. For many businesses, credit card fees are now their single-highest non-labor operating cost.



With almost any other equipment, supplier or service, retailers can comparison-shop, negotiate or otherwise influence its final cost of doing business. Store owners can conserve on energy usage and seek out the most competitive prices for merchandise, just to cite a few examples.



Not so with credit card interchange fees. Visa and MasterCard control more than 80 percent of the marketplace. They set the fees in secret, give businesses no ability to negotiate and virtually insist they be buried in the price of merchandise. Unfortunately, the card companies’ hidden fees get passed on to all consumers in the form of higher prices and lower value for nearly everything they buy.











“It’s bad enough that the credit card companies force these hidden fees on us and our customers when we can least afford it,” noted NACS Vice Chairman of Government Relations Tom Robinson, president of Robinson Oil Corporation.

“But when we are paying more than anywhere else in the world, and other countries have taken action to protect their citizens from abuse, it is inconceivable that our government would turn a blind eye to the issue. It is time for Congress to step up and defend the principles of the free-market economy by taking action on (interchange) fees.”



Though Congress and the White House have addressed other credit card reforms, the MPC is arguing that any fix will be incomplete without addressing interchange fees. Consider:



  • Banks raked in an estimated $48 billion in interchange fees in 2008 – an average of $427 per American household in just one year.

  • This $48 billion total is more than triple the amount collected as recently as in 2001.

  • Hidden interchange fees cost Americans more than all credit card annual fees, cash advance fees, over-the-limit fees, and late fees combined.

  • U.S. interchange fees are the highest in the developed world. The U.S. pays approximately 60 percent of interchange fees globally – about double the U.S. percentage share of global GDP.



Compared to the rest of the world, U.S. interchange fees are more than two times the rates in the U.K. and New Zealand, four times the rates in Australia and more than six times the cross-border rates recently agreed upon by MasterCard and the European Union.



Meanwhile, the payments industry hit back with its own “study.”



In a September 17 press release, Visa announced the findings of a new study that shows that “consumers believe retailers benefit far more from accepting credit and debit cards than they pay in costs.



The press release noted that consumers believe merchants see card cost acceptance as a part of doing business, much like paying for utilities such as electricity.  "



Among the survey's findings:



  • By a 2-to-1 margin, consumers say retailers should pay the cost of accepting credit and debit cards.


  • 78 percent of consumers believe the value and benefits retailers receive from accepting credit and debit cards outweigh the costs of accepting them.


  • 83 percent of those surveyed believe that any savings retailers realize will be used to increase their own bottom lines and will not be passed on to consumers.


  • 91 percent of consumers say they are more likely to shop at stores that accept credit and debit cards.

“Retailers and their well-funded trade associations have filed lawsuits and are aggressively lobbying Congress to allow them to shift their business costs to consumers by allowing merchants to charge checkout fees whenever consumers use credit or debit cards. At the same time, national convenience store chains have launched misleading, in-store petition campaigns to cover for their checkout fee efforts, noted Visa’s press release.



"The response is loud and clear: consumers aren't buying the message convenience store chains and big retailers are selling," said Bill Sheedy, group president of the Americas for Visa Inc., in the release. "This research demonstrates that consumers are well aware that legislation is a Trojan horse that likely will lead to higher prices for cardholders while retailers pocket the savings."



Reblog this post [with Zemanta]

Disqus for ePayment News