Tuesday, February 9, 2010

For the Third Consecutive Year, 50% of UK Consumers Won't Shop Online



New CyberSource UK Fraud Report finds:



  • 71% are concerned about the level of risk when purchasing online, up from 66% in 2008 – so their perception of online shopping as a safe activity is not improving.

  • 76% of these consumers say that they would never use a mobile phone to make purchases. 

  • 3D Secure schemes (Verified by Visa and MasterCard SecureCode) are being used by 69% of respondents  (Editor's Note:  According to a recently released study (PDF) 3DSecure Schemes are a "textbook" example of how NOT to authenticate an online user.)

  • Card reader usage increased slightly in 2009 - 29% of consumers now utilize such devices as part of their online banking process.

  • 68% of consumers who shop online said they trust retailers with their personal details and payment information. In direct contrast, when looking at all consumers (including those who do not buy online), 59% are not comfortable with retailers storing their credit card details

CyberSource Fraud Report: Consumers Hold Retailers Responsible for Safety of Online Shopping





READING, England--(BUSINESS WIRE)--Fraud Report: Almost a quarter (24%) of UK adults believe retailers are primarily responsible for making online shopping safer, according to a survey of 1004 consumers by CyberSource Ltd. This sentiment has not changed since 2007. Significantly, only 12% of consumers state that they are personally responsible.



Sixteen percent of respondents feel that banks are answerable, whilst 12% believe their ISPs are responsible. The same percentage said the government or the card schemes are accountable. Only 5% of respondents feel the police own responsibility for making online shopping safer.



The survey revealed that UK online shoppers are taking measures to protect themselves. Eighty-five percent of respondents say they look for signs that the payment page is secure, such as the green address bar; the same percent prefer to buy online from reputable retailers. 3D Secure schemes (Verified by Visa and MasterCard SecureCode) are being used by 69% of respondents, whilst card reader usage increased slightly in 2009 – in all, 29% of consumers now utilise such devices as part of their online banking process.



Simon Stokes, Managing Director at CyberSource Ltd, said, “Consumers say they feel retailers are primarily accountable for making online shopping safer. But consumers themselves have a role in this effort, and they should be encouraged to play it. Never divulge personal information on social networking sites, for example; never respond to requests for personal information from banks or government agencies that should already have that information. And of course those of us in the eCommerce industry need to do more to help educate consumers on ways security can be boosted.”



Third Consecutive Year: Half of UK Consumers Still Not Shopping Online

Fifty percent of UK consumers (aged 16+) still do not buy online, representing a large untapped market. This figure has only declined slightly since the first survey in 2007. The non-buyers cite several reasons in the survey – 67% say they prefer the high street experience. 41% say they are concerned about online security, and 36% say they don’t have internet access. When looking at the total sample, 71% are concerned about the level of risk when purchasing online, up from 66% in 2008 – so their perception of online shopping as a safe activity is not improving.



The primary motivator for those who do shop on the internet, according to the survey, is to save time and hassle (83%). Other significant reasons include immediate access to a wide range of products and services (73%) and greater cost savings (61%). Interestingly, 76% of these consumers say that they would never use a mobile phone to make purchases.



Stokes continued, “Mobile payments mean different things to different people – both merchants and consumers. This may have contributed to a lack of understanding about the whole area. It will be interesting to see how consumer perceptions evolve as we move out of the early adopter phase and mobile payments become more mainstream. The introduction of new smart phone devices and technologies should also help to drive consumer acceptance.”



Uncertainty Surrounds Payment Data Security

Sixty-eight percent of consumers who shop online said they trust retailers with their personal details and payment information. In direct contrast, when looking at all consumers (including those who do not buy online), 59% are not comfortable with retailers storing their credit card details. This may, in part, be due to media coverage; survey respondents hear more negative stories about the safety of shopping online (59%) than positive news (46%).



“With the right strategies in place, online retailers can provide a safe and secure environment for their customers,” said Stokes. “However, the public perception may differ. Retailers should clearly inform consumers not only about the anti-fraud methods they employ, but also the efforts they take to secure sensitive payment data. This is particularly important as companies look to grow their internet sales channel and tap into the high proportion of consumers that are yet to embrace online shopping.”



This survey was conducted by market research firm GfK NOP as part of a wider CyberSource project – the findings constitute the sixth annual UK Online Fraud Report, available now.



To obtain a copy of the report, please visit www.cybersource.co.uk/ukfraudreport. Journalists or analysts, please contact Danielle Cook or Sarita Sawhney on +44 (0)1628 628080 or cybersource@noiseworks.com.



The sixth annual UK fraud survey was commissioned by CyberSource Ltd and conducted by market researchers Vanson Bourne and GfK NOP. The report this year examines data from 204 merchants and 1004 consumers, aged 16+. The consumer survey took place 16-18 October 2009. The survey group was designed to be nationally representative of adults throughout the United Kingdom, and weighting was applied to the results to bring the data in line with national profiles.



About CyberSource Ltd

CyberSource Ltd is a wholly-owned subsidiary of CyberSource Corporation (NASDAQ: CYBS). CyberSource solutions enable electronic payment processing for web, call centre, and POS environments. CyberSource also offers industry leading risk management solutions for merchants accepting card-not-present transactions. CyberSource Professional Services designs, integrates, and optimises commerce transaction processing systems. Approximately 295,000 businesses use CyberSource solutions, including half the companies comprising the Dow Jones Industrial Average. The company is headquartered in Mountain View, California, and has sales and service offices in Japan, Singapore, the United Kingdom, and other locations in the United States including Bellevue, Washington and American Fork, Utah. For more information on CyberSource please visit www.cybersource.co.uk or email uk@cybersource.com.



©2010 CyberSource Corporation. All rights reserved. CyberSource is a registered trademark in the U.S. and other countries. All other brands and product names are trademarks or registered trademarks of their respective companies.









Vesta’s New Mobile Payment Platform Delivers Innovative, Secure Payment Features for Mobile Operators

Portland, Ore., Feb. 8, 2010 -- Vesta Corporation (www.trustvesta.com ), a global pioneer and leader in electronic payment solutions, today announced the availability of version 5.0 of its industry-leading secure Mobile Payment Platform. The new platform enables wireless operators worldwide to increase subscriber ARPU, accept more payment types and achieve Payment Card Industry (PCI) compliance through a managed service that includes a portfolio of new payment services and features.



“Vesta’s new payment platform offers a wide range of benefits to mobile operators,” said Chris Parsons, chief marketing officer at Vesta Corporation. “In addition to facilitating secure transactions, operators can also enjoy significant time to market advantages and a full suite of innovative features. Having processed hundreds of millions of transactions, Vesta has the experience, knowledge and agility to effectively deliver the payment technology desired by mobile operators and their subscribers.”



For operators, the 5.0 version of the Mobile Payment Platform offers a dynamic business reporting portal and Vesta’s token service that provides robust self-care functions and isolates operators from PCI compliance requirements. Enhancements for mobile subscribers include Vesta’s quick code functionality which enables even faster payments through multiple channels; wallet functions supporting multiple users and payment devices; and the integration of social networking applications where subscribers can request, send and receive payment-related gifts.



With the growth of mobile payments, and the increased diversity of new payment channels and methods, Vesta continues to place utmost importance on safeguarding the security and privacy of customer payment information.



Vesta’s Mobile Payment Platform is fully compliant with the PCI data security standard (PCI DSS) as mandated by the payment card networks, ensuring best practices when handling sensitive card holder information. This compliance relieves the operator from the costs and burdens of maintaining compliance themselves, even through emerging channels like handset applications.



Another key benefit of the Mobile Payment Platform is that it allows operators to increase subscriber ARPU while reducing churn. This is accomplished through Vesta’s patented, industry-leading fraud engine which increases the rate of successful payments, and by analyzing the customer data that flows through the Mobile Payment Platform.



Vesta helps mobile operators better understand customer behavior by analyzing payment usage and demographic data, allowing the operator to effectively up sell and cross sell, establish targeted marketing campaigns and optimize their prepaid and postpaid subscriber portfolios.



“As mobile consumers’ payment preferences evolve and they pay via increasingly diverse methods, more and more mobile operators are embracing the flexibility, convenience and security our platform delivers,” continued Parsons. “Vesta’s new Mobile Payment Platform release enables operators to ensure customer needs are met as seamlessly and securely as possible.”



To learn more about Vesta’s Mobile Payment Platform 5.0, visit Vesta Corporation at Mobile World Congress in Barcelona from 15–18 February 2010.



About Vesta Corporation




Headquartered in Portland, Oregon, with operations in Europe and China, Vesta has been a pioneer and worldwide leader in electronic payment solutions since 1995. Vesta has established long-term, successful relationships with leading international companies including AT&T, Boost Mobile, China Mobile, China Unicom, Cricket Communications, Meteor Mobile Communications, O2, Sprint, T-Mobile, Tele2, Verizon, Vodafone and Yoigo.



Source: Company press release.






ClickandBuy: New Facebook App Makes Money Transfer Possible for 350 Million Facebook Users Worldwide

This summary is not available. Please click here to view the post.

Merchant Risk Council Expands Presence to Help European Merchants Fight Online Payment Fraud

Inaugural European e-Commerce Payments and Risk Conference Set for Brussels in April



(Seattle, WA—February 9, 2010) The Merchant Risk Council (MRC) announces the creation of MRC Europe. This expansion will formally launch with its inaugural European e-Commerce Payments and Risk Conference in Brussels, Belgium on 21 and 22 April 2010.



“MRC Europe is a natural extension of our successful U.S.-based programs,” says Tom Donlea, MRC Executive Director. “U.S. and European online merchants face many of the same fraud issues, security risks and payment challenges – there are nuances that MRC Europe will adapt to best serve European merchants.”



The two-day conference in Brussels will include 18 unique sessions delivered by over 25 industry-leading presenters. Attending the Brussels conference will help European retailers improve their electronic payment strategies and adopt operational best practices for managing online payment risk.



“MRC has a proven structure for connecting its members to other members, sharing best practices, creating essential benchmarking research and working together to improve the industry,” says Belgium-based Philippe Depautex, General Manager of Sales and Operations of SonyStyle. “I am excited to employ their experience to create successful MRC programmes in Europe.”



Other merchants who are actively building MRC Europe include: Canon, Carphone Warehouse, eDreams, Eurostar, Ezetop, Lastminute.com, Nike, Philips, Seatwave.com, Skype, Symantec, Tesco and Tommy Hilfiger.



“This is truly a merchant-driven expansion,” adds Donlea. “European merchants are very eager to begin a cross-Atlantic collaboration to better fight globally-organized online fraud.”



The MRC Europe Conference takes place at NH Hotel du Grand Sablon in the heart of downtown Brussels. For conference registration details, or to receive MRC membership information, please visit the MRC’s website at www.merchantriskcouncil.org.



About the Merchant Risk Council



The Merchant Risk Council (MRC) is a merchant-led trade association focused on electronic commerce risk and payments globally. The MRC leads industry networking, education, benchmarking and advocacy programs to make electronic commerce more efficient, safe and profitable.



Today, with the power of its member-base, the MRC is the leading trade association for managing payments, preventing online fraud and promoting secure e-Commerce. The MRC is dedicated to working with e-Commerce and multi-channel merchants, payment processors, credit card issuers, credit card companies, alternative payment providers, risk management experts, and law enforcement to make the Internet a safer and more profitable place to conduct business.



The MRC Board of Directors and Advisors includes: Accertify, Apple, Chase Paymentech, CyberSource Corporation, Dell Inc., Discover, Expedia Inc., Gap Inc. Direct, GlobalCollect, Linden Lab, Microsoft, Neiman Marcus Direct, PayPal, Trustwave, Visa Inc. and Wal-Mart.



The MRC is headquartered in Seattle, Washington, USA



# # #






Acacia Subsidiary Enters into Settlement Agreements Regarding Credit Card Fraud Protection Technology

Agreements reached with Diesel USA and Gymboree Retail Stores

Editor's Note: They've been busy already this year. On February 2nd, they Acquired Rights To Patents for Portable Credit Card Processing Technology.



Last week they won a $12.4 judgment against Yahoo for patent infringement.





NEWPORT BEACH, Calif.--(BUSINESS WIRE)--Acacia Research Corporation (Nasdaq: ACTG) announced today that its Financial Systems Innovation LLC subsidiary has entered into settlement agreements covering a patent that applies to credit card fraud protection technology with Diesel USA, Inc. and Gymboree Retail Stores, Inc. This resolves a dispute that was pending before the United States District Court for the Northern District of Georgia concerning the companies listed above.



The expired patent asserted in this litigation generally relates to a computerized system for protecting retailers and consumers engaged in credit card, check card, and debit transactions. The system includes an electronic card reader, and the generation and use of a transaction number, which specifically identifies each transaction processed within the system.

ABOUT ACACIA RESEARCH CORPORATION



Acacia Research’s subsidiaries develop, acquire, and license patented technologies. Acacia Research’s subsidiaries control over 140 patent portfolios, covering technologies used in a wide variety of industries.



Information about Acacia Research is available at www.acaciatechnologies.com and www.acaciaresearch.com.















02/05/10
02/04/10
02/03/10
02/02/10
01/29/10
01/26/10
01/25/10
01/25/10
01/22/10
01/08/10
01/07/10






Cedacri Selects TSYS for Complete Payment Card Solution

 TSYSCOLUMBUS, Ga. & MILAN--(BUSINESS WIRE)--TSYS today announced that it has been chosen by Cedacri, Italy’s leading provider of outsourcing services to the banking industry, to provide card and payments services to Cedacri’s clients. Cedacri will utilize TSYS’ fully outsourced processing solution, TS PrimeSM.


The agreement marks TSYS’ entry into the Italian market while also providing full connectivity to the domestic bank network and local clearing houses. This relationship aligns with TSYS’ strategy to expand its capabilities across Europe as an established pan-European processor.



“Cedacri was looking for a true partner to help offer our banking clients issuing services and card processing services,” said Fabio De Ferrari, General Manager of Cedacri. “TSYS have the right solution with TS Prime, strong experience across Europe and an interest to invest and develop together in the Italian market, enabling growth for our clients.”



“The payments environment in Italy is changing, with banks looking for alternatives to the traditional in-country processors,” said Bob Evans, group executive of TSYS International. “Italy is a key European market and this partnership with Cedacri provides a great foundation for TSYS to develop its long term presence in this region.”



Italy is the seventh largest card market in Europe, with 70 million cards (excluding prepaid) in circulation. It is also the largest market in Europe for prepaid cards, with 8.2 million cards in circulation, accounting for 9 percent of the total cards in the country.1



Terms of the agreement were not disclosed but include the complete, end-to-end card processing solution for consumer, commercial and prepaid cards, as well as 3D Secure services and TSYS fraud solutions.



1”Payment Cards Western Europe 2010,” Retail Banking Research



About Cedacri




Cedacri is Italy’s leading provider of application, infrastructure and process outsourcing services for the entire world of banking (retail, private, corporate, virtual and specialist) and finance. Its 100 clients include banks of all types and sizes, and Italian subsidiaries of major foreign companies. With over 2,700 counters managed and more than 31,5 million transactions handled daily, the company’s computer centre is among the top providers serving Italian banks. For more information, log on to www.cedacri.it.



About TSYS




TSYS (NYSE: TSS) is one of the world's largest companies for outsourced payment services, offering a broad range of issuer- and acquirer-processing technologies that support consumer-finance, credit, debit, healthcare, loyalty and prepaid services for financial institutions and retail companies in the Americas, EMEA and Asia-Pacific regions. For more information, contact news@tsys.com or log on to www.tsys.com. TSYS routinely posts all important information on its website.





Monday, February 8, 2010

A PIN for All Reasons - GreenSheet







The GreenSheet
is publishing a story on PIN Debit written by Scott Henry of Verifone.  In it they say:







  • A PIN pad for every countertop. (or laptop) Those words might be as effective an economic stimulus as anything else we have tried over the past year or so.

  • Losses for PIN debit were just 15 cents per card issued in 2008, compared to $1.81 for signature debit. (translation: Signature Debit is 12+ times more likely to to incur a loss)

  • PC-integrated PIN pads: Personal computer-based payment processing is attractive to a growing number of storefront merchants; especially appealing is a bundled solution that includes hardware and payment processing software.

  • Merchants who are missing out on the trend toward PIN debit are paying for it in additional interchange fees. According to a Federal Reserve report (PDF) on interchange published in May 2009, interchange fees for PIN debit "typically average 35 cents to 50 cents per transaction; interchange fees for a typical signature debit transaction are about 1.2 percent of the transaction value; and interchange fees for a typical credit card transaction for Visa and MasterCard are in the range of 1.5 to 2 percent of the transaction value."

  • PIN debit use was up 12.8 percent compared to the same period in 2008, while credit and signature debit were up just 5.8 percent. 

  • PIN debit is "preferred by 45 percent of consumers, while 35 percent prefer signature (20 percent have no preference).





Here's the article:



February 08, 2010
  •  Issue 10:02:01


A PIN for all reasons 

By Scott Henry

VeriFone


A





PIN pad for every countertop. Those words might be as effective an economic stimulus as anything else we have tried over the past year or so. Just about everyone - merchants, payments industry businesses and individual consumers - have felt pinched by the impact of the credit crunch.



For consumers, sky-high interest rates are prompting more and more cardholders to dump their credit cards in the drawer and rely increasingly on debit cards instead.



For example, the National Retail Federation released a survey in November 2009 that indicated 45 percent of consumers planned to use debit or check cards to pay for gifts this past holiday season. Those planning to use credit cards for similar purchases fell to 28 percent.



In May 2009, Visa Inc. reported that in the three months ending Dec. 31, 2008, spending volume on debit cards exceeded that of credit cards for the first time. By the end of June 2009, debit accounted for more than 70 percent of all Visa transactions.



Consumer choice



Not only is debit card use increasing at the expense of credit cards, but consumers are more often opting for PIN debit. First Data Corp.'s SpendTrend report for November 2009 showed that PIN debit use was up 12.8 percent compared to the same period in 2008, while credit and signature debit were up just 5.8 percent.



In the 2008 Study of Consumer Payment Preferences conducted by BAI Research and Hitachi Consulting, it was reported that PIN debit is "preferred by 45 percent of consumers, while 35 percent prefer signature (20 percent have no preference).



Those preferring PIN debit consider it more secure, faster and easier to use than signature. Consumers preferring signature debit do so for the security, lack of fees, their inability to remember a PIN and, in some cases, rewards programs."



Paying for steerage



Is it any wonder that consumers are often steered to signature debit when they check out at the grocery store? As the Boston Globe reported in late 2007, banks "prefer the credit option for debit cards because they make more money in fees.



For example, on a $200 transaction, a bank would make $1.99 if the customer chooses 'credit' and signs his or her name; according to one estimate that would be more than three times the 60 cents they make from customers who choose 'debit' and enter a PIN."
Merchants who are missing out on the trend toward PIN debit are paying for it in additional interchange fees. According to a Federal Reserve report (PDF) on interchange published in May 2009, interchange fees for PIN debit "typically average 35 cents to 50 cents per transaction; interchange fees for a typical signature debit transaction are about 1.2 percent of the transaction value; and interchange fees for a typical credit card transaction for Visa and MasterCard are in the range of 1.5 to 2 percent of the transaction value."


It may seem counterintuitive to tell merchants how they can lower their transaction fees, but remember, anything that helps merchants achieve greater profitability will increase loyalty and retention.



Security is a value-add



There's no doubt consumers today are more aware of card fraud issues than they were three or four years ago. Millions of cards have been replaced due to breaches of retailer and processor data centers, as well as payment networks.



PIN debit is inherently more secure than signature debit, which requires just a signature that few store clerks attempt to verify. According to the 2009 Debit Issuer Study, commissioned by Discover Financial Service's Pulse network, POS losses for PIN debit were just 15 cents per card issued in 2008, compared to $1.81 for signature debit. (Signature Debit is 12 times more likely to to incur a loss, yet Visa still pushes the less secure signature debit.)






Nevertheless, when you're selling PIN debit you need to be ready to answer questions about skimming incidents in which criminals have been able to surreptitiously obtain card data and associated PINs.



These incidents have been attributed to the compromise of pre-Visa PIN entry device (PED)-approved systems. Amazingly, there are still PIN pads in use that predate any security certification. As of July 1, 2010, these pre-Visa PED systems must be removed from service.



Today's Payment Card Industry (PCI) PED systems feature certified tamper prevention and tamper detection schemes designed to ensure that efforts to compromise systems will be immediately visible and unsuccessful. Merchants can use their new systems as a compelling marketing point to show customers that security is a priority.



PIN for any counter



There is no merchant scenario (except eCommerce, even though Visa, MasterCard, Discover, AMEX and JCB PCI Certified the PED manufactured by HomeATM) that cannot accommodate a PIN debit solution in this day and age.



PIN debit can easily be added by selling merchants PCI PED devices containing an internal PIN pad or by adding a secure PIN pad to an existing terminal. With security requirements becoming ever ore stringent, many merchants must upgrade their terminals anyway, so why not provide them with solutions that offer more flexibility and payment options?



Among those options are:

  • Terminal-driven PIN pad peripherals: Compact PIN pads that attach to existing payment terminals and take up little counter space are a quick and easy way to equip merchants for PIN acceptance.

  • Customer-activated PIN pads: Once seen only in supermarkets and high-end department stores, consumer-activated facing terminals that integrate with cash register systems are suited to high-traffic venues.

  • PC-integrated PIN pads: Personal computer-based payment processing is attractive to a growing number of storefront merchants; especially appealing is a bundled solution that includes hardware and payment processing software. (don't need payment processing software with HomeATM...just plug-in our PCI 2.0 Certified PED to any USB port and you are good to go)



PIN is In
(and only HomeATM can provide it for eCommerce)  Editor's Note:  If you're thinking, what about Acculynk, remember...Acculynk isn't really  a PIN Debit transaction.  It is simply an alternative payment designed for eCommerce.  Using Acculynk's payment scheme, the consumer must TYPE their debit card number into a box on a website in the browser, putting the user at risk.  A Genuine PIN Debit requires the card to be present because the magnetic stripe must be swiped and the PVV and PVKI must be captured by the card reader.  Because Acculynk's scheme requires the user to type in their PAN (primary account number) it is, by definition,  a "card not present" transaction.  This technically disqualifies/eliminates it as a genuine PIN debit transaction.  Card Not Present PIN Debit does not exist.  Therefore, ONLY HomeATM offers genuine PIN Debit for eCommerce merchants.  HomeATM is the only eCommerce solution in the world which instantly encrypts the the magnetic stripe data (including the Track 2 data) at the mag-head.  It is also the only eCommerce solution in the world which provides true end-to-end encryption for the PIN, using Derived Unique Key Per Transaction. (DUKPT)  



ISOs and merchant level salespeople able to offer merchants a variety of PIN-entry device options will ensure maximum adaptability and security. When you combine the cost savings associated with PIN debit with increasing card volume, given current consumer trends and the higher security standards for PIN debit transactions, you've got a winning formula for sales now and in the future.






Scott Henry is Director, North America Product Marketing, for VeriFone. He can be contacted at scott_henry@verifone.com










Jack Henry & Associates Increases the Quarterly Dividend on Its Common Stock by 12 Percent to $.095 per Share

Image representing Jack Henry & Associates as ...Image via CrunchBase

MONETT, Mo., Feb. 8 /PRNewswire-FirstCall/ -- Jack Henry & Associates, Inc. (Nasdaq: JKHY) today announced that its Board of Directors has increased the quarterly cash dividend by 12 percent to $.095 per share. The cash dividend on its common stock, par value $.01 per share, is payable on March 9, 2010, to stockholders of record as of February 24, 2010. At February 2, 2010, there were 84,500,457 shares of the common stock outstanding.



Kevin D. Williams, CFO of Jack Henry & Associates, stated, "This increase in our dividend is reflective of our ongoing commitment to generate a return on our stockholders' investment. We established our dividend policy in 1990, and our dividend has increased every year since its inceptions. Our announcement of this dividend increase during our third fiscal quarter is consistent with previous years."



Jack Henry & Associates, Inc. (NASDAQ: JKHY) is a leading provider of computer systems and ATM/debit card/ACH transaction processing services primarily for financial services organizations. Its technology solutions serve more than 11,800 customers nationwide, and are marketed and supported through three primary brands. Jack Henry Banking supports banks ranging from de novo to mid-tier institutions with information processing solutions. Symitar™ is the leading provider of information processing solutions for credit unions of all sizes. ProfitStars® provides highly specialized products and services that enable financial institutions of every asset size and charter, and diverse corporate entities to mitigate and control risks, optimize revenue and growth opportunities, and contain costs. Additional information is available at www.jackhenry.com.



SOURCE Jack Henry & Associates, Inc.



RELATED LINKS



http://www.jackhenry.com





In Defense of Animals Enlists Tempo Debit Card Platform

SOURCE: Tempo Payments, Inc.



Affinity Debit Card Program Generates Revenue From Everyday Purchases for Helping Animals





SAN MATEO, CA--(Marketwire - February 8, 2010) - Tempo announced today that In Defense of Animals (IDA), an international, non-profit animal protection organization based in California, is offering contributors an affinity debit card powered by Tempo.



Every time In Defense of Animals debit cards are used to make a purchase, IDA will receive a portion of standard card transaction fees. The cards can be used anywhere Debit MasterCard cards are accepted and also provide cash-back and ATM withdrawal access to the cardholders' existing checking accounts.



"It's a painless, great way to help IDA raise much needed funds for our chimpanzee sanctuary in Cameroon, Africa; our veterinary clinics and ambulance service for the thousands of street animals of Mumbai, India; and for our investigative and sanctuary work in rural Mississippi," said IDA founder and President Elliot M. Katz, DVM.



Tempo technology makes it easy for organizations to offer affinity debit cards and provides a web portal for consumers to apply for and activate cards, as well as track purchases and rewards. The cards are issued by Tempo partner First Bank & Trust of Brookings, SD, part of Fishback Financial Corporation.



"IDA's affinity Debit MasterCard empowers supporters to link their existing checking accounts to such a noble cause as helping animals," said Tempo CEO Mike Grossman. "Using software-as-a-service technology, Tempo provides a speedy and cost-effective way to enable this type of affinity program and make it easy for consumers to apply, activate cards and track purchases online."



Tempo-enabled debit cards are affinity partner-branded, generate valuable cardholder rewards, and can be used for online and offline purchases and ATM withdrawals. Working with First Bank & Trust, Tempo manages all aspects of card issuance, including risk management, application processing, card fulfillment, authorization and settlement.



Other non-profits that are offering Tempo-powered affinity debit card programs include the Breast Cancer Fund, Greenpeace, Surfrider Foundation and World Emergency Relief.



About In Defense of Animals



Founded in 1983 by veterinarian Elliot M. Katz, IDA is an international non-profit organization with a distinguished record for challenging the exploitation and abuse of animals by protecting their rights, welfare and habitats. IDA fights to elevate the status of animals beyond that of mere property, commodities, objects, or things to be bought, sold, and discarded at an "owner's" whim. IDA operates the Project Hope sanctuary in rural Mississippi, the Sanaga-Yong Chimpanzee Rescue Center in Cameroon, Africa, and its animal rescue centers in Mumbai, India. Working with grassroots organizations, and initiating litigation, research and investigations, IDA is on the cutting edge of animal rescue, protection and advocacy around the world. www.idausa.org



About Tempo



Tempo is the leader in enabling organizations to quickly and easily offer affinity and co-branded debit cards to their customers, contributors and members. The open loop cards are rewards-based, partner-branded, and linked to the consumer's existing checking account. Tempo provides its affinity partners with a Web-based platform that makes it easy to launch and market co-branded debit programs. The partners benefit by generating new revenue, and building loyalty through the delivery of enhanced cardholder value. Tempo is privately held and is headquartered in San Mateo, CA. For additional information, visit www.tempo.com. These cards are issued by First Bank & Trust, Brookings, SD, pursuant to a license by MasterCard® International Incorporated. MasterCard is a registered trademark of MasterCard International Incorporated. First Bank & Trust is a member of the FDIC and part of the Fishback Financial Corporation.





PCI Security Standards Council Deploys Translations.com's GlobalLink(TM) Technology To Translate Global Website

NEW YORK, Feb 08, 2010 (BUSINESS WIRE) -- Translations.com, the world's largest privately held provider of translation services and language management technologies, today announced the successful localization of www.PCISecurityStandards.org into French, Spanish, Chinese, Japanese, Portuguese, Italian, and German.



Founded in 2006 by American Express, Discover Financial Services, JCB International, MasterCard Worldwide, and Visa Inc., the PCI Security Standards Council is responsible for the development, management, education, and awareness of the PCI Data Security Standards, which are designed to ensure the security of cardholder data worldwide. The PCI Security Standards Council has over 600 Participating Organization companies worldwide. Bob Russo, general manager of the PCI Security Standards Council, explained, "As a global organization focused on securing payment card data, it is critical we provide our stakeholders worldwide with the resources they need to meet this goal, in their own language."



Translations.com's GlobalLink(TM) technology offers companies both hosted and installed options for launching and automatically maintaining translated websites with minimal IT involvement. By combining GlobalLink OneLink with Translations.com's language services, PCI was able to localize its website and related documents into 8 languages in only 2 months with a completely hosted solution. When PCI makes updates to the English website in the future, GlobalLink will automatically detect and route new content to Translations.com for localization by professional human translators, then insert the completed translations back into the proper location on the global websites.



"As we continue to develop PCI Security Standards and produce new resources for our stakeholders, it was critical for us to partner with a company who could help us manage our dynamic multilingual site in a cost effective and timely manner," added Russo.



Translations.com CEO Phil Shawe said, "By making their website and standards information accessible to stakeholders in a range of languages, the PCI Security Standards Council has made a significant step forward in its mission to secure payment card data worldwide. We applaud the Council for its efforts and look forward to supporting their ongoing global initiatives for years to come."



About PCI Security Standards Council



The mission of the PCI Security Standards Council is to enhance payment account security by driving education and awareness of the PCI Data Security Standard and other standards that increase payment data security.



The PCI Security Standards Council was formed by the major payment card brands American Express, Discover Financial Services, JCB International, MasterCard Worldwide and Visa Inc. to provide a transparent forum in which all stakeholders can provide input into the ongoing development, enhancement and dissemination of the PCI Data Security Standard (DSS), PIN Transaction Security Requirements (PTS) and the Payment Application Data Security Standard (PA-DSS). Merchants, banks, processors and other vendors are encouraged to join as participating organizations.



About Translations.com



Translations.com is a leading provider of software, website, and enterprise-wide localization services, as well as localization-related technology products. Translations.com solutions allow customers to conduct business more effectively in international markets. The company has a global presence on four continents and services a variety of clients with dedicated practice groups for every major industry. Translations.com is part of the TransPerfect family of companies. For more information, please visit www.translations.com or www.transperfect.com.



SOURCE: Translations.com Translations.com

Jacquelyn Lane, +1 619.696.9000

mediainquiry@translations.com















Saturday, February 6, 2010

Full Text Of Cambridge Report On Verified by Visa and MasterCard SecureCode











Evan Schuman, Editor of StorefrontBacktalk.com, released the full text of the recent Cambridge Report that, in no uncertain terms, states that: Verified by Visa is a "Textbook Example of How NOT to Design an Authentication Protocol"



If you are unfamiliar with Evan's blog, take a moment to visit. I've provided a link (title of post) to StorefrontBacktalk below:



Full Text Of Cambridge Report On Verified by Visa and MasterCard SecureCode



Written by Evan Schuman, today, February 6th, 2010



Verifed by Visa and MasterCard SecureCode: or, How Not to Design Authentication

Steven J. Murdoch and Ross Anderson: Computer Laboratory, University of Cambridge, UK






Editor's Note:  Way back, In October 2008  I posted a story from The Register regarding the the lack of protection afforded Verified by Visa users. Is Verified by Visa also Verified by Hackers?  Here's what they had to say about VbV back then.  I dug it back up and am republishing a comment that stuck in my head at the time. 



Verified by Visa and Mastercard SecureCode are there purely to protect the banks, not the card holder. They offer zero additional protection to the consumer, but allow the bank to claim that transactions using purloined credit card credentials were really made by the card holder. It is as simple as that. 



The issue has been noted, and commented on in the blogosphere as far back as June 2008, but has received little attention in the mainstream media, despite the obvious security implications.




Editor's Note from October 2008: The more I learn about securing a transaction on the web, the more I realize how unsafe many transactions actually are. Here's an interesting article in the Register regarding Visa's supposedly more secure program designed to fool cardholders into thinking their transactions are more secure. They call it "Verified by Visa." Caveat:  First it has to verified by consumers, (by typing into a web browser) which means it can also be keystroke logged and  "Verified by Hackers." (VbH?)



"VbyV login credentials
make it easier for crooks to make purchases online while simultaneously making it harder for consumers to deny responsibility for a fraudulent transaction".


Since card information is can be bought online for as low as $2.50, "Stolen Card Info Plunges to $2.50 in Black Market" and obtaining a DOB is so easy a caveman could do it, it's looking like VbV is more of a marketing ploy than of any real value when it comes to protecting the security of an online transaction. What I found even more interesting was Visa's declination to comment about the story which the Register tells us at the end of this article:


VbyV password reset is childishly simple • The Register



Both VbyV and SecureCode are based on 3DSecure, a name that hints at the introduction of some kind of three-factor authentication scheme. But unlike robust authentication techniques, hackers don't have a hardware token generating one-time passwords to worry about - it's just more of the same.



And since card details + CVV number is no longer considered as secure enough then it's hard to see how card details + CVV number + VbyV login is any more robust.



Much was made of how easy it was for a hacker to reset Sarah Palin's webmail account password and gain illicit access to emails, but resetting passwords for Verified by Visa - which supposedly makes online transactions more secure is arguably even easier. To reset Palin's email account a hacker needed to know the Republican VP candidate's birth date, her zip code and the answer to a secret question on where she met her husband. Resetting a Verified by Visa password, by contrast, requires only card details (got $2.50?) and a date of birth.



Register commenter Anthony explains.



Verified by Visa (VbV) allows anyone who has the credit card number in their hands to set a new password for VbV with just the card details and the card owner's date of birth. Since the latter is trivial to discover for most people, this adds almost no additional security to the process.



Register reader Jusme reports the same issue. Verified by Visa is one of the reasons I no longer use Barclaycard. Pretty much every time I had to use it the password was not recognised and I had to "reset it", which just meant entering my DOB and a new password, hardly very secure.



Online shoppers who buy goods and service with participating retailers are asked to submit a VbyV or SecureCode password to authorise transactions. These additional checks are typically submitted via a website affiliated to a card-issuing bank but with no obvious connection to a user's bank. Punters aren't informed up front that a merchant has signed up to Verified by Visa. Sites used to authenticate a VbyV or SecureCode password routinely deliver a dialogue box using a pop-up window or inline frame, making it difficult to detect whether or not a site is genuine.  The appearance of phishing attacks hunting for Verified by Visa passwords are among the reasons some punters are wary of the technology. Once obtained by fraudsters, either by direct phishing attack or through other more subtle forms of social engineering trickery,





An anonymous commenter to our original stories agrees:

Verified by Visa and Mastercard SecureCode are there purely to protect the banks, not the card holder. They offer zero additional protection to the consumer, but allow the bank to claim that transactions using purloined credit card credentials were really made by the card holder. It is as simple as that.
The issue has been noted, and commented on in the blogosphere as far back as June, but has received little attention in the mainstream media, despite the obvious security implications.


Read more: http://pindebit.blogspot.com/2008/10/is-verified-by-visa-also-verified-by.html#ixzz0emaZgxJW









Websense Security Labs Report - State of Internet Security, Q3-Q4 2009

The second half of 2009 saw malware authors focus their efforts to ensure they drove victims straight to them. In contrast to the first half of the year where mass injection attacks like Gumblar, Beladen and Nine Ball promoted a sharp rise in the number of malicious Web sites, Websense Security Labs observed a slight (3.3 percent) decline in the growth of the number of Web sites compromised. Instead, attackers replaced their traditional scattergun approach with focused efforts on Web 2.0 properties with higher traffic and multiple pages.



Over the six month period, Search Engine Optimization (SEO) poisoning attacks featured heavily, and Websense Security Labs research identified that 13.7 percent of searches for trending news/buzz words lead to malware. In addition, attackers continued to capitalize on Web site reputation and exploiting user trust, with 71 percent of Web sites with malicious code revealed to be legitimate sites that had been compromised.



Web security intelligence remains a critical component of any email and data security strategy as illustrated by the continued popularity of blended threats (spam emails with embedded URLs). During the second half of 2009 Websense Security Labs discovered:
• 13.7 percent of searches for trending news/buzz words (as defined by Yahoo Buzz & Google Trends) lead to malware

• 95 percent of user-generated comments to blogs, chat rooms and message boards are spam or malicious

• 35 percent of malicious Web attacks included data-stealing code

• 58 percent of data-stealing attacks are conducted over the Web

• 85.8 percent of all emails were spam

• an average growth of 225 percent in malicious Web sites




These discoveries, along with details on other exploits and analysis of Web, email and data security trends during the second half of 2009 are explored in the Websense Security Labs “State of Internet Security” report.



The full report is available here.  (Registration Required)



An archived Webcast presentation about the report can be found here. Watch the video overview of the findings below,









Malware Infects One in 150 Legitimate Sites vs. One in 20,000 in 2006

Operation Swipe



Kapersky Lab's Blog, Threat Post reports that more and more (1/150 vs. 1/20,000) legitimate websites are becoming infected by Malware.



While one in every 150 doesn't sound like a "huge" number, that level of penetration still represents unprecedented levels.



"In 2006 the rate was about one infected site in every 20,000 otherwise clean sites. By 2009 that number had skyrocketed to one in every 150 sites" - Kapersky Labs



I would predict that those numbers would become worse, except for the fact that the latest trend shows that hackers are becoming more savvy and targeting "Big Phish."



After all, why bother targeting 150 small credit unions when the bad guys could focus on one big net/catch?  (a Top 10 bank)



Therefore, I would expect to see a shift in the bad guys behavior. Rather than taking a mass distribution approach, as they have, they will also put together well prepared and specifically targeted attacks at higher traffic sites. (for example search engines which lead to malware infected sites)



The motivation is clear - target a smaller number of websites that have more traffic and gain more in less time.



Speaking of "less time", that's how much we have before the web becomes SO dangerous, it's untenable.  For that reason, I'm not alone when I say that it is only a matter of (less)  time before there is a PCI certified PED in every home, just as there is one at every point of sale in the world.  (except the most dangerous place of all...the Internet)   To continue on the path we are on, is insanity. (doing the same thing over and over again and expecting a different result)



Simply put, we have but two choices.



1. We can continue with the insane "type" of behavior that allows the bad guys to "SWIPE" our credit and debit card details in order to use them to steal from us in the "card not present" web environment or



2. We can take protect our sensitive data and start "SWIPING" our own credit and debit card details in the privacy of our own home, thus preventing our cardholder data from entering the dangerous browser space. At the same time, we would eliminate "card not present" fraud by performing transactions in a securely encrypted "card present" environment. We would also eliminate the threat posed by phishing, by eliminating the practice of typing.



Finally, if malware is designed to look for online banking credentials as we "type" them into boxes at genuine or cloned online banking websites, what would the bad guys find if we stopped typing those same username and passwords and instead, started swiping our bank issued card and entering our bank issued PIN? (replicating the same trusted process used to withdraw cash at an ATM)



Suffice it to say that that the 73% of consumers who use their online banking credentials to log-in to non-banking websites would be taken right out of harm's way. 



While one in 150 websites represent a mere .0066 infection rate, consider that almost one in six, or 13.7 percent of searches for trending news/buzz words lead to malware and 71% of Web sites with malicious code are legitimate sites.



Websense, in their recently released "State of Internet (IN)Security, Q3-Q4 2009: Over the six month period, Search Engine Optimization (SEO) poisoning attacks featured heavily, and Websense Security Labs research identified that 13.7 percent of searches for trending news/buzz words lead to malware."Attackers continued to capitalize on Web site reputation and exploiting user trust:   " 71 percent of Web sites with malicious code were revealed to be legitimate sites that had been compromised. - Websense Security Labs Report - State of Internet Security, Q3-Q4 2009


It's obvious to me that it's time to stop typing and start swiping.  Here's an excerpt from Threat Post:



One in Every 150 Legitimate Sites Infected by Malware by Dennis Fisher



MOSCOW--The problem of attackers infecting legitimate Web sites with malware that then silently exploits vulnerabilities in users' browsers reached unprecedented levels in 2009, with 1 in every 150 legitimate sites serving up malware, experts say.



Analysts at Kaspersky Lab have been monitoring a pool of about 300,000 legitimate Web sites for the last several years, looking to see how many become infected with malware and how long the infections last. In 2006 the rate was about one infected site in every 20,000 otherwise clean sites. By 2009 that number had skyrocketed to one in every 150 sites, a massive increase driven by the continued success of mass SQL injections campaigns by malware such as Gumblar, Asprox and others.







Many of the infections also are using stolen FTP credentials to perpetuate a vicious cycle of user compromise, credential theft, site infection and malware storage. Once a user's machine is infected with a particular type of malware, the program searches the user's PC for FTP user names and passwords, which it then sends off to a remote server. The attacker behind these campaigns then use the FTP credentials to gain access to remote FTP servers, where they will store attack tools and exploit kits that later can be used for other infections.



It's a frighteningly efficient and simple infection method that shows little evidence of slowing down. As long as it's still effective, there's no reason for the attackers to move on to other more complicated tactics.



Continue Reading













Disqus for ePayment News