Tuesday, August 26, 2008

Keeping up with the Jones' (& the Discover vs. MasterCard/Visa Lawsuit)

Finds No Conspiracy Between Visa and MasterCard

Purchase, NY. - MasterCard Worldwide said  it is pleased that Judge Barbara S. Jones narrowed the scope of Discover’s antitrust case against MasterCard by granting certain aspects of MasterCard’s summary judgment motion.

In particular, Jones found that despite Discover’s assertions, there is no evidence of a conspiracy between MasterCard and Visa. She also dismissed Discover’s debit-related claims against MasterCard.

In dismissing Discover’s claims of an inter-association conspiracy between MasterCard and Visa, the court’s decision recognizes the intense competition between MasterCard and Visa, which benefits consumers in the form of innovative products and programs.

Further, Judge Jones limited the scope of the trial by dismissing Discover’s debit-related claims against MasterCard. In granting MasterCard’s motion, the Court recognized that Discover failed to establish that MasterCard’s Competitive Programs Policy (CPP) somehow excluded Discover from offering debit cards. This is not surprising since, the CPP only applied to credit and charge cards, not debit cards.

MasterCard said it is disappointed that the Court granted aspects of Discover’s summary judgment motion seeking to apply collateral estoppel in its claims against MasterCard, but pleased it rejected Discover’s attempt to obtain broader findings. Collateral estoppel is the application of certain findings in one lawsuit to a subsequent one. 

However, in no way does Judge Jones’ ruling change the fact that Discover will have to establish that MasterCard and Visa, rather than its own business decisions, caused the damages it alleges. The jury will be able to fully evaluate all evidence concerning Discover’s damages claims, and MasterCard looks forward to demonstrating the weaknesses of those claims in court.

For example, public results of Discover’s business performance after the CPP was withdrawn show that Discover has not seen any increase in its overall percentage of the credit card volume share from third-party issuance. This real world evidence highlights the weakness of Discover’s claim that the CPP damaged Discover by preventing Discover from entering into third-party issuing relationships. Indeed, the most recent results show that Discover’s overall credit card volume share—including both Discover-issued and bank-issued Discover cards—actually declined from 5.46% in 2006 to 5.33% in 2007.

A further demonstration of the weakness of Discover’s damages claim is the testimony of Discover’s own executives, who had testified before and during the DOJ case that the repeal of the CPP would hurt their company, and create a situation where Discover would not be able to build volume by attracting third-party issuers.

Visa responded to Judge Jones ruling as well with the following release:
 
"Visa is pleased that the court resolved several disputes in this case at this stage. Among other things, the court:
  • Dismissed Discover's claims of debit monopolization against Visa; and
  • Rejected Discover's allegations of an inter-association antitrust conspiracy between Visa and MasterCard.

"As a consequence of these summary judgment rulings, Discover cannot challenge the legality of the agreements Visa has signed with its debit issuance partners. As such, it is unlikely the Discover litigation will have a significant impact on Visa's ongoing business operations.

"In addition, the court granted collateral estoppel on a limited number of issues that were determined in an earlier, related lawsuit. This ruling, however, does not establish all the elements of Discover's claims. Discover must still prove the remaining elements of its case and any damages at the upcoming jury trial.

"Visa believes it will be clear to a jury that it is Discover's own business model and decisions - not the actions of competitors - that have limited its options in the marketplace. Discover has been free to engage in bank issuing partnerships since 2004, but has yet to demonstrate that it can do so in a meaningful way.

"Although we expect Discover will be unable to prove the level of damages that it seeks in this case, Visa remains committed to resolving legal challenges in a manner that allows us to remain focused on our business activities. To that end, as part of the Visa Inc. restructuring process, the company developed a retrospective responsibility plan that addresses potential liability in certain U.S. litigation ("covered litigation"), including the Discover case. Additional information regarding the company's retrospective responsibility plan is available in the company's Final Prospectus, dated March 18, 2008, at http://www.sec.gov/."

Monday, August 25, 2008

Online Travel Numbers Grow

This year US travel sales booked online will reach $105 billion, up 12% from 2007 according to http://www.emarketer.com/
According to the graphic, illustrated on left, it will continue to grow.

eMarketer forecasts that US online leisure and unmanaged business travel sales (including airline, hotel, rental car, vacation package, intercity rail and cruise) will reach $105 billion. Furthermore, from 2007 to 2012, sales will increase at an 11.6% average annual rate. Even though online travel sales are growing, fewer travelers are booking their trips online.

"The fact that fewer travelers are booking online is not due to economic concerns—online travel bookers are an affluent demographic—it is caused by frustrations related to the planning and booking capabilities of online travel agencies," says Jeff Grau, senior analyst at eMarketer and author of the new report, US Online Travel: Planning and Booking. "This, in turn, is spurring a renewed appreciation for the expertise and personalized services offered by traditional travel agents."

In other words, online travel sites are steering customers back to offline travel agents—a complete turnaround of what has been happening in the category for the last decade.

"Not so long ago industry observers cast traditional travel agents as has-beens," says Mr. Grau. "Perhaps this has helped them to focus on what they do best: provide travel expertise and personalized service." Customer dissatisfaction with online travel agencies (OTAs) stems specifically from unfriendly booking engines and navigation tools. With few points of differentiation, OTAs have a hard time building customer loyalty and have driven travelers right into the open arms of traditional travel agencies—and new online competitors.  "Mired in old technology, the OTAs have failed to keep pace with a newer and more innovative breed of travel Websites built around user-generated content," says Mr. Grau.   Online travel communities are emerging to carry the torch of innovation.

"In addition, a new breed of matchmaking travel sites is bringing traditional travel agency talent online," says Mr. Grau. "Sites like Zicasso and Tripology help travelers to exotic locales find travel agents tailored to their interests and needs."

World's Largest Hotel Chain Hacked - 8 Million at Risk

Eight million people at risk of ID fraud after credit card details are stolen by hotel chain hackers


Security breach: A Best Western Hotel in Amsterdam

Up to eight million people are at risk of ID fraud after a hacker breached the security system of the world's largest hotel chain.  An Indian hacker broke into the IT system of Best Western Hotel Group and stole personal details of everyone who has stayed there in the past 12 months.  The details, which included home addresses, phone numbers, place of employment and credit card details, were sold on through an underground network controlled by the Russian Mafia.

The information is thought to be worth up to £2.8billion. Experts say that if it falls into the wrong hands it could spark a 'major crimewave'.   'They've pulled off a masterstroke here,' said security expert Jacques Erasmus, an ex-hacker who now works for the computer security firm Prevx.

He added: 'There are plenty of hacked company databases for sale online but the sheer volume and quality of the information that's been stolen in the Best Western raid makes this particularly rare.  'The Russian gangs who specialise in this will have been exploiting the information from the moment it became available. In the wrong hands, there's enough data there to spark a major European crimewave.'  

Best Western became aware of the theft on Thursday night. It instantly disabled the log-in account from which the information was stolen, but not before the details of millions of people had been removed.   Tim Wade, head of marketing for Best Western in Britain, said it was 'unlikely' the thieves got details of every booking in Europe because of the way their system worked. He added: 'We are investigating further and working with our credit card partners to ensure the interests of our guests are protected.'  Last night a statement on the Best Western website said it did not believe British customers had been affected.

Fraud Takes A Toll on Bay Area

Fraud has taken it's toll on the Public Transportation Industry which has seen a flurry of actvity regarding recent hacks on their RFID based card programs. 

First there was the Oyster Card Hack in London,  followed by  the Massachusetts Bay Transportation Authority's "Charlie Card." which was hacked by 3 MIT students.  ("Sorry Charlie...You'/ve Been Hacked!") Now it appears that the RFID based FasTrak, I-Pass and E-Z Pass Tollway systems are easily hackable as well.   

Here's a story published in MIT's Technology Review:

Drivers using the automated FasTrak toll system on roads and bridges in California's Bay Area could be vulnerable to fraud, according to a computer security firm in Oakland, CA  Despite previous reassurances about the security of the system, Nate Lawson of Root Labs claims that the unique identity numbers used to identify the FasTrak wireless transponders carried in cars can be copied or overwritten with relative ease.

This means that fraudsters could clone transponders, says Lawson, by copying the ID of another driver onto their device. As a result, they could travel for free while others unwittingly foot the bill. "It's trivial to clone a device," Lawson says. "In fact, I have several clones with my own ID already."

Lawson says that this also raises the possibility of using the FasTrak system to create false alibis, by overwriting one's own ID onto another driver's device before committing a crime. The toll system's logs would appear to show the perpetrator driving at another location when the crime was being committed, he says.

So far, the security flaws have only been verified in the FasTrak system, but other toll systems, like E-Z Pass and I-Pass, need to be looked at too, argues Lawson. "Every modern system requires a public security review to be sure there aren't different but related problems," he says. Indeed, in recent weeks, researchers announced flaws in another wireless identification system: the Mifare Classic chip, which is used by commuters on transport systems in many cities, including Boston and London. However, last week, the Massachusetts Bay Transportation Authority (MBTA) filed a lawsuit to prevent students at MIT from presenting an analysis of Boston's subway system.

The Bay Area Metropolitan Transport Commission (MTC), which oversees the FasTrak toll system, maintains that it is secure but says it is looking into Lawson's claims. "MTC is in contact with vendors who manufacture FasTrak lane equipment and devices to identify potential risks and corrective actions," says MTC spokesman Randy Rentschler. "We are also improving system monitoring in order to detect potentially fraudulent activity."

In the past, authorities have insisted that the FasTrak system uses encryption to secure data and that no personal details are stored on the device--just two unique, randomly assigned ID numbers. One of these is used to register the device when a customer purchases it, while the other acts as a unique identifier to let radio receivers at tolls detect cars as they pass by.

But when Lawson opened up a transponder, he found that there was no security protecting these IDs. The device uses two antennas, one to detect a request signal from the toll reader and another to transmit its ID so that it can be read, he says.

By copying the IDs ­­­of the readers, it was possible to activate the transponder to transmit its ID. This trick doesn't have to be carried out on the highway, Lawson notes, but could be achieved by walking through a parking lot and discreetly interrogating transponders.

What's more, despite previous claims that the devices are read only, Lawson found that IDs are actually stored on rewritable flash memory. "FasTrak is probably not aware of this, which is why I tried to get in touch with them," he says. It is possible to send messages to the device to overwrite someone's ID, either wiping it or replacing it with another ID, says Lawson.

"Access to a tag number does not provide the ability to access any other information," says MTC's Rentschler. "We also believe that significant effort would need to be invested in cloning tags." He adds, "If any fraudulent toll activity is detected on a customer's account, the existing toll-enforcement system can be used to identify and track down the perpetrator."

Lawson says that using each stolen ID just once would make it difficult to track down a fraudster. A better solution, he believes, would be to require toll readers and transponders to carry out some form of secure authentication. But this would require changes by MTC. As an alternative, Lawson is working on a privacy kit to let drivers turn their transponders on and off so that they are only vulnerable for a brief period as they pass a toll.

There is another way, he says. "It's probably in the user's best interest to just leave it at home." This is because FasTrak uses license-plate recognition as a backup.

Ross Anderson, a professor of security engineering at Cambridge University, in the U.K., says that "very many embedded systems are totally open to tampering by anyone who can be bothered to spend some time studying them."  Competent use of encryption is the exception rather than the norm, Anderson adds, and the situation is unlikely to change soon. "One industry after another is embracing digital technology, and none of them realize that they need computer security expertise until it's too late and they get attacked," he says.

Bruce Schneier, chief security technology officer at BT, based in Mountain View, CA, says that it is too easy for companies to get away with lousy computer security. "Honestly, the best way is for the transportation companies to sue the manufacturers," he says. "Then they'll think twice about selling shoddy products in the future."

Sepa Clarifies Sepa Cards Framework with new Q&A

European Payment Council clears up Sepa for Cards confusion


The European Commission and the European Central Bank have welcomed a document published by the banking industry-backed European Payment Council that paves the way for a competitive single market for card payment card schemes by 2010.

The document, which takes the form of a Q&A, clarifies key aspects of compliance with the Sepa Cards Framework (SCF) for payment card schemes and banks, as well as the conditions for geographical coverage of card schemes within the Euro zone.

In particular, it rules that any national card scheme can be deemed to be compliant with the SCF if the cards it issues are technically and commercially capable of being accepted everywhere in the Sepa territory. Earlier interpretations of the Framework appeared to imply that a card scheme could only be deemed SCF-compliant if it covered all 31 Member states.

The ECB and Commission had expressed fears that such an interpretation would create a "de facto monopoly" for Mastercard's Maestro debit card system and had been encouraging banks to set up an alternative scheme in competition.

The ECB had become particularly concerned about moves by some banking associations to ditch domestic schemes in favour of internationally-accepted programmes by MasterCard and Visa.

The new guidance from the EPC clarifies the situation and makes it clear that the Sepa provisions for cards will allow many - possibly national and regional - schemes to develop into 'SCF compliant' schemes.  Nonetheless, the Commission warns that work is still needed by the EPC to develop a full set of technical standards allowing any card to be used, for payments in euro, potentially anywhere in the Sepa area.

"This is a precondition for the expansion of existing domestic debit card schemes across the Sepa countries, for the emergence of (a) new European card scheme(s), for pan-European processing and certification, and for market consolidation," says the Commission in a statement.

"More competition would be very welcome," the Commission continues. "The success of new initiatives will depend crucially on banks not simply selling the national debit card scheme to the existing schemes."

The European Payment Council's Q&A.

Gartner's Avivah Litan on PCI Version 1.2

In an article pubished in ComputerWorld last week, Avivah Litan, distinguished analyst at Gartner shared her thoughts on the summary of changes of PCI 1.2. 

Here they are:

The new version is a "definite improvement" on the existing PCI standard, said Avivah Litan, an analyst at Gartner Inc. But, she added, the PCI council appears to have missed a chance to introduce some other long-needed changes. 

According to Litan, one of the biggest issues with the PCI standard is that it makes very little distinction between networks belonging to large companies that process large volumes of card transactions and those belonging to businesses with much smaller transaction volumes. In large, complex network environments, it's often hard to say what exactly is covered by PCI and what isn't, she said. The standard, Litan claimed, allows for too much interpretation and leaves it entirely to PCI assessors to determine the scope of what needs to be protected.

Moreover, the standard is targeted primarily at e-commerce systems and isn't always clear on how the requirements should be applied in highly distributed brick-and-mortar environments, Litan said. For instance, many retailers continue to connect servers at each of their stores to systems in other locations but thus far, at least, the PCI standard has provided little guidance on that risky practice.

Litan said there also is considerable ambiguity surrounding the requirements for third-party service providers, such as call centers that might be processing cardholder data on behalf of retailers. "What are your obligations," she asked, "if you are taking in card numbers and phone numbers and entering them into systems that are not yours?"

Another key missing element is guidance on how end-to-end encryption of cardholder data would affect a company's compliance obligations, Litan said.

To Litan, the new version of the standard would have been an ideal opportunity for the PCI council to have incorporated language clarifying such issues. "The questions that come up every day are not addressed at all by this upgrade," she said. "This is just really more of tinkering around the edges."

Saturday, August 23, 2008

Partially Shredded Bank Checks Used as Packing Material?


Check This Out:         


I saw this on CNN this morning and thought it would make for an amusing post.  A Texas company uses a bank's processed checks for packing material.  Some of the checks are not even fully shredded and contain drivers license numbers, routing numbers, addresses and bank account numbers.  The video clip above, if nothing else is entertaining.  Here's an excerpt from the video story...

"I was just in shock. I couldn't believe they were using shredded up checks as packing material," said Michelle McBride.  So Michelle and her step daughter Amelia started piecing it all together and found out they were right.  WHH Ranch uses its local bank's shredded checks to cushion their jars. They're checks from hospitals, medicare, schools, businesses, personal accounts, even government agencies.  WHH Ranch Company owner Billie Hamzy says, "We've been doing it so long. We are all out of sorts about it because it's so out of place for something like this to happen."  Hamzy says in the roughly 20 years his company's used the bank's shredded paper, the McBrides are the first customers to notice.  "That he knows of. How does he know he doesn't have a particular customer who is doing this to get this information," Michelle said.

It's information the McBrides found is not too hard to unravel. Michelle says, it's "very easy. You look at the colors, then you get the routing numbers and the bank information."

"We didn't piece any of this together. We just taped it to hold it all together. None of this is torn through at all," Amelia said."You get the wrong people getting this information, they could have a hay day with one box, a hay day and a shopping trip. It's scary." Michelle said.

Friday, August 22, 2008

Video - First Data Announces New Payment Technology "Go Tag"


New Contactless Payment Technology Showcased at Democratic National Convention
First Data Gives Attendees a Glimpse into the Future of Paying "On the Go"


DENVER, August 22, 2008 /PRNewswire/ — During this year's Democratic National Convention (DNC), Denver's Pepsi Center will serve not only as a focal point of American politics, but also as an arena for the future of how people will pay for goods and services.

Next week, First Data will introduce a new payment technology to thousands of select media and delegates attending the DNC. Beginning August 25 through August 28, media and delegates receiving a limited edition pin from First Data can use the commemorative pin as a payment device to purchase refreshments up to $10 in value at participating Pepsi Center concession stands.

The First Data® GO-Tag™ Solution behind the limited edition pin utilizes contactless payment technology that is easy to use and makes the shopping experience quick and convenient. Its flexibility allows for many different forms such as stickers, attachable to personal items like mobile phones or employee badges, wristbands and novelty key chains. This new technology provided by First Data eliminates the need to carry cash, credit or debit cards.

"First Data, as a leader in electronic and mobile payments, gives you a glimpse into the future where cash is not needed and purchases can be made simply by the tap of your mobile device," said Michael Capellas, chairman and chief executive officer of First Data. "Consumers will be able to make purchases faster and easier—no more waiting in long lines—and better yet they can leave their wallets at home."
Consumers will experience the technology first as a contactless sticker, like the GO-Tag Solution, and then directly inside their mobile phones. Merchants will benefit from the ability to offer more value through faster speed of service and increased customer loyalty.

"Contactless is a key mobile commerce technology especially well suited for fast payment applications at quick service restaurants, theme parks, event concessions and even vending machines," said George Peabody, director of emerging technologies, Mercator Advisory Group. "As contactless continues to gain traction, the GO-Tag Solution helps both merchants and consumers become familiar with the benefits of this technology."

First Data is distributing a limited number of commemorative pins while supplies last. Credentialed media attending the Democratic National Convention may pick up a pin on August 25 and 26 between 9:00 a.m. and 8:00 p.m. at the First Data-hosted media lounge located in Pavilion 5 outside the Pepsi Center.

For questions about obtaining a limited edition pin or for images and b-roll please contact:

First Data Media Relations
303-967-6323
mediarelations@firstdata.com

For more information about First Data, please visit www.firstdata.com/dnc.

About First Data
|
First Data is a global technology leader in information commerce. The company processes transaction data of all kinds, harnesses the power of that data and delivers innovations in secure infrastructure, intelligence and insight for its customers. With operations in 37 countries, First Data serves more than 5.4 million merchant locations and more than 2,000 card issuers and their customers. It powers the global economy by making it easy, fast and secure for people and businesses around the world to buy goods and services using virtually any form of payment. The company's portfolio of services and solutions includes merchant transaction processing services; credit, debit, private-label, gift, payroll and other prepaid card offerings; fraud protection and authentication solutions; electronic check acceptance services through TeleCheck; as well as Internet commerce and mobile payment solutions.

The company's STAR Network offers PIN-secured debit acceptance at 2.1 million ATM and retail locations. Through First Data's centers of excellence, such as security, analytics, customer loyalty and mobile payments, it offers data-driven commerce solutions for customers around the globe. For more information, visit www.firstdata.com.

Credit Card Useless Overseas? PIN it with HomeATM

The headline might be a bit dramatic, but it's true that more and more merchants in Europe and elsewhere will not accept credit cards without the "Chip and PIN" system — The term is "chip and PIN" (or EMV, for Europay, Mastercard and Visa). Most European banks and merchants are switching to it. Canada's switching too. By 2010, you'll have trouble using a standard American credit card at many Canadian merchants.

Banking officials say the chip-and-PIN method has reduced credit-card fraud substantially in Europe, where the problem grew exponentially when former Soviet bloc countries joined the European Union.  Sure...blame it on the bloc heads.

Chip and PIN has an embedded chip in the card along with a PIN number (similar to that you are probably accustomed to with your ATM card).  What's that you're thinking?  You don't have a PIN associated with your credit card right?  That is correct, and, unfortunately, as this L.A. Times article reports, it's not an easy problem to fix:

If you don't have a credit card with an embedded ID chip and accompanying PIN, you may be limited in the number of transactions you can make.  Here's the catch: Americans cannot get such a card through U.S. card issuers.


So what do you do? Well, one way to be sure you always can get by is if your bank offers a combination ATM / debit card with the Visa or MasterCard logo. That has a PIN, so you're OK. But of course this means the money will come straight out of your checking account, so you'd better have enough in there to cover your purchases.

Of course, that's not really credit, it's plain ole PIN Debit.  What about acquiring a chip-and-PIN "credit" card?  Neither American Express nor HSBC, despite their global scope, offers such a product for U.S. customers.  So I guess credit cards really ARE useless overseas.

But hold on...there is another alternative that the Times article does not address!


HomeATM ePayment Solutions has come up with a way to solve this problem.  We call it PIN my Card.  It allows consumers to create a PIN for their "credit card" and was initially designed to increase the security of an online "credit transaction" and reduce the cost for internet retailers to accept online credit card transactions.  (The transformation redefines the "card not present, or CNP transaction as a "card present" one, which makes the transactions more secure thus lowering interchange fees for online retailers).  It also appears that PIN my Card would solve the dillemma of Americans traveling abroad with their credit cards.  Just attach a PIN and you're good to go!

HomeATM is currently awaiting approval and issuance of global patents regarding "attaching a PIN to a credit card."  I'll provide more on this process as it develops, or you can search this blog using the keywords "PIN my Card" to find out more right now.

For now, it's certainly not impossible to get by with your American credit card, but it's becoming more work to do so, so take this into consideration if you're hitting Europe any time soon. (or going to Canada in the near future)  Why chip and PIN in the first place?  If your credit card requires a PIN, the reasoning goes, it's useless to a thief.   So...for American's that means no stays at a fabulous luxury suite or a night on the town or a pair of Gucci shoes, courtesy of your "credit" card  unless you "PIN your Card"!  Stay tuned.

Don't Leave Home With It? Card Fraud Fearing Brits Carry Cash

Britons going abroad this summer are warned levels of card fraud overseas has shot up by 77 per cent between 2006 and 2007. Fraud on credit and debit cards cost Brits £207.6 million last year, insurer CPP found, with France, Italy and Spain the top spots for card crime

Four in five of Brits are worried about possible fraud if they use their cards overseas with many (60 per cent) choosing to carry cash instead.

Card cloning tops the list of fraud worries (46 per cent) followed by card not present fraud (42 per cent) among a sample of 1,700 Brits quizzed on behalf of marketing and travel assistance services firm CPP earlier this month. The survey follows recent figures from banking ssociation APACS that show fraud abroad accounts for 39 per cent of theft and fraud on UK-issued cards. International fraud losses rose from £117.1m in 2006 to the £207.6m level in 2007, a big rise that helped push overall losses up to £535.2m.

In the period from June 2007 to June this year, no less than 7000 cards were reported stolen from Brits abroad, according to the research.    Kerry D’Souza, card fraud expert from CPP, said: "We are urging Brits to be particularly vigilant when they travel abroad this summer.  When relaxing on holiday, people can be less aware of their belongings and more prone to card fraud and mugging scams. We are encouraging people to contact their banks before travelling, to keep their valuables out of sight once abroad, and to be especially careful when they use their credit and debit cards."

According to card and payments association Apacs, paying with plastic is very popular abroad – in 2007, card purchases accounted for 50 per cent of all overseas spending.  However, Apacs highlights the fact the introduction of Chip and Pin technology in France and Spain have cut card fraud.  Sandra Quinn, director of communications at APACS, added: "As a nation we are all using our cards more frequently abroad so it pays to be aware of any extra costs that may be incurred for using them overseas, as well as taking steps to protect them from fraud. "Card thieves are hoping to catch us relaxed and off-guard when we are overseas, so we need to take the same sensible precautions with our cards abroad as we would in the UK."

However, the majority of card fraud occurs when card details are stolen in the UK, and used fraudulently abroad.  Fraudsters copy the magnetic stripe details, typically by skimming cards, then create fake magnetic stripe cards that they use overseas in countries that do not have chip and PIN.  CPP advises travellers taking their cards to keep them in a safe if they are in your hotel room and keep your eye on them when you are out and about. The firm also recommends telling your bank if you are away – some will stop your account if they see 'suspicious activity', which may include overseas transactions.

HomeATM Partner Procures Canadian Financial Provider

SAN ANTONIO, TEXAS, Aug 22, 2008 (MARKET WIRE via COMTEX) -- As Stated by SmartCard Marketing Systems Inc. (PINKSHEETS: SMKG) "Management is pleased to announce that we have signed an agreement to provide 4000 Pin debit and Prepaid cards to a Canadian Financial service provider in Canada with online and retail services, this is additional from the 9000 with Kiyss.com.


The agreement includes the use of the Velocitymoney.com loading network, HomeATM's Pin Debit solution and instant issue prepaid cards for money remittance services.

The agreement established is over a period of 2 years to fulfill delivery giving access to their members, which will double our existing number of accounts and make the Velocitymoney.com a service leader in the online payment segment. The price established per customer implemented is $27.50 for a total of $101,000.00 dollars with an estimated number of 8 transactions per month of $150.00 to $240.00 range. This does not include email money transfers, card to card transfers or multi-currency settlement between clients once funds in transit.
Velocitymoney.com continues its strong growth through 2008 and believes strongly that 2009 will see more aggressive growth as more merchants and financial institutions continue to realize the benefits of our services online worldwide.

Thursday, August 21, 2008

BBC: So How Secure Is Our Card Info?

In light of the biggest identity theft case ever prosecuted in America, the spotlight is being turned on just how secure is our credit and debit card information? The question is a simple one but the answer might appear to be a bit harder to pin down.

VeriSign, a firm that secures websites for e-commerce, told the BBC that credit and debit card information is "vulnerable" but they are working with retailers to change that.

"Credit and debit card information is just not incredibly secure," said Perry Tancredi, VeriSign's senior product manager for fraud detection. "But it is counterbalanced by the amount of fraud losses due to cheque fraud and direct debit fraud which is much greater than credit card fraud."

Mr Tancredi said: "Regardless of how strong the security measures, and how vigilant, the weak part of the chain is there is always a human who is responsible and who has overall control over the information." He suggested the best bet was for all consumers to "assume that there will be some sort of fraud on your account sooner or later" and put in place a plan to deal with it.

Getting safer

Espousing a completely different view is Jerry Tabeling who is the president of IDP, a company that carries out vulnerability assessments of networks and online business applications. "Our information is a lot more secure after all the publicity we have had about attacks," he said. But yes there are still problems that still exist though it is getting safer." These, Mr Tabeling told the BBC, tend to centre around a retailer not doing a good enough job securing its network.

"If the proper encryption is configured on the wireless access point, then an attacker will not be able to get any information. I would have to bet in this case that didn't happen."

At stake for victims of fraud is more than just money The authorities said the details of the 40 million credit and debit card holders was obtained by the hackers "wardriving" past stores to find wireless networks they could hack into. This entailed driving around using a hand-held device to detect a wireless signal much in the same way a radio scanner hunts for a signal.

The US justice department said the hackers then loaded "sniffer" software onto the retailers' networks which captured numbers as well as passwords and account information as it moved through the retailers credit and debit processing networks. That information was then sent to servers that the group controlled in Eastern Europe and the United States.

The justice department said the stolen numbers were "cashed out" by encoding card numbers on the magnetic strips of blank cards and then used to withdraw tens of thousands of dollars from ATMs.

Identity loss

The Justice Department is not putting a figure on just how much the fraud has cost, but Mr Tancredi said the money is not the point with most card liability ranging around $50 (£25).

MasterCard says it strives to safeguard account information "If you are a victim of credit card fraud you might get your identity stolen and then you lose more than just money. You lose time, you lose trust and it could take years to fix your credit." MasterCard said preventing fraud and safeguarding financial information is a top priority for the company. Spokesman Chris Monteiro told the BBC: "If a cardholder is concerned at all about the security of their account they should immediately contact their issuing financial institution."

The Payment Card Industry, or PCI, has developed standards for retailers to adopt when handling credit and debit payments. A spokesperson said while it is trying to get merchants to adopt these standards "it is not our job to go around checking who is compliant with this. That is lead by the credit card brands."

Meanwhile Mr Tabeling, an IT security specialist, suggested that all consumers need to play a more proactive part in policing their own transactions and their credit information. "We have no choice but to trust the retailers are doing their bit but we can do more. "We can keep track of our credit report once or twice a year, check our statements and set up a notification so that if there is any suspicious activity on our account we are told about it right away."

Related Stories on the BBC:
Concern over rising fraud cases 28 Jul 08 Scotland
Hi-tech criminals target Twitter 05 Aug 08 Technology
Oyster card hack to be published 21 Jul 08 Technology
Phishing attacks soar in the UK 15 Apr 08 Technology


Related Links: VeriSign PCI IDP MasterCard

U.S. Consumers Lost Nearly $8.5 Billion to Viruses, Spyware, and Phishing

U.S. consumers lost almost $8.5 billion over the last two years to viruses, spyware, and phishing schemes according to latest projections from the Consumer Reports State of the Net survey.

Additionally, report estimates that American consumers have replaced about 2.1 million computers over the past two years because of online threats. Survey has also reveals some hopeful signs such as declining chances of becoming a cybervictim—consumers have 1 in 6 chance of becoming a cybervictim, down from 1 in 4 in 2007.

Other findings include:
  • Spam: One in three survey respondents reported heavy levels of spam. One of the newest types, cell-phone spam, is a minor nuisance to most online homes. 1.2 million people nationwide are estimated to have received more than 25 such messages each during a recent six-month period.
     
  • Viruses: The rate of serious virus problems has declined 32% over the years however 19% of respondents reported that they didn't have antivirus software on their computer.

  • Spyware: One in 14 respondents reported a serious computer problem as a result of spyware, compared to 1 in 6 respondents in 2005. In the past six months, 566,000 households replaced computers due to spyware infections.

  • Phishing: Over the past two years, about 6.5 million consumers, or roughly 1 in 13 online households, gave phishing scammers personal information. 14% of them lost money. Consumer Reports estimates that American consumers lost about $2 billion to phishing scams.
Related: 

7 Online Blunders - These common mistakes can ruin your computer or invite identity theft

Will Banks Contribute to Innovation(s) in Retail Payments?

Aneace Haddad, founder and chairman of Welcome (Real Time), and an industry associate of mine, has recently published a seminar presentation with full audio, entitled “How will banks meet the challenges of innovations in retail payments"? 

He chaired a conference in Hong Kong (Financial Cards & Payments Asia) and gave the keynote address, which you can view below.

Along with the HomeATM PIN Debit blog, "Aneaces Blog" among others, is recommended by Glenbrook's Payments News.  So take a look when you have some extra time.  You can visit Aneaces Blog by clicking the link.


Haddad July 2008
View SlideShare presentation or Upload your own.

Wednesday, August 20, 2008

PIN Debit White Paper on Improving Merchant Profitability

A white paper educating merchants on the benefits of migrating their electronic payments from credit and signature debit, to PIN Debit has been released by Optimized Payments Consulting.

Of course, it goes without saying, that I couldn't agree more.  In addition to reducing your card processing fees by 73%, Internet Retailers also virtually eliminate chargebacks and reduce risk related expenses signficantly.  Given that majority of consumers have at least one debit card with PIN functionality, e-commerce merchants would be best served to recognize this fact and take advantage  of the myriad benefits provided by HomeATM's Internet PIN Debit solution – lower acceptance costs, greater security, faster funding, and typically faster checkout.

Moreover, merchants see reduced fraud and chargebacks with PIN debit transactions. Since only the card holder knows the PIN, it is less likely to be stolen and used fraudulently like credit and signature debit cards. And PIN‐based debits are not subject to the same chargeback rules as their counterparts, although some of this is changing in the industry.

So if you are or know of an internet retailer who would like to investigate our PIN Debit solution further, visit HomeATM or give us a call or email me to request further information and I'll make sure you get it.   As always, click any of the graphics to enlarge.  Here's the press release from Optimized Payments Consulting which was released today:

Atlanta, Ga. (PRWEB) August 20, 2008 -- In today's plastic society, electronic payment processing is a must for businesses to operate and to be competitive.  Unfortunately, the high fees associated with credit card processing and merchant accounts are setting recession-hit firms back even further. To help companies meet this challenge, the payment processing experts at Optimized Payments Consulting (OPS) are sharing their expertise - gained over ten years working with retail, Internet, and healthcare clients - in a new white paper titled "How Accepting ATM Cards Can Improve Merchant Profitability."


The chart on the left  highlights the cost differential between the three dominant payment methods depending on average ticket size. A merchant’s actual cost of processing a PIN transaction will depend on the specific ATM network (Interlink, Star, Pulse, NYCE, etc.) used to process the sale and the mark‐up added by the payment processor. Using a weighted average cost based on market share of the ATM debit networks in the U.S., a $50 sales transaction will cost about 54 cents with PIN‐debit, versus 73 cents for signature debit, and 93 cents for credit.  From a merchant’s perspective, accepting PIN debit becomes more attractive as the average ticket grows, but this product is not competitive if the average ticket is below $25.

As the table shows, the fixed per‐item and switch fees do not make PIN transactions cost effective for smaller ticket transactions. However, on the flipside.. for average tickets above $25, a merchant can save 25%‐61% over signature debit, and 39%‐73% over credit transactions.

R
ecognizing that over 90 percent of merchants were unknowingly overpaying for credit card processing services, Goel established Optimized Payments Consulting to help merchants understand and reduce their payment processing costs.  In the most recent in a series of white papers on the topic, OPS experts provide in-depth background and analysis on how merchants can accept and promote ATM cards and drive profitability.

"Businesses can save 25% to 73% percent on their processing costs for every transaction they migrate from signature debit and credit to PIN debit respectively".



By 2010, Morgan Stanley estimates that credit card processing rates will "rise to 1.86 percent and generate $32.4-billion in interchange fees." Those skyrocketing interchange rates, along with processing fees, are squeezing businesses as credit card processing fees eat away at their already shrinking bottom lines. Fortunately for these businesses, there are lower cost alternative payment options.

According to Digital Transactions, an industry publication, the use of PIN-based debit cards in the U.S. has been rising faster than signature debit cards and credit cards.

Merchant sales volume for PIN transactions has been growing 21 percent annually since 2000, slightly ahead of signature debit and "significantly ahead of credit cards." And according to a recent study by Star electronic funds transfer (EFT) network, "consumers preferred PIN debit over signature debit", with 54 percent opting for PIN and 38 percent for signature.

This trend spells good news for businesses that know how to leverage it.  To find out how to leverage it click here to email me.

How to hack RFID-enabled Credit Cards for $8 Bucks

Having learned a lot over the course of the last two or three weeks about "WarDriving" (and warcarting) it occurred to me that if it's that easy to access wireless networks, then why the heck would Visa and Mastercard come out with a Radio Frequency ID (RFID) card.  Even with my newly ascertained, albeit, limited knowledge on the subject, I thought:  "certainly they would be easier to breach than plain old magnetic stripe cards right"? 

Right...but what surprised me is that it can be done for only $8, which is less than the cost of a movie ticket.  Speaking of movies...here's one on how to do it.

Sorry Charlie...Boston Transit Authority Gag Order Lifted

A federal judge has lifted a gag order on three MIT students who were barred from talking publicly about security flaws they discovered in the Boston transit system's automated fare network.

So here's the Presentation!

A lawyer for the transit agency acknowledged its CharlieTicket system has security flaws. But the lawyer asked Judge George O'Toole Jr. to impose a five- month injunction continuing to block the students from revealing anything publicly about the security system. O'Toole rejected the request Tuesday.

The students had been blocked from presenting their findings on the security flaws in early August at DefCon, an annual computer hackers' conference.

"Judge O'Toole said he disagreed with the basic premise of the MBTA's argument: That the students' presentation was a likely violation of the Computer Fraud and Abuse Act, a 1986 federal law meant to protect computers from malicious attacks such as worms and viruses. Many had expected Tuesday's hearing to hinge on First Amendment issues and what amounts to responsible disclosure on the part of computer security researchers. Instead, O'Toole based his ruling on the narrow grounds of what constitutes a violation of the CFAA. On that basis, he said MBTA lawyers failed to convince him on two points: The students' presentation was meant to be delivered to people, and was not a computer-to-computer 'transmission.' Second, the MBTA couldn't prove the students had caused at least $5,000 damage to the transit system."
O'Toole did not rule on the students' claim that the MBTA had violated their First Amendment rights by stopping them from speaking at the hackers' convention.

This from the Boston Globe:
Cindy Cohn, a lawyer for the students, said the students had complied with the MBTA's request to turn over slides from their presentation and a 30-page "security analysis" that outlines everything they discovered about weaknesses in the fare system.

"The MBTA ultimately is trying to silence some uncomfortable truths that these students uncovered," said Cohn, legal director for the Electronic Frontier Foundation, a San Francisco-based legal organization that specializes in civil liberties issues related to technology.

"They brought an action against three college kids rather than address the problems in their own house," Cohn said.  Cohn said the students never intended to reveal key details that would have given hackers information to help them hack into the fare collection system and ride the system for free, despite what the online ad for the demonstration said.

But Ieuan Mahony, an attorney for the MBTA, said the MBTA simply wanted the students to refrain from revealing details about the security problems publicly until the MBTA has time to correct the flaws, which could take five months.  Mahony said that after reading the security analysis submitted by the students last week, the MBTA "has determined that the CharlieTicket system is compromised." 

"We've known that there are some issues with the CharlieTicket, but we realized after reading this paper that they were able to clone and counterfeit the CharlieTicket," Mahony said after the hearing.  Mahony said the MBTA still wants to get additional information from the students on how they were able to clone the CharlieTicket.

Some details about the vulnerabilities of automated fare system were released before the students' planned talk at the DefCon conference. Electronic copies of their 87-slide presentation were included on CDs handed out to conference attendees before the conference officially began and before the MBTA filed its lawsuit.  - Boston Globe

Card Skimming Perps Show Patience if not Virtue


Patient thieves make off with thousands from stolen card data

Jeez...it seems like there's about four or five of these stories per day now. I guess I was spot on with my prediction to look for more of these gas station skimmer stories in the near future. One has to wonder what the long term effect on consumers trust of Point of Sale devices may be as they become more aware of how simple it is to fall victim to this type of fraud.

Maybe HomeATM can look into creating a system whereby consumers (knowing that their own personal card swiping device is safer than the ones at gas stations) can "prepay for gas at home" using their HomeATM wedgie,  get a gas disbursement code, and then go to the gas station, enter the code and dispense their gas.  Anyway, here's yet another story on card skimming at gas stations.  This time, the perpetrators waited a full year before empyting the bank accounts of their victims.  I guess patience is not always virtuous.

Last summer, thieves skimmed debit card information from a South Hill gas station. Then, nearly a year later, they withdrew tens of thousands of dollars from Pierce County residents’ bank accounts, Pierce County Sheriff’s officials said.

By waiting, the thieves can be pretty sure surveillance videos showing them will have been erased. And by making their ATM withdraws over a holiday weekend, it created an extra day for banks to realize something was amiss, said Pierce County Sheriff’s spokesman Ed Troyer said.

Detectives have identified about 75 victims, including cases reported to Tacoma police, and expect many more may be out there, he said. Some victims lost several hundred dollars, others lost thousands.

“Someone might have only had $500 in their account, but the bank lets them take out $3,000 because of overdraft protection,” Troyer said.

By comparing the bank statements of the victims, investigators believe the cards were skimmed from the ARCO station at 11608 Meridian East last August.

“We don’t know if they have more cards and are planning to do another round,” Troyer said. Anyone who used a debit card at the station in August 2007 should get their card replaced, he said.

The thieves used an electronic device that records the customers’ card numbers and pin information, he said. People should be on the look out for card readers that don’t look right or keypads that have been placed over the existing one, Troyer said.

While these types of scams are sophisticated, the electronic components are relatively easy to come by. The next generation of electronic theft, which taps into Bluetooth and wireless technology, is even scarier, Troyer said.

Tuesday, August 19, 2008

More on the "WarDriving 11" and their 40 Million Card Data Theft

A loose-knit ring of hackers stole credit card data from unsuspecting US retailers. Though 11 people have been indicted, experts say the case shows how sophisticated identity-theft schemes have become.

Five years ago, Albert Gonzalez allegedly used an unsecured radio link to tap into the computers of a BJ's Wholesale Club store in Miami and access customer credit-card numbers.

It was a simple trick, but it was only the beginning.

From that first break-in, Gonzalez and a ring of accomplices flew up the learning curve, prosecutors charge. They wirelessly broke into the computer networks of other stores including those operated by OfficeMax Inc., Boston Market Corp., Barnes & Noble Inc., and TJX Cos. And they apparently learned to decrypt customer PIN numbers, install sophisticated software, and park payment card data in offshore databases, in what the Justice Department on Aug. 5 called the biggest hacking and identity-theft case it has ever prosecuted - compromising more than 40 million credit and debit card accounts.

Court filings and interviews with investigators paint a picture of an international ring of 11 loosely knit conspirators from China to Ukraine, and show how quickly such criminal groups can graduate to increasingly sophisticated schemes to exploit the vulnerabilities that remain in the payment card network.

Despite the arrests, Gartner Inc. technology analyst Avivah Litan said it's too soon to relax. Though prosecutors tied the ring to some of the biggest breaches in this decade, their cases don't mention other intrusions such as one of Maine grocer Hannaford Bros. earlier this year.

Also worrisome, Litan said, was that the group allegedly was able to use fake ATM cards with real account numbers to withdraw money from bank machines, indicating they cracked the encryption of PIN numbers.

"The implications are ominous," Litan said. While many banks and retailers have begun using tougher encryption since then, some companies are still on the older standards that she called "inherently vulnerable."

Another technology analyst, Mary Monahan of Javelin Strategy & Research, said more stores have met data-security standards spelled out by Visa and MasterCard since the time of breaches like the one at TJX in 2005, which should make customers' card numbers more secure. Still, Hannaford met those standards at the time of its breach, illustrating how criminal tactics have evolved to stay ahead of defensive measures.

One lesson from this months' indictments, Monahan said, is how the hackers learned to become more sophisticated and global. "You can see that they're developing their skills over time, and transferring skills among one another," she said.

A defense attorney for Gonzalez, Rene Palomino, said his client will plead not guilty to the charges. He described Gonzalez, 27, as a self-taught computer consultant who first met several of the other defendants online.

Former informant

Ironically, the story of how the group of accomplices came to be begins with Gonzalez helping law enforcement officials. Though arrested in connection with theft from an automated teller machine in 2003, Gonzalez soon became a key Secret Service informant and even gave the agency security lectures, Palomino said. Gonzalez was best known for helping officials bring charges against a group known as the "Shadowcrew" after one of the online message boards that served as a marketplace for stolen payment card numbers - 1.7 million of them in all, prosecutors would charge.

Despite serving as an informant, the Justice Department claims, Gonzalez also began "wardriving" in the areas around US Highway 1 in Miami, according to this month's indictments. The term refers to the tactic of cruising in a vehicle with a laptop computer to spot unsecured connections to wireless systems maintained by various stores.

Gonzalez' partner in the wireless probes allegedly was another twentysomething, Christopher Scott, who Palomino said Gonzalez had met in online circles in Miami. Scott's attorney said he hasn't yet entered a plea.

According to the indictments, the pair first got lucky in 2003 at a BJ's Wholesale Club store, which wasn't using encryption software to protect customers' data, and accessed the account numbers of payment cards used by customers.

The next year Scott and another accomplice, described only by the acronym "J.J.," went further. Tapping into a similar access point at an OfficeMax store near the highway, they located data including customers' encrypted PIN numbers punched in when they used debit cards. They turned the data over to Gonzalez, who allegedly sent it to an unnamed coconspirator for decryption.

Filings and investigators say other stores hit by the ring included Barnes & Noble and Sports Authority, many in the Miami area. The indictments suggest the biggest breach began in July 2005 when Scott compromised two wireless access points of Marshalls' stores in the Miami area, both operated by Framingham retailer TJX Cos.

Soon the group was downloading payment card data from TJX's home servers. By the following May, in 2006, Scott had graduated to setting up a "virtual private network" connection to a TJX server, making it harder to detect the intrusion.

Next, Gonzalez brought in a Ukrainian, Maksym Yastremskiy, who prosecutors describe as an international trafficker of stolen card data who sold it on the Web. Via instant message in May 2006, Gonzalez allegedly asked Yastremskiy for help finding an undetectable "sniffer" program that would pick up customer card numbers and provide a feed of stolen data. Several days later, Scott, Gonzalez, and others installed sniffer programs onto a TJX server - likely provided by Yastremskiy, the indictment implies.

Craig Magaw, special agent in charge of the Secret Service's criminal investigative division, which led the probe of the hacker ring, said he had no evidence that Gonzalez and Yastremskiy ever met or spoke outside of their electronic communications. But their virtual connections, he said in an interview, were a common trait to criminal rings using web-based message boards.

"It's the usual M.O., where they can go to be anonymous and help each other further their activity," he said. "It's not just that they're selling the information but, if you go on these [message] boards, it's how to do compromises and giving advice. It's the criminals' playground."

Authorities arrested Yastremskiy in Turkey a year ago while he was visiting a resort. The US Postal Inspection Service confirmed to the Globe at the time that he was tied to the TJX probe. Since then, neither the Justice Department nor Turkish officials have provided contact information for Yastremskiy or an attorney representing him.

Yastremskiy's laptop provided a trove of details including an e-mail tie to Gonzalez, Magaw said. Gonzalez was arrested May 7 at a hotel room in Miami in connection with a related hacking case to which he has also denied wrongdoing. Court papers show officials seized from him three laptop computers, and a Glock 27 automatic pistol.

Encoding blank cards

In addition to showing how the group allegedly stole information, the indictments also shed light on how the ring may have used the data on the streets.

In 2005 and 2006, Gonzalez allegedly sold large amounts of payment card data to a person named only by the initials "J.W." This person allegedly encoded the information on the magnetic stripes of blank plastic payment cards, then used the cards to withdraw hundreds of thousands of dollars from ATMs and split the money with Gonzalez. Another unnamed San Diego purchaser also bought 100 blank payment cards from an individual in China connected to Yastremskiy in 2005, prosecutors charge.

Both examples recall cases in Florida last year in which state prosecutors won guilty pleas from six people who misused card numbers stolen from TJX. After obtaining blank cards magnetically encoded with the stolen numbers, they took the plastic to various Wal-Mart stores in Florida to buy gift cards that could be used like cash. In turn they used those cards to buy $8 million worth of expensive electronics, jewelry, and other items, officials said, returning some items for cash.

Details of how to encode blank cards with stolen account numbers are among the topics typically discussed on underground websites, security experts say; the Secret Service estimates there are 20 message boards or websites in the United States and overseas where criminals sell stolen numbers, trade tips, and form bonds like those between Gonzalez and Yastremskiy. Was theirs like an underground university? "I guess, but there's no diplomas coming out of there," Magaw said.

Or, as Massachusetts US Attorney Michael Sullivan put at a press conference announcing the indictments on Aug. 5: "There's no evidence that any of these people had PhDs."

Globe staff reporter Marion Schmidt contributed to this report. Ross Kerber can be reached at kerber@globe.com.

Disqus for ePayment News