Saturday, December 27, 2008

Max Vision/Blind Justice

Click here to read what I consider to be a fantastic story "on Wired (One Hacker's Audacious Plan to Rule the Black Market in Stolen Credit Cards) about one Max Butler, better known amongst security researchers as "Max Vision" who's about to (yet again) see what happens when subjected to "blind justice." At the end of the day, you can steal all the credit card information you want, but if you don't know the PIN code, you wouldn't be able to use them...except online, where PIN debit is frightening absent. HomeATM aims to correct this faux pas with "it's vision" of bringing PIN based transactions to the web...

Apparently Max isn't quite the visionary he thought he was...because most everyone else would've seen this coming from a million miles away.

Speaking of seeing something coming from a million miles away...let me take a crack at being a visionary...

The way I see it Max is positioned to become the next Frank Abagnale Jr. Unlike Frank Abagnale, Max Vision was a renowned security consultant first, but got played by the FBI (see Max Vision...FBI Pawn?) and, in what I'm guessing was an act of rebellion, evolved into "Evil Max" after his release from jail.

His "storied" hacking past (dating back to May 1998 when he penetrated a series of Defense Department computers) makes for a novel book idea and even merits some big screen potential. The stars are aligned...2009 is predicted to be the "Year of the Hacker" so I suspect he'll get some maximum exposure, being one of the original super hackers.

Ironically another "Max", former PayPal founder, Max Levchin rubs elbows in Hollywood, (he was Executive Producer for Thank You For Smoking , which BTW was absolutely hilarious) Given his "payment processing" background, combined with the fact that Evil Max wanted to "rule the black market world in stolen payment cards" he'd be the ideal person to bring this to the silver screen.

Speaking of movies, click below to see how professional card counterfeiting differs from card cloning, which the Today Show ran last week.

Fraudsters rack up millions of dollars in merchandise using fake credit cards with legit numbers hacked off the Internet. Detective Bob Watts of Newport Beach PD shows how it's done.

More on Max Vision:

Max Vision charged with hacking -- again
Sep 12, 2007 ... Federal prosecutors charge former security consultant Max Butler, better known amongst security researchers as "Max Vision," alleging that ...

Max Vision
: FBI pawn?
May 5, 2001... FBI agents called him 'the Equalizer': a security expert and confessed hacker who infiltrated the electronic underground to help the Bureau. www.securityfocus.com/news/203 - 34k

A 'White Hat' Goes to Jail

"Max Vision," a renowned hacker, security expert and FBI informant, is sentenced to prison in a case that angers many in the hacking and cracking community.


Reblog this post [with Zemanta]

Friday, December 26, 2008

"Going Dutch" Sets Debit Records?


On Christmas Eve, there were 10.4 million pinpas (pin debit card) transactions, the highest number ever recorded in the Netherlands on a single day. The figures come from Equens, the company which operates the electronic payments. Christmas Eve smashed the record set only the day before, Tuesday, when the cards were used 9.7 million times.


There were many more pinpas transactions during the last four days before Christmas, 39 million, than in the same period last year, 30 million. The fact that the cards were used more this year does not necessarily mean that more money was actually spent.

Editor's Note:  I can't help wondering if there were really only 5.2 million purchases made, but it wound up double that because they "go dutch" on everything...one dinner bill but two separate debit transactions :-)



Reblog this post [with Zemanta]

Wednesday, December 24, 2008

PC's Are Insecure...So Are You?

PC's are insecure and hackers constantly exploit flaws in their security.  This article provides some insight as to why software based solutions designed to run on a PC are sitting ducks for potential hackers... which, once again, is why HomeATM has taken a personal swiping device approach to bringing PIN debit to the web.  It's how they've done it in the stores, and it's how it should be done online.  Keep in mind that the Internet was not designed for eCommerce, it was originally designed as the "information highway." 

With our approach, the transaction is done "outside" the browser space, therefore "man-in-the-browser" attacks are nullified, as are keylogging, screen capturing and a symposium of  other hacking methods designed to drain  data from your PC.

Someone's eventually going to be swipin' your credit/debit card data...shouldn't you be the one doing the SwipePIN?  Any doubts?  See how easy it is..."to hack a PC"  

This, from the Wired Blog Network:

SecuniaImage via WikipediaHardly anyone runs a PC without known holes that hackers can exploit, a Danish security company reports. Of those who run the company's free security-scanning tool, nearly half have more than 11 out-of-date programs.

Secunia Software's Personal Software Inspector checks programs installed on a user's computer to see if the latest, patched version is installed. More than 98 percent of users had at least one program that wasn't the latest version, the company found in a study of 20,000 users of its software.

The sobering statistics are not surprising, but they come as malware makers turn from simply exploiting easy holes in Windows.

In addition, hackers have been finding vulnerabilities in browsers, media players and file-reading software as a way into other people's computers.

While it may not seem likely that a hacker would rig a website to exploit a patched hole in a lesser-known media player like VLC, hacking tools make it increasingly easy for an infected webpage to check for many vulnerabilities in a person's computer.

Number of insecure programs per PC/user:
0 insecure programs: 1.91% of PCs
1-5 insecure programs: 30.27% of PCs
6-10 insecure programs: 25.07% of PCs
11+ insecure programs: 45.76% of PCs

Secunia's Mikkel Winther says the study shows that its just as important to keep programs up to date, as it is to have a good firewall and anti-virus programs. He also says the real numbers in the general populace are likely worse, because their sample is of people who have looked for security software.

"The results are shocking and prove as well as emphasize the need for a patching solution for private users," Winther said. Keeping up with software updates can be quite tedious and annoying, even as software makers like Microsoft and Mozilla have built better update tools. Those who don't care to download Secunia's software can try it's online scanner, though it only checks version numbers on a hundred or so programs.

Secunia does not sell security software to individuals, but does market a networked version of this scanner to companies.

Reblog this post [with Zemanta]

B2C E-Commerce in Canada - 2007-2012

In the previous post I featured eMarketer's report on e-Commerce projections in the UK through 2012...here's their projections for Canadian eCommerce...

Canadians Are Warming Up to Online Shopping

In 2007, Canadian retailers sold C$13.8 billion ($12.9 billion) of consumer products and travel bookings online. But by 2012 eMarketer projects that Canadian business-to-consumer (B2C) e-commerce sales will reach C$22.8 billion ($22.2 billion).

That means that between 2007 and 2012, Canadian B2C e-commerce sales will show a compound annual growth rate (CAGR) of 10.6%. Not bad numbers in a tough economy.

But the numbers could be better.

“Until Canadian consumers show a larger appetite for buying big-ticket physical goods online, such as home furnishings and consumer electronics, the Canadian e-commerce market will remain small compared with other G-7 countries,” says Jeffrey Grau, eMarketer senior analyst and author of the new report, Canada B2C E-Commerce.

Consumers in Canada are avid online product researchers, on par with their US counterparts. But they are much more likely to make a subsequent purchase in-store rather than on a Website.

“The fact that Canadian Web retailers are required to charge sales tax is certainly a disincentive to online buying,” says Mr. Grau.

Because of the tax structure, Canadian shoppers have never seen much of a price advantage to buying online. This is one reason why Canadian e-commerce has grown at a more gradual pace compared with the explosive growth that occurred in the US.

“The upside of this is that the Canadian market is enjoying a longer period of solid growth,” says Mr. Grau, “albeit on a much smaller scale.”

Another factor that has depressed the growth of B2C e-commerce in Canada is the lack of product selection online. In fact, many prominent Canadian retailers have not found the ROI compelling enough to run an online sales channel.

“While Canada has about one-tenth the population of the US, the cost of running a transactional Website is about the same,” says Mr. Grau. “This creates a challenge for small to medium-sized retailers with fewer financial resources.”

Nevertheless, Canadian retailers are in a better position than foreign merchants to understand the needs and interests of local consumers. And like consumers across the world, those in Canada prefer to shop with indigenous retailers.

Reblog this post [with Zemanta]

B2C E-Commerce in UK, 2007-2012


According to eMarketer, Business 2 Consumer E-Commerce in the UK will continue it's strong growth pattern.  The tough economic climate will not affect e-commerce as much as it will bricks and mortar retail.  Here's their analysis:

UK e-commerce revenues will remain strong in 2009, as Internet stores continue to weather the recessionary storm better than their brick-and-mortar counterparts. In September 2008, eMarketer forecast that UK business-to-consumer (B2C) online sales in 2009 would be worth £68.4 billion ($127.9 billion), and we have seen no reason to alter that forecast.

B2C E-Commerce: UK, 2007-2012

Major online retailers that upgrade to offer true multichannel shopping and delivery/return options, as well as value for money, will gain market share while a number of second-rank e-shops stagnate or go out of business. But market leaders will spend more than in 2008 to ensure they attract and keep consumers’ attention.

Most online retailers will continue to court shoppers with money-off promotions and discounted delivery charges, and at least one supermarket chain will experiment with large-scale e-mail distribution of promotional coupons for grocery products bought in-store.

Mobile marketing will take significant steps next year—albeit from a small base—as more UK advertisers, heartened by the growing number of high-specification (3G) mobile users, move to exploit this always-on medium. Data from the Office for National Statistics suggested that 19% of adults ages 16 and older accessed the Web via their mobile phone in the three months prior to polling in early 2008—and this was before the highly successful UK launch of the 3G iPhone in July.

The 2009 mobile growth spurt will take two main forms: increasingly sophisticated usage of SMS, short codes and bar codes in direct-response campaigns, and microsites designed for mobile users. November 2008 research by mobile marketing agency Sponge found that 40% of UK e-retailers polled already had a transactional Website that was mobile-friendly. Another 50% said they planned to create such a site in the next 12 months. Moreover, one in five online retailers reported having used mobile microsites to drive promotions during 2008.

Reblog this post [with Zemanta]

Mother of All Hacks Coming?

There is a disturbing development brewing in the payments world.   It's bad enough when a retailer's computer  security is breached but now we've got us a completely different ballgame.  When hackers penetrate the computer systems of major acquirers and processors, well to use a famous quote, "We've got a problem Houston." 

This could turn out to be a "Royal pain in the ***" for Visa and Mastercard themselves because acquirers like Royal Bank of Scotland link directly into their networks. 

On the surface, this appears to be "one small step for hackers but it's "one giant step" for hack-kind."  
 
According to reports I've read this morning,  according to Gartner Research analyst Avivah Litan, this could be the beginnings of the mother of all hack attacks...

“It’s very bad news,” says distinguished analyst Avivah Litan. Unlike retailers’ computer systems, processors’ systems connect directly to the networks of Visa Inc. and MasterCard Inc. “An attacker that breaks into a processor conceivably can get into the heart of the system,” and attacks on acquirers and processors are increasing."

Here's the press release:

RBS WorldPay Announces Compromise of Data Security and Outlines Steps to Mitigate Risk

ATLANTA, Ga. – December 23, 2008 – RBS WorldPay (formerly RBS Lynk), the U.S. payment processing arm of The Royal Bank of Scotland Group, today announced that its computer system had been improperly accessed by an unauthorized party.  RBS WorldPay has urgently taken a number of important steps to mitigate risk in response to this situation.

The issue, which affected pre-paid cardholders and other individuals, was identified on November 10 and law enforcement agencies and federal regulators were notified by RBS WorldPay shortly thereafter. RBS WorldPay’s internal security professionals and outside experts are working with federal and state law enforcement authorities in an investigation of this event.  The affected pre-paid cards include payroll cards and open-loop gift cards. Personal information associated with certain payroll cards may have been improperly accessed. PINs for all PIN-enabled cards have been or are being reset.

Affected individuals are being notified and information has been posted on the RBS WorldPay Web site, www.rbsworldpay.us.
The fraud that has been identified to-date is associated with RBS WorldPay’s computer system supporting its U.S. pre-paid and open-loop gift card issuing business. Actual fraud has been committed on approximately 100 cards. Cardholders will not be responsible for unauthorized activity associated with this event. Certain personal information of approximately 1.5 million cardholders and other individuals may have been affected and, of this group, Social Security numbers of 1.1 million people may have been accessed.

RBS WorldPay is offering impacted individuals whose Social Security numbers may have been affected a complimentary one-year membership in a national subscription credit monitoring service that provides access to individuals’ consumer credit reports and daily monitoring of their credit files from all three national consumer reporting agencies.

Gift cards that have already been purchased retain their value and can be used wherever they are accepted by merchants. Those gift cards that had not been purchased have been deactivated and are being removed for destruction from stores as an additional precaution.

Ben Barone, president and CEO of RBS WorldPay, said, “Privacy is important to RBS WorldPay and we regret any inconvenience this may cause affected individuals. We have taken important, immediate steps to mitigate risk and none of the affected cardholders will be responsible for unauthorized activity on their account resulting from this situation. We are working closely with leading computer security firms to further safeguard our system, and with law enforcement agencies, which we hope will result in the criminals being brought to justice.”


Reblog this post [with Zemanta]

Kohl's Leads Online Sales in Unique Way

According to Internet Retailer Kohl's enjoyed  the sharpest rise in holiday traffic this season...

Among 10 top retail sites, Kohl's has the sharpest rise in holiday traffic

Providing more evidence of the increasing importance of the online channel to retail chains, the e-commerce site of nationwide chain Kohl's Department Stores showed the sharpest year-over-year growth in the number of unique visitors, at 53.1%, in a recent survey of 10 sites. Amazon.com posted the second-large increase, up 48.5%, while Macy's was up 36.1%.

The survey, conducted by Compete Inc., was based on unique visitor totals from Nov. 1 through Dec. 13, 2008, the latest day for which data was available, compared to the same period of 2007. Overall, the number of unique visitors at the 10 surveyed sites rose 25.6% to 765.99 million visitors.

The year-over-year changes were affected, however, by the later start of the 2008 peak holiday shopping season. Thanksgiving, typically the official kickoff of peak holiday shopping, fell on Nov. 27 this year, compared to Nov. 22 in 2007.

Following are the 10 sites surveyed by Compete with their year-over-year rise in unique visitors and their total number of visitors (in millions) for the period Nov. 1 through Dec. 13, 2008:
  1. Kohl's, 53.1%, 38.55
  2. Amazon.com, 48.5%, 382.02
  3. Macys.com, 36.1%, 35.69
  4. Sears, 25.1%, 58.62
  5. Walmart.com, 22.8%, 181.62
  6. ToysRUs.com, 21.7%, 60.04
  7. Target.com, 20.3%, 137.23
  8. JCP.com, 18.2%, 60.04
  9. BestBuy.com, 12.3%, 77.51
  10. Overstock.com, -9.8%, 42.01


Reblog this post [with Zemanta]

Tuesday, December 23, 2008

Visa "Anti-Trust Worthy" Discover's Morgan Stanley

As I mentioned in a post on December 5th, Morgan Stanley apparently had "secret talks" with Visa behind Discover's back and now they are suing each other over the $2.75 billion take that Discover collected from Visa in an antitrust lawsuit. What was Morgan Stanley thinking?


Bottom line is that Discover says it's not paying a dime to Morgan Stanley because they tried to sabotage the settlement talks behind their back and thus forced them to settle for less than they would have. Kind of puts a new twist on antitrust, and once again Visa is involved. Morgan Stanely should have just left well enough alone, but since they were capped at 1.5 billion, Discover claims they had no vested interest in seeing the case go to trial.

As the title of this post suggests, my guess is that Visa played Morgan Stanley in order to reach a lower settlement...and it worked. Now there's a whole new court case that is arising out of the settlement of another. It's a crazy world, but that's life, and life accepts Visa! Apparently, Visa is worthy of forever being associated with antitrust...

I'll continue to follow the case here on the PIN Debit blog. As it looks right now, the case won't reach trial until the end of 2009, but I'm sure there will be some interesting tidbits in the meantime, and I'll cover those tidbits here.

From todays New York Post:
"The negotiations with Visa and MasterCard dragged on, and the two sides were set to go to trial this October.

But the weekend before the trial was to start, Discover claims that it learned for the first time that Morgan Stanley was talking separately to Visa and MasterCard to try to settle case before it moved to trial. Fearing that Morgan Stanley had in some way compromised its trial strategy, Discover says that it was forced to settle the case for much less than what it might have gotten at trial.


Discover then refused to pay Morgan Stanley its cut of the settlement, claiming that Morgan Stanley violated the terms of their agreement that Discover had sole negotiating power.

Morgan Stanley sees things quite differently. It has sued Discover to get its $1.3 billion cut of the $2.75 billion payout.

Morgan Stanley claims that Discover always knew it was speaking with Visa and MasterCard in order to work out a deal. It even gave up $100 million of its cut to get Visa to sign on to the $2.75 billion, nonnegotiable figure proposed by the arbiter of the case.

Discover has now countersued, claiming that Morgan Stanley’s attorneys were under pressure from John Mack, Morgan Stanley’s chief executive, to settle the case quickly. Discover claims that since Morgan would not get a penny over $1.5 billion, it had no interest in seeing the case go to trial, where Discover could have reaped more cash

Continue Reading at NY Times



Reblog this post [with Zemanta]

TSYS Enters Turkish Payments Market


TSYS Hires New Business Development Director for Turkey

Columbus, Ga. and London, 22 December 2008 — TSYS today announced Bulent Senver as Business Development Director for its entry into the Turkish payments market.

Mr. Senver brings more than 25 years experience and extensive knowledge of the Turkish banking and card payments industry. He has worked with more than 20 Turkish and foreign banks in an advisory role as a management consultant and as a senior executive in the bank environment, a position in which he was named 'Banker of the Year' by the Turkish Press Institution.

Kelley Knutson, executive vice president of Global Services for TSYS, said, "TSYS is very pleased to welcome Bulent as Business Development Director for Turkey. He has helped achieve many milestones in his respective market, including the first photo credit card, the first soccer club debit card and the first telephone banking system. He has in-depth knowledge of the payments industry and local market requirements, and embodies the service excellence and integrity associated with the TSYS brand."

"With a strong, stable economy, growing population and rising income levels, we believe that the Turkish card market shows tremendous potential for further growth. It is a key, strategic market to TSYS and we are fully committed to investing long-term in the region," added Knutson.

The Turkish payments market has grown at an accelerated rate during the last five years and is now the third-largest card market in Europe. In terms of payment options and product differentiation, Turkey is one of the most sophisticated and innovative markets in the world.


TSYS, which grew its international operations 33 percent in 2007, confirmed its intent to participate in the Turkish marketplace with its unique value proposition, TS Prime, an efficient server-based issuing and acquiring card management platform adopted by more than 100 financial institutions worldwide.

TSYS supports more than 300 clients in 75 countries and has been a leader in the global payments industry for more than 25 years. Its market presence extends to 18 offices supported by more than 8,000 personnel.

About TSYS
TSYS (NYSE: TSS) is one of the world's largest companies for outsourced payment services, offering a broad range of issuer- and acquirer-processing technologies that support consumer-finance, credit, debit, debt management, healthcare, loyalty and prepaid services for financial institutions and retail companies in the Americas, EMEA and Asia-Pacific regions. For more information, contact news@tsys.com or log on to www.tsys.com. TSYS routinely posts all important information on its website.

Reblog this post [with Zemanta]

Chip and PIN Coming to Dubai

Decision to switch based on recent hack and rise in card related fraud.
Many banks across the UAE experienced a concerning rise in the instances of card related fraud in the latter part of this year.

Much of the fraud involved card “skimming” which is when a device is attached to an ATM or a Point-Of-Sale card reader and details are copied from the card’s magnetic strip. Details copied would include the card’s PIN number making it possible for fraudulent transactions to be made.

To help combat this Lloyds TSB Middle East has taken the decision to launch Chip and PIN cards – a more protected system for cards.

Chip and PIN cards contain a chip, making them more difficult and more expensive to counterfeit. Signatures can easily be forged and are often not checked carefully. So entering your PIN at a till instead of signing a receipt helps to prevent someone else from using your card.

One of the World's biggest banking groups, today announced that the bank will launch its Chip and PIN offering in January 2009. Following the increase in card-related fraud activity across the UAE, Lloyds TSB Middle East has accelerated the launch of its Chip and PIN credit and debit cards to ensure their customers' banking experience is even more secure.

"We are committed to delivering excellent customer service and protecting our customers", said Richard Musty, Consumer Banking Director. This is why we have brought forward the launch of our Chip and PIN credit and debit cards. These cards will offer our customers a more secure way to pay and improved protection against card-related fraud. Furthermore, our sophisticated fraud monitoring system will give us an early warning signal to potential fraudulent activity so we will be able to proactively tackle it.

Cards will be issued to existing customers on a renewal basis
Reblog this post [with Zemanta]

Visa's WarChest: $1.1 Billion


Visa Inc. (NYSE:V) today reported that it has deposited $1.1 billion into the litigation escrow account previously established under the company's retrospective responsibility plan (the "Plan").

Under terms of the Plan, when Visa funds the litigation escrow its U.S. financial institutions, the sole holders of Class B shares, bear the expense via a reduction in their as-converted share count.

"This transaction not only adds the necessary funds to our litigation escrow, but effectively acts as a $1.1 billion Class B share repurchase program," said Joseph Saunders, Visa's chairman and chief executive officer. "It has always been our stated intent to return excess cash to our shareholders in the form of dividends and share repurchases. We are obviously pleased that our strong financial position and excess cash flow allows us to do this."

The Plan was established at the time of Visa's initial public offering. It provides coverage and a payment mechanism for judgments or settlements in specific U.S. legal cases, protecting Visa and its Class A and Class C shareholders from any direct losses.

The deposit of the funds into the escrow account reduces the conversion ratio applicable to Visa's Class B common stock outstanding from 0.7143 per Class A share to 0.6296 per Class A share. On a converted basis, the 245,513,385 Class B shares currently outstanding are equal to 154,566,658 Class A shares of common stock.

The deposit of loss funds has the effect of a repurchase of 20,800,824 Class A common share equivalents from the Company's Class B shareholders. The amount paid per share represents the volume weighted average price (VWAP) of the Company's Class A common shares for the 15-day trading period December 1, 2008 to December 19, 2008.

About Visa: Visa operates the world's largest retail electronic payments network providing processing services and payment product platforms. This includes consumer credit, debit, prepaid and commercial payments, which are offered under the Visa, Visa Electron, Interlink and PLUS brands. Visa enjoys unsurpassed acceptance around the world and Visa/PLUS is one of the world's largest global ATM networks, offering cash access in local currency in more than 170 countries. For more information, visit www.corporate.visa.com .

Source: Company press release.


Reblog this post [with Zemanta]

Sorry Charlie...You've Been...Hired!

Last August I wrote a couple posts (Sorry Charlie...Youve Been Hacked and Sorry Charlie...The Cat's Outta the Bag) about the three MIT students that hacked into Boston's subway payment card system. (CharlieCard)

They had planned to present their findings at Defcom, but instead were sued by the Massachusetts Bay Transit Authority. The MBTA took legal action just before the students were scheduled to discuss: "generating fare cards","reverse-engineering magnetic stripes", and "hacking the RFID technology in the cards".

Instead, a judge issued an injunction ordering them to refrain from doing so. Now they've been "hired" by the MBTA. Ironically, yesterday I wrote a post entitled "Who Says Crime Doesn't Pay" and today, I saw this article that the MBTA had "hired" the three hackers who broke into their system.

So apparently it also pays to hack into a system and threaten to publicly share the results in a presentation at a hack convention.

It's a different world out there...the only "Hack" I ever heard of as a kid was "Hack Wilson" who set the record for most RBI's in a season (191) in 1930 for the Chicago Cubs.

Anyway, it's been an interesting turn of events so here's a follow up on the Sorry Charlie series from Yahoo news.

SAN FRANCISCO - A trio of Massachusetts Institute of Technology students who found a way to hack into the Boston subway system's payment cards have agreed to partner with transit officials there to make the system more secure.

The Electronic Frontier Foundation announced the agreement Monday, two months after the Massachusetts Bay Transportation Authority dropped a lawsuit against the students, who were represented for free by the EFF, a civil-liberties group that frequently takes up cases involving security researchers and computer hackers. The transit agency had sued to stop the students from presenting findings at a computer-security conference.

The students — Zack Anderson, R.J. Ryan and Alessandro Chiesa — have argued all along they were trying to help the MBTA by giving it advance notice of their planned talk last summer and keeping specific details of their hack secret. But the MBTA worried of widespread fare fraud if students discussed how they were able to add hundreds of dollars in value to MBTA's two primary payment cards — CharlieCard and CharlieTicket.

Before they could take the stage at the DefCon hacker conference in Las Vegas in August, the students were slapped with a lawsuit and a restraining order preventing them from giving the talk. Everyone found out what they were going to say anyway: All 87 slides of the students' presentation were already online, having been given out to conference attendees on CDs before the lawsuit was filed.

The MBTA argued it needed time to fix the problems, but the issue touched off a legal battle about whether the students' free-speech rights were violated and prompted the EFF to take up the students' case.

The judge eventually lifted the gag order and the transit agency dropped its lawsuit in October. The two sides have been working since then on how they would collaborate to make the fare system more secure and have the students' work taken seriously, said Jennifer Granick, the EFF's civil liberties director.

Reblog this post [with Zemanta]

Monday, December 22, 2008

Skim Milks Bank Accounts Dry


I don't know how good of an idea it is to print stories like this.  Law enforcement is, in essence, admitting that these types of crimes are very difficult to solve. 

Criminal Minds have to be thinking that, compared to robbing a bank, for example, skimming  seems to provide less danger, (non-violent) a higher  take (not many bank robberies result in an $800k purse),  and the risk of getting caught is lower.  Scary thought, yes, but off base?  Me thinks not.  I covered this story back in July...the update is that there is no update.  They haven't made any headway as far as identifying who the culprits are...

Gas debit thieves still on the loose

Police still haven’t caught up with the scam artists who made off with half a million dollars this summer from debit card information stolen at two Pierce County gas stations. Local agencies are coordinating with police in California and with federal agents to stop what they believe is a crime spree that spans the West Coast. The patient and wily thieves are believed to have left a wake of at least 675 victims and $800,000 in losses, according to police and news accounts.

“We are in touch with multiple agencies up and down the West Coast and the FBI is involved,” Pierce County Sheriff’s Department spokesman Ed Troyer said Friday. “We’re swapping photos and other information.”

But despite those efforts, the thieves remain steps ahead of their pursuers.

“We haven’t really made any headway as far as identifying who these people are,” said Puyallup police detective Jason Visnaw said Thursday. His case alone has 283 victims with losses of more than $268,000.

The crimes have several common features:

• The thieves target ARCO stations, which take debit cards but not credit cards.

• They use card-reading devices placed on the payment machine to “skim” account and PIN information.

• They often wait for months after taking the card information before making withdrawals – which is long enough for surveillance video to be taped over.

• They raid their victims’ accounts over holiday weekends, when there’s a better chance the thefts will go undetected for an extra day.

The thieves drew on accounts stolen from the station at 1502 South Meridian St. over Memorial Day weekend. Over the July Fourth holiday, more than 125 people who used their debit cards at the ARCO at 11608 Meridian Ave. E in South Hill became victims; they had all used their cards at the station the previous August.

The July Fourth case was investigated by the Pierce County Sheriff’s Department. A total number of victims and losses was not immediately available. Earlier estimates placed Pierce County losses around $500,000.

A May San Jose Mercury News article said a group that had targeted stations in South San Jose and Los Altos was “likely the same group that has been targeting stations statewide.”

San Jose detective Patrick Ward told The News Tribune that his case alone involved another 190 victims and another $210,000 in losses. The Los Altos case has more than 80 victims and $100,000 in losses.

Los Altos detective Wes Beveridge said the case is being investigated by a high-tech task force composed of officers from several jurisdictions in northern California and the FBI.  “We’ve got one of the suspects identified,” he said, noting it was unclear how big the group is. “I’ve got six different suspects in my cases.”

The information police have gathered indicates the group may have been active in Florida and Arizona before making southern California its home base. Members of the group are thought to be from Eastern Europe and are likely sending the proceeds overseas, possibly to fund other illegal activities, Beveridge said.

A comprehensive estimate of victims and losses was not available. Photographs from several ATMs where the thieves made their withdraws have been released to the public.

“Right now we’re all kind of in the same boat,” Ward said. “We’re trying to contact as many local agencies as possible. At this time, we don’t know exactly what the entire scope of it really is. It’s still an ongoing investigation.”



Reblog this post [with Zemanta]

Who Says Crime Doesn't Pay?

According to Brian Krebs, a Computer Security journalist with the Washington Post, Cybercriime is a lucrative business and is growing exponentially.  He refers to McAfee's annual "Virtual Criminology Report" (pdf) which states that online scams quadrupled in the last quarter of 2008. 

Also, (see chart on left) the number of viruses/bots, trojans and potentially unwanted programs (PUPs) are not only on the rise, but almost off the charts.  Why is this relevant?  Because (see 3 Key Findings illustration below) based on the report, law enforcement is "ill-equipped" to cope with this growing (insurmountable?) surge in PC attacks designed to steal personal information. 

So apparently "Crime Does Pay"...at least cybercrime. 

Put in simple terms,  software is soft... which is why HomeATM's Internet PIN debit approach is hardware based.  As long as hardware isn't tampered with (I  would find it highly unlikely that anybody's going to break into one's home to tamper with HomeATM 's Personal Card Swiping Device) it's the safest, most secure way to transact.  It's more convenient too...just swipe versus type!  But convenience takes a back seat to security, and if you have any doubts about how easy it is for cybercriminals to see what you type, then Google "PC Hijacking" or "keylogging." 

He's a snippet from Mr. Krebs article.

Report: Cybercrime is Winning the Battle Over Cyberlaw

Law enforcement agencies worldwide are losing the battle against cyber crime at a time when criminals are increasingly using the global economic downturn to make headway in recruiting more computers and computer users to further illegal online activities, a scathing new report from security vendor McAfee concludes.

McAfee's annual "Virtual Criminology Report" (PDF) notes that the number of compromised PCs used for blasting out spam and facilitating a host of online scams has quadrupled in the last quarter of 2008 alone, creating armies of spam "zombies" capable of flooding the Internet with more than 100 billion spam messages daily.

In an increasing number of cases, those missives are playing on public fears over the battered economy, pitching recipients on too-good-to-be-true job offers aimed to enlist them in cybercrime operations, McAfee said.

"Cybercriminals are cashing in on the fact that the economic downturn is causing people worldwide to increasingly turn to the Web to seek the best deals and jobs, and to manage their finances," the report charges. "They are preying on fear and uncertainty and taking advantage of the fact that consumers are often more easily duped and distracted during times of difficulties. In fact, opportunities to attack are on the rise."

At the forefront of this worsening problem are so-called "money mule" scams, in which criminals make use of third parties -- often unsuspecting consumers -- to launder stolen funds. Mule recruitment is an integral part of many cybercrime operations because money transferred directly from a victim to an account controlled by criminals is easily traced by banks and law enforcement.

The mules, therefore, serve as a vital buffer, making it easier for criminals to hide their tracks. However, criminals tend to view money mules as expendable resources, because those unwitting accomplices usually either are confronted by authorities or lose money as a result of their participation in the scams.

In most cases, money mules are recruited via online job postings touted in spam. McAfee said that some 873 money-mule recruitment Web pages were detected in Britain alone in the first half of 2008, a 33 percent increase over the first half of 2007. That data was gathered by APACS, the United Kingdom's payment-industry trade group.

An investigation by washingtonpost.com earlier this year into a money mule network uncovered a database of thousands of U.S. citizens who had responded with interest to a single money mule scam e-mail campaign.

(continue reading at the Washington Post) or go to the McAfee Report here




Reblog this post [with Zemanta]

Gemalto Wants EMV in USA


In an article written by Kirk Ladendorf of the American Statesman, he talks about Gemalto's preference to do away with  the magnetic stripe.  Most of Europe has already converted from magstripe to Chip and PIN, as has Australia and Canada...along with many other parts of the world.  The USA is the last vestibule for Gemalto, and they believe America will convert to EMV in the next 5 to 6 years.  At least one analyst does anyway. 

"The world's largest smart-card supplier shipped 1.2 billion of its cards last year and has more than 1 billion users around the world. It recorded sales last year of 1.6 billion euros (about $2.2 billion U.S.). The company says its growth this year is running about 10 percent in the face of a weakening economy.

Now, the Amsterdam, Netherlands-based company is looking for new worlds to conquer, including the United States, which traditionally has been a smart-card laggard. The company is relying on its 150-person marketing and engineering team in Austin to develop products, services and business alliances that help keep its revenue growing.

North America is a comparatively undeveloped market for Gemalto in part because many of the big banks here remain wedded to old-fashioned "magnetic stripe" bank credit cards and debit cards, rather than to smart cards, which predominate in Europe and other parts of the world.

Despite some reports of increased fraud cases involving magnetic stripe cards, many U.S. banks are hesitant to change because of their heavy investment in the technology, said analyst Ed Kountz with Jupiter Research.

"Our (banks') willingness to make a change is somewhere between kicking and screaming on the payment side of things," Kountz said.

Smart cards can contain 1,000 times as much information as a magstripe card and can contain multiple software applications that enable them to handle more functions. More data and more software translates into more security and more functionality, Gemalto says.

As the rest of the banking world adopts smart cards, the analyst expects U.S. banks will eventually follow in the next five or six years.

If the banks are slow to move, other U.S. customers, including the federal departments of Defense and State, have moved faster. Gemalto is one of two main suppliers of smart cards that go into the State Department's new e-passports, which began in 2006. It has also won over big security-conscious corporate customers including Boeing Co., Chevron Corp. and drugmaker Pfizer Inc..

Some of those companies have begun using a new Austin-developed product, the Smart Enterprise Guardian, that can be used to authorize user access to computer networks, the secure transport of stored digital files and digital signatures for e-mail documents to make an official record.

Pfizer is using the "digital signature" feature to reduce the logistical requirements, money and time involved in creating an official record for its complex drug development process.

The SEG was developed to work with Microsoft Corp.'s Windows operating system.Gemalto's technical team in Austin keeps close ties to Microsoft's operating system developers.

"Microsoft is a huge supporter of Gemalto because we are the largest provider of secure devices in the world," said Paul Beverly, who heads the company's North American operations and also serves as the global company's executive vice president for marketing. "What we are seeing is, we are in a position where things are evolving in our direction. The pressure is coming from various mandates for increased security, and there is a lowering of the technical barriers to adoption."

Microsoft founder Bill Gates has said that one of the major points of vulnerability to computer networks lies in its heavy dependence on passwords as the main form of authorization for users. Passwords can be stolen or lost, and they can create an administrative burden to manage.

Gemalto says it offers a way around the problem.

"We all realize that we can make the world more secure and more convenient if we can get rid of the damned password," Beverly said. "That is our mission, to get rid of the password, because it creates so many problems" for computer systems administrators...

(continue reading in a new window)


Reblog this post [with Zemanta]

Sunday, December 21, 2008

Debit Card Fraud 101


Beginner's guide to: Credit/debit card fraud
What are the most common types of card fraud?

The most common type of card fraud in Britain is known as "card not present" fraud. This is where fraudsters obtain your card details, and use them to buy products on the internet or over the telephone. 

(Editor's Note:  Card Not Present Fraud can be eliminated by providing a means to make the card present, which is what HomeATM has done with it's personal swiping device.)

How do fraudsters get my card details?

There are a number of ways. One method is "phishing", whereby a fraudster will email you posing as your bank or an official institution, and ask you to verify your details.

Fraudsters also use "skimming" devices to copy card details. When you hand your card to a shop attendant to pay for something, it is possible that they could pass it through a device underneath the counter. This records all your card details, which they can then use later. Fraudsters can also extract your details from your computer if you do not have adequate firewalls and virus software.

Wasn't Chip & PIN supposed to stop card fraud?

Chip & PIN has reduced fraud in Britain, but many other countries do not have the same technology. So criminals can clone cards in the UK, and then use them overseas.

How can I protect myself against fraud?

Don't let your cards out of your sight. With Chip & PIN technology, you shouldn't need to hand your card to the cashier. Also, be wary of emails asking for your personal information. Your bank would never email you asking you to enter your account or card details. Finally, make sure your home computer network is secure. Buy the latest virus packages, and secure your internet connection.

Will I have to pay up if I am a victim of fraud?

As long as it's not your fault, your bank will cover the cost of any fraud on your cards. However, if there's any evidence that you haven't taken proper care to protect yourself, you may have to pick up the bill. For more information about card fraud, visit www.apacs.org.uk.






Reblog this post [with Zemanta]

Video - ATM Card Skimming Tech Bar Raised

This is just the beginning of more sophisticated equipment being used to "skim" your card details.  Look for more advancements in technology both at ATM's and in the store as the skimming market evolves from it's current infancy mode into adolescence.  In this particular case, the technology was good, but c'mon man...a speaker?  What possible need would there be for a speaker at an ATM machine?  At least there's the blatant possibility these fraudsters can be outsmarted...








Reblog this post [with Zemanta]

Disqus for ePayment News