Thursday, January 29, 2009

HomeATM Meets PCI 2.0 Requirements

Witham Labs Provides A=OK, Certification Next Step
Above photo courtesy of HomeATM CEO, Ken Mages


I am pleased to report that since October 2008, HomeATM's personal card swiping device has undergone the scrutiny and rigors of PCI 2.0 testing at  Witham Labs, and that as of today, 1/29, our SafeTPIN device has either met or exceeded  the PCI 2.0 requirements "for a PIN Entry Device for online PINs".

Congratulations are in order for our CTO, Ben Lo, who works out of our Hong Kong location.  Congrats to Ben and his team for their integral role in achieving this milestone! 


When you combine this news with the fact that HomeATM already provides "end to end encryption" which is only a topic of discussion for other processors, it escalates HomeATM to the top of the security ranks in the payments industry.

* E2EE = Continuous protection of the confidentiality and integrity of transmitted information by encrypting it at the origin and decrypting at its destination. For example, a virtual private network (VPN) uses end-to-end encryption.  Another example, HomeATM uses end-to-end encryption.

Back to our PCI 2.0 story.  Here's a sampling from the Witham Labs report:  Click on the graphics to enlarge and read.


Executive Summary

HomeATM of 1010 Sherbrooke West, Monreal, Quebec, Canada H3A 2R7, has designed and manufactured a PIN Entry Device named “SafeTPIN”. This PED has magnetic stripe reader.

Witham Laboratories was asked to study the SafeTPIN and comment on its compliance with the PCI requirements for PEDs, v2.0. Under NDA, working units were provided for destructive analysis, along with wiring schematics and layouts, test data, loader application and firmware source code. We tested and evaluated the submitted samples of the device.



This report presents our findings for compliance to the PCI-PED requirements (v2.0), with detailed analysis of each requirement, overview of architecture and methods and cost estimates of possible attacks.

Witham Laboratories was able to verify the compliance of the SafeTPIN with all applicable PCI requirements v2.0 for PIN entry devices.

This report details the results of the evaluation, and is suitable for submission to PCI.

“The PED uses tamper detection and response mechanisms which cause the PED to become immediately inoperable and results in the automatic and immediate erasure of any secret information which may be stored in the PED. These mechanisms protect against physical penetration of the device by means of (but not limited to) drills, lasers, chemical solvents, opening covers, splitting the casing (seams) and using ventilation openings and there is not  any demonstrable way to disable or defeat the mechanisms"







Reblog this post [with Zemanta]

Is Google Checking Out Austraila?

Is Google Going Down...Under?  The Herald Sun says it very well may be, mate. 


How do you want to pay? Google? | Herald Sun
GOOGLE Australia is considering a plan to take on payments giants such as Visa, Mastercard and B-Pay in the booming online payments market. The move comes as the search giant secured a financial services license from local regulators.

The Australian Securities and Investments Commission recently issued Google Australia with an authority to provide deposit and payments services to local merchants and shoppers.  While the licence does not permit Google to provide cash-based payments services to Australian clients, it will enable the group to facilitate digital or online transactions.

Web-based commerce is a hotly contested and lucrative market for payments providers and has spawned a raft of new players including E-Bay subsidiary PayPal.

The ASIC licence potentially opens a fresh revenue stream for Google which will be able to collect processing and transaction fees for bringing shoppers and merchants together via its websites.

Google Australia spokesman Rob Schilken confirmed that the company was working on options to roll out an internet payments platform in Australia.
  "It's a matter of doing the due diligence and the homework so that if we're in a position to launch we can do it," he said.


But no decision has been taken."  Through PayPal, EBay has stolen a march on Google in the Australian online payments arena.

Market research published earlier this month by Neilson Online found that 7.3 million Australians shop over the internet.



Reblog this post [with Zemanta]

Malware = $1 Trillion Problem


Malware Increased  by 400% in '08

DAVOS, Switzerland (Reuters) - Businesses risk losing over $1 trillion from loss or theft of data and other cybercrime, according to a study released on Thursday by security technology firm McAfee Inc.

The California-based company launched the survey after detecting a rapid acceleration of malicious software, or "malware," last year, CEO David DeWalt told Reuters. Malware increased by 400 percent in 2008, he said.

"This was a very insidious type of malware that was designed either to steal your data, steal your identity, steal your money, and in many cases the scale as well as the sophistication was very alarming," DeWalt said in an interview at the meeting of the World Economic Forum in Davos, Switzerland.

Editor's Note: In the wake of the Massive Heart(land) Attack some industry leaders are calling for end-to-end encryption. (E2EE)  HomeATM already incorporates E2EE and is awaiting PCI  2.0 certification for their personal swiping device with PIN Pad.

The survey of 800 companies in 8 countries showed that 80 percent of malware aimed to make a financial gain, in contrast to traditional viruses and worms which just had nuisance value.

In the survey, 42 percent of companies said that laid-off employees were the single biggest threat to their data security.

The increase in the availability and power of removable storage, such as mobile phones, laptops, and USB sticks, has made data loss or theft easier. And global supply chains mean that sensitive data is often stored abroad.

DeWalt said the survey showed that the average company has $12 million of data stored outside its home country -- often in countries with little intellectual property law.

Data lost accidentally or through theft can be expensive to replace or damaging to a company's reputation or brand.

In April last year, discount retailer TJX said it would pay up to $24 million as part of a settlement with MasterCard over a security breach that put credit card data for tens of millions of shoppers at risk.

The British government has been repeatedly embarrassed by losses of data, such as when the tax authority, HM Revenue and Customs, lost data on 25 million people exposing them to the risk of identity theft and fraud.

(Reporting by Jonathan Lynn; editing by Simon Jessop)

Reblog this post [with Zemanta]

Wednesday, January 28, 2009

Heartland Sniffer Found in Unallocated Portion of Disk Drive

StorefrontBacktalk: Heartland Sniffer Hid In Unallocated Portion Of Disk

Evan Schuman, who first reported that the Secret Service has identified the person(s) responsible for the Heartland attack, writes more about the attack in his publication, StoreFront Backtalk. 



He says that the sniffer malware used in the Heartland attack was cloaked in an unallocated portion of Heartland's server, which is a well-known tactic.  What's unique in this type of attack is that it requires "tricking" the Operating System either by modifying the OS itself, or installing a modified device driver.  Either way, one consultant said that the fact the hacker(s) got around the OS itself is a "scary mother."

SFBT also says in the article that Robert Baldwin, President and COO of Heartland, says they were contacted by V/MC in late October.  It then took two weeks by two different forensic teams, (who , according to Heartland) were both about to issue a clean bill of health, to find some .tmp files in an unallocated portion of the disk drives, which turned out to  be a by-product of the malware. 

Finally, Evan Schuman addresses Heartland's decision to pursue End 2 End Encryption, questioning how feasible it is, given the cost, the amount of payment players that would have to participate, combined with the fact that it is the card brands themselves, who insist on dealing with unencrypted data.

This from StoreFront Backtalk:

The sniffer malware that surreptitiously siphoned tons of payment card data from card processor Heartland Payment Systems hid in an unallocated portion of a server’s disk. The malware, which was ultimately detected courtesy of a trail of temp files, was hidden so well that it eluded two different teams of forensic investigators brought in to find it after fraud alerts went off at both Visa and MasterCard, according to Heartland CFO Robert Baldwin.


Regarding end-to-end-encryption, Evan quotes Heartland CEO Bob Carr and explains the potential problem with it...


"Heartland CEO Robert Carr said in a statement. “Nevertheless, I believe the development and deployment of end-to-end encryption will provide us the ability to implement increasing levels of security protection as they become needed.” 

End-to-end encryption is far from a new approach. But the flaw in today’s payment networks is that the card brands insist on dealing with card data in an unencrypted state, forcing transmission to be done over secure connections rather than the lower-cost Internet. This approach avoids forcing the card brands to have to decrypt the data when it arrives."

Read Evan Schuman's complete article here







Reblog this post [with Zemanta]

Banks Not HPY with Heartland

It appears some financial institutions aren't very HPY with Heartland Payment Systems...


The Washington Credit Union League (WCUL) in Federal Way, Washington is seeking to revive legislation that would mandate specific data protection controls on all merchants and third parties, such as Heartland.  The bill (HB 1149) received its first hearing last Thursday in the Washington State House Committee on Financial Institutions and Insurance, according to a statement released by the WCUL. 

But in reading between the lines, or  actually reading the yellow highlighted one's below, it looks like the beginnings of a class-action lawsuit against Heartland in order to recoup "$20 per issued card," the "30 minutes of staff time" it takes to get it done, and monetary damages to reimburse the "reputational damages" incurred by the Financial Institution.  They also state that "if someone's careless actions result in financial loss, they should have to pay for it" and that some institutions are reporting that "more than 50% of their card base has been affected" by the Heartland breach.  All bad news for Heartland's ticker...and like they say, this may just be the tip of the iceberg...

FOR IMMEDIATE RELEASE

Contact:    David Bennett - Washington Credit Union League
                 Office: 206.340.4828  Mobile: 425.221.1237

 
‘THE TIP OF THE ICEBERG’
Latest Data Breach Causing Significant Harm to  Washington’s Consumers, some Financial Institutions
A credit union-written bill now before the state legislature encourages all financial institutionsto take extraordinary measures to protect consumers from identity theft and fraud.
 

FEDERAL WAY, WASH—The state’s credit unions have been prepared for tough times on behalf of their members for more than 75 years, but the latest whammy leveled on them may cause as much harm to some as the current national financial meltdown.

Last Tuesday’s revelation by third-party credit and debit card processing company and Princeton N.J.based Heartland Payment Systems, a company that completes about 100 million transactions per month on behalf of more than 250,000 merchants, disclosed that it had begun to receive fraudulent activity alerts last year from MasterCard and VISA. According to reports, all of the unauthorized transactions were applied to cards that rely on Heartland to process payments.

Heartland still does not know how long the breach occurred prior to its discovery and refuses to release the names of the merchants that contract with them, which deprives consumers who patronize those merchants the ability to be more vigilant in monitoring their credit and debit card accounts.

Some of the Washington’s financial institutions have reported that more than half of their card base has been affected by the breach.


Most credit union leaders believe that the effect during the initial days is just the “tip of the iceberg,” and have already begun to notify members, block accounts, reissue cards and numbers and provide ongoing fraud monitoring.

According to some industry insiders, fraudulent activity alerts began to arrive in mid-November, however because of liability reasons the alerts did not mention where the breach occurred. At least one has confirmed that counterfeit cards have been created from the stolen information and so far used in Florida and Mexico.

“The state’s credit union community is appalled, but unfortunately not very shocked by the immense size of the Heartland data breach,” said Washington Credit Union League President/CEO John Annaloro.

“In far too many cases, negligent data breachers do business as if they were immunized from liability when they fail to protect their customers’ personal information. In our view, if someone’s careless actions result in a financial loss to others, they should have to pay for it.”

In the past, it has been standard operating procedure following a data breach for credit unions to block accounts, reissue cards and numbers and provide ongoing fraud monitoring.

However, taking those aggressive steps to protect members from financial fraud and identity theft is becoming cost prohibitive because the frequency and size of data breaches is skyrocketing and costs the financial institution around $20 per card, depending on the extent of the action taken.

This number does not include costs associated with staff time, which can be as much as
30 minutes per card, or the negative reputational impact on the financial institution.

“While there are processes that are "supposed to provide" some reimbursement for fraud losses, the truth is that
these processes only recoup pennies on the dollar,” (translation:  we want more money) said Stacy Augustine, the Washington Credit Union League Senior Vice President in charge of government relations. “More importantly, the costs that are recouped don’t pay anything toward costs associated with a financial institution’s proactive steps to protect consumers from fraud and identity theft.”


Because of this, Washington’s credit unions have once again introduced legislation aimed at encouraging financial institutions to take extraordinary proactive steps to protect the state’s consumers from identity theft and financial fraud following a data breach. Like last year’s proposed bill, HB 1149 encourages financial institutions to take proactive measures to protect consumers by allowing them to sue negligent data breachers for the cost of aggressively protecting Washingtonians’ personal and private information.


Reblog this post [with Zemanta]

Class-Action Suit Against Heartland

In an article titled, "Banks, credit unions scramble in wake of Heartland breach," Jaikumar Vijayan writes for Computer World that several banks have begun reporting fraud and have been forced to issue replacement cards. 

In addition, the first class-action lawsuit has been filed on behalf of a woman in Woodbury,MN.

I would think this may just be the "tip of the iceberg" when it comes to lawsuits, as numerous credit unions and small banks will look for ways to recoup some of the exorbitant costs associated with a breach of this size.  Maybe Heartland Bank will lead the way.  Wouldn't that be a full circle and a half?

More likely it will be the Washington Credit Union League.  Based on the tone of their language in this document (Word) they are not very HPY with Heartland right now.

Here's a couple paragraphs from the ComputerWorld article.
"In the first real indication of the scope of the recently disclosed data breach at Heartland Payment Systems Inc., banks and credit unions from Washington to Maine have begun to reissue thousands of credit and debit cards over the past few days.

Several have also begun disclosing fraud associated with payment cards that were reported to them by Visa and MasterCard as having been exposed in the breach.

A Pennsylvania law firm today filed the first class-action lawsuit related to the breach. Chimicles & Tikellis LLP in Haverford, Pa., filed the lawsuit on behalf of Alicia Cooper, a resident of Woodbury, Minn., and others who might have been affected by the breach.

The complaint, filed in the U.S. District Court for the District of New Jersey in Trenton, alleges that Cooper, whose card was compromised in the breach, and others, were victims of Heartland's negligence in protecting cardholder data. The lawsuit, which calls for a jury trial, charged Heartland with breach of contract, breach of implied contract and breach of fiduciary contract for the breach..."


Looks to me like this is going to get rather messy for Heartland.  Click here to read the whole story at ComputerWorld.com

Reblog this post [with Zemanta]

One in Four Brits Hit w/Card Fraud

The Press Association, is reporting that: "One in four Briton's are a victim of card fraud."  According to their story, "1 in 4 Britons have been the victim of credit or debit card fraud."  Research has shown that:

Around 26% of people have now had their card used fraudulently, up from 21% when the same research was carried out 12 months ago, according to life assistance group CPP.  (Editor's Note: Unless they lived in London, where nearly 40% of Brits were victims.)

On average, fraudulent transactions totalled around £650, but 6% of people reported losses of more than £2,000.  But despite the large sums of money involved, 42% of card fraud victims did not spot the rogue transactions themselves, and only found out about them when they were alerted by their bank.

London remained the country's credit and debit card fraud hot spot, with 38% of people living in the capital having been hit by the problem, a 10% jump on the number of people who had been affected last year.
  It was closely followed by Cardiff at 34%, Manchester at 29% and Brighton at 27%, where there was a 15% jump in the proportion of people hit during the year.


Nearly four out of 10 victims had their card used online, while 21% had it cloned when using a cash machine or chip and Pin device, with others losing money after their card was lost or stolen. 

Kerry D'Souza, card fraud expert at CPP, said: "The dramatic increase in card fraud shows no sign of abating which isn't surprising given the desperate measures some people will resort to during the recession.


"Fraudsters are becoming increasingly sophisticated, especially when it comes to online transactions which are a particular cause for concern."


"Cardholders need to remain vigilant with their cards and take the necessary steps to protect themselves - from checking statements more frequently to keeping sight of their card when paying for transactions. It might seem like simple steps but they will go a long way in preventing fraud."




Reblog this post [with Zemanta]

Tuesday, January 27, 2009

Here to Stay - AltPay


Alternative Payments are on the rise, and they are cutting into the margins of the Dynamic Duo-poly. As credit card use declines, and debit, ACH and Money Transfer options increase, V/MC will take an even bigger hit...especially as the lime leeches from the mortar in the bricks of the house that retail built.


This article, about alternative payments, doesn't even touch on PIN Debit for the web. But it's the consumers preferred payment, which is what make s the potential for this industry so enticing. BTW, the rest of the AltPay's aside, PIN based transactions for the web is really starting to gain some "major momentum." The chatter around PIN Debit for the web has picked up tremendously over the past 10 months or so. And rightfully so...after all what part of online debit for online shopping doesn't make sense?)

I'll answer my own question. The part that doesn't make sense is the part where it's more secure than the way it's done now... and the part whereby lower interchange rates would potentially save internet retailers hundreds of millions of dollars annually.

Is it that simple...the fact that because interchange is lower, it's not as profitable to the banks, EFT's, processors and networks? Nah...couldn't be...no matter anyway because that is all about to change. Hackers have changed the game and "now it's all about security." TJX, CardSystems, Hannaford, RBS Worldpay, and now Heartland have seen to that. We need a more secure transaction, one that's encrypted from beginning to end and not only have we already got it but it's already the consumers preferred method.

Here's a tidbit from Bala J.'s article:

Alternative Payments: More Ways to Close the Sale
By Bala Janakiraman
Online customers are increasingly turning to alternative payment methods, and merchants who don't want to miss out on sales should consider accepting some or all of them. Banks also are getting in on the act, creating Secure Vault Payments, which authenticate customers through online banking portals.

For the past few decades, checks, ACH, credit cards and debit cards have been the primary means of payments for consumers. These payment methods have been successful because consumers can pay for their purchases without carrying cash, merchants can increase sales by reaching a wider consumer base, and banks are able to establish themselves as trusted financial providers to both merchants and consumers. However, changing market trends are creating opportunities for alternative payment methods and practices.


The Driving Forces Behind Payments Innovation

Communications technologies, mainly the Internet and mobile phones, have dramatically altered the ways in which individuals interact with each other and, in turn, consumers are shifting more of their purchases from the physical world to the virtual. Merchants have adapted by becoming multichannel marketers and banks are following suit by providing new means for consumers to interact with their finances through popular tools such as online bill pay and mobile banking.

Second, the rise of online purchases has brought with it concerns of security. While most banks fully protect consumers against fraudulent transactions, consumers don't want to go through the hassle of identifying and fixing fraud. And merchants are even more concerned especially since they end up digesting most of the liability in the event of a security breach.

Merchants are also concerned about managing the rising costs of payment acceptance. Over the last 20 years, credit card interchange fees have gone up 25 percent to 90 percent, depending on the card type and the nature of the merchant business... continue reading



Reblog this post [with Zemanta]

Heartland - End 2 End Encryption 2 End Hacking

Here's an update on Heartland Payment Systems.  This is a better press release than the previous ones.  It makes sense that transactions are encrypted at all times.  I was miffed at the previous press releases, the first on inauguration day and the second being pure spin.  This one however, addresses the problem head-on.   It's a good move for Heartland in their valiant attempt to make "lemonade." 

It says here they hired former ICVerify founder/payments guru Steve Elefant as the executive director of the new division.  Mr. Elefant is also the Managing Director at VC Firm Soaring Ventures in Silicon Valley.  Click here for his bio.


Heartland Payment Systems, Inc. :: Heartland Payment Systems Accelerates Development of End-to-End Encryption
 

Payments Processor Forms Dedicated Department and Names Executive Director

PRINCETON,  N.J., Jan. 27 /PRNewswire-FirstCall/ -- Payments processor Heartland Payment Systems today announced it has formed an internal department dedicated exclusively to the development of end-to-end encryption to protect merchant and consumer data used in financial transactions.

For the past year, Robert O. Carr, Heartland's chairman and chief executive  officer, has been advocating for payments industry adoption of this technology - which will protect data at rest as well as data in motion as an improvement for payment transaction security.

Carr stated, "PCI is a good and effective standard, but the bad guys have become more sophisticated to the point where encryption of data in motion appears to be one of the next required steps. There is no single silver bullet that will secure payment systems, and constant vigilance and monitoring of the infrastructure will always be required.  Nevertheless, I believe the development and deployment of end-to-end encryption will provide us the ability to implement increasing levels of security protection as they become needed. 


"Heartland has been working on the development of end-to-end encryption, but in light of our recent data breach and the impact cyber fraud has had on the public and processors nationwide, we are ramping up our efforts," Carr continued. "To do this, we are forming a dedicated internal department  and have named Steven M. Elefant, a well-known expert in point-of-sale payments, executive director."

Elefant is a member of the US Secret Service Electronic Crimes Task Force and Infragard, a public/private partnership of the Federal Bureau of Investigation. He is the co-founder and former chief executive officer of ICVerify Inc. ICVerify became the leader in payment processing integration of PC-based point-of-sale software. In 1998, Elefant merged ICVerify with CyberCash Inc. to form an Internet service provider for electronic commerce.

Recently, Elefant has been involved in numerous technical ventures in the payments and venture capital industries. His breadth of experience spans a wide spectrum including merchant and  consumer services for online consumer auctions and ASP services for merchandise and payments management.

"Late last year, Steve began a consulting project to help us define a business model for  bringing Software as a Service (SaaS) applications to our merchant base," Carr noted. "Now, as a Heartland employee, he will focus on the first leg of end-to-end encryption - getting encrypted data from the point of swipe/entry at the merchant to our switch so malware cannot steal data in motion. The internal network encryption infrastructure will be handled by a combination of new and existing IT professionals under Steve's direction."

Elefant said, "I have known Bob Carr for more than 20 years. We gained respect for one another as  competitors in the late '80s and '90s, and I believe Heartland's desire to bring end-to-end encryption to market and work with other processors to share information about cyber crime incidents are significant steps for our industry."

Source: Company Press Release


 





Reblog this post [with Zemanta]

Money Transfers to Mexico Drop 3.6%

Annual Mexican Remittances Drop for 1st Time on Record

According to Yahoo News,  this is the first drop since they started tracking the money in 1996...

MEXICO CITY – Mexico's central bank says the amount of money migrants sent home fell 3.6 percent in 2008, the first drop on record.

The slide is part of a global trend that is expected to worsen as more emigrants from developing countries lose jobs in the financial crisis battering the United States, Europe and Japan.

The central bank said Tuesday it is the first time remittances have fallen year-to-year since the bank starting tracking the money 13 years ago.


It gave no forecast for 2009. But Mexico's largest bank, Banamex, has predicted that remittances could drop by at least 2.5 percent in 2009.

Experts blame the U.S. recession and a crackdown on illegal immigration.


(continue reading)


Reblog this post [with Zemanta]

TrialPay Adds 5 Million Users in 54 Days

TrialPay says it has 20 million "users" of it's service.  That's amazing, because last December 3rd, in a press release, TrialPay announced that their user base had reached 15 million with 7500 retailers.

They remain at the same "7500 merchant level  but their new users are multiplying like rabbits.   I guess it makes sense,  cause, come to think about it,  I'm pretty sure that  rabbits "get it" for free too.  Still, that's a whopping 5 million newbies in the 54 days (7.71 weeks) comprising the period between 12/3 and 1-26. 

It also equivocates into the following:
  • 2,777,777 new users per month (1.8 months)
  • 648,508 new users each week (7.71 weeks)
  • 92,593 new users per day (54 days)
  • 3858 trial users per hour (24 hours per day)
  • 64 newbies per minute and
  • 1.07 new users per second...
A most impressive 54 day marathon (in a good economy) .  At this rate, they'll add 33,333,324 newbies wanting buy one/get one freebies by 1/1/10.  I guess in a bad economy, you can't beat free.   A clever idea, yes, but sometimes being in the right place at the right time can't be beat iether. 

E-Commerce Payment Platform TrialPay Shines in a Dark Economy
Despite recession, TrialPay achieves record sales, tops 20 million users

Mountain View, Calif. (PRWEB) January 27, 2009 -- TrialPay has just marked its most profitable quarter, charted its highest sales day on record and reached an astonishing 20 million users--all at a time when most businesses are struggling to attract customers. By offering consumers a free product with every purchase and helping more than 7,500 industry-leading merchants increase their online sales, this rapidly growing alternative payment system is proving to be a bright spot in a bleak economy.

"In the midst of a holiday shopping season with the worst sales drop in four decades, TrialPay witnessed its highest sales day ever, experienced its best quarter to date and doubled its user numbers in less than 6 months," says Alex Rampell, co-founder and CEO of TrialPay. "TrialPay offers an inventive way for shoppers to stretch their dollars while providing a creative way for online merchants to increase sales from their current traffic."

Through TrialPay, more than 7,500 premier merchants such as McAfee, Match.com and The Wall Street Journal give away their products or services for free when shoppers try or buy one offer from one of 2,000 blue-chip advertisers (e.g. send flowers from FTD, sign up for Netflix or buy clothes from Gap). TrialPay pays the merchant the full value of the free product--and often even more--using revenue from the advertiser.

Online shoppers in more than 100 countries worldwide have stopped shopping the old-fashioned way and started checking out with TrialPay to get a 2-for-1 with every transaction. As a result, the 2-½ year-old company earned its place in the top 5 alternative electronic payments, along with PayPal, Bill Me Later, eCheck and Google Checkout, according to Javelin Strategy and Research.

"TrialPay's innovative payment method continues to be a compelling choice for consumers as our tremendous growth rivals that of the biggest names in the payments industry," adds Rampell. "Reaching 20 million users at such a rapid pace proves that TrialPay shows no signs of slowing down, even in the middle a recession." To see TrialPay in action and get products from many premier brands for free, please visit: http://www.trialpay.com/shop

About TrialPay
TrialPay is the only payment method that increases a customer's willingness to pay. Visa, MasterCard, PayPal and other standard payment options process transactions but they do nothing to boost sales. TrialPay entices shoppers to complete their purchase by giving a 2-for-1 with every transaction. Shoppers get their original product for free by completing one offer from blue-chip advertisers. With TrialPay, everyone wins: merchants make more sales from their current traffic, advertisers acquire new customers on a pay-for-performance basis and shoppers get a free product with every purchase.
TrialPay works with more than 7,500 premium merchants, including McAfee, The Wall Street Journal, Skype, Match.com and other industry leaders in software, games, publishing, online services and retail. TrialPay currently has more than 20 million registered users and offers 2,000 ways to pay by transacting with name-brand advertisers. For more information, visit http://www.trialpay.com.


Reblog this post [with Zemanta]

Apple Today Keeps ProcessAway

iPhone Credit Card Processing - ProcessAway Makes It Possible
iPhone Credit Card Processing - ProcessAway Makes It Possible

TUSTIN, Calif., Jan. 27 /PRNewswire/ -- Apple had no idea when it launched its iPhone that it would be releasing about 5 million mobile credit card terminals into the hands of business owners. That's exactly what Apple did. The sleek phone has been turned into a mobile credit card processing device, thanks to an impressive little application called ProcessAway.

The software is made for an Apple iPhone or iPod Touch and works over any available network connection. Transactions can be processed at places such as conventions, street fairs, antique shows, and by business owners performing mobile detailing, on-site consultation or construction. The list is endless on who could benefit by offering the convenience of accepting credit cards on the spot and the confidence of getting immediate authorization for a credit card payment.

Business owners can use their iPhone to conduct real business. The ProcessAway software utilizes the Authorize.net gateway. Authorize.net was one of the very first Internet payment gateways and today they have one of the largest customer bases. They are continually releasing new and innovative tools to make their payment gateway even more powerful. The Authorize.net API is what fueled the development of ProcessAway and allows the millions of iPhone (and iTouch) users to turn their device into a credit card terminal.

The business owner is not limited to mobile transactions through their device. The Authorize.net merchant account used with ProcessAway includes an option to download transactions into Quickbooks and also a comprehensive Virtual Terminal. This gives business owners the benefit of processing transactions out of the office with ProcessAway and in the office through the web-based Virtual Terminal, all with a single account. Even though the Virtual Terminal is available, ProcessAway was designed as a stand-alone comprehensive processing solution that can be used effectively in any environment.

The ProcessAway software will be sold through the iTunes AppStore for $19.99. A fully functional free version, called ProcessLite, is identical to ProcessAway except the charge amount is limited. Additional information, screenshots, and FAQs can be found at http://www.processaway.net. Both ProcessAway and ProcessLite were submitted to Apple for review on January 26, 2008, and will appear in the AppStore according to Apple's approval schedule.

Contact:

Randy Palermo, 714/656-4426
Fax: 714/475-6957
Email: randy@rapadev.com
http://www.processaway.net

This release was issued through eReleases(TM). For more information, visit http://www.ereleases.com.

Reblog this post [with Zemanta]

AmEx Earnings Fall 79%

American Express CompanyImage via Wikipedia
Yesterday, American Express fell 5 percent to close at $15.20, and the credit card companies Visa, MasterCard and Discover closed lower. After markets closed on Monday, American Express reported that its net income fell by 79 percent in the fourth quarter.  Ouch.

The Associated Press

American Express earnings fall 79 percent -By SARA LEPRO

NEW YORK (AP) — American Express Co. said Monday that its profit tumbled 79 percent in the fourth quarter as cardmembers cut back their spending amid the harsh economy and the company took a big severance-related charge.

This marks the fifth-straight quarter of profit declines
at American Express — a credit card company that has prided itself on catering to a more affluent clientele — proving that few have been spared from the pain of the recession.

The New York-based company also said it expects spending to continue to slow in 2009, and forecast for higher delinquencies and loan losses as consumers and businesses battle worsening economic trends. The outlook echoes remarks made by fellow credit card issuer Capital One Financial Corp. last week.
  For the final three months of the year, AmEx earned $172 million, or 15 cents per share, compared with earnings of $831 million, or 71 cents per share, a year earlier.

During the quarter, AmEx set aside $1.4 billion to cover bad loans, down slightly from the $1.45 billion set aside in the prior-year period when the company took a $274 million credit-related charge. 
In the company's U.S. card segment, net income fell to $4 million from $7 million, as total revenue decreased 13 percent.  Average basic cardmember spending declined 13 percent to $2,758 from $3,161.  The international segment held up better in the fourth quarter, the company said, with net income falling 8 percent to $36 million. Average cardmember spending slipped 2 percent on a foreign exchange adjusted basis.

Adil Moussa, an analyst at Boston-based research firm Aite Group, said the international results were encouraging, but he warned of further deterioration to come.  "What happens in the U.S. is going to happen outside of the U.S. in a year or so," he said, referring to American consumers' pullback in spending.

The fourth quarter saw American Express transform itself into a bank holding company — a surprise move that signaled to investors just how severe the credit card giant's troubles had become.
  In approving AmEx's request for bank holding company status, the Federal Reserve cited "emergency conditions."  Funding its daily operations had become more difficult and more costly amid the credit crisis. The securitization market, which AmEx uses to raise operating capital, has dried up as investors shy away from purchasing all but the safest forms of debt.

As a bank holding company, AmEx can now accept deposits and permanently access financing from the Fed. The status change also enabled AmEx to tap into the government's $700 billion financial bailout package. In January, the company received a $3.4 billion investment from the U.S. Treasury Department in the form of a preferred stock purchase.

Additionally, AmEx said it raised $6.2 billion through a new retail certificate of deposit program it launched in October.  As a result of the additional capital, the company's total capital to total managed assets was 7.9 percent at the quarter's end, up from 6.7 percent at the end of 2007.  AmEx said it remains committed to growing its deposit base and plans to launch a direct deposit program in the second quarter. 

In October, AmEx announced plans to cut 7,000 jobs, or about 10 percent of its global work force, in an effort to slash costs by $1.8 billion this year.

For the full year, the company said net income fell 34 percent to $2.63 billion, or $2.27 per share, from $4.01 billion, or $3.36 per share. Revenue rose 3 percent to $28.37 billion.






Reblog this post [with Zemanta]

Are Smart Phones as Smart as Hackers?

Bank of America has launched a specialized mobile banking application for BlackBerry smartphones. The software is available at mobilebanking.bankofamerica.com//bbapp and it is available for BlackBerry devices with an Operating System 4.2 or higher.

With that said, Tom Wills, from Javelin Strategy and Research wrote an amusing blog post this morning...

Android: Beware the Dark Side

"Picture this. You’re the proud owner of a shiny new Googlephone. You’ve just spent the best part of Sunday afternoon getting it configured and transferring your data onto the device, and now you’re ready to load up on some cool apps. Browsing one of the Android download portals, you’re overjoyed to see that your financial institution has a mobile banking application available, and with a few deft clicks, you download it to your handset.


You eagerly launch the app, and then the fun starts. Or … hang on … maybe this isn’t so much fun. The screen goes dark for few seconds, and then your device freezes. The only way you can turn it off is by sticking a hairpin into that little hole on the back, and when the device reboots, all of your data is gone. Address book and calendar – both wiped.

Then later that evening, several of your friends and business contacts (including the one who interviewed you on Friday for that job you’ve always wanted) email you asking why you’ve been sending them messages offering to sell them C1ali$ and V1agra. You know that kind of message. Turns out that the friendly looking banking app was actually a virus..."


He goes on to ask if he's being paranoid or writing sci-fi.  The answer is neither.

continue reading at Javelin's blog site



Reblog this post [with Zemanta]

Disqus for ePayment News