Thursday, February 19, 2009

Please Take This Poll



If you have a moment, our Chairman and CEO, Ken Mages, would be interested in hearing your opinion. After you vote you will be given the results

Would you use a personal swiping device if it 100% protected your ID/Card Data?

Click Here to take the Poll

Thank you in advance for taking the time to share your valued opinion and for visiting the HomeATM PIN Debit Payments Blog!

John B. Frank
HomeATM ePayment Solutions

Also, feel free to leave your comments on this post!

HomeATM Slider Now Compatible with Your Blackberry!


Yesterday, in a post I saracastically dubbed "DumbPhoneded" I talked about security vs. convenience and a new McAfee report showing mobile device manufacturers are seeing more malware attacks than ever before.   Here's some excerpts from DarkReading's Smartphone Threats Intensify
  • Security threats were bound to catch up with the proliferation of smartphones across the enterprise...

  • Experts have long warned that smartphones...could become the new weakest link in the enterprise...

  • But they are [typically] completely bypassing the IT infrastructure." They are also bypassing security, he says, putting sensitive data at risk...

  • McAfee's report, which is based on a survey of 30-plus mobile device manufacturers from around the world, found these vendors are getting hit with more malware attacks than ever before. As a result, they are spending more money on recovering from them.

  • Around 48 percent said their devices accounted for data loss problems, up from around 27 percent in 2007. (Editor's Note: You mean like my card information, and other personal data?)
      Of course, as this blog has been consistently stating, if you want security in your transactions, it CANNOT be done in a browser environment and that especially includes phones.  Think of the highly publicized Caylee Anthony case.  Her mother's every single phone call, every single text...(even pinged her locations) to PINpoint her whereabouts on certain days and certain times.  If they can do it, don't think for a moment the hackers can't.

      In fact, they are "wizards" at it.

      So should you ever be in the market for a "guaranteed" secure/end-to-end encrypted financial transaction (send or receive: direct payment, person 2 person, bill pay, you name it) using existing bank rails, there's no place like HomeATM.

      P.S.  Our Smart Phone Personal Swiping Device is network agnostic. CDMA or GSM and will secure transactions via phone to PC, phone to merchant, phone to phone, etc. 

      For more information, feel free to contact me and I'll make sure you get to through to the necessary channels.
      Reblog this post [with Zemanta]

      The Rising Threat of Alternative Payment Channels - Report

      There's a new report on Alternative Payments Channels being released tomorrow from VRL.

      The graph on the left is from a previous released Celent Report and shows that PIN Debit has the highest Customer Value Proposition and only slightly trails "Invoicing" in Merchant Value Proposition.  Of course, when you add our Email-based P2P application, HomeATM looks like it's sitting pretty. 

      Here's an overview from the latest report.

      Alternative Payment Channels
      By: Ray Cain

      Published: 20 February 2009

      Cost: £1297

      There is a growing awareness of the importance of payments in the retail banking business. The transaction account is at the core of the customer relationship and payment services play a critical role in customer acquisition and retention. Payments are also an important source and driver of revenue. At the same time banks´ traditional role in retail payments is coming under growing threat from a plethora of alternative payment providers. This is being driven by a need for payment mechanisms that are faster, more convenient, and more secure, and that meet the needs of new transaction channels and emerging market segments, along with a confluence of regulatory factors and market conditions.

      In many respects banks are in a strong position to compete. They already have an installed base of customers who rely on them for payment services. They are trusted as repositories of funds and financial intermediaries. And network externalities pose a formidable barrier to new entrants. At the same time alternative players establishing themselves in market niches consistent with the classic model of disruptive innovation are looking to expand from there into the mainstream payments space.

      Report Content
      • Alternative payments – background to the threat
      • Drivers of alternative payments
      • Alternative payments - serving niche markets
      • Micropayments
      • The un(der)banked
      • Alternative POS networks
      • Enhancing point-of-sale payments
      • Enhancing online payments
      • Enhancing payments with promotions
      • Integrating payments with the shopping process

      Who should read this?
      • CEOs, heads of retail banking, strategic planners, e-channels, IT and marketing managers of financial institutions
      • CEOs, strategic planners, marketing managers of alternative payments providers
      • Consultants, analysts and industry observers
      • What are they looking for?
      • To understand alternative payments and the potential threat they pose to banks’ position in retail payments, initiatives underway and solutions available to allow banks to respond to this threat.
      • To understand the current state of the industry and what alternative payments mean to banks.
      • To deepen their understanding of the potential impact of alternative payments on the financial services industry and the industry’s response.

      About the author:

      Ray Cain is a researcher specialising in banking and finance. He holds a post-graduate Diploma in banking and a Master of Management in banking from Massey University in New Zealand. He is also studying for a PhD in economics at the University of Fribourg in Switzerland. During his working career, he has held management and consulting roles in economic development projects in Indonesia and Serbia.


      Wyndham Hotel Hack Followup



      Here's a follow-up to the Wyndham Breach

      It seems that the criminals not only were able to get guest names, credit card numbers and expiration dates,  but they also were able to steal the data from the card's magnetic stripe, Wyndham said.  That magnetic stripe information contains Track 1 and Track 2 data including the (CVV) code, "which is critical if the thieves want to make fake credit cards, according to Avivah Litan, an analyst with Gartner Research."

      "That's the hot information," she said. "You can sell that information for much more on the black market." CVV codes were also taken in the high-profile Heartland Payment Systems and The TJX Companies credit card thefts.

      When fraud is perpetrated using fake cards that include the CVV codes, the banks are responsible for the charges;

      When they are able to obtain only the card numbers and expiration dates -- for example,online transactions NOT DONE by HomeATM --
      then the retailer is responsible for the charges.

      "The banking industry is all up in arms whenever bank stripe data is stolen," Litan said.  

      As posted in "DumbPhoneded" the retailers should be up in arms everytime a transaction is conducted without the  Track 2 data being swiped.  Not only are they paying up to 100 basis points more, but in the face of increased fraud, they could lose their product and lose the money they thought they got for it.  Call that a double whammy, no cheese.




      Reblog this post [with Zemanta]

      Wednesday, February 18, 2009

      Dumbphoneded...

      So you say that you can't wait for mobile payments eh? 

      Well, in an article published by Kelly Jackson Higgins of DarkReading.com, (Smartphone Risks Intensifying)  quoting research from  McAfee, you might want to wait until they figure out how to make those Smartphone's more secure. 

      I say we tackle the Internet payment problems first, then  move  on to mobile.

      M-Payment supporters cite convenience as the thrust behind the interest in mobile payment. 

      Convenience may be nice but it's way overrated.  Anyone who argues that convenience is the number one driving force behind the popularity of a payment methodolgy simply doesn't get it.   Security is the key and convenience arrives at the expense of security.  (How convenient is airport check-in and boarding post 911?  Yeah, quite the "departure" from convenience, is it not?)  Allow me to provide another analogy.


      Would it not be of the "utmost" convenience for you and your family to get in and out of your house, (along with your relatives and/or neighbors who want to come and pay you a visit) if you always left the front and back doors of your house unlocked?  Sure it would. 

      Then why don't we do it?

      It's because that very same convenience comes at the expense of security which in turn, would also be likely to attract malicious characters.

      On the flipside, if you always locked your door, you may occasionally be  "inconvenienced" by having to fumble around in your coat-pocket or purse, looking for (those damn) keys. 110% inconvenienced if you've ever lived in the US/Midwest in January, I might add. 

      But we go through these same insanely inconvenient motions everyday anyway. Why?  Because it's worth it to us have the peace of mind in knowing that it's safe.   Why should it be any different with securing payments?  Don't the bad guys want to get into our house to steal our money?  Don't we use money to make payments?   

      (BTW, I know we used to leave our doors unlocked back in the "Leave it to Beaver" days, but sadly, even prior to "Beavis & Butthead" becoming the number 1 movie in America {which marked the day I started locking my doors, heh heh heh...}, it became a much different world out there.  

      We threw convenience out the window and not only started locking our doors, but also the very window we threw convenience out of...along with locking our garages, our bicycles, blah blah blah...etc. etc. etc.) 

      So, convenience is not really the core issue.  Risk and security are.
       

      So the question begs to be asked: When will retailers understand that because fraud is rising exponentially (a trillion last year) and because it's them who are always the one's getting stuck with the bill, maybe it's time to stop complaining about Interchange and time to "implement change."   I would argue that it's time to "take charge" and stand up and fight.  Instead of being responsible for chargebacks and fraud, take responsibility and implement and push a more secure (thus lower interchange) payment method.  (such as the one afforded by HomeATM?  You betcha!) 


      Face it, consumer's only want convenience in the face of zero liability.

      V/MC knows that, which is why they have implemented their so-called "zero liability" programs...to make consumers feel like they have no risk of exposure.

      Heck, if my auto insurance had a zero liability program, I'd never take my keys out of and never lock the door to my car.  Wouldn't it be nice if you never had to look for your car keys or worry about losing or leaving them somewhere?  They'd always right where you left them, right where they need to be...in the ignition.  If that isn't convenient, I don't know what is.  So why don't we do it if it's "all about convenience?"  Because it's not.  It's all about safety, security and protection.
       

      The bottom line, is if you ask anyone who has had their purse,wallet or ID stolen, it's a very time consuming, aggravating and frustrating effort to deal with all the financial institutions, credit bureaus' etc. to right the ship.  Not one would say they found the process to be anything but "inconvenient." So one could argue that there are some "untruths that lie" beneath the zero-liability programs pushed by V/MC. Imagine that. 

      Even worse, on the flip-side, (of zero liability), it's the merchants whom are almost certainly always at risk. We'll call that program the "100% Full Liability Merchant Left Holding the Bag Program."  They're the one's liable for fraud, chargebacks, thefts, etc.  It's no secret that V/MC has them by the bollocks because they can't afford to NOT take credit cards.  Or can they?

      With the decline in credit card usage and the rise in debit card usage, now may be the perfect time to make a move and switch over to a more secure payment mechanism.  What is a more secure payment mechanism? 

      For one, Card Present is more secure than Card Not Present.  That's the singular purpose of HomeATM's personal swiping device...to facilitate card present transactions.  Wait, there's a dual purpose to our "slider" as we take it a step further in order to provide "dual authentication" Therefore, we have incorporated a PIN Entry Device into our "slider."  Why?  To make it more convenient for people who want a secure transaction.

      According to this months issue of Card and Payments,

      "PIN Debit transactions have lower fraud rates because of the required PIN, while signatures are relatively easy to forge.  Betwen 2005 and 2007, the average fraud cost on PIN Debit transactions was 1.09 cents per $100 of card spend compared with 5.4 cents per $100 of card spend on signature debit transactions."       

      Through HomeATM, online retailers now have a choice.   A choice whereby they can increase security, reduce risk, hence interchange fees, virtually eliminate chargebacks and increase their bottom line...all in one fell swoop. 

      In these times of both fraud and economic frugality, you'd think, now more than ever, retailers would demand security over convenience.  Transactions don't have to be "inconvenient," they just should NEVER be insecure.
       

      Let's use HomeATM as an example...just how "inconvenient" is it to swipe a card into our Slider versus type in a 14 or 16 digit number, an expiration date and a CVV?  Most would agree that it's actually "more convenient" to "swipe vs. type."  One thing is certain...with HomeATM's E2EE, it's about a million times more secure.

      Anywho, I almost forgot...here's the article questioning the security behind smartphones...and always remember...hackers are smart too.  They figured out the insecurity behind web browsers, amounting, by at least one account, to $1,000,000,000,000 (one-trillion) dollars in losses due to cybercriminal activity.  That was in 1 (one) year. 


      Maybe we should secure the Internet with PIN before we start worrying about transacting with mobile phones. HomeATM feels it has already accomplished that task, having engineered a patented process that utilizes existing bank rails and provides end to end encrypted (E2EE) internet transactions. 

      But did you know that HomeATM has also engineered and is testing a secure SmartPhone PIN based (click pic to enlarge) E2EE mobile transaction platform?  More on that later. 

      Let's get this Internet payments mess fixed first...


           Smartphone Threats Intensify - DarkReading

      Enterprise data at risk, according to new McAfee report, which shows mobile device manufacturers seeing more malware attacks than ever before.  IEditor's Note:  Oh yeah?  Wait til Next Year!)

      By Kelly Jackson Higgins - DarkReading

      Security threats were bound to catch up with the proliferation of smartphones across the enterprise. More than half of mobile device-makers said their products experienced malware, voice-, or text spam attacks last year, according to a newly published report from McAfee.

      Experts have long warned that smartphones, such as Windows Mobile and iPhone handsets, could become the new weakest link in the enterprise, with more users relying on them for accessing corporate email, surfing the Web, and other applications. "[Users] want to do everything on them," says Stewart Allen, a Toronto-based independent consultant. "But they are [typically] completely bypassing the IT infrastructure." They are also bypassing security, he says, putting sensitive data at risk.

      McAfee's report, which is based on a survey of 30-plus mobile device manufacturers from around the world, found these vendors are getting hit with more malware attacks than ever before. As a result, they are spending more money on recovering from them.

      Nearly 55 percent said network or service-capacity problems have ensued due to mobile security incidents -- up from 25 percent in 2007. Around half said third-party application/content problems had plagued their devices last year, up from around 25 percent in 2007.
      Around 48 percent said their devices accounted for data loss problems, up from around 27 percent in 2007.

      Continue "DarkReading"

       , , ,














      Reblog this post [with Zemanta]

      1 in 8 UK firms lose 5% of Revenue to Fraud


      Computer Business Review

      Business left to fight online fraud
      By Kevin White

      Lacks government coordination: security vendors

      Businesses are largely being left on their own to counter financial fraud, security companies have agreed.

      In a newly issued study CyberSource has said its findings highlighted online retailers’ frustration at the lack of coordination and government support in the fight against fraud.

      It concluded that merchants continue to bear the increasing burden of fraud.

      In the absence of any recommendation in the report for the creation of a centralised anti-fraud body to coordinate efforts across the financial and enforcement industries, Yuval Ben-Itzhak CTO at secure web gateway supplier Finjan Inc said is clear that companies are on their own.

      Although technology can significantly mitigate the risk of a company’s systems being breached,
      it appears that as many as one in eight online UK firms are losing more than 5% of their revenues to fraud...this illustrates the phenomenal cost that card fraud is costing UK organizations...

      Continue Reading at CBR




      Reblog this post [with Zemanta]

      V/MC to Slash Expenses, Increase Prices

      Standard  and Poor - "The companies have not been run very tightly"

      Reuters is reporting that Visa and MasterCard are slashing expenses and increasing prices.  I
      NEW YORK (Reuters) - As cash-strapped U.S. consumers think twice before buying a coffee or a newspaper, and banks fight for survival, Visa Inc and MasterCard Inc are cutting costs to sustain earnings.

      In their latest quarterly results, the world's largest payment networks beat expectations by slashing expenses and increasing prices.

      That contrasts with previous periods when the companies could rely more for growth on people switching to electronic payments from cash for an increasing number of transactions.

      That trend had Mastercard and Visa in the sweet spot of the credit and debt card industry -- getting paid each time a transaction took place on their branded cards while not having to deal with the risks of consumers defaulting that are faced by the credit card issuers.

      Rising defaults have led to mounting charges for the issuers, such as Citigroup Inc or Bank of America Corp, which are major clients of Visa and Mastercard. American Express is both an issuer and a payments company.

      Governments around the world have bailed out many of the battered banks, making it more difficult for the credit card-payment networks to raise the prices they charge them for transactions.

      "Most likely, the bottom line will benefit from cost cuts (rather) than growth in volumes," said Michael Kon, an analyst at Morningstar

      "The companies have not been run very tightly and there is room to cut," said Standard & Poor's analyst Stuart Plesser.

      The article goes on to say that Visa, which slashed expenses as part of a restructuring plan to integrate the former U.S., Canada and international operations into one company, has accelerated the pace and expects to finish that plan -- which will save $300 million in 2009 -- a year earlier than expected.

      Editor's Note:  I didn't see where they stated they'll increase prices, however, that usually happens in April anyway when new Interchange Rates come out.   It'll be interesting to see what happens this year when the new rates are released.  Regardless, if you'd like to save up to 100 basis points off of Interchange, you can make the switch to HomeATM's E2EE Internet PIN Debit platform.  





      , , , ,

      Prepaid Not Good Solution to Combat Fraud

      Yesterday I touched upon an article in the Telegraph.co.uk about whether or not Prepaid Cards could keep fraudsters at bay. She wondered if prepaid cards were the solution to rampant fraud.  In that post, which I entitled "Can Prepaid Cards Be Loaded by Hackers?" I stated that I didn't think so, because it is much easier to produce a $50.00 counterfeit prepaid card than to produce a counterfeit $50 bill.  Therefore I imagined that hackers have probably got close eye on the prepaid industry. 

      As it turns out, only one day later, there's a report that prepaid Visa gift cards are being targeted by the bad guys.  Here's that video report from KTEN.



      Visa Gift Cards Turned into Phony Credit Cards





      Reblog this post [with Zemanta]

      Tales from Encrypt

      Prediction: "Encryption" is going to wind up being one of the biggest buzz words of 2009.  End to End Encryption (E2EE) more specifically.   There are some seriously nasty hackers with some seriously nasty approaches and companies that don't secure their data are, simply put, the walking dead.  

      Last week I posted about a company named  Voltage Security who announced that their SecureData program now provides end-to-end-encryption or E2EE.  (I also made mention of the fact HomeATM has provided E2EE since January of '07, so it's been a buzz word for us at HATM for quite a while now) 

      Yesterday Voltage Security announced that Wells Fargo has agreed to implement
      Voltage SecureMail™, their Identity Based Encryption email solution.  That's not only a "good get" for Voltage, but it probably paves the way to "securing" other Financial Institution's as clients.    Watch out for Zombies! 

       

      Voltage Security Protects Email at Wells Fargo
      Palo Alto, CA --  Voltage Security, the global leader in information encryption, today announced that Wells Fargo & Company, (NYSE: WFC), has selected and deployed Voltage SecureMail™ to secure email communications between Wells Fargo team members, customers, vendors and extended business partners.

      Voltage SecureMail was selected and deployed by Wells Fargo because of the following:

      1. Ease of adoption by team members, and customers.
      2. Lowest total cost of ownership; there are no directories, certificates, or duplicate systems to manage.
      3. Ease of Integration with the pre-existing messaging environment.

      “We see secure communications as a mission critical part of our overall business strategy and a valued service to enable our customers to interact with the bank,” said Steve Ellis, executive vice president of Wells Fargo’s Wholesale Services Group. “With Voltage, our team members, customers, and business partners can interact online in a secure simple manner,” said Ellis.

      “Wells Fargo’s deployment of
      Voltage SecureMail has quickly grown to be one of the largest use cases of secure email in the world,” said Sathvik Krishnamurthy, president and CEO of Voltage Security, Inc. “Voltage SecureMail, powered by Identity-Based Encryption (IBE), is the only solution that scales to this level across very large, complex extended business networks,” continued Krishnamurthy.

      In the past, secure email systems at the financial services company went largely unused because inherent complexities in the user experience. Voltage provided a solution that is essentially invisible to internal team members and extremely easy to use for external recipients.

      About Voltage Security
      Voltage Security, Inc., an enterprise security company, is the global leader in information encryption. Voltage solutions, based on next generation cryptography, provide encryption that just works for protecting valuable, regulated and sensitive information persistently and based on policy. Voltage delivers power, simplicity and the lowest total cost of ownership in the industry through the use of award-winning Voltage Identity-Based Encryption™ (IBE) and a new breakthrough innovation: Format-Preserving Encryption (FPE). Voltage Security offerings include Voltage SecureMail™, Voltage SecureData™ and the Voltage Security Network™ (VSN), an on-demand managed service for the extended business network.

      Voltage Security is the number one OEM provider of email encryption technology in the world with OEMs that include Microsoft, Proofpoint, Secure Computing, Sendmail, Canon, Code Green Networks and NTT Communications. The Company has been issued several patents based upon breakthrough research in mathematics and cryptographic systems. Customers include Global 1000 companies in banking, retail, insurance, energy, healthcare and government, such as American Board of Family Medicine, Diebold, Integro Insurance Brokers, NTT Communications, SafeAuto Insurance, Winterthur Life UK Ltd. and XL Global Services. For more information please visit http://www.voltage.com.

      ###

      Source: Press Release


      Reblog this post [with Zemanta]

      Tuesday, February 17, 2009

      How To Hack an ATM Part II

      Last Wednesday I did a post on How to Hack an ATM.  Apparently using ATM Bombs is more common that one would have thought. 

      Sydney gets hit again by explosive ATM raiders 

      (Melbourne, Australia) Herald Sun:



      ATM raiders have blown up another ATM in Sydney, the third attack in less than a week. 


      Police said the ATM was extensively damaged, but it was not known if any cash had been taken. A spate of ATM blasts across New South Wales and Queensland has prompted the formation of a special police task force.




      Reblog this post [with Zemanta]

      UATP and Alternative Payments - DTN


      UATP Keeps Its Eye on Alternative Payments—and Hotels

      (February 17, 2009)

      Universal Air Travel Plan Inc. is still in growth mode despite some weakness in its core corporate travel business, thanks in part to an ongoing alternative online-payments initiative that started in 2005. Now the specialty payment processor is looking to sign hotels as merchants.

      Processing volumes rose about 20% last year for Washington, D.C.-based UATP. “In 2007 we broke the $10 billion mark; in 2008 we were at $12 billion,” president and chief executive officer Ralph Kaiser tells Digital Transactions News by e-mail. “Our profitability is not public, but suffice it to say 2007 was a good year and 2008 was even better.”

      UATP has 19 airline shareholder-owners worldwide. Thirteen issue its card, and its brand is accepted by nearly 250. Online payment systems are an increasingly important part of the mix as UATP seeks to offer airlines new product offerings beyond its core corporate travel card, especially ones that cost the carriers less to accept than general-purpose credit cards (Digital Transactions News, Aug. 20, 2008). Already accepted or planned payment brands usable through UATP include PayPal Inc., Bill Me Later Inc. (recently acquired by PayPal parent company eBay Inc.), Moneta Corp., the PIN-based specialists HomeATM and Acculynk Inc., and prepaid cards through Ceridian Corp.’s Stored Value Solutions....

      Continue Reading at Digital Transactions




      , , ,

      A Billion Internet Users



      eMarketer.com is reporting that Internet users surpassed the billion landmark in December.   China's number 1, but it is predicted that #7 India will eventually surpass #2 United States.  That surprised me a little bit.  Here's what eMarketer has to say about the comScore World Metrix...  (You may click the graphics to enlarge.)

      FEBRUARY 17, 2009

      Growing and growing and growing and...

      The moment when the Internet passed 1 million users is veiled in history.

      The truth is, whenever it happened, no one was counting—or even had the means to do so. But according to the “Internet Growth Survey” from MIT, there were 1 million hosts (defined as either a computer or IP address) in 1995.


      At the time, it was estimated that the Internet was doubling in size every year, so there would be over 1 billion users in 2005.

      That timeline proved overly optimistic. But according to the comScore World Metrix audience measurement service, the Internet surpassed 1 billion visitors in December 2008.

      “Surpassing 1 billion global users is a significant landmark in the history of the Internet,” said Magid Abraham, comScore CEO, in a statement. “It is a monument to the increasingly unified global community in which we live and reminds us that the world truly is becoming more flat.”

      comScore got to a billion users without counting access from Internet cafes, mobile phones or PDAs.

      By contrast, eMarketer employs a slightly broader audience definition—access by anyone of any age from any location—to estimate that there were 1.172 billion Internet users worldwide in 2008.

      Either way you count, one thing few prognosticators foresaw in 1995 was that the US would have only the second-largest online population when the Internet hit the billion-user mark. China ranks No. 1.

      The Web still has plenty of room to grow.

      “China has taken the lead in the number of Internet users worldwide, and today only about 20% of its residents are online,” said Lisa E. Phillips, eMarketer senior analyst. “While China will continue to lead the world in Internet users, look for India to eventually overtake the US, Japan and Germany.”

      While Internet usage is close to saturation in the US, Japan and Germany, India’s Internet population lags behind its status as the second-most-populous nation on earth. “But eventually India’s Internet population will grow large enough to overtake those smaller countries that are now in the top spots,” Ms. Phillips continued.
      “The second billion will be online before we know it,” said Mr. Abraham, “and the third billion will arrive even faster than that.”

      See all that’s happening in digital marketing and media around the world, look into an eMarketer Total Access Subscription for your company today.





      Reblog this post [with Zemanta]

      The Cost of PCI Compliance - Element Payment Services Blog





      In a great informational post provided by the PCI DSS Compliance Blog, published by Element Payment Services they talk about the cost of PCI compliance. 

      I had the pleasure of working with Sean Kramer,  the founder and CEO of Element Payment Services, when he was with Concord EFS.  We jointly provided an innovative payments package/solution for U.S. FoodService members.  I am happy to see (but not surprised by) the growth enjoyed by Element.  It couldn't happen to a nicer guy!  Congrats to Sean and his team, including Roy Bricker who previously worked at Pay By Touch.

      Here's their post: 

      PCI DSS Compliance Blog: Cost of PCI Compliance
      Cost of PCI Compliance

      'What does it cost be PCI compliant?’ is a common question by business owners and software providers facing compliance requirements. Several estimates have been generated by industry leaders on PCI compliance costs.

      For Merchants (Complying with PCI DSS)

      IT security firms Solidcore Systems, Emagined Security and Fortrex Technologies have identified three main categories of PCI compliance costs:

      • Upgrading payment systems and security infrastructure,
      • Verifying compliance (assessments), and
      • Sustaining compliance.

      New components that might have to be installed to upgrade payment systems and security infrastructureWorld image include additional firewalls, upgraded anti-virus and anti-spyware software, secure wireless systems, data encryption technologies and file-integrity monitoring software.

      Compliance assessments include the PCI Self-Assessment Questionnaire (PCI SAQ) for Level 2, 3 and 4 merchants and an on-site audit for Level 1 merchants.

      In 2008, IT research giant Gartner reported that merchant spending to protect cardholder data and become PCI compliant increased nearly fivefold during the previous 18 months. Among the Level 1 retailers Gartner surveyed, an average of $2.7 million was spent to become PCI compliant, excluding the costs of PCI assessment services. That number compares with an average of $568,000 reported by Level 1 merchants in a fall 2006 Gartner survey. Level 1 merchants spent an average of $237,000 on PCI security assessments.

      Level 2 merchants reported spending $1.1 million on PCI compliance (compared to $267,000 in fall 2006) and an average of $135,000 on assessment. Level 3 merchants, those processing between 20,000 and one million transactions per year, spent an average of $155,000, excluding security assessment. Gartner did not discuss Level 4 merchants in the report.

      For Software Developers (Complying with PA-DSS)

      To achieve PA-DSS compliance, software providers must undergo the lengthy and costly process of validating their application. This involves a security audit from a PA-DSS Qualified Security Assessor (QSA) and the development time and expense to bring the application into compliance. These PA-DSS certification costs can range from tens to hundreds of thousands of dollars.

      Additionally, software providers are required to pay $1,250 annually per software application to have their solution listed as a validated PA-DSS-compliant solution.

      To visit the PCI DSS Compliance Blog click here.  Element Payment Services site is located at: www.elementps.com








      Reblog this post [with Zemanta]

      Can Prepaid Cards Be Loaded by Hackers?

      Kara Gammell writes in today's Telegraph.com.uk about prepaid cards and questions whether or not they would provide more protection than credit or debit cards and entice 50% of the UK population to shop online in an article entitled: "Will Prepaid Cards Keep the Fraudsters at Bay?" 
      "More than half of the population are so worried about becoming a victim of fraud that they refuse to shop online. The research, conducted by CyberSource, a company specialising in electronic payments, said that one in three respondents knew someone who had been the victim of fraud.

      But for these reluctant shoppers, a prepaid card might just be the answer.

      A prepaid card looks just like a normal credit or debit card, and enables you to buy products and services where ever these cards are accepted.

      The main difference is that you can only spend the balance that has been preloaded onto it. This means there is no risk of running into debt as it has no credit or overdraft facility and crucially, the card has none of your personal bank details attached to it.

      In the beginning prepaid cards were used by parents to manage their children's spending habits and the market has been typically has been dominated by Mastercard and Maestro. But now a number of rival cards have appeared, targeting everyone from overseas travellers, nervous online shoppers to new mothers.

      Andrew Hagger, spokesman for Moneynet.co.uk, said: "Prepaid credit cards allow such people to be part of the modern day 'plastic culture' which allows you to take advantage of online shopping discounts as well as access to hugely popular sites such as eBay."

      For those shoppers who are hesitant about spending on the web, this type of card could help reduce the potential for fraudsters to steal your personal details.

      Mr Harrison said: "The risk with a credit card is that the fraudsters will be able to max out your card, where a prepaid card is almost like a pay-as-you-go mobile phone. The only money that can be stolen, is the money you have loaded on.

      "And unlike a debit card, a prepaid card does not have any link to your bank account or address, so the chance of fraud is next to none."

      Editor's Note:  The problem the UK is having is with cloning/counterfeit cards.  I would imagine that hackers have their eye on the prepaid market as it is readily more easy to counterfeit $50 cards than $50 bills.

      How do prepaid cards work?

      Money – typically up to £5,000 – can be loaded on to a prepaid card by cash at a bank, Post Office, at Pay zone or PayPoint terminals, bank transfer, through your employer or even by another credit card.  Editor's Note:  or even by a hacker using a stolen credit/debit card! 

      Continue Reading




      , , ,

      Aconite Extends Chip & PIN Support to Banks in Middle East


      Aconite extends Chip & PIN support to banks in the Middle East

      London, 17th February 2009

      New webinar provides guidance to banks as they prepare to roll out Chip & PIN cards

      London, 16th February, 2009: Aconite, a leading provider of software and consulting services for managing business applications on chips in smart cards, tokens or mobiles, is running a webinar to provide timely support to banks in the Middle East in light of recent increased pressure from Central Banks in the region on banks operating locally to implement Chip and PIN cards. These mandates, issued in the United Arab Emirates, Kuwait, the Kingdom of Bahrain and Saudi Arabia for example, require banks to quickly deploy chip technology to increase card security and reduce fraud. And whilst some countries have been mandated to migrate, neighbouring countries will also feel the pressure to increase security on their cards as fraudsters target lesser protected card schemes.

      The complimentary webinar entitled “Your guide to introducing Chip & PIN cards” will provide practical advice and highlight important considerations to assist card issuers in making a smooth transition to Chip & PIN cards. The webinar programme will be led by Aconite’s David Worthington, Regional Manager for the Middle East and Bev Stevens, Senior Consultant. Collectively, they have over 25 years chip experience and have delivered various EMV and consulting projects in the Middle East. This includes assignments at numerous banks across Bahrain, Kuwait, Jordan, Oman, Qatar, Saudi Arabia and the UAE, as well as periods spent working directly for KNET and SAMA.

      David comments “Aconite is well placed to assist banks taking up this challenge as the company’s team has been engaged in the migration of chip technology since the first pilot of chip cards in the UK in 1993. Through hands-on international experience, we have gained a thorough understanding of every stage of the migration process; our aim is to share best practice to make the migration process for card issuers in the Middle East as straight forward as possible”.

      The webinar is schedule for 11am GMT on Wednesday, March, 4th. For more information or to register for the webinar please visit:
      www.aconite.net/newsEvents/webinars.aspx.

      I've provided further information about the Aconite webinar below:

      "Your guide to introducing Chip and PIN cards in the Middle East"

      Overview

      It was recently announced that the UAE Central Bank has requested that all banks operating in the country are required to upgrade their ATM cards to Chip & PIN cards to reduce the risk of debit and credit card fraud, whilst in the Kingdom of Bahrain, the Central Bank of Bahrain has also issued mandates for Chip & PIN implementation for both Issuers and Acquirers. Whilst some countries are being driven to increase the security of their card base by such national mandates, neighbouring countries will quickly feel the pressure to follow suit as fraudsters will inevitably target lesser protected card schemes.

      As a card issuer in the Middle East, what exactly does that mean from you? What are the cost implications? And just how do you go about embarking on such a migration project?

      Aconite has been helping financial institutions define their Chip & PIN strategy since the very first chip pilot in the UK back in early 1990s. We would like to share with you practical advice and considerations to help you make a smooth transition from magnetic stripe to chip cards.


      Reblog this post [with Zemanta]

      330+ Banks Impacted by Heartland Breach as Numbers Climb

      Heartland Data Breach: More Than 330 Institutions Impacted
      Bermuda, Canada and Guam Now Report Effects from Breach

      Bank Info Security is reporting that more than 330 Financial Institutions have reported that they are being impacted by the Heartland Payments Systems Data Breach.

      From their site:
      "The Heartland Payment Systems [HPY] data breach is the first major information security incident of 2009. As first reported on Jan. 20, Heartland, the sixth-largest payments processor in the U.S., revealed that its processing systems were breached in 2008, exposing an undetermined number of consumers to potential fraud. Since then, a growing number of banking institutions have stepped forward to announce that their customers were among those affected by the breach."

       see a full list of all the affected institutions, click here



      Reblog this post [with Zemanta]

      Biometric Facial Authentication Hacked


      Researchers Hack Faces In Biometric Facial Authentication Systems - DarkReading
      Vietnamese researchers have cracked facial recognition technology in Lenovo, Asus, and Toshiba laptops; demonstration planned for Black Hat DC next week

      By Kelly Jackson Higgins
      DarkReading

      A Vietnamese researcher will demonstrate at Black Hat DC next week how he and his colleagues were able to easily spoof and bypass biometric systems that authenticate users by scanning their faces.

      The researchers cracked the biometric authentication embedded in Lenovo, Asus, and Toshiba laptops by spoofing the biometric systems with everything from a photo of the authorized user to brute-force hacking using fake facial images. They successfully bypassed Lenovo's Veriface III, Asus' SmartLogon V1.0.0005, and Toshiba's Face Recognition 2.0.2.32 -- each set to its highest security level -- demonstrating vulnerabilities in the systems that let an attacker cheat them with phony photos of the legitimate user and gain access to the laptops.

      Editor's Note:  Guess it's time for HD-3D webcam's eh?

      These Windows XP and Vista laptops come with built-in webcams that work with the facial-recognition technology. This form of authentication is considered more convenient than fingerprint scans and more secure than traditional passwords. The software scans the user's face and stores the images and facial characteristics. Then the user can log in by scanning his or her face, which is then matched against the image data.

      Continue "DarkReading"


      Accumulate Strengthens Mobile Credit Card Transaction Security


      Barcelona 2009 Accumulate strengthens security of credit card transactions via the mobile
      Presse Anglaise

      The launch of the ME-platform and the Check ME product enables enhanced security and opens up for new, innovative and cost-effective services in payment and identification using the mobile phone.

      Barcelona, February 17, 2009 – At the Mobile World Congress 2009, Accumulate will launch its new mobile technology platform – Mobile Everywhere (ME). The platform is based on patented technology that enables new and innovative payment and identification solutions on the mobile device.

      The first product to be released from the Accumulate ME-platform is Check ME, which extends security and control features of the mobile phone, so that consumers can comfortably conduct credit card transactions over their device.

      “When online fraud increases, it hinders business opportunities. With the Accumulate ME-platform, card issuers and online shop owners can increase their business while greatly minimizing the fear many end-users have when using credit cards for online transactions”, says Stefan Hultberg, CEO of Accumulate.

      Check ME is based on the ME-platform and secures online credit card transactions using the mobile to verify and authenticate the user. Customers are typically credit card issuers such as banks. Key benefits are:

      • Mobile is always with you – increasing accessibility
      • As secure as token generators – eliminates need for extra device
      • No external storage of credit card data
      • Works with almost every mobile phone
      • Easy to use
      An example Check ME’s usage: A consumer makes a credit card purchase online, and authenticates her identity with a pin code provided to her via Check ME on her mobile.

      “The launch of the ME-platform and Check ME will be followed by additional new, innovative and cost-effective identification and payment services using the ever present mobile phone”, says Stefan Hultberg.

      ME-platform – the technology
      The core components of the ME-platform consist of a mobile client that is distributed to users and a back-end transaction server system. The ME-platform offers 3D security and uses a standard mobile phone as a security device, making truly secure authentication accessible for the masses.

      For each transaction two separate lines of communication are established – simultaneously – between the customer and the service provider, using two different communication systems: the mobile phone and computer-to-computer communication via the Internet. The end users use their regular computer and standard cellular phone. The service provider sends encrypted information – and receives encrypted reconfirmation – using their web server, and an external transaction service.

      The ME-platform products currently work on all major mobile platforms including Android, Blackberry, iPhone, Java, Linux, Nokia Series 40/60 and Windows Mobile.

      Visit Accumulate at MWC 2009
      If you would like to meet Accumulate in Barcelona, just send a mail with your request to info@accumulate.se Cette adresse email est protégée contre les robots des spammeurs, vous devez activer Javascript pour la voir. . We will reply with more information on where and when to meet.

      More information
      Stefan Hultberg, +46 70 350 5704, stefan.hultberg@accumulate.se Cette adresse email est protégée contre les robots des spammeurs, vous devez activer Javascript pour la voir. .

      About Accumulate
      Accumulate – world leading provider for secure connected mobile solutions. For more information please visit www.accumulate.se or contact us in Stockholm or London.
      London office: Accumulate UK Limited, 306 Harbour Yard, Chelsea Harbour, London SW10 0XD, United Kingdom. Phone + 44 207 351 5944
      Stockholm office: Accumulate AB, Norrlandsgatan 23, S-111 43 Stockholm, Sweden. Phone +46 8 20 46 15




      Reblog this post [with Zemanta]

      Nominations Open for Outstanding Smart Card Achievement Awards



      Nominations Open for Smart Card Alliance 2009 OSCA Awards

      PRINCETON JUNCTION, NJ, February 17, 2009 –The Smart Card Alliance will once again honor the companies and individuals who have significantly impacted and influenced the market for smart cards in North America with its prestigious “Outstanding Smart Card Achievement” (OSCA) awards.

      The 2009 OSCA awards will be presented during the Smart Card Alliance 2009 Annual Conference held in conjunction with CTST 2009 – The Americas Conference on May 4 - 7, 2009 in New Orleans. Complete details and nomination forms can be found at http://www.smartcardalliance.org/pages/activities-osca-awards. All nominations must be received by March 20, 2009.

      Nominations are open in three award categories – two for organizations and one for an individual.

      • Outstanding Issuing Organization Award. For an organization that is issuing smart card technology to its internal clients or external customers for their use in North America.

      • Outstanding Technology Organization Award. For an organization with offices in North America that designs, develops or manufactures smart card technology; or that integrates, designs or implements systems in which smart card technology as an important part of an overall solution; or that provides services that support smart card usage in North America.

      • Outstanding Individual Leadership Award. For an individual who stands out for his or her individual contributions to the smart card industry in North America based on a professional record of leadership, vision, support and commitment to the smart card industry in North America.
      A judging panel consisting of North American smart card industry suppliers, end-users and individuals from the analyst and media communities will review all qualified OSCA applications. They will select three finalists in each category based on the nominee’s merits and qualifications as outlined in the applications and determine the award for 2009.

      Visit the Smart Card Alliance Web site to see the 2008 OSCA Award winners.
      Reblog this post [with Zemanta]

      CheckSavers Plans Rollout

      Check Savers (www.checksavers.com) is pleased to announce the planned 2009 rollout of its new payment technology.  Click their comparison chart on left to enlarge.

      Check Savers uses a patented technology to receive data over the web and create payment items which get deposited directly into merchants’ accounts.

      The payment system developed by Check Savers has taken the best features from traditional payment methods - credit cards, ACH and checks in order to bring a comprehensive solution suitable for any industry.

      At a reduced operating cost of approximately 25% to 50% of the price of credit card acquiring, and elimination of traditional chargeback exposures, merchants have more protection in their business operations than ever before.

      "We have predictable pricing models ensuring that companies can accurately forecast their operating costs. This feature, coupled with enhanced fraud management and the fact that companies can use their existing banking relationships, means that we truly have a merchant-centric product. Companies can now promote sensible spending across their client base, whilst at the same time pass on significant savings to their clients; something which is not lost in the financial climate of 2009" Teo Leonard - Operations Director

      It has been commonly misinterpreted as ’another Check 21 product’ . Check Savers provides a whole new concept in acquiring technology; a single solution for all bill payment, acquiring and invoice management is now at your fingertips.

      Government, non-profit and traditional commerce industries, contact us to see how we can fit into your world.


      Reblog this post [with Zemanta]

      Disqus for ePayment News