Monday, June 1, 2009

Canadian Payment Processor Screws Online Gambling Websites

Payment Processor Screws Online Gambling Websites | Gambling911.com

There is outrage in Costa Rica after a Canadian-based payment processor has reportedly screwed over a dozen online gambling sites out of millions of dollars. 

Many of the Costa Rican based Internet gambling businesses were utilizing Smart Banking Systems (SBS), represented by one Ben Waldman. (Editor's Note:  I assume that it not the same Ben Waldman and SBS (Small Business Stick) who works at Microsoft)

"(Ben) Waldman provided the platform for another individual to screw everyone down here and their mother," said one angry operator. "He went through the whole crowd (of Costa Rican-based operators), then disappeared."

Smart Banking Systems bills itself as "Tomorrow's ATM and Credit Card Processing Technology Today"  They claim to be an independent sales organization/merchant service provider involved in the placement of Automated Teller Machines (ATM's) in retail locations and in the processing of Merchant Point of Sale Card Transactions (Visa, MasterCard, Amex, Discover).

"I am owed several hundred thousand dollars from this scumbag," said one operator, who wished not to be identified. Two other operators have notified Gambling911.com of the business practices of Waldman, Chris Connor (an alias) and Smart Banking Systems.

"Please get the message out about these pariahs. Everyone reads Gambling911.com and needs to know."

Since passage of the Unlawful Internet Gaming Enforcement Act (UIGEA), the online gambling sector has had a tough time finding "reliable" processing companies in which to conduct business with.

Christopher Costigan, Gambling911.com Publisher





Reblog this post [with Zemanta]

Alipay Up to 185 Million Registered Users

JLM Pacific Epoch - Alipay Breaks 180M Registered User Mark
Alipay Breaks 180M Registered User Mark

Alibaba Group's online payment subsidiary Alipay has recorded 185 million registered users, and its total transactions exceed more than RMB 700 million per day, reports 163.com quoting Alipay President Shao Xiaofeng on Wednesday. Alipay had recorded 150 million registered users, including 460,000 corporate users, by end of February.

Abu Dhabi Expects to Double Online Revenues by End of Year

Abu Dhabi government expects 35% of commercial transactions to be made online by 2012
The Abu Dhabi government estimates that its commercial transactions conducted online are to climb from 9 percent in 2009 to 35 percent in 2012, the online publication business24-7.ae reports.



Abu Dhabi is looking at doubling its online revenues to more than Dh40 million by the end of this year as the UAE capital embarks on a more aggressive marketing campaign, a senior government official said.

The Abu Dhabi Government aims that 35 per cent of its commercial transactions would be made via online by 2012. Currently, only nine per cent of the transactions are done via e-services.

"Last year, we had 9,000 transactions representing six per cent of the total commercial transactions. Although it's only six per cent we were nevertheless able to make Dh20m as income, which goes to the government," Abdalrhman Saif Al Khader, Head of Online Services Section at the Abu Dhabi Department of Economic Development told Emirates Business on the sidelines of the 15th GCC eGovernment and eServices
Forum.

He said the government is now looking at increasing the coverage to 14 per cent, which will in turn see more than Dh40m in revenues. Currently the coverage has risen to nine per cent from 6 per cent last year.

"The first two years are the most difficult, especially because most of the people are still not aware and some are
hesitant to use credit cards via online transactions. But we will meet the 35 per cent target by 2012," Al Khader said.


Source:
http://www.business24-7.ae


, ,

Reblog this post [with Zemanta]

HPY CEO to Speak at iapp Event

IAPP - International Association of Privacy Professionals - Carr gets to heart of it
Heartland Payment Systems CEO discusses breach, previews speech

Not a week had passed after the announcement of what some have described as the largest data breach ever, when the CEO of Heartland Payment Systems, Robert Carr, began calling for better industry cooperation and new efforts directed at preventing future breaches.

Recently, Carr announced that trials will begin late this summer on an end end-to-end encryption system Heartland is developing with technology partners. It is expected to be the first system of its kind in the U.S. The company is also pushing for an end-to-end encryption standard.

At the upcoming Practical Privacy Series in Silicon Valley, Carr will discuss the Heartland breach and the role industry, including privacy professionals, must play to prevent future breaches.

Here’s a preview:

IAPP: Many companies have experienced breaches. What made yours different?

Ours was different because we are a processor and had passed six years of PCI audits with no problems found. Yet, within days of the most recent audit, the damage had begun.

IAPP: Did you have a chief privacy office or a privacy professional on staff before your breach? Do you now?

Ironically, when we learned of the Hannaford’s breach, we hired a Chief Security Officer who started just three weeks before the breach began.

IAPP: In the era of mandatory breach reporting, what is the trajectory of consumer reaction?

As a processor it is difficult to really know this. Our customers are merchants who accept card payments.

IAPP: Do you think consumers will become numb to breach notices?

I believe that many are numb to so many intrusion notices.

IAPP: Are breach notices good public policy? Do the notices provide an incentive for companies to change or improve practices?

I don’t think so. Nobody wants to get breached and the damage caused by a breach is sufficient reason for most of us to do everything we can to prevent them.

IAPP: What has Heartland done differently since the breach?

We have added multiple layers of additional security, helped form the Payment Processors Information Sharing Council and ramped up our timetable to deploy the industry’s first TRSM encryption processing network.

IAPP: You will deliver a keynote at the IAPP Practical Privacy Series event in California next month. Can you give us a preview of your remarks?

I am going to discuss our breach and what we have done and are doing to help others prevent breaches to their own systems.


,

PayLeap Introduces PayLeap.com


PayLeap, an innovative online payment processing service, introduces its newly redesigned website--PayLeap.com. The new site reflects the company's commitment to finding the best way to serve its clients.

(PRWEB) -- PayLeap, a new and innovative way to process payments online, would like to formally introduce its newly designed website, PayLeap.com. The company is dedicated to serving its potential and current clients with the highest level of support, and the new website was designed with that philosophy in mind. Its enhanced usability is a direct reflection of the quality of the PayLeap payment solution and the company's high standards for customer service.

On the new site, users will find an intuitive navigation and clear design. Visitors are immediately directed, through color, design and content, to their area that will serve their needs best. Merchants, resellers and developers each have a dedicated section, just to provide topical information regarding the benefits of the PayLeap solution for their use. Along with a new online presence, the company also introduces a new logo, slogan and brand identity, brought to the consumer to better represent the customer-oriented philosophy of the company.

PayLeap lowers overhead processing costs and simplifies integration and billing by bundling the merchant account and payment gateway for brick-and-mortar and online merchants. Priding itself on service, the PayLeap mission is to be an outstanding corporate citizen in the electronic payments industry. Transparency, simplicity and service are the core values of the innovative payment processor.

###

Trackback URL: http://www.prweb.com/pingpr.php/U3F1YS1GYWx1LUhvcnItTG92ZS1IYWxmLUNvdXAtWmVybw==

See the original story at: http://www.prweb.com/releases/2009/05/prweb2464724.htm


SAN JOSE, Calif. -- EBay Inc. isremaking its e-commerce marketplace to combat declining sales. In theprocess, it has pitted merchants such as Jack Sheng and Walt Kolendaagainst each other.

Mr. Sheng describes his company, eForCityCorp., as a "mini Wal-Mart." It buys electronics accessories from Chinaand sells 4.3 million of them each year to people looking for dealsonline. After eBay made it cheaper and easier to list products in largequantities for sale last year, his eBay sales in April were up 46% froma year before. The site's changes have "helped good sellers come ...
Reblog this post [with Zemanta]

Top 6 Financial Services Fraud/Scams

BankInfoSecurity.com has published an article discussing the Top 6 Scams which Fraudsters utilize to attack Financial Institution customers:  To read the entire story, click here: Classic Fraud: 6 Scams That Don't Go Away

From Check Fraud to Phishing, All the Old Tricks are Back with a Vengeance
June 1, 2009 - Linda McGlasson, Managing Editor

Bank fraud has evolved over the last several years (See: Fraud Update: The 13 Hottest Schemes You Need to Prevent), but some classic variations keep financial institutions busy.

Here are six old fraud tricks that are back with new twists to bedevil fraud departments and information security professionals.

#1. Check Fraud


Since 1997, the number of fraud attempts against bank accounts has doubled every two years. Ever since the desktop publishing era began with color copiers and computer scanners, counterfeit checks have become harder to detect, which is reinforced in the number of checks the New York crime group spread among the various banks in the city over a two-year period. Banks routinely process more than 10 billion checks each year, says a 2007 Federal Reserve payments study.


#2. Elderly and Immigrant Identity Fraud
#3. ATM Fraud/Skimming


This type of fraud made it into President Barack Obama's speech announcing his cybersecurity initiative, when he said "thieves used stolen credit card information to steal millions of dollars from 130 ATM machines in 49 cities around the world -- and they did it in just 30 minutes." The big question is: Can it happen at your institution? The answer is seen in the numbers from a Pulse EFT study (Pulse is one of the leading ATM/debit networks in the U.S.) -- the banking industry lost $662 million to debit card fraud in 2005. Of these losses, 60 percent resulted from ATM transactions, 37 percent from signature transactions, 37 percent from signature debit transactions and 3 percent from PIN point-of-sale (POS) transactions.

While the same Pulse study done in 2007 doesn't give a total loss due to debit card fraud, it does say that is higher than in 2005. Survey participants said they lost 5.40 basis points (0.054 percent) per dollar spent through signature debit transactions in 2007 and 1.09 basis points (.0109 percent) through PIN debit transactions. All of the 62 financial institutions surveyed in the 2007 Pulse study had debit cards potentially compromised in skimmers, and more than 80 percent of those surveyed reported implementing new fraud tools within the past year.

Even with the new fraud tools, stopping criminals from placing skimmers on your institution's ATMs require vigilance and monitoring by your employees.


#4. Phishing
#5. Vishing
#6. Insider Threat


Illinois Lawmakers Approve Online Gambliing

While HomeATM was at ETA, we had the pleasure to meet with the folks from YouBet.com who are taking a look at our real-time payments solution.  With momentum beginning to build towards the reversal of UIGEA ban, (Barney Frank) it appears that some states are simply not going to take a wait-and-see approach on what the Federal Government decides.

Last week I wrote that California is weighing in on legalizing online gambling, meanwhile, Illinois lawmakers passed a Bill late last weekthat "will" allow online gambling. The Bill was passed in both the Houseand the Senate, and now only awaits the signature of the governor ofIllinois.  The new law will allow residents to bet on horse racesfrom the comfort of their own homes, through the Internet. The measureis being met with widespread excitement from people in Illinois.

State legislators were uncertain as to how the UIGEA ban might affectthe online gambling action in Illinois. Other states allowing Internetgambling, such as New Hampshire and North Dakota who use the Internetto sell lottery tickets, have found the payment block to inadvertentlyinclude programs it should exempt.

The new system will allow the establishment of online accounts. Wagerscould be placed from home computers, and winnings and losses dded anddeducted from the balance, just like barred online casinos.

The House voted 87-27 to pass the measure, just days after videogambling machines were legalized throughout the state. A bill seekingto expand casino gambling was voted down.

"Hopefullythis is only the first step," said Billy Cormate, " if we are allowedto bet on horse online, then we should also have the right to playpoker or play at an online casinos."
Reblog this post [with Zemanta]

Facebook begins testing virtual payments system

Socialnetworking site Facebook has begun testing its much-anticipated virtualcurrency payments system with third party application GroupCard.

Userswho want to buy a GroupCard e-card through the company's app are nowoffered the option of clicking on a "Pay with Facebook" button.

Theythen pay with their credits, worth 10 cents each. The currency can bebought - with a credit card - from the Facebook gift shop.The testing comes after Facebook updated its payments terms and conditions on Wednesday to pave the way for the platform.

Continue Reading at Finextra


Reblog this post [with Zemanta]

Saturday, May 30, 2009

3DES, DUKPT & E2EE Explained


I received a couple questions via email and wanted to take the time to provide a "coupla" of answers. If you have any questions about anything I've blogged about over the past year, feel free to shoot me one. I've got my email below:

Here's the first question:

Q: Is Triple DES a better encryption standard than DUKPT? (Derived Unique Key Per Transaction)?

A: I've used the terms Triple DES and DUKPT quite a bit in recent posts. To clarify, let's just start by saying that DUKPT does not really compete with Triple DES. Let's go over them one by one.

Worldwide, POS devices handle billions of transactions per day. If the keys to even a small portion of that traffic was discovered, we'd have a tremendously huge problem. Which is my segway to DUKPT.

The benefit of DUKPT is that even if an attacker discovered the key to a particular transaction, none of the other transactions from the same device could be decrypted with that key.

The DES stands for Data Encryption Standard, a block cipher that was selected as an official Federal Information Processing Standard (FIPS) for the United States in 1976.

Triple DES, sometimes shortened further as 3DES, increases the difficulty of cracking the encryption by applying three rounds of action: an encryption, a decryption and an encryption, each with independent keys.

3DES has become popular for encrypting financial transactions because it is potentially far more secure than DES, which has been shown to yield its secrets somewhat quickly to relatively cheap hardware.

Both DES and 3DES use a symmetric key. In other words, the same key enciphers and deciphers the protected data. To keep the key secret, a secure key-management system is required.

One way to prevent fraud is to use a different key for "each transaction," (Derived Unique Key Per Transaction) HomeATM's secure devices (and thus your transactions) are "Protected by DUKPT" and each one is initialized with a master key. The master key is from which the unique keys are derived, one for each"per" transaction.

That said, a potential attack point (from a fraudster) would be the master key stored in the encrypting device. However, because HomeATM utilizes DUKPT, our device is built so that tampering with the device wipes this master key out.

These derived keys are used to encrypt transaction data with a symmetric cipher such as 3DES. HomeATM also takes it one step further and encrypts the Track 2 data as well. If you ever have any questions regarding financial transaction security or how HomeATM provides true end-to-end-encrypted transactions, feel free to email me.

Before I get to the next question, I've got one for you.

When you "type" your card number into a "box" on a merchant website, is it protected by DUKPT? Is it encrypted? If so, DES or 3DES? First one to send me the correct answer gets a Free HomeATM PED!

Q: What is TRUE end-to-end encryption? (E2EE)

A: First of all, "true" end-to-end encryption can only occur with a PIN based transaction. It doesn't exist outside of that scope because there is a point in the process where the cardholder data is decrypted and before it is re-encrypted is that is the point where it is vulnerable.

With that said, Heartland's proposal for end-to-end encryption has promulgated E2EE into a hot topic.

I would point out that Heartland's E2EE proposal came "AFTER" their breach...while HomeATM instituted their end-to-end encryption from "the very beginning." I'm not bragging. I'm proudly displaying our insight into the weaknesses inherent in the payments system and how we improved upon said weaknesses.

But let's get back to Heartland, shall we? In this post I will attempt to explain why they CANNOT magically snap their fingers and introduce E2EE on their own. They need cooperation from others in the industry.
While it's true that some large U.S. retailers encrypt cardholder data while in transit, it's also true that most don't. Therefore...in order for E2EE to work, a lot of retailers would need to revamp their system(s). Very costly indeed.

In addition, the top full-service U.S. payment processors don't currently support E2EE; thus, retailers that encrypt card data in transit typically must decrypt it before they send it to their processor.

The key word here is decrypt. That is the weak point, the vulnerability, and as such, also the problem.

That said, PIN Debit is an entirely different animal. Card brand standards require that PINs are encrypted end-to-end. In fact, speaking about Heartland's quest for E2EE, Distinguished Gartner Analyst Avivah Litan stated:

End-to-end encryption would be most effective if data was encrypted from the timea card was swiped at a POS until it reached the card issuer, similar tothe way personal identification numbers (PINs) currently are encrypted according to card brand standards.
Starting to get the point? If not here's some more insight as Ms. Litan went on to state:

"Heartland is limited by the scope of systems it manages and from which it accepts data;it can only seek to influence the card industry to carry end-to-end encryption beyond the processor stage, through the card networks and onto the card issuers.

"The proposal's success also depends on merchants' willingness to invest in terminal upgrades that support card data encryption."

(Editor's Note: For instance...HomeATM's PCI 2.0 Certified SafeTPIN PED which also encrypts the Track 2 data.) Avivah continues:

"If Heartland implements its proposed project more securely than it hasmanaged in the past with its network, it will make payment cardprocessing more secure for merchants, especially if they don't managethe encryption keys and leave key management to their processor.

Nevertheless, the process will always include vulnerabilities at the point where data is encrypted and decrypted.

"These vulnerabilities can be limited by using "sound key management practices" and enforcing extra security measures, such as "requiring two separately managed sets of keys for cryptographic operation"

HomeATM practices what she preaches by incorporating a"sound key management practice."

That is why HomeATM is the closest thing to TRUE end-to-end encryption in the industry. (our industry being eCommerce payments and Real Time Money Transfer.)



In the bricks and mortar world, end-to-end encryption doesn't exist and the whole system would need to be revamped. You can learn more about that in this related post where Avivah Litan asks:
Hacked! Is Visa Next? (pindebit.blogspot.com)

Hole in the Whole Card Security System

Credit Cards' Unintended Security Hole - CBS News
Credit Cards' Unintended Security Hole
Retail Realities: Why Zero Liability Programs Are a Wonderfully Early Holiday Gift to Cyber Thieves Everywhere

Editor's Note:  First of all, I call it "Zero Lie Ability." because the truth is that signature debit vs. pin debit brings "nothing to the table, yet Visa pushes it over the more secure 2FA PIN debit system.  Lie Ability also has the dual meaning that the banks have "no clue" (zero) on how Visa fooled them into agreeing to partake in this so-called "zero liability" program...the one that pushes the "LIE" in order to provide Visa with the "ABILITY" to make more profits.  It doesn't take a rocket scientist to PIN down the fact that Visa's "Signature" product, given the two choices (PIN or SIG) is the less secure of the two. 

I'll expand further on Tuesday.  For now, here's Evan Schuman's rant...which by the way...contains zero lies!

(CBS) This column was written by Evan Schuman, the editor of StorefrontBacktalk.com, a site that tracks retail technology, e-Commerce and security issues. He can be reached by e-mail and on Twitter.

In one of the most delicious ironies in retail today, the single most significant element that makes it easier for cyber thieves to steal consumer credit and debit card information from retailers is something the credit card companies themselves cooked up.

To be fair, this unintended consequence is a domino effect, where the innocuous-seeming program has set off a series of chain reactions that, today, makes credit and debit card breaches a lot more likely and more lucrative for the thieves. The program is called zero liability and it was initiated by some of the major credit card players many years ago to try and make consumers more comfortable making purchases online. The premise is that any fraudulent purchases will not have to be paid for by the consumer. Some banks have spoken of no liability beyond $50, but in operation, almost all banks cover all of the charges.

The program worked wonderfully and consumers quickly did become comfortable making E-Commerce purchases. But as identity theft and straight-out stealing from credit cards became much more common, large retailers became popular targets. The onus was on the retailers-not the banks-to pay millions of dollars to install and manage sophisticated security programs. But these costs were almost impossible to justify. After all, no chain was going to advertise: "We just installed state-of-the-art firewalls and encryption systems. Come shop with us." And the risk of being breached seemed too remote to make a compelling argument to a board of directors.

Then came the retail world's wakeup moment.  (Continue Reading...but first...an Editor's Note)

Editor's Note:  When will the e-tail world "wakeup?"  AFTER or BEFORE the next big breach?  Look for Tuesday's PIN Payments News Blog for an analysis of why an e-Breach is inevitable...unless online shoppers swipe instead of type.  I've long said, that if cardholders data is going to be swiped, should it not be the cardholder doing the SwipePIN? 

BTW: It's ironic that this story was run on CBS, because there's a lot of BS that I C. involving e-payment security on the web.  (includinig BSMS)  When it comes to asking who "nose" this more than anyone, the engineering team at HomeATM has been conscious of this fact for years.  So what is Visa doing?  Jiminy Cricket!  Where's the conscience? 

Heartland Update: 656 Institutions Impacted

While it's hard to get a handle on just how many consumers were affected by the Heartland Payment Systems (HPY) data breach, the total number of institutions now reporting card compromises is at 656.

Read Entire Article



Reblog this post [with Zemanta]

NACS Says Interchange Reform Badly Needed

'A penny times billions adds up'
Trade group (NACS) representing convenience stores and grocers upset with recent credit card fee increase
BY BILL FREEHLING
Date published: 5/29/2009

An association of retailers is upset about a recent fee increase charged to merchants each time a customer uses a credit card to pay.

The National Association of Convenience Stores calls last month's usage-fee increases by Visa and MasterCard "beyond outrageous." The fees, which took effect April 17, increase a merchant's per-charge transaction cost by more than a penny. Merchants are now charged about 2 cents per transaction on usage fees, which are in addition to other costs.

"A penny may not seem like much, but a penny times billions adds up quick," said NACS spokesman Jeff Lenard. "And when business costs go up, they get passed along to consumers, so we are all the losers."

MasterCard spokesman Chris Monteiro declined to comment on the pricing adjustments but noted that "every business establishes a price for the goods and services it provides, and the electronic payments industry is no exception.

Continue Reading


In related news, the NACS also ran an editorial on their website complaining that Interchange Fees need to be regulated or the benefits to the recent Credit Card Bill of Right will be badly affected:

Editorial: Merchants Need Interchange Reform 


Unless interchange fees are regulated, the benefits to consumers of recent credit card reform will be sharply reduced



MINNEAPOLIS, MN – An editorial in the Minneapolis Star-Tribune
welcomed the passage of the Credit Cardholders’ Bill of Rights as one
protecting cardholders, although the bill failed to address interchange
fees.

 The editorial urged Congress or courts to act and
eliminate interchange fees, costs that total $45 billion annually. The
authors,
Craig Wildfang and Mark Williams, recommended the following:


  • Congress should regulate interchange fees, those charged to
    merchants by card-issuing banks. Collectively, the fees total $45
    billion annually and are rising.
  • U.S. interchange fees are among the world’s highest and are
    not supported by commensurately higher costs to banks or card networks.
    In fact, the costs of running computer hardware and software — “the
    principal costs of running a payment card network” — have been
    decreasing.
  • Interchange fees are essentially a privately enacted sales
    tax by the country’s largest banks (creators of Visa and MasterCard),
    “except that the revenue goes to the country’s largest banks, not to
    the government.” No controls have been in place to regulate these
    “fixing of prices to merchants” by the banks. Indeed, “the five largest
    card-issuing banks account for 80 percent of all cards.”
  • Other countries have contested interchange fees, including
    Australia and the European Union. In those cases, authorities lowered
    or eliminated the fees.
  • Canada’s Interac debit network, as well as other foreign debit card networks, voluntarily do not charge interchange fees.

Wildfang and Williams summarized that eliminating the $45
billion interchange fee would provide an immediate stimulus to the
economy. And noting that Citibank and Bank of America have accepted
hundreds of billions of dollars of taxpayer funds to endure the current
financial crisis, a reciprocal gesture is especially merited. Without
doing so, the benefits of the Cardholders’ Bill of Rights are sharply
reduced. And if Congress fails to act, merchants will turn to the
courts to seek relief.

Cybersecurity Tsarina - ISR

In an article written by Kevin M. Nixon, he muses as towhether Melissa Hathway is the next Cybercrime Czar...

Is She America’s New Cybersecurity Tsarina?

May 29, 2009 by ADMIN · 2 Comments
By Kevin M. Nixon, Information-Security-Resources.com Security Editor

Information Security Resources staff had received an advance copy of the official White House Press Release (05/29/2009)and was all ears today during President Obama’s East Room remarks onthe highly anticipated and long awaited release of the “CyberspacePolicy Review: Assuring a Trusted and Resilient Information andCommunications Infrastructure”.

The report has become known as “TheHathaway 60-Day Report” in “homage” to Melissa Hathaway, the personPresident Obama picked as “Acting Senior Director for Cyberspace of theNational Security Council (NSC) and the Homeland Security Council(HSC)”.

Not only did the President bestow atitle too long to technically print on a normal sized business card,also he gave her a the shortest runway I have ever seen to assemblerecommendations, gain consensus, and publish a report for the ChiefExecutive.

Just pulling together all agencies,departments, stove-piped information while overcoming all the turfbattles can only be likened to attempting a huge worm wrestle.

Ms Hathaway accomplished the task anddelivered the goods and so everyone anticipated that the Presidentwould recognize her “get it done” work ethic and also announce from theEast Room today, her appointment as America’s Cybersecurity Tsarina.

However, everyone holding their breathin the East Room today probably passed out from lack of oxygen.  ThePresident was blatantly and conspicuously silent on his appointment.

The President’s silence left everyonewondering “does she or doesn’t she” and left reports attempting to findany hints of the President’s plan.  ISR think that we may be on tosomething. As POTUS stepped in front of the gathered experts, somewherein the back offices of the White House there was a shadowy figurehunkered over a keyboard waiting for the exact moment to press enterand publish an article on the White House Blog.

Could that person have even beensitting in the East Room audience with the President holding onto herthree Blackberry devices just waiting for President Obama to give thesecret word or phrase to “press the send” button?

We may never know, but President Obamadid acknowledge Melissa Hathaway at about the same time that an articleby her was posted on the White House Blog.

What is noticeable is in Ms Hathaway’sarticle is her title in the article’s by-line.  Gone is “MelissaHathaway, Acting Senior Director for Cyberspace of the NationalSecurity Council (NSC) and the Homeland Security Council (HSC)”.  Thenew by-line reads:  Melissa Hathaway, Cybersecurity Chief at theNational Security Council.

Which still leaves us wondering andwaiting?  Is the White House making new robes as the Catholic churchdoes when a new Pope is elected or has Ms Hathaway been appointed“Camerlingo” (1st runner up in a papal contest).  Guess we will justhave to wait.

Melissa Hathaway’s Blog post “Securing Our Digital Future” is re-published here:
Melissa Hathaway, Cybersecurity Chief at the National Security Council, discusses securing our nation’s digital future:

Published:  FRI, MAY 29, 10:00 AM EST — The White House Blog

The globally-interconnected digitalinformation and communications infrastructure known as cyberspaceunderpins almost every facet of modern society and provides criticalsupport for the U.S. economy, civil infrastructure, public safety andnational security.

The United States is one of theglobal leaders on embedding technology into our daily lives and thistechnology adoption has transformed the global economy and connectedpeople in ways never imagined. 

My boys are 8 and 9 and use theInternet daily to do homework, blog with their friends and teacher, andemail their mom; it is second nature to them.

My mom and dad can read thenewspapers about their daughter on-line and can reach me anywhere inthe world from their cell phone to mine.  And people all over the worldcan post and watch videos and read our blogs within minutes ofcompletion.  I can’t imagine my world without this connectivity and Iwould bet that you cannot either.   Now consider that the same networksthat provide this connectively also increasingly help control ourcritical infrastructure.

These networks deliver power andwater to our households and businesses, they enable us to access ourbank accounts from almost any city in the world, and they aretransforming the way our doctors provide healthcare.  For all of thesereasons, we need a safe Internet with a strong network infrastructureand we as a nation need to take prompt action to protect cyberspace forwhat we use it for today and will need in the future.

Protecting cyberspace requiresstrong vision and leadership and will require changes in policy,technology, education, and perhaps law.  The 60-day cyberspace policy review summarizesour conclusions and outlines the beginning of a way forward in buildinga reliable, resilient, trustworthy digital infrastructure for thefuture.

There are opportunities foreveryone–individuals, academia, industry, and governments–to contributetoward this vision.  During the review we engaged in more than 40meetings and received and read more than 100 papersthat informed our recommendations.   As you will see in our reviewthere is a lot of work for us to do together and an ambitious actionplan to accomplish our goals.

It must begin with a national dialogue on cybersecurity and we should start with our family, friends, and colleagues.

We are late in addressing thiscritical national need and our response must be focused, aggressive,and well-resourced.  We have garnered great momentum in the last fewmonths, and the vision developed in our review is based on theimportant input we received from industry, academia, the civilliberties and privacy communities, others in the Executive Branch,State governments, Congress, and our international partners.  We nowhave a strong and common view of what is needed to achieve change.

Ensuring that cyberspace issufficiently resilient and trustworthy to support U.S. goals ofeconomic growth, civil liberties and privacy protections, nationalsecurity, and the continued advancement of democratic institutionsrequires making cybersecurity a national priority.
Kevin M. Nixon, MSA,CISSP®, CISM®, CGEIT®, has testified as an expert witness before theCongressional High Tech Task Force, the Chairman of the Senate ArmedServices Committee, and the Chairman of the House Ways and MeansCommittee. He has also served on infrastructure security boards andcommittees including the Disaster Recovery Workgroup for the Office ofHomeland Security, and as a consultant to the Federal Trade Commission.
The Author gives permissionto link, post, distribute, or reference this article for any lawfulpurpose, provided attribution is made to the author and to Information-Security-Resources.com





Reblog this post [with Zemanta]

Friday, May 29, 2009

Online Banking Under Attack!

ITWeb :Online banking under attack
[ Johannesburg, 29 May 2009 ] - In today's trying economic climate, it is becoming clear that every organization in every industry sector, be it financial, retail or telecommunications, is a target for cyber criminals. If they conduct banking online or host customer and supplier information, businesses must ensure they have proper security measures in place not to fall victim to these crimes.

This is according to Costin Raiu, Chief Security Expert at Kaspersky Lab, EEMEA, addressing delegates at ITWeb's 4th Annual IT Security Summit 2009 in South Africa this week.

The conference provided information security professionals and IT managers with the most up-to-date information, tools, trends, legislation and strategies to address information security issues.

“Cybercrime accounts for billions of dollars in terms of losses annually and the criminals are becoming more professional in developing technologies designed to counteract traditional anti-virus solutions every day. It is not so much an issue of computer malware, but the countless vulnerabilities in operating systems as well as the installed software applications that make it very hard to run secure computer systems,” he says.

Raiu says contributing factors that lead to the flourishing of premeditated online crime is the evolution of malicious code from viruses to Trojan horse attacks, designed to steal personal information for financial gain.

“Online payment systems and online banking systems often make use of simplistic authentication technologies, and hackers use keystroke loggers, password-stealing Trojans and social engineering to gain access to accounts which are later emptied of funds.

“Even systems that use complicated multi-factor authentication techniques are at risk with the introduction of specialised Trojan horses, which are able to intercept transfers on-the-fly and replace the destination account with the attacker's account or highjack an online banking session,” he says.


“At the same time, banking institutions that offer financial services online must use a blended approach to security, using two-factor authentication methods that rely on external devices to ensure that user accounts are not compromised,” he says.

In his closing comments, Raiu said businesses have to begin to realize that the IT security threat is not going to go away. The protection against such risks, he says, must be international priority, involving various industry experts and associations to guard against these financial risks.


Reblog this post [with Zemanta]

How to Hack an ATM Part VI

E-Germany

Kaufen Sie schnell!

Theprogress of e-commerce in Germany—home to Europe’s largest Internetpopulation—was relatively slow, retarded by many of the same issuesseen earlier in other countries, such as the UK and the US. Heightenedsecurity concerns and adherence to traditional payment habits on thepart of many Germans hindered the development of online selling.
But the situation has changed.

By the end of 2008, the GfK Groupreported that retail e-commerce sales—excluding event tickets,financial products and travel—reached €13.6 billion ($20 billion), up€2.2 billion ($3.2 billion) from 2007.

“Consumers in Germany have largely overcome their reluctance aboutbuying online,” says Karin von Abrams, eMarketer senior analyst andauthor of the new report, Germany Online: Europe’s Biggest E-Commerce Market Comes of Age.
Eurostatcalculated that 89% of Germany’s male Internet users ages 16 to 74shopped online in 2008—the same percentage that sent or receivede-mails.

Among males ages 25 to 54, the percentage who shopped online was 93%.


Continue Reading at eMarketer
or

Read Below How to Order eMarketer's Report on E-Germany

Germany Online:  Europe's Biggest E-Commerce Market Comes of Age

The progress of e-commerce in Germany, Europe’s largest Internetpopulation, reflects patterns seen earlier in other countries, such asthe UK and the US. But cautious consumers’ security concerns andtraditional payment habits are increasingly being overcome.

The Germany Online report analyzes the factors driving the surge in German e-commerce.

Many German retailers were slow to recognize the advantages ofInternet sales—30% of the German firms selling on the Web last yearlaunched their online stores in 2007 or later.

Nevertheless, sales are growing.

By the end of 2008, German retail e-commerce sales—excluding eventtickets, financial products and travel—reached €13.6 billion ($20billion), up €2.2 billion ($3.2 billion) from 2007.

Key questions the “Germany Online” report answers:
  • How many German consumers are buying products and services on the Internet?
  • How do online buying patterns vary with age and gender?
  • How is the arrival of online shopping clubs changing the e-commerce landscape?
  • What is the current level of interest in mobile commerce?
  • And many others…
eMarketer Reports—On Target and Up to Date
The Germany Onlinereport aggregates the latest data from international marketing andcommunications researchers with eMarketer analysis to provide theinformation you need to make fast, whip-smart business decisions.

To download the report to your desktop—click Add to Cart:





Reblog this post [with Zemanta]

Western Union Malware Attack Launched

Finextra has a story on the Western Union scam (The PIN Payments Blog told you about it on May 12th) but "their" story talks about Graham "Cluely" (a senior tech consultant at Sophos) complaining that people are "Clueless"

Oh really Graham? And you just figured that out? Who Clued you in? Was it that Pareto guy?

A Phunny Phishing story. Oh, and if you are one of the dumb people, please don't be offended by the graphics...just a dumb attempt on my part to be phunny.

Western Union malware attack launched

WesternUnion has become the latest firm to have its brand hijacked byphishers, with a flood of trojan-laden e-mails purporting to come fromthe money transfer outfit hitting inboxes.

Graham Cluley, senior technology consultant, Sophos, suggests the attack is unlikely to fool all but the most gullible.

"Ifyou haven't sent any money via Western Union, then why would they betelling you it failed to be delivered properly? Common sense is yourfriend. It's just such a shame that it doesn't seem to be very common,"says Cluley.

Editor's Note: Common Sense dictates that "If everyone else is drinking the Kool-Aid, then maybe I should drink it too!"

It's the uncommon sense that prevails. Don't believe me? Ask the lemming that "didn't" jump off the cliff.



Reblog this post [with Zemanta]

Thursday, May 28, 2009

"Both Sides of the Mouth Syndrome Syndicated

Information Security Resources , an industry leading "InfoSec" blog shared the BSMS with their readers.   

Both Sides of the Mouth’ Security Analysis

May 27, 2009 by ADMIN · Comment

By John B. Frank, Marketing Strategist with HomeATM ePayment Solutions

It was nice that Javelin Strategy and Research took the time to write about HomeATM in their analysis of Finovate Startup09, but I’m a little confused about something they say in their report.

Maybe a reader might be able to clarify what they mean, because right now I’ve got  a kindova BSMS (Both Sides of the Mouth Syndrome) taste in my - for lack of a better word - mouth.

Why do I say BSMS?

Well, in the first portion of Javelin’s analysis of HomeATM, they say that our Safe-T-PIN device provides (the more secure) card present (vs. the less secure card not present) credit card transaction, and the even more secure PIN Debit transaction.

Here’s their quote:

Launched in April 2009, P2P Safe-T-PIN offers home-based “card present” credit card and PIN debit transactions online using a PCI-certified device attached to a personal computer through a USB port.


Users also could make online purchases by swiping their credit card or debit card and PIN at checkout. The device allows for secure real-time money movement with an option for delayed transactions.


Then, after stating that, the next thing they say is:


There is greater potential for HomeATM as a frequent high-value P2P solution such as a Western Union money transfer than for enabling e-commerce. Many consumers may be hesitant to swipe their ATM cards on hardware attached to their computer because of security concerns.

Therein lies my confusion.

First they state that our PCI certified device allows for “Card Present” and “Online PIN Debit” transactions, along with the statement that our device ALLOWS SECURE REAL TIME MONEY MOVEMENT, and then in their next breath they say that many consumers may be hesitant to use that very same PCI 2.0 Certified PIN Entry Device because of security concerns?

Did they possibly mean to imply that many consumers may be hesitant to swipe their ATM cards on hardware attached to their computer because they don’t want “improved” security?


Someone help me out here!  I’m not being sarcastic.  I’m being serious. Okay, I admit…I’m being totally sarcastic. But there’s good reason; in fact 117 good reasons. You may have noticed when you first visited the HomeATM site, there was a popup that appeared asking if you would please partake in our survey.


Well, I started the survey yesterday and already have 117 responses, and it doesn’t appear to me that very many consumers may be hesitant to swipe their ATM (or debit or credit) cards on hardware attached to their computer.  In fact, 117 said they would prefer to Swipe their Card and 117 said they would prefer NOT to Type in a Username/Password.


Click below to enlarge and read two questions pertaining to whether individuals would prefer to Type or
Swipe their Card information at a merchant website or Online bank:







The analysis did go on to say that two of the “differentiators” enjoyed by HomeATM is that we provide “end to end encryption” and our device is PCI certified, so I’m still left confused by what they meant about many consumers being hesitant because of security concerns… chime in if you know!


HomeATM Differentiators:


• A HomeATM Mobile device will be available for mobile phones with Web access, allowing transactions on the go
• PCI-certified device
• Hardware-based end-to-end encryption
• 100% acceptance with all bank cards

Author’s Note:  Plus our PCI 2.0 Certified PED also “encrypts” the Track 2 data and utilizes DUKPT key management as an additional layer of security.


HomeATM’s Engineering Team Designed and Manufactures the World’s FIRST and ONLY PCI 2.0 PIN Entry Device Specifically Designed for eCommerce. Our device provides “Card Present” rates on credit cards and “True PIN Debit” Interchange on debit cards as well as secure 2FA authentication for online banking sites and live, “real-time” money transfer from P2P, B2B, B2P, P2B and mobile.


To learn more about our product’s and services click here or email us at: info@homeatm.net


Stay Informed With RSS Feeds or Email Alerts Here: 










Reblog this post [with Zemanta]

Disqus for ePayment News