Thursday, June 18, 2009

Voltage Security to Assist Heartland with E2EE

Heartland, Voltage Security partner for end-to-end

Princeton, N.J., June 18, 2009 -- Heartland Payment Systems (NYSE: HPY - News), one of the nation’s largest payments processors, has selected Voltage Security as a partner to develop end-to-end encryption (E3) software specifically suited to payments processing. Voltage is a global leader in information encryption.

“Heartland is developing a complete end-to-end encryption solution designed to protect cardholder data at all stages of a transaction – from card swipe through delivery to the card brands,” said Bob Carr, Heartland’s chairman and chief executive officer. “Together with Voltage, we are developing a comprehensive solution that currently does not exist.”

Heartland’s new E3 solution will significantly enhance the security of payment card information throughout the processing lifecycle. The Voltage SecureData™ product line, based on its Format-Preserving Encryption™ and Identity-Based Encryption™ approaches, will power the software component of Heartland’s E3 solution. Heartland also employs Voltage SecureMail™ and Voltage SecureFile™ to protect personal information throughout its corporate and extended business network.

“Heartland’s vision for E3 sets a new security standard for the payments industry,” said Sathvik Krishnamurthy, president and chief executive officer of Voltage. “With Heartland E3, merchants will be able to significantly reduce their PCI audit scope and compliance costs, and because data is not flowing in the clear, they will be able to dramatically reduce their risks of data breaches.”

Heartland will launch its E3 pilot in Q3 and will continue to roll out additional features and products through 2010.

About Heartland Payment Systems

Heartland Payment Systems® (NYSE: HPY - News), the fifth largest payments processor in the United States, delivers credit/debit/prepaid card processing, payroll, check management and payments solutions to more than 250,000 business locations nationwide. Heartland is the founding supporter of The Merchant Bill of Rights, a public advocacy initiative that educates merchants about fair credit and debit card processing practices. For more information, please visit http://www.heartlandpaymentsystems.com and http://www.MerchantBillOfRights.com .

About Voltage Security

Voltage Security, Inc., an enterprise security company, is the global leader in information encryption. Voltage solutions, based on next generation cryptography, provide encryption that just works for protecting valuable, regulated and sensitive information based on policy. Voltage delivers end-to-end encryption with rapid implementation and the lowest total cost of ownership in the industry through the use of award-winning Voltage Identity-Based Encryption™ (IBE) and a new breakthrough innovation: Format-Preserving Encryption™ (FPE). Voltage Security offerings include Voltage SecureMail™, Voltage SecureData™ and the Voltage Security Network™ (VSN), an on-demand managed service for the extended business network. The Company has been issued several patents based upon breakthrough research in mathematics and cryptographic systems. Customers include Global 1000 companies in banking, retail, insurance, energy, healthcare and government, such as the American Board of Family Medicine, Diebold, Integro Insurance Brokers, NTT Communications, SafeAuto Insurance, Winterthur Life UK Ltd. and XL Global Services. For more information please visit http://www.voltage.com .

Source: Company press release.



56,000 More Victims of Heartland Breach


About 56,000 members of Suncoast Schools Federal Credit Union have been notified that their debit card accounts were exposed to fraud.

It is the latest casualty of last year's breach of Heartland Payment Systems, one of the country's largest credit card processors, where information from more than 100 million credit and debit card transactions was exposed.

Not until the end of May did Suncoast discover that some of its customers who use Visa Check Cards could be in danger. The Tampa credit union is issuing new cards to all members whose accounts were compromised.

"It was not a Suncoast exclusive event nor was it through any fault of our own," said Melva McKay-Bass, senior vice president of member service operations for Suncoast. "It was not anything that we had done wrong."

Suncoast, which has more than 450,000 members, has determined that less than 1,000 members were actually affected by fraud as of Wednesday, McKay-Bass said.

Only encrypted card data was compromised, not personal information such as names, addresses and Social Security numbers. The credit union began notifying affected members by letter in the first week of June, McKay-Bass said. Suncoast released a statement explaining the breach Friday in response to what it said was an inaccurate Fox News report that, McKay-Bass said, panicked some of its members...

Continue Reading at the St. Petersburg Times







Reblog this post [with Zemanta]

PayPal Prez Says No Spinoff

In an article written by Douglas MacMillan for and published in BusinessWeek's TechBeat, he reports that PayPal's president, Scott Thompson is dispelling any notions that PayPal (and recently acquired BillMeLater) will be spun-off.  Skype, maybe, PayPal, no.

PayPal President: No Spinoff - BusinessWeek

PayPal President: No Spinoff
Posted by: Douglas MacMillan on June 17

After eBay said in April that it planned to spin off its Skype business, some investors and analysts started wondering about the e-commerce company’s other major subsidiary: What about PayPal? In the past two weeks, a number of sources have said they have heard talk that eBay is exploring different options for realizing more value from the lucrative payments business.

One source said he had heard the company was considering selling PayPal to a consortium of private equity investors while keeping an equity stake. Another heard a rumor that eBay would issue a tracking stock for PayPal.

But during a visit to BusinessWeek, PayPal president Scott Thompson dispelled these notions. Thompson says that although even he has heard the speculation about spinning off PayPal, he and eBay CEO John Donahoe have not discussed any such options. “We have not talked about that,” he says. “I think we’re going to be part of the eBay Inc. family for a long time to come.”

Thompson admits that he “understands the logic” of wanting to unlock value in PayPal, but he argues that eBay’s strong balance sheet is an important asset to have while his business is growing. The parent’s deep pockets helped with the $945 million acquisition of Bill Me Later in October, Thompson says. “If we were a separate company, would we have done it? I’m sure we would have tried because it was the right thing to do for the business. But it was fundamentally easier having that very strong balance sheet.”

Continue Reading at BusinessWeek



Reblog this post [with Zemanta]

Heartland CEO Calls Breach "Devastating"


Heartland Payment Systems CEO Robert Carr calls the data breach that rocked the payment processor "
devastating." Since the incident, the company has been working overtime to repair the damage.

According to Computerworld, Heartland expects an end-to-end encryption program for protecting card data to be complete in the third quarter. The company also is pushing for an industry-wide standard for encrypting data white it's moving through networks. Heartland has co-founded the Payment Processor Information Sharing Council, which gives organizations in the industry a forum for sharing information about security threats, vulnerabilities and fraud.

Gartner analyst Avivah Litan praised Carr's efforts, saying the

"the bottom line [is that] he is doing some good work. He is elevating the debate around card security and even got the card companies to speak about end-to-end encryption,"




Reblog this post [with Zemanta]

Level 2 Merchants Now Need QSA On-Site Assessments

Branden Williams, on his VeriSign Security Convergence Blog posted that MasterCard is now going to require that all Level 2 merchants use a QSA to perform an onsite assement of their Site Data Security.  This is a HUGE departure from the previous requirement of an in-house "self-assessment" of their Site Data Protection programs.  So, with that, all I have to say is:

Attention:  All Level 2 eMerchants! (greater than 1 Million, but less than 6 Million transactions annually)  Based on the fact that HomeATM is already PCI 2.0 PED certified, should you incorporate our "swipe vs type" payment methodology, you would be effectively removed from the scope of PCI.  Problem solved, money saved, security improved. 
(also provides additional significant benefits such as replicating "card present" environment and "true" PIN Debit Interchange rates,)

Here's an excerpt from Branden's blog post: 

Branden Williams' Security Convergence Blog: NEWS FLASH: MasterCard Requires On-Site QSA for Level 2 Merchants
NEWS FLASH: MasterCard Requires On-Site QSA for Level 2 Merchants
Thanks to Smiley for the tip!

MasterCard has posted a change to their Site Data Protection program that requires Level 2 merchants to use a QSA and an on-site assessment. This is a dramatic change from the current, industry wide requirement of self-assessing for merchants processing less than six million transactions annually.

While this is definitely going to put a dent in Level 2 merchant budgets from this point on, I truly believe that this is a smart move by MasterCard. Level 2 merchants are extremely significant in size, many of which being household names. Unfortunately, PCI self-assessments are typically poorly handled simply due to the complexity of the standard and lack of training provided to those individuals performing the assessment. When our folks are contracted to review these, we typically find that a previously fully in-place Self Assessment Questionnaire is only about 70% accurate. Meaning, that 30% of the items answered "Yes" or "N/A" are actually "No."

Continue Reading 


, , , , ,

Kasperky Lab Announces Malicious Software Detection Patent


Kaspersky Lab, a leading developer of secure content management solutions, announces the successful patenting of information security technology in the US. The technology in question effectively detects and deletes malicious software and removes any trace of its effects by running automatically generated scripts.

Today's computers are exposed to a growing number of increasingly complex and rapidly changing malicious programs. Greater emphasis is now being placed on automatic protection methods that ensure fast data processing and prompt responses to threats. However, such technologies often generate false positives or suffer from low levels of new threat detection.

The recently patented technology from Kaspersky Lab is a combination of existing and newly developed methods to combat malicious software. Its automated methods are effective at processing large volumes of data. Moreover, processing and storing large volumes of information is advantageous in that it helps optimize and train the protection system, while security experts have the option of adjusting and fine-tuning the protection system as it operates.

This combination produces a synergy effect that saves resources and provides a high level of malware detection. Use of empirical data and the system's learning capabilities enables a gradual specialization and perfection of its functions.

The cutting-edge technology was invented by Oleg Zaytsev, a senior technical specialist at Kaspersky Lab. The patent for the new technology and its implementation was registered as No. 7 540 030 by the US Patent Bureau on 26 May, 2009.

The patented system automatically aggregates statistics on programs and their activities. Information is collected from event logs, system scan results and user records about quarantined files. The data are used to identify malware, automatically generate scripts to remove detected threats and carry out an in-depth analysis of the system.

The scripts generated by the system can be improved by computer security specialists, which may be beneficial in cases where the system does not have sufficient knowledge to develop and take decisions in complex situations. This allows subsequent problems of a similar nature to be resolved automatically. In other words, as the amount of statistical data collected increases with time, the system operates more effectively.

Kaspersky Lab currently has more than 30 patent applications pending in the US and Russia related to a range of innovative technologies developed by company personnel.

Source: Company Press Release

Reblog this post [with Zemanta]

PDG Software: Industry First PCI PA-DSS Certification for Shopping Carts

PDG Software Announces PCI PA-DSS Certification for PDG Commerce Version 5
Certification & validation helps ensure the highest degree of security and privacy for merchants operating and consumers shopping at PDG Commerce enabled eCommerce storefronts.

Atlanta, GA (PRWEB) For Immediate Release -- PDG Software, Inc., a leading provider of internet storefront and eCommerce shopping cart solutions, announced today the certification of PDG Commerce Version 5 as a PCI PA-DSS certified payment application.

PDG Commerce now becomes the first internet shopping cart and storefront solution currently recommended for new deployments to achieve validation and certification with the Payment Card Industry Standard Security Council's (PCI SSC) Payment Application Data Security Standards (PA-DSS) program.
(Editor's Common Denominator Note:  HomeATM is the "first and only" company to achieve validation and certification for the Payment Card Industry's 2.0 PED program.) 

The PCI PA-DSS program, previously known as the Visa Payment Application Best Practice (PABP) Program, was created to help software vendors develop secure payment applications that do not store prohibited data and to support compliance with the PCI Data Security Standard (PCI DSS).

With current mandates from Visa and other major card brands requiring that acquiring banks only approve new merchant accounts for organizations utilizing a PA-DSS certified solution or merchants who have demonstrated their own overall PCI DSS compliance, PDG Commerce provides a simple and affordable option for merchants wanting to accept credit cards through their eCommerce storefronts who do not have the technical skills or funds required to build their own PCI DSS compliant systems. Cardholder data, once collected through a merchant's secured website, is immediately transmitted to PCI approved payment gateways for processing, without the data ever being stored or transmitted within the merchant's back-office systems.

"We're very happy to be in a position to facilitate the process for new merchants looking to establish an eCommerce presence. With the high-risk of unscrupulous hackers intent on taking advantage of small to mid-size merchants that do not have the technical staffing or know-how to build and manage their own secure networks, the peace of mind that comes from knowing that you are working with a PCI certified shopping cart is invaluable," said Karen Snyder, President of PDG Software. "Merchants utilizing PDG Commerce can sleep well knowing that their customer's cardholder data is never stored within their storefront and cannot lead to costly and embarrassing security breaches."

About PDG Software, Inc. and PDG Commerce

PDG Commerce, the culmination of over 12-years of research and development, provides an all-in-one eCommerce storefront software solution for internet merchants. Utlilized by thousands of merchants worldwide, PDG Commerce can be used to build highly customized eCommerce Web Stores that integrate directly with major shipping carriers, payment services and existing accounting, POS and other software commonly used to internet retailers. PDG Software is an Intuit Gold Developer and offers the highest rated QuickBooks compatible shopping cart storefront solution. Real-time synchronizations between a merchant's local QuickBooks company file and their PDG Commerce enabled store front allows the merchant to manage virtually all aspects of the day-to-day operation of their eCommerce business from directly within QuickBooks. For additional informtion, please visit http://www.pdgsoft.com.



, , ,

Only 4 of 1000+ eShopping Carts will Make PA-DSS Cut


This article, from Jamie Estep at Practical eCommerce states that out of 1000's of shopping cart providers, there it appears that only 4 will make the cut-off date (July 2010) for PCI Compliance.   Wow. 

To date, there is only ONE, PDG Commerce. 

Here's an excerpt from his article...
"A few weeks ago I blogged about the PA-DSS regulations which are going to be taking effect over the next year.
PA-DSS (Payment Application Data Security Standard)is an additional security policy that addresses applications that storeor transmit credit card data. The current regulation is ambiguousenough that many ecommerce shopping carts fall under the PA-DSSenvelope. If you use an API method of integrating with your paymentgateway, your shopping cart may need to be PA-DSS certified.
The current timeline for PA-DSS adoption is as follows:
  1. New PCI Level 4 merchants (including new locations of existingrelationships) may not use vulnerable payment application versions –those that store prohibited cardholder data. January 1, 2008
  2. New PCI Level 4 merchants using third-party payment software mustbe either PCI DSS-compliant or use PA-DSS validated compliant paymentapplications. October 1, 2008
  3. ALL PCI Level 4 merchants (new and existing) using third-party software must use validated applications. July 1, 2010
Here's the problem:

There is currently only one shopping cart that is PA-DSS certified: PDG Commerce. Additionally, Magento Enterprise, Miva Merchant, and X Cartare scheduled to become PA-DSS certified.

Other than that, no othercarts have announced that they will be, or are planning on becomingPA-DSS certified before the deadline of July 2010. There's still timeto get certified, but 4 of the thousands of shopping cart providers isnot a promising number."

It's unclear how hard-line of a stance the card companies aregoing to take on non PA-DSS or PCI compliant websites. If they go thefull mile, they could shut down any website's credit card processingthat isn't compliant. They could also hand down some major fines fornon-compliance.

Read Article in Full at Practical eCommerce



Reblog this post [with Zemanta]

Facebook Get's in MySpace Face

Top 20 Social Networking Sites Among US Internet Users, May 2008 & May 2009 (thousands of unique visitors and % change)Facebook Overtakes MySpace

JUNE 18, 2009

YourSpace is shrinking.

In May 2009, Facebook became the most popular US social networking site.

But it was close.

According to comScore,Facebook totaled 70,278,000 unique visitors, up 97% from May 2008 toMay 2009. MySpace hits shrank 5% over the same timeframe, fading to70,255,000 unique visitors.

Possibly in response to the trend, MySpace downsized around 400 employees.

“Simply put, our staffing levels were bloated and hindered ourability to be an efficient and nimble team-oriented company,” saidMySpace CEO Owen Van Natta in a statement.

MySpace still dominates Facebook in one importantrespect—advertising. MySpace visitors viewed 31.8 million ads in April2009, accounting for almost 47% of the total social network advertisingspace. Facebook was second, serving nearly 25 million ads and making upabout 37% of the sector.

Continue Reading at eMarketer


Reblog this post [with Zemanta]

UK Online Sales Enjoy 8% Growth in May

Editor's Note:  You'll notice that the title of the article below is signifcantly more negative than mine, but my thoughts were: 8% growth is still "growth," and since I'd be willing to bet that the majority (if not all) of companies,  businesses, in fact, industries as a whole, would have welcomed half of that (4%) with wide open arms, I went with "Enjoy 8% Growth" vs. "Stumble During May."  

Online sales stumble during May - Computer Business Review : News
Published:18-June-2009 By Steve Evans

Recession and hot weather stop (slow down) shoppers

Latest figures for online retail sales have revealed growth of just 8% for May 2009, the lowest since records began. The figures, from IMRG Capgemini e-Retail Sales Index, suggested the warmer weather during the month contributed to the slower growth.

Online sales for May 2009 totalled over £3.7bn.

Growth of 8.2% for May 2009 represented a 3.5% dip compared to April 2009 as people abandoned their computers to enjoy the Bank Holiday sunshine. This did have one positive impact - sales in the health and beauty sector shot up by 14.9% month on month as Brits stocked up on sun cream and moisturiser during the hot weather.  Online sales of beers, wines and spirits fell 17.4% during May, probably as a result of shoppers stocking up on supplies before April’s Budget. Online alcohol sales were also down 6.5% year on year. Sales of electrical goods slipped 5.7% during April but that sector seems to be holding up well during the recession as year on year sales were up 27.9%.

Mike Petevinos, head of consulting for retail for Capgemini UK, said: “Although online sales remain healthier than on the high street, UK shoppers are clearly changing their behaviour as a result of the recession – even those heading online to economise are now beginning to trim spending habits. So, whilst the underlying trend is still one of growth for online retail, the market conditions are placing all retailers under intense pressure to ensure their offerings remain competitive.”

Continue Reading at CBROnline.com



, ,

Discover Announces 2Q Net Income




Discover Financial Services Inc. on Thursday reported second-quarter net income of $225.8 million, or 43 cents a share, compared with $234.1 million, or 48 cents a share, in the year-ago period. 

PIN Debit Payments Blog did the math and that constitutes about a 3.6% drop.  I assume analysts thought it would be worse, because their stock is up.  According to MarketWatch,  Discover Financial Services jumped 7.2% to $9.55 after it reported second-quarter net income.  What makes Discover unique, is that unlike most of its peers, which either issue plastic or process thetransactions, Discover does both

Discover also pointed out that net income in the latest quarter included about $295 million related to the Visa/MasterCard antitrust litigation settlement.
Reblog this post [with Zemanta]
Heartland aims to improve campus safety with Alert Notification

According to CR80 News, Heartland Payment Systems’ Campus Solutions division is integratingits Campus OneCard with Alert Notification, a nationwide membershipservice that provides a 24-hour-a-day call center to alert family whenan accident or medical emergency occurs. Students who sign up for the Alert Notification system will havetheir Alert Notification numbers on their OneCards. If an incidentoccurs, emergency personnel report it to the call center and give thestudent’s Alert Notification number. The call center in turn notifiesthat person’s “in case of emergency” contacts.

Heartland’sCampus OneCard is a multi-functional campus ID card as well as aprepaid card that can pay for books, laundry, vending and off-campuspurchases. In addition, the card can provide access control toresidence halls and campus buildings and has campus-wide notificationabilities–enabling administrators to reach an entire campus or selectgroups with emergency messaging.

“This new offering enables us to bring the best aspects of campussecurity and personal safety to our campus clients. Not only do weprovide access control and mass notification, but we now have theenhancement of emergency notification to alert contacts if an accidenthappens,” said Fred Emery, vice president and general manager,Heartland Campus Solutions.

40,000 Websites Behind the "Nineball"


New Injection Attack Compromises More Than 40,000 Websites

"Nineball" exploit is distinct from Gumblar, Beladen, researchers say
By Tim Wilson | DarkReading

A new injection attack that redirects users' Web search queries is in the wild, and researchers at Websense believe it may have already affected more than 40,000 sites.

In a blog posted yesterday, Websense researchers indicated that more than 40,000 legitimate sites have been compromised with "obfuscated code that leads to a multilevel redirection attack, ending in a series of drive-by exploits which, if successful, install a Trojan downloader on the user's machine."

When users visit one of the infected sites, they are redirected through a series of different sites owned by the attacker and brought to the final landing page containing the exploit code, the researchers say. The final landing page records the visitor's IP address.

When the site is visited for the first time, the user is directed to the exploit payload site. But if the user returns from the same IP address, he is simply directed to the benign site of Ask.com, the researchers report...

Continue Dark Reading


Wednesday, June 17, 2009

PIN Payments Blog is Globa(lol)

Does this catapult me to all the way up to third-rate blogger status :-)

http://thefinanser.co.uk/fsclub/2009/06/things-worth-reading-16th-june-2009.html



Things worth reading: 16th June 2009
Things we're reading today include:


Robert Peston: Should we trust the regulators? (BBC)
FSA Must Assess Impact Of Rule Changes On Bank Lending (Times)
John B. Frank: Anti-Phishing with Two Factor Authentication (PIN Payments News/Information Security Resources)
Africa pioneers mobile bank push (BBC)
Sumitomo Mitsui: Japanese Bank Plans $9.4 Billion Share Sale (New York Times)
Financial crisis: Worst may be still ahead, says IMF chief(Guardian)
European recession will worsen, says economist(Independent)
Eurozone Banks 'face $283bn of further writedowns' (Times)
Financial Stability Review June 2009 (ECB)
US recession will be less severe than feared, IMF says(Telegraph)
It’s Too Soon to Call an End to the Banking Crisis (New York Times)
Helping countries emerge from the economic crisis: a World Bank perspective (Insead)




The Finanser is sponsored by Vocalink

For details of sponsorship email us.






Reblog this post [with Zemanta]
http://www.typepad.com/services/trackback/6a01053620481c970b0115701fb8aa970c

Dynamic Card Solutions easyPIN Available

Dynamic Card Solutions Announces CardWizard® easyPIN
Cardholders Now Have the Freedom to Change Their EMV PINs Anywhere, Anytime

ENGLEWOOD, Colo.--(BUSINESS WIRE)--Dynamic Card Solutions (DCS), the leading instant card issuance, PIN selection and PIN change provider for financial institutions, today announced the availability of its new patent-pending EMV PIN change solution — CardWizard® easyPIN — that allows portable and remote changing of cardholder’s EMV PINs. By utilizing DCS’ new software-based easyPIN solution and associated unconnected smart card readers, issuers can now offer their cardholders the freedom to perform EMV PIN management from their home, office or anywhere the customer has access to a web browser or telephone.

Cardholders typically need to change their PINs because they either cannot remember a randomly assigned PIN, they want to use one PIN across multiple cards, or they have entered the wrong PIN multiple times and their card is now blocked. Traditional EMV PIN management methods require cardholders to physically go to their financial institution’s chip-enabled ATM to change their PIN. With DCS’ easyPIN, issuers do not need any brick and mortar branch or ATM location to achieve the PIN change or card unblock.

DCS’ easyPIN makes use of an Internet or phone connection and a small unconnected handheld smart card reader that is issued by their financial institution. Cardholders can simply insert their EMV card into the smart card reader and follow the instructions that prompt them to change their PIN. This can be done through the online banking website, interactive voice response (IVR) support, or an optical interface.

“Until now, changing chip-based PINs required costly brick and mortar-based infrastructure, but now, thanks to easyPIN, cardholders can change EMV PINs anywhere,” said Spencer Cark, director of international markets for DCS. “DCS easyPIN saves issuers significant infrastructure investment, while enhancing cardholder satisfaction and ultimately increasing card usage.”

DCS works with multiple card reader manufactures to develop devices compatible with CardWizard easyPIN technology. The flexible design of DCS’ easyPIN means it can be integrated into issuers’ existing customer delivery channels such as home banking, and the solution is also compatible with standard Two Factor Authentication (2FA) functionality, such as MasterCard CAP & Visa DPA, ensuring that the deployed readers provide a wide range of features to cardholders.

The easyPIN platform is available now. For more information about the system and other DCS’ instant issue technology offerings, please visit www.instantissuance.com.

About Dynamic Card Solutions

Founded in 1996 and a wholly owned subsidiary of Dynamic Solutions International, Dynamic Card Solutions (DCS) develops instant issuance, PIN selection and PIN change solutions for banks, credit unions and retailers that issue EMV, contactless and magnetic stripe cards. DCS is the leading instant issuance provider for Visa® and MasterCard® debit cards. The company offers fully integrated solutions that allow financial institutions and retailers to quickly and securely issue debit, credit and ATM cards instantly at branch or store locations, and change PINs virtually anywhere, anytime. Issuing cards instantly increases customer service, card sales and revenue, and eliminates current card issuance costs. DCS' system includes a user-friendly administration component that provides full reporting, card inventory and more. All solutions utilize encryption and are compliant with recommended security procedures for instant issuance. For additional information, call +1 303.754.2000 or visit the Dynamic Card Solutions Web site at www.instantissuance.com.

© 2009 Dynamic Card Solutions. All Rights Reserved. All trademarks, service marks and trade names referenced in this material are the property of their respective owners.


, , , , , , ,

Visa Clashes with Wal*Mart on $48 Billion Card Fee

Visa Clashes With Wal-Mart on $48 Billion Card Fee
By Peter Eichenbaum

June 17 (Bloomberg) -- Visa Inc., MasterCard Inc. and JPMorgan Chase & Co., already squeezed by new U.S. curbs on how credit cards are marketed to consumers, are girding for a renewed battle over $48 billion in fees levied on merchants.

Lawmakers are promising new rules to bring down the interchange fee, a charge on purchases sometimes topping 3 percent that’s split by the two banks serving the customer and merchant. Supporters of the legislation include the biggest retail chains, restaurants and small businesses, which say the fees erode profit and inflate prices.

The debate pits the largest card lenders including JPMorgan and the two biggest payment networks, Visa and MasterCard, against Wal-Mart Stores Inc. and Target Corp. Interchange is the second-biggest cost after payroll, Target said, and merchants want to negotiate lower payments collectively without running afoul of antitrust law.

“The real question is whether the government is going to jump in and get into the game of price control in the free market,” Chris McWilton, MasterCard’s U.S. markets president, told investors at a June 4 conference. San Francisco-based Visa said June 5 the legislation would raise consumer costs and cut rewards. A similar bill failed last year, the firm said.

Continue Reading at Bloomberg


, , , , , , , ,

Canada Starts Chip and PIN Propaganda


With Canada completing the move from magnetic stripes to smart cards by the end of 2010, they are beginning their "Smart Card's Are  Safer" Campaign.  Here's a story from the Vancouver Sun pointing out that if you use smart cards, then you won't ever have to buy $10,000 worth of TV's in Memphis... 


How smart is the smart chip?

By Eric Lam, Financial PostJune 16, 2009
 
With credit and debit card fraud on the rise, Canadian issuers and banks are switching to more secure smartchips in place of the vulnerable magnetic stripe. But, according to experts, the chip is no guarantee of a fraud-free world.

Last year, when Bruce Cran went to Europe, he had all kinds of trouble with his Canadian credit cards. Cashiers in shops and restaurants everywhere gave him funny looks because his card was the old-fashioned kind: No space-age microchips, just a magnetic stripe. Still, they took his card and Mr. Cran, head of the Consumers' Association of Canada, went home without a care in the world.

That changed when he tried to get into an Ottawa hotel room 10 days later.
"Someone tried to purchase $10,000 worth of TVs in Memphis, Tenn. using my card," he said with a chuckle. "I just couldn't believe it."
Mr. Cran managed to get a room using another card, but it took him a day to find out what actually happened and another two weeks to get a new card. He does not know whether the crooks who nabbed his card number, probably when he handed it over at a Parisian outdoor cafe, managed to get away with the Sony TVs.
"If it had been a chip card, they couldn't have done it," he said.
Mr. Cran's story is the kind of cautionary tale that Canadian banks and credit card companies are looking for as they move to the next generation smartchip credit card. Many people already have one, and the industry expects complete market adoption by 2010.

The new cards are meant to curb credit card fraud by encrypting account information on a microchip protected by a personal identification number (PIN). Instead of signing receipts, consumers enter a PIN to validate a transaction.

Continue Reading at the Vancouver Sun







, , , , ,

Wasn't Me...It Was the Russian Hackers!


From the Washington Post

An Odyssey of Fraud - Brian Krebs

Andy Kordopatis is the proprietor of Odyssey Bar, a modest watering hole in Pocatello, Idaho, a few blocks away from Idaho State University. Most of his customers pay for their drinks with cash, but about three times a day he receives a phone call from someone he's never served -- in most cases someone who's never even been to Idaho -- asking why their credit or debit card has been charged a small amount by his establishment.

Kordopatis says he can usually tell what's coming next when the caller immediately asks to speak with the manager or owner.

"That's when I start telling them that I know why they're calling, and about the Russian hackers who are using my business," Kordopatis said.


The Odyssey Bar is but one of dozens of small establishments throughout the United States seemingly picked at random by organized cyber criminals to serve as unwitting pawns in a high-stakes game of chess against the U.S. financial system. This daily pattern of phone calls and complaints has been going on for more than...

Continue Reading at Security Fix by Brian Krebs

 

Fraud Constantly "Dogging" Online Banks

Starting to become Pet Peeve?

With so much online fraud aimed at users of Web-based banking and brokerage sites, experts have long postulated that financial services providers would eventually play a bigger role in helping end users defend themselves, such as via offering advanced security features and anti-malware tools directly to customers versus relying on end users alone to protect their own devices.

However, as many of these companies have attempted to foster such programs over the years, as in the distribution of two-factor authentication tokens and the like to their customers, users have frequented rebelled in the name of keeping their online interactions as straightforward as possible, instead of embracing the extra devices or passwords they've been asked to use to go about their e-business.

In fact, some experts have maintained that the more virtual levers that banks and other companies force their users to throw in order to get into their online accounts, the more likely those customers are to simply to move to another service provider whose systems aren't as onerous to use. (Editor's Note:  Besides NOT being limited to 2FA, and providing a money transfer platform, bill payment platform and eCommerce transactional platform, "straightforward" is yet another reason HomeATM's PCI 2.0 Certified device is superior to tokens and OTP dongles.  There is nothing "onerous" about using it and you can't get anymore "straightforward."  Last time I checked, "everyone" knows how to swipe their card and enter their PIN.  It's what they do at ATM's and/or brick and mortar locations everyday of their lives.)

At the same time, attacks including Trojans and Web-based drive-bys targeting e-banking and trading applications have only continued to become more ubiquitous and sophisticated.

Now, some proponents of the provider-driven anti-malware model contend that the time has actually come for the concept to take off, based both on the sheer amounts of money, and customers, that banks are losing at the hands of cyber-crime.


With the towering costs of customer churn and people returning to paper-based accounts staring them in the face, online banks are looking for new ways to solve the problem, claims Michael Stanfield, CEO of Virginia-based Intersections, a vendor of so-called identity risk management solutions.

In addition to the continued proliferation of threats, the arrival of more effective anti-fraud tools, such as those sold by Intersections, is driving more widespread adoption of the systems among banks and trading companies, he said.

To note, 90 percent of the company's current business is coming from white-label OEM deals with big name banks


"The perception that integrating more expansive security features into their services will actually cost them business has led some of these providers to hesitate to be more proactive, but in the next two or three years I think we're going to see a dramatic shift as these companies simply can no longer afford the levels of fraud and customer turnover that they've seen over the last few years," Stanfield said. including Bank of America, CapitalOne and CitiBank, the executive said.



Reblog this post [with Zemanta]
ON-DEMAND WEBCAST 
About the Sponsor



VeriSign Enterprise Security Services
VeriSign Enterprise Security Services is a division of VeriSign, the trusted provider of Internet infrastructure services for the networked world. Through this business unit, VeriSign provides a suite of security services for IT professionals seeking a balance between escalating information security demands and resource availability. The Enterprise Security Services suite includes Managed Security Services, iDefense Security Intelligence Services, and Global Security Consulting. This flexible portfolio of services make use of the most current, real world intelligence, experience and technology to deliver proven solutions that address the growing issues of cost, complexity and compliance that challenge IT security professionals.
> Click here for more information

Poorly integrated application security efforts waste time and money, and put data and business at risk. Application security is an essential security program that should be integrated into all aspects of the application lifecycle across the enterprise. Without a well-defined and integrated application security program, opportunities for improvement are lost and the application portfolio costs rise along with risks to the business.

VENDOR WEBCAST
Managing Application Security Programmatically: Learn How to Increase Security and Compliance and Reduce Business Risk, All While Lowering Application Security Program Costs
WHEN:AVAILABLE ON DEMAND
SPEAKERS:Fred Langston, Senior Product Manager, CISSP, VeriSign Global Security Consulting
 Dr. Chenxi Wang, Principal Analyst, Forrester Research
SPONSOR :  VeriSign Enterprise Security Services
 VIEW WEBCAST! 


ABOUT THE WEBCAST:
By developing and implementing a holistic application development process, you can measure actual, positive ROI that is more difficult to show in other security program disciplines. In this webcast, featured guest Dr. Chenxi Wang, principal analyst at Forrester Research, discusses this methodical approach to application security and how it enables attainment of the following key objectives:
  • Efficiently and effectively assess and mitigate application security risks to business
  • Leverage existing processes to minimize business impacts of securing the enterprise applications
  • Re-engineer existing poorly, less secure operating processes - developing an enterprise framework for a set of application security controls
  • Create a real-world, highly relevant set of metrics to measure program success and ROI

ABOUT THE SPEAKERS:
Fred Langston, Senior Product Manager, CISSP, VeriSign Global Security Consulting

Fred Langston has over 20 years of professional information security experience working on projects for hundreds of clients in a variety of markets. He has specialized in risk assessment and risk management program development, developed several risk analysis tools, and is a well known industry expert in information security regulatory compliance. His areas of expertise are far ranging and cover the technical, management, and business aspects valuable to the executive audience.


Dr. Chenxi Wang, Principal Analyst, Forrester Research

Dr. Chenxi Wang is a leading expert on content security, application security, and vulnerability management, and she leads the effort at Forrester to build the application security and Web 2.0 security research portfolio. Chenxi was an associate professor at Carnegie Mellon University (CMU). Chenxi received her Ph.D. in computer science from the University of Virginia, where her thesis work was awarded an ACM Samuel Alexander award for excellence in research.

VIEW WEBCAST




VIEW WEBCASTS 
Get informed. Check out all our available webcasts to get the information you need to make the right IT Business decisions from leading industry experts and vendors.

View all Webcasts

Disqus for ePayment News