Saturday, September 12, 2009

No Freedom For You! SoupNazi/Gonzalez Pleads Guilty

Hacker Gonzalez pleads guilty to 20 charges | ITworld

IDG News Service —



Hacker Albert Gonzalez, accused of masterminding the massive data thefts at BJ's Wholesale Club, TJX and several other retailers, has pleaded guilty to 19 charges related to computer hacking and credit card fraud, the U.S. Department of Justice said.



Gonzalez, 28, of Miami, was a member of a group of hackers that stole more than 40 million credit and debit card numbers from TJX, BJ's Wholesale Club, OfficeMax, Boston Market, Barnes & Noble and Sports Authority, the DOJ said. He pleaded guilty Friday to 19 counts of conspiracy, computer fraud, wire fraud, access device fraud and aggravated identity theft in U.S. District Court for the District of Massachusetts.



Gonzalez also pleaded guilty to one count of conspiracy to commit wire fraud relating to hacks into the Dave & Buster's restaurant chain, which were the subject of a May 2008 indictment in the Eastern District of New York. The pleas in both cases were entered before U.S. District Court Judge Patti Saris in federal court in Boston.



In August, Gonzalez was also indicted in New Jersey for the theft of more than 130 million credit and debit cards. He was charged, along with two unnamed co-conspirators, with using SQL injection attacks to steal credit and debit card information. Among the corporate victims named in the two-count indictment were Heartland Payment Systems, a New Jersey card payment processor; 7-Eleven, the Texas-based convenience store chain; and Hannaford Brothers, a Maine-based supermarket chain.



Continue Reading








Reblog this post [with Zemanta]

Webcast: There's No Such Thing As a Trusted Website










 

 


























REGISTRATION PAGE
     First Name:
     Last Name:
     Title:
     Company:
     Address:
     Dept/BOX/ MS:
     City:
     State/Prov:
     Zip/Postal Code:
     Country:
     Email:
     Phone: - -
     Fax: - -
     Company URL:










 







How many employees in your entire organization? (including all divisions, branches, and subsidiaries)
 
Register Now



 
Featured Speakers:



Chris McCormack, Web Security Expert, Sophos



Fraser Howard, Principal Researcher , Sophos






Sophos Privacy Policy





Bookmark and Share  

 



A Dark Reading Vendor Perspectives WebCast:

Web Attacks: How Hackers Create and Spread Malware







Duration: One Hour
A brand new infected webpage is discovered every 4.5 seconds.

The web has become the key vector for online attacks and even trusted websites are no longer safe. With hackers continually changing tactics, the majority of businesses are left unprotected against modern web-based malware. Businesses can no longer get by with just protecting their email and endpoint systems.



Join this live one-hour webcast featuring web security expert Chris McCormack, and principal researcher Fraser Howard from Sophos to learn how web threats are created and spread -- and the impact they have on your business.  They’ll also discuss these key topics and more:


  • There's no such thing as a trusted website

  • How today's web attacks work

  • Three tips to safeguard your systems

Register today to attend this informative webcast.


 
 



United Business Media LLC - 600 Community Drive, Manhasset, New York 11030 - Privacy Statement

Payment Processinig Inc. Announces Exclusive Agreement with Self Storage Association







Payment Processinig, Inc. Announced as Exclusive Credit Card Processor with SSA Partner Status





Payment Processing, Inc. (PPI), the industry leader for integrated payment solutions, announces that it has been named an official partner sponsor of the Self Storage Association (SSA). In this role, PPI is the only payment processing company with SSA Partner status and will be a featured panelist for a session titled "Customer Privacy Regulations" at the upcoming SSA Fall Conference being held September 10-12th in Las Vegas, Nevada.

"We are thrilled to be the only payment processing company with Partner status for the Self Storage Association and a featured panelist at their fall convention," stated Eddie Myers, President of Payment Processing, Inc. "This platform allows PPI to continue to educate SSA members on the necessary steps that should be taken to ensure they secure a customer's private data, including payment processing information."



As the leading association for the self storage market, the Self Storage Association (SSA) is the official not-for-profit trade association representing over 6,000 direct and indirect members that own or operate over 22,000 self storage facilities throughout the United States. Headquartered in Alexandria, VA, the SSA provides members with educational resources and represents them on key legislative issues affecting the self storage market.



PPI provides self storage companies with a full range of services for integrating electronic credit and debit card payments, including gateway services, integration support, merchant support and services, and PA DSS/PCI-DSS security assistance. The company's proprietary PPI PayMover platform can be integrated with virtually any business application and is the leading payment processing solution used in the self storage market.



About the Self Storage Association

Since 1975, the Self Storage Association (SSA) has been the official not-for-profit trade association representing the self storage industry and the registered lobbying organization before the United States Congress and the federal agencies. The SSA represents the huge U.S. self storage industry that is comprised of more than 52,000 facilities. The SSA publishes the "official voice of the self storage industry," the SSA Globe magazine, on a monthly basis. The magazine is the industry's largest paid-circulation magazine and has a monthly circulation of approximately 17,000 and a national annual readership in excess of 500,000. Learn more at www.selfstorage.com.



About Payment Processing, Inc.

Since 1995, PPI has been the industry leader in providing software developers with a full range of services for developing and promoting integrated payment solutions, including PPI-developed payment gateway technology, integration support, merchant support, marketing assistance and PA DSS/PCI-DSS security services. Today, PPI is the most successful company in the world focused on integrated payments, supporting more than 1,200 partners and over 34,000 merchants with efficient, cost-effective payment solutions. In 2008, PPI processed in excess of $5 billion in Visa® and MasterCard® payments. Learn more at www.paypros.com.

Friday, September 11, 2009

Internet is "Card Not Present"...

"Card Not Present" Fraud is Growing Rampantly!



HomeATM Eliminates "Card Not Present" Fraud by enabling transactions to be conducted in a "Card Present" Environment.



HomeATM provides a low cost, 2FA 3DES E2EE PCI 2.x Certified Solution which allows Internet Retailers and Consumers to level the playing field by eliminating the "card not present" environment. 



If an online consumer was instructed to  "Swipe their Card thereby capturing the data on the magnetic stripe, it would be, by definition, a "card present" transaction. 



Therefore, our device would eliminate "card not present" fraud by "morphing" the "card not present" environment into a "card present" environment.  Yes? 



You might say that HomeATM changes the way card information is swiped. 





The way it is done now, the card details are "swiped by the fraudsters."   Does it not make more sense for the online shopper to "swipe" their own card details? Then again, we could ignore all the red flags and just keep on typing!





No let up by fraudsters as online card spend soars | Response Source

Fraud prevention specialists reveal Britain’s top UK card fraud hotspots



Many of Britain’s high street shops may have been affected by the economic downturn, but millions of consumers have been more than happy to spend their money online and through mail order with their favorite retailers. However, once again the dark side of card usage is revealed as fraud specialists, the 3rd Man, unveil the extent of criminal card activity and in particular the worst places in Britain for attempted card fraud.
An analysis of the 3rd Man’s comprehensive and detailed records shows that between August 2008 and August 2009, shoppers spent an estimated £46 billion using their cards in ‘card not present’ transactions, the term used to describe purchasing when, for example, a customer is buying online or by phone. Of this figure, fraudsters have tried their best to relieve retailers of more than half a billion pounds worth of goods.


“Although Britain has been in a serious recession, it appears that many consumers have been happy to spend their money over the Internet, which is good news,” says Andrew Goodwill, fraud specialist with the 3rd Man.



“However, fraudsters show no signs of giving up. They know that online shopping has become big business and they try every scam imaginable to dupe retailers. More and more honest people are using their cards to buy over the Internet, but unfortunately more and more fraudsters are also upping their game.” 





Editor's Note:  Time to "up OUR game" or these "jokers" will continue to steal our identities, cash, and peace of mind.  Eliminate Typing, Start Swiping and "Card Not Present" fraud will be eliminated. It's really not that difficult to grasp the concept...is it?  


Reblog this post [with Zemanta]

How To Hack an ATM Part IX (Collect All 10!)

ATM Thefts

EFT Canada Announces Agreement with Bell Canada



Toronto, Sept. 10, 2009 -PIN Payments News Blog- EFT Canada Inc. (TSX VENTURE:EFT), a leader in electronic transaction processing, today announced an agreement with Bell Canada, the country's largest communications company, to provide its Bell Business Markets division with a fully integrated business-to-business (B2B) and business-to-consumer (B2C) electronic transaction processing platform.



The solution will enable customers of Bell Business Markets to automate and process the collection and disbursement of funds online.



The EFT Canada application is a division specific solution, acting as a virtual gateway, simplifies and automates the processing of electronic funds transfer in Canada. The solution is expected to assist the Bell Business Markets in competing for and completing special projects.



"Through our comprehensive and leading solution, the Bell Business Markets is gaining a powerful and easy to use transaction processing platform," said Jonathan Pasternak, EFT Canada President. "Having been chosen by Bell as a vendor and being able to meet their high standard vendor code of conduct and practices, further enforces our credibility in the marketplace."



EFT Canada, founded in 2003, is a financial processing company that offers a complete solution to the collection and payment processing needs of small and medium sized business merchants, banks, credit unions, and other financial firms in Canada and the United States. The Company develops, maintains and delivers innovative electronic transaction processing technologies, such as customized electronic payment and collection processing solutions and gift and loyalty card services, by drawing on its operational and applications expertise. For more information, please call Jonathan Pasternak 416-781-0666 or visit www.eftcanada.com .



Source: Company press release.



Reblog this post [with Zemanta]

TransFirst Releases Way Systems way5000



Boston, Sept. 11, 2009 -PIN Payments News Blog- WAY Systems, manufacturers of mobile POS solutions and TransFirst one of the leading providers for merchant acquiring solutions announced today the release of the way5000, a credit, PIN-Debit, low-cost, pocket sized mobile point of sale device. The way5000 will be fully supported and sold throughout the TransFirst sales network.



“WAY Systems is very pleased to continue our long time partnership with an industry leader like TransFirst. WAY has built a reputation for bringing high quality, low-cost mobile point of sale devices to the mobile merchant market which has long been an important market segment for TransFirst. We are excited to be able help TransFirst enhance their leadership position with those mobile merchants”, said Mike Ryan Director for Distribution Channels for WAY Systems.



“Mobile merchants are a key part of TransFirst’s overall strategy. WAY Systems is an excellent fit to ensure we provide our merchants a cutting edge product that rounds out our suite of products and services and provides our merchants with a robust mobile device”, said Steve Cadden President and Chief Operating Officer for TransFirst.



About WAY Systems, Inc.



WAY Systems has designed, developed, tested and delivered end to end payment solutions for mobile merchants all over the world. Our products and services are designed to meet the payment transaction needs of mobile merchants and exceed industry security standards. We empower merchants to conduct business any time any where and increase their revenue by accepting credit and pin based debit cards. WAY’s innovative mobile POS devices and dedication to service make us the ideal partner for you to conduct Transactions Without Boundaries. Users of WAY terminals are invited to explore the limitless possibilities of commerce.



About TransFirst



A leading provider of secure transaction processing services and payment enabling technologies, TransFirst offers innovative products and services designed with financial institution, independent sales organization, healthcare, eCommerce, government and merchant customers’ unique needs in mind. By collaborating with our customers and utilizing strong industry knowledge, we help them grow their businesses. Founded in 1995, TransFirst continues to attain significant market share and world-class expertise in growing and profitable industry segments. Built on a platform of personal service, customer commitment and flexible pricing, TransFirst is headquartered in Hauppauge, New York, and has operations facilities in Aurora, Colo., Louisville, Colo., Omaha, Neb., Kansas City, Kan., and executive headquarters in Dallas, Texas. Company-wide, TransFirst currently processes approximately $30 billion in annual sales volume for more than 175,000 merchants and more than 1,000 financial institutions. For additional information, please call 1-800-745-2659

or visit www.TransFirst.com )





Source: Company press release.

How to Hack an ATM - Part VIII (Collect All 10!)



Pair steal 800 lb ATM with $96G inside



By Sam Wood | Inquirer Staff Writer



In our ongoing series "How to Hack an ATM" we bring you this from Philly.com



No pictures yet, so here's a picture from a previous "How to Hack and ATM" post.



Police are looking for a pair of brazen, "sophisticated" thieves who disconnected an 800-pound ATM with about $96,000 inside and rolled it out of a Delaware County hospital on a dolly.



The ATM, minus the cash, and the van the thieves used for their getaway were found aflame in Southwest Philadelphia last night, more than 24 hours after the the heist at he Delaware County Memorial Hospital in Upper Darby.



Upper Darby Police Superintendant Michael Chitwood said the pair, wearing baseball caps and keeping their heads down to conceal their facial features from surveillance cameras, disconnected three cables and successfully disarmed the ATM's alarm to carry out their caper.



"This was sophisticated, well planned, well managed," Chitwood said. "When you view the video, they didn't have a care in the world. They knew what they were doing and where they were going.



With one carrying a clipboard and the other pushing a dolly, the pair entered the hospital's lobby about 8:24 p.m. Monday and left two minutes later with the ATM, which was valued at $17,000 and had in excess of $96,000 inside, police said.

At 8:45 p.m., they are seen leaving the parking lot in a white Ford econoline van.



Continue Reading

Wal*Mart Phisher Pleads Guilty



Guilty plea in Wal-Mart phishing case

11 September 2009 - 11:54 - Finextra



A member of a phishing gang that stole financial information from thousands of people and used it to open credit accounts at Wal-Mart stores has pleaded guilty.



Tien "Tim" Truong Nguyen, from California, pleaded guilty to conspiracy, access device fraud, aggravated identity theft and being a felon in possession of a firearm, the day before his case was set to go to trial.



Nguyen was arrested in 2007, accused of setting up Web sites designed to look like they belonged to banks and other firms like PayPal. He then sent out phishing e-mails directing victims to the sites, where they were asked to enter sensitive information.



The scam netted him, and Eastern European accomplices, thousands of credit and debit card numbers, social security numbers and other personal identification information.



Continue Reading at Finextra

29 US Banks Receive Mobile Banking “Report Card” From ABI Research






Mobile Money Research Service | Mobile Banking: US Banks Report Card
NEW YORK - September 10, 2009 Contact: Christine Gallen

Contact PR

www.abiresearch.com


It has been two years since mobile banking was introduced in the United States, and analysts at ABI Research believe it is time to assess its progress, with a focus on the user-friendliness (or otherwise) of the services on offer. The firm has published a mobile banking “report card” which assesses 29 banks on the discoverability and accessibility of their mobile banking services.


Senior analyst Mark Beccue says, “People are asking ‘Is mobile banking taking off in the US?’ For that to happen, two things are required: the services must be easy to find, and accessible to a broad range of consumers . So the ‘grades’ in this report card are not about subscriber numbers or any other measure of success, but about how consumer-friendly the banks’ offerings are.”
The results are as follows:
 

                        A — Exceptional: BB&T, Eastern Bank, Fifth Third Bank, Northeast Bank,    USAA, Wells Fargo

                        B+    Very Good: Bank of America, Chase

                        B — Good: Capital One, US Bank, Huntington Bank

                        C — Average: America First, Bancorp South, Citibank, PNC, Wachovia

                        D — Below Average: Carolina First, 1st Bank, IBC Bank, Mercantile Bank, Regions, SunTrust, Synovus

                        F — Failing: M&T, Provident Bank

                       

No mobile banking offering: Citizens Bank, Comerica, HSBC, KeyBank
Of 29 banks examined, 17 are the nation’s largest retail banks. The remaining dozen banks are a sampling of other community and regional banks.


Summarizing the results, Beccue says, “We have two observations/recommendations. First, mobile banking’s reach in the US isn’t as good as it could be. If banks want mobile banking to be ubiquitous and available to as many consumers as possible, they’ll have to promote text messaging in particular as the method of choice. Secondly, if you’re in the retail banking business and you don’t have a link – or at least a list of your mobile banking services – on your website’s homepage, then you’re undermining your whole effort. Discoverability is critically important.”


Mobile Banking: US Banks Report Card” evaluates and grades 29 US banks on the reach, breadth of services offered, security, and discoverability of their mobile banking operations, resulting in a report card which shows the leaders and laggards of mobile banking in the US.


It forms part of the firm’s Mobile Money Research Service.


ABI Research provides in-depth analysis and quantitative forecasting of emerging trends in global connectivity. From offices in North America, Europe and Asia, ABI Research’s worldwide team of experts advise thousands of decision makers through 25 research and advisory services. Est. 1990. For more information visit www.abiresearch.com, or call +1.516.624.2500.






Reblog this post [with Zemanta]

Society of Payment Security Professionals Announcment

SOURCE: Society of Payment Security Professionals

The Society of Payment Security Professionals Announces New CPISM/A Training Dates and a New Industry Certification

As Membership Grows So Do Offerings



Payment Security Professionals



PARK CITY, UT--(PIN Payments Blog- September 11, 2009) - The Society of Payment Security Professionals (SPSP) announced today that due to high demand Certified Payment-Card Industry Security Manager (CPISM) and Certified Payment-Card Industry Security Auditor (CPISA) training courses will be held once each quarter. Courses were booked to capacity the past two quarters and the numbers are anticipated to remain the same for the upcoming course scheduled for November 10-13th, 2009 in Dallas, TX.



In addition to increasing the frequency of public CPISM/A courses, the SPSP also announced that it will be unveiling a new certification in 2010. Like the CPISM/A certifications, the new certification, Certified Payment-Card Industry Privacy (CPISP), will be created by the Society of Payment Security Professionals (SPSP) with the collaboration of industry and educational experts. CPISP will focus on privacy and regulatory information within the Payments Industry as it applies to PCI DSS.



Privacy and regulatory expert, Dr. Heather Mark, has said "We have received an overwhelming amount of interest from people in the Payment Card Industry wanting to increase their knowledge regarding privacy and regulation. This new certification will educate participants on these issues and help identify them as experts in the industry."



"In response to the large amount of inquires we receive about privacy and regulatory issues, an article focusing on these issues has been and will continue appearing in Secure Payments Magazine," says Dr. Mark. The next third quarter issue of Secure Payments is scheduled to be released on October 1st, 2009. This issue includes a product guide and several articles focusing on emerging technologies as well as Dr. Mark's regulatory column.



For more information about the SPSP, any of the certifications offered, or Secure Payments Magazine please visit www.securepaymentsmag.com, www.paymentsecuritypros.com or contact info@paymentsecuritypros.com.



About the Society of Payment Security Professionals



The Society of Payment Security Professionals' objective is to provide individuals and organizations involved in payment security with an online community to share information, and access education and certification opportunities. Society members come from a variety of businesses including card brands, merchants, acquirers, ISOs, and more. Though their organizations may vary, they all share one purpose: to protect sensitive customer data using the most current, viable technologies and processes. The SPSP is managed by The Aegenis Group.





Media Contact:

Tracie Byron

Email Contact

435-615-6711

Society of Payment Security Professionals

Director of Business Development

Never Forget!











































































Finovate 2009 - Today is the Last Call for Early Bird Registration

Finovate 2009 - Last Call for Early Bird Registration!



Finovate2009_logo-140px.jpgFinovate will return to New York City on Tuesday, September 29 to showcase the best new financial and banking technology innovations from established leading companies and hot young startups. Handpicked from hundreds, the companies get a mere 7 minutes on stage to demo (no powerpoint allowed) their latest and greatest.





Early bird registration closes Friday, Sept. 11th - so if you're interested in attending and saving some money in the process, be sure to register ASAP!   It's a great event and HomeATM was honored to be handpicked from the hundreds of companies during Finovate Startup09 last April.  Below is our 7 minute (no powerpoint allowed) demo on our P2P "real-time" 2FA 3DES DUKPT E2EE PCI Certified 2.x Money Transfer Application.





http://finovate.com/startup09vid/homeatm.html
New iPhone Anti-Phishing Feature Fails Researchers discover iPhone OS 3.1's anti-phishing feature is not working properly



Sep 10, 2009 | 03:46 PM By Kelly Jackson Higgins

DarkReading



The new Apple iPhone OS 3.1 software comes with a new anti-phishing feature for the Mobile Safari browser, but researchers say the filter doesn't work.




"I've not been able to get it to block anything," says Michael Sutton, vice president of research at Zscaler, who has been testing the mobile browser's security feature against several phishing sites identified on PhishTank. While Apple's Safari for the desktop blocks many of the sites, the iPhone's mobile version didn't block any that he tested.



Continue Reading






Reblog this post [with Zemanta]

Placecast Announces Study on mCommerce Usage

San Francisco, (PIN Payments News Blog) -- Today 1020 Placecast announced the beginning of a six-part series exposing the realities of America's consumer and what they really want to use their mobile device for when it comes to shopping, mobile advertising, mobile marketing, coupons and location-based services.



The Alert Shopper is an online series that is located at http://blog.placecast.net/, featuring both first-person and third-party research in conjunction with Harris Interactive on consumer shopping habits and interest around the use of mobile devices and alerts when shopping.  With all of the hype surrounding emerging mobile content and mobile advertising, Placecast sought out to talk to America's consumer, face-to-face and captured quite a bit of insightful feedback on what people want and don't want.



Over the next few months, the Alert Shopper blog will feature unique insights into the mobile usage patterns of today's American consumers, quantitative survey research from Harris Interactive as well as a broad range of retail shopping trends. You'll meet Joni, a 46-year-old mother who talks to us about her dependence on her cell phone and her tactics of savvy shopping and brand-loyalty. Then you'll meet Joseph, a 31-year-old early adopter, who discusses exactly how he looks for sales and what retailers like Levi's can do to improve his experience.



These real consumer profiles are supplemented with quantitative survey research from Harris Interactive, focused on gauging interest levels in different types of mobile marketing, as well as a broad range of retail categories.



The Alert Shopper will cover trends as they relate to multi-location retail outlets like Target, Walmart, Kroger, Safeway, Best Buy, Kohl's, Home Depot, Walgreens, Lowes, CVS, Sears, SuperValu, Rite Aid, Macy's, Publix, JC Penney, GAP, Meijer, Staples, Toys 'R' Us, Office Depot, Nordstrom, Whole Foods, Menards, Dillard's, Giant Eagle, Auto Zone, PetSmart, Neiman Marcus, The Shack, Sheetz, Starbucks, and Dick's -- to restaurants like Sonic, Applebee's, Chili's Olive Garden, Red Lobster, Friday's, Burger King, McDonald's, Jack in the Box, KFC, Taco Bell, Pizza Hut, Subway, Wendy's, Outback, Arby's, Chick-Fil-A, Quiznos and The Cheesecake Factory .



Also the series will take at look at specialty stores such as REI, American Eagle, Pottery Barn, Williams Sonoma, Crate & Barrel, Children's Place, Brooks Brothers, Coach and Chanel. "It's our hope that The Alert Shopper will pioneer research in retail as it relates to understanding the role of the mobile device," states 1020 Placecast CEO Alistair Goodman



The first installment of the Alert Shopper can be found here:



New installments will appear monthly on the site:  (http://blog.placecast.net/)  To sign up for alerts on new installments, follow the series by adding @placecast on Twitter.



About 1020 Placecast, Inc.

1020, Inc. is the developer and owner of Placecast Media, the first location-based platform specifically designed to use digital marketing on the web and mobile to drive consumers into physical environments. 1020's groundbreaking Placecast service recently earned the company the OnMedia Top 100 Award, given to game-changing companies in the marketing, branding, advertising, and PR industries. Current partners include NAVTEQ and Alcatel-Lucent, and current advertisers include Microsoft Windows Mobile, FedExOffice, Avis and Budget Rental Cars and Hyatt Hotels. 1020 is funded by Voyager Capital and Onset Ventures.



For more information about Placecast, visit www.placecast.net .



Source: Company press release.





Reblog this post [with Zemanta]

Thursday, September 10, 2009

Dynamic Duo(poly) Needs to be Challenged for SEPA Ration

10 September 2009 - 10:26

New schemes vital to Sepa for cards success - ECB's Tumpel-Gugerell

MasterCard and Visa need to be challenged by at least one new scheme if Sepa (Single euro payments area) for cards is to succeed, according to ECB executive board member Gertrude Tumpel-Gugerell.

In a speech at the EFMA conference on cards and payments, Tumpel-Gugerell says a single market for cards is the "missing piece in the Sepa puzzle" and warns Europe needs to overcome the "current stagnation".



Citing research from the ECB and De Nederlandsche Bank, she says a new Europe-wide card scheme could provide a "decisive impetus" to solving interoperability and overcoming fragmentation in the market, benefiting customers and merchants.



There are currently three scheme initiatives and Tumpel-Gugerell has called on those involved to "get down to business now"...



Continue Reading at Finextra 



Related:



Aug 13, 2009


MasterCard Inc. and Visa Europe could face competition in the coming years from new European-centered payment card networks such as Payfair and Monnet. Belgian retailer Colruyt Group is planning to begin testing the Payfair debit card ...


Jul 10, 2009


I would suspect that Monnetwould be based on the Chip and PIN system, which is more secure than what Visa and MasterCard have been pushing with their signature debit. I have long said that signature debit should be scrapped in it's



Jul 14, 2009


Several major French and German banking companies are said to be backing the Monnet debit card, and said last week that they expect to create a company then that would focus on building a payments network. See "Is Monnet Painting Visa into a corner?









Reblog this post [with Zemanta]

Happy Birthday ATM! Does Life Begin at 40?

09/09/09 was more than just a calendrical anomaly...



It was more than "A Day in the Life"



It was also the ATM's 40th birthday!




Wired put together the graphic on the left.  Here's a snippet from their posting:



"September 9 is the 40th birthday of the automated teller machine in the US. To celebrate the invention that spews twenties at two in the morning, we're spitting out some numbers of our own."



From: Wired.com



Interesting!  Yes?

Reblog this post [with Zemanta]
Is PCI DSS a Safe Investment?

By Robert Vamosi, Javelin Strategy & Research



Should merchants continue to invest in Payment Card Industry Data Security Standards (PCI DSS) in a down economy? Yes.



The losses—not just in fines and litigation, but also reputational damage—associated with the consequences of a data breach are astronomical when compared with the annual burden of maintaining compliance. PCI is an excellent baseline for cardholder security, but should PCI be made law? On this, there is plenty of room for debate...



Continue Reading at Bank Systems and Technology





Reblog this post [with Zemanta]

Trustwave Acquires VERICEPT









Data Loss Prevention Technology to be Integrated into Trustwave's Security and Compliance Suite




Chicago, Sept. 10, 2009 -(PIN Payments News Blog) – Trustwave, the leading provider of on-demand data security and payment card industry compliance management solutions to businesses and organizations throughout the world, has acquired Vericept, a leading provider of data loss prevention (DLP) and intellectual property protection solutions. The terms of the deal are confidential.



Data loss prevention solutions are most often used to monitor business processes in support of compliance mandates, to protect brand and reputation by enforcing customer data privacy and to defend strategic information and intellectual property against inadvertent and malicious loss. Leading organizations across multiple industries including financial services, healthcare, aerospace and defense, manufacturing, technology, education and retail utilize DLP solutions. With DLP, advanced content inspection is performed on data in use (e.g., endpoints), data in motion (e.g., network) and data at rest (e.g., data storage) to help detect and prevent the unauthorized use and transmission of confidential information. DLP is also used to demonstrate compliance across multiple standards and regulations, such as the PCI DSS and HIPAA, as part of a system of control over information.



The core of Vericept’s DLP solution is its patented Content Analysis Engine, which analyzes content against policy, helps detect and classify structured and unstructured content, as well as, text extraction of any file type. This patented detection and classification technology extends to data-in-motion to address Web 2.0 threats by identifying the use of applications such as blogs, social networking sites and Webmail to accurately identify and control sensitive data. Once data is classified, it can be managed consistently according to policy from the moment it is created.



Specifically, Vericept’s leading DLP solutions help address multiple requirements of the Payment Card Industry Data Security Standard (PCI DSS) version 1.2. PCI DSS is the payment card industry security requirement for entities that process, transmit and/or store cardholder data, which has been endorsed by all the major card brands – Visa Inc., MasterCard Worldwide, Discover Network, American Express and JCB. Using DLP technology, businesses can meet the following seven of the 12 requirements, further strengthening Trustwave’s position as a leading provider of PCI DSS services and solutions:
  • Requirement 2: Do not use vendor-supplied defaults for system passwords and other security parameters


  • Requirement 3: Protect stored cardholder data


  • Requirement 4: Encrypt transmission of cardholder data across open, public networks


  • Requirement 6: Develop and maintain secure systems and applications


  • Requirement 8: Assign a unique ID to each person with computer access


  • Requirement 9: Restrict physical access to cardholder data


  • Requirement 10: Monitor all access to network resources and cardholder data




“We’re very excited to offer our customers a leading DLP solution that can manage sensitive data, scale to meet expanding business requirements and maintain high performance as business continues in real time,” says Robert J. McCullen, chairman and CEO of Trustwave. “Vericept’s DLP technology complements our current portfolio of security solutions offered to our global customer base.”



“The 451 Group believes concerns about data security and leak prevention are central to both regulatory compliance and network security,” says Paul Roberts, senior analyst for enterprise security at The 451 Group. “Trustwave’s acquisition of Vericept will allow it to marry Vericept’s expertise in inspecting data flows to and from the endpoint and on the network with Trustwave’s broad portfolio of managed security products and compliance offerings.”



Vericept’s DLP solutions help customers streamline and demonstrate compliance. With pre-defined compliance categories that specifically address standards such as PCI DSS, HIPAA and GLBA, Vericept’s patented DLP classification technology precisely monitors data to ensure compliance with company policy.



“We’ve developed a leading DLP technology for scanning and detecting sensitive information and mitigating risk based on policy requirements. Our DLP solutions ensure that a business’ sensitive data or competitive intelligence is not lost or leaked, compliance is enforced and brand equity is protected,” says Dave Parkinson, former CEO of Vericept, who will become Trustwave’s general manager of security services.



About TrustwaveTrustwave is the leading provider of on-demand and subscription-based information security and payment card industry compliance management solutions to businesses and government entities throughout the world. For organizations faced with today’s challenging data security and compliance environment, Trustwave provides a unique approach with comprehensive solutions that include its flagship TrustKeeper® compliance management software and other proprietary security solutions. Trustwave has helped thousands of organizations—ranging from Fortune 500 businesses and large financial institutions to small and medium-sized retailers—manage compliance and secure their network infrastructure, data communications and critical information assets. Trustwave is headquartered in Chicago with offices throughout North America, South America, Europe, Africa, China and Australia. For more information, visit https://www.trustwave.com .









PULSE and TRIONIS Sign Long-Term European ATM Acceptance Agreement



Houston and Brussels, Belgium -PIN Payments News Blog— PULSE, the Discover Financial Services business unit responsible for expanding global cash access for the company, has signed a long-term ATM acquiring agreement with TRIONIS, a European interbank processing network. TRIONIS is jointly owned by retail banks from nine European countries, the European Savings Banks Group and First Data.



Under terms of the agreement, when fully implemented, more than 74,000 TRIONIS ATMs across Europe will be able to process ATM transactions for Diners Club International® and Discover® cards.



“Since acquiring Diners Club, one of Discover’s priorities has been to strengthen global acceptance,” said Dave Schneider, PULSE president. “Our agreement with TRIONIS is a significant multi-country acquirer agreement to further European acceptance of Diners Club and Discover cards and an important step in helping reach that goal.”



The service went live in several countries on July 1, with acceptance of Diners Club cards at the ATMs of banks in Austria, Switzerland, Portugal, Spain, Luxembourg and Belgium. Discover cards are expected to be accepted at TRIONIS European ATMs beginning in October 2009.



“TRIONIS is pleased to be able to facilitate broader card acceptance at European cash access machines,” said Ernst Verbeek, TRIONIS managing director. “Acceptance of Diners Club and Discover cards will allow us to serve more cardmembers, while giving ATM operators access to additional ATM transactions.”



About PULSE



PULSE is one of the leading U.S. ATM/debit networks, currently serving more than 4,500 banks, credit unions and savings institutions across the United States. PULSE is owned by Discover Financial Services (NYSE: DFS). The network links cardholders with more than 289,000 ATMs, as well as POS terminals at retail locations in the U.S. The company is also a valued resource for industry research related to electronic payments and is committed to providing its participants with education on evolving products, services and trends in the payments industry. For more information, visit www.pulsenetwork.com .



About TRIONIS



TRIONIS offers the issuers of 165 million cards access to cash at more than 74,000 ATMs across Europe. TRIONIS provides processing services to its users for switching POS and ATM card payment transactions on EUFISERV and all other payment card brands. TRIONIS is a Brussels-based company owned by retail banks from nine European countries, the European Savings Banks Group and First Data. Its mission is to develop, maintain and operate international payment services for the financial industry. More on www.trionis.com .



Source: Company press release.





Reblog this post [with Zemanta]

Disqus for ePayment News