Saturday, February 13, 2010

Interac Disappointed Govt Won't Allow it to Profit

The Star reports that (apparently clueless) Canadian regulators have decided that allowing Interac to go for profit would be anti-competitive? 

Interac to remain non-profit: Regulator

In a decision Interac described as "disappointing," the federal competition watchdog said Friday that it could not support the debit service provider's bid to become a for-profit company.



Catherine Swift, president and chief executive officer of the Canadian Federation of Independent Business, called the decision "disappointing," saying it's "laughable" to suggest allowing Interac to go for-profit would be anti-competitive in the face of "the giant behemoths Visa and MasterCard."











Friday, February 12, 2010

Microsoft to Take Another Stab at Mobile

Microsoft to Take Another Stab at MobilePeter Svensson writes for Tech News World that Microsoft is getting back into the mobile game with a "major revamp" of it's phone software, combined with the fact that Steve Ballmer will speak at Mobile World Congress.



If Microsoft unveils Zune-like software for mobile phones on Monday, it might attract some badly needed interest.  The company's efforts in the smartphone realm have paled next to the successful Apple and RIM models in recent years.



"This is kind of their last chance," said Forrester analyst Charles Golvin. "If Windows Mobile doesn't get it right this time around, they're probably toast."


Microsoft (Nasdaq: MSFT) is expected to announce a major revamp of its phone software Monday, in an attempt to regain momentum in a crucial market where it's been overshadowed.
CEO Steve Ballmer will be speaking at Mobile World Congress in Barcelona, Spain, the world's largest cellphone trade show, and analysts expect him to reveal Windows Mobile 7. The software could be in phones by late this year.


Continue Reading









Western Union to Pay $94 Million in Settlement, No Wrongdoing

Western Union to Pay in Border-Crime Deal



By RANDAL C. ARCHIBOLD

Published: February 11, 2010



Western Union will pay $94 million to settle a long-running battle with Arizona over whether the company turned a blind eye to the use of its services in border-related crime.



Under the agreement, in which Western Union admitted no wrongdoing, as much as $50 million will go to support law enforcement agencies working to crack down on drug and human smuggling in Arizona and three other border states. The company also agreed to provide border state prosecutors access to wire transfer records, something the company had resisted but Arizona officials considered crucial to their cases.



Continue Reading at NYTimes.com











Mobile Remote Deposit Capture Will Eliminate Over 1.5 Billion Check Deposit Transactions From U.S. Bank Branches By 2014

Mercatus Study Indicates Strong Consumer Interest in Mobile Remote Deposit Capture, Creating Platform for 'Thin Branch' Expansion Strategies




BOSTON, Feb. 11 /PRNewswire/ -- Strong consumer interest in Mobile Remote Deposit Capture (Mobile RDC) will dramatically alter the current deposit-taking activities of retail banks and provide a viable roadmap to banks pursuing 'thin branch' strategies, according to a study released today by Mercatus LLC, a strategic consulting and investing firm focused on retail financial services.



The Mercatus Mobile RDC Adoption Research Study was conducted in December 2009 as part of Mercatus' on-going Franchise Health study. The research queried more than 2,100 US consumers regarding their retail banking services needs, decision making, and behaviors.



"We expect consumers to significantly embrace mobile remote deposit capture and it will be the 'killer app,' said Bob Hedges, Mercatus managing partner. "With consumers placing a premium on convenience, mobile RDC has the potential to significantly change retail banking's business model by providing a way for people to do basic banking without branches. Retail financial service companies have the game-changing opportunity to provide both increased convenience and lower costs. Mobile RDC definitely levels the playing field across competitors."



According to the study, close to two thirds (59%) of today's mobile banking customers are likely to adopt mobile remote deposit capture if the technology is offered by their banks. At the segment level, 66% of mobile banking consumers age 26 to 34 and 69% of mobile banking users age 35 to 44 years old indicated they were likely to adopt mobile deposit capture.



Adoption potential was also strong among consumers not currently using mobile banking. Among consumers not currently utilizing mobile banking, 35% of consumers 18 to 34, and 25% of those age 35 to 44 indicated they were likely to adopt mobile RDC if it were offered by their bank.



Likely adopters pointed to several key factors driving interest in mobile remote deposit capture, including:

  • Convenience and accessibility of mobile phone-enabled deposits (52%)

  • Faster accessibility to funds (45%)

  • Lower time cost relative to other deposit options (39%).





Consumer reluctance to adopting mobile RDC was focused on a limited set of factors. In the Mercatus study, not surprisingly, potential security concerns were cited as the leading consumer factor in not being positively inclined to adopt mobile RDC. Reflecting the routine nature of deposit-making transaction, the next set of reasons cited by consumers for not using mobile RDC were the already convenient locations of branches and ATMs. Convenience is clearly the dominant consumer consideration.



"Consumer interest in mobile RDC, and mobile financial services in general, suggests that a significant percentage of deposit volume is available for migration to those financial services institutions offering mobile RDC," said Hedges. "Despite the potential opportunity mobile RDC presents, only a limited set of competitors have launched mobile RDC applications today. A significant strategic opening exists for the early adopters in that they can gain new customers, as well as reduce bank branch operating expenses," he said.



Beyond the compelling convenience benefits for Mobile RDC to consumers, the adoption of Mobile RDC represents a significant opportunity to reduce traditional branch deposit transaction volume. The Mercatus study found that consumers likely to adopt mobile RDC, today, are responsible for approximately 30% of branch consumer deposit volume. "With only moderate adoption of Mobile RDC by consumers, banks can expect to see dramatic reductions in the volume of branch deposit transactions. The incredible convenience benefit to consumers is equally matched by the strategic cost structure benefit to banks," Hedges said. Mercatus forecasts that with Mobile RDC, more than 1.5 billion check deposit-making transactions will be eliminated from U.S. bank branches by 2014.



The Mercatus Mobile RDC Adoption Research Study builds on previous mobile financial services consumer research conducted by Mercatus. Among the findings of the December 2009 study, were:
  • Banks offering mobile financial services can increase new customer acquisition by as much as 60%

  • Nearly one-third of consumers are using, or considering using, mobile financial services in the next year

  • Consumer mobile financial services adoption will reach 53% by 2015, and exceed the use of online banking.



"Owing to its rapid pace of adoption, mobile is a market that offers a clear first-mover advantage. Banks that act soon, and aggressively deploy mobile financial services, will capture a clear market opportunity. Banks that delay will risk losing their best customers to the competition," said Hedges.

Methodology

This Mercatus research study surveyed more than 2,100 consumers over the age of 18. The survey was fielded to an online panel managed by Market Tools in December 2009. The results are representative of the U.S. population. The Mercatus Mobile RDC Adoption Research study was part of the on-going Mercatus Franchise Health consumer research program.

About Mercatus LLC

Mercatus LLC is a strategic consulting and investing firm focused on the retail financial services. Mercatus works with industry executives and private equity investors to make investment and business growth decisions. Mercatus is dedicated to delivering the insights, innovative thinking, and information required to equip clients for success in today's fast-changing marketplace.

SOURCE Mercatus LLC







Fifth Third Bank and MasterCard to Provide Next-Generation Corporate Purchasing Solution

MasterCard Worldwide

MasterCard inControl
Fifth Third Bank to use MasterCard's Innovative inControl(TM) Service to Enhance Control for Corporate Purchasing Programs

PURCHASE, N.Y. and CINCINNATI, Feb. 10 /PRNewswire/ -- Fifth Third Bank and MasterCard Worldwide, a leading global payments solutions provider, today announced the availability of a solution that will change corporate purchasing for Fifth Third's commercial clients. Fifth Third Bank will utilize MasterCard's powerful inControl service to offer Purchase Control from MasterCard, a tool that provides a level of control and flexibility in payments management.



With MasterCard Purchase Control, Fifth Third Bank will offer corporate clients enhanced global controls and increased transaction security that combines an integrated preapproval process with secure virtual account numbers. Also, the seamless integration of the Purchase Control application into existing corporate financial infrastructures will enable improved transparency through spend controls, comprehensive administrative tools, as well as enhanced transaction reporting and reconciliation capabilities that may reduce supplier misuse and the risk of card fraud.



"Against the backdrop of an economy where corporations are seeking to find the best ways to efficiently track their spending while ensuring transparency, security and compliance, MasterCard's Purchase Control is the application that our commercial clients are looking for," said Jeff Ficke, senior vice president, Director of Treasury Management for Fifth Third Bank. "This product will allow our commercial clients enhanced transaction control and security with minimal investment and IT support required."



Furthermore, MasterCard Purchase Control provides a flexible solution that enables organizations to face competing strategic goals head on by allowing them to optimize their commercial payments programs in a way that provides employees with efficient tools, while also helping to effectively control spending, and promoting compliance for both employees and suppliers.



"As organizations seek new solutions that will help them to look ahead through the recovery and increase financial control, we are happy to work with Fifth Third Bank to offer a solution that helps meet these goals," said Joshua Peirez, Group Executive, Innovative Platforms, MasterCard Worldwide. "Leveraging our innovative inControl service, Fifth Third Bank will help its clients streamline complex processes, help decrease the number of payments made with cash and checks, and increase the number of secure transactions made with electronic payments."



About MasterCard inControl



MasterCard inControl is an innovative, flexible service which enables issuers to easily introduce payment products that offer unparalleled controls and real-time alerts to both consumer and commercial cardholders. The suite of inControl offerings satisfies strong end-user needs for security and controlled access to spending accounts, while providing cost-efficiencies and speed-to-market for issuers and no need for any changes in the payment process at the merchant. MasterCard inControl builds on MasterCard's unparalleled global processing platform.



About MasterCard Purchase Control




With MasterCard Purchase Control, corporations can gain transaction security, increased operational efficiency, reduced fraud exposure and expert tools for budget control. MasterCard Purchase Control provides corporations with the ability to:
  • Set authorization controls that enable managers to define specific spending parameters for their employees while allowing flexibility for emergencies;

  • Receive real-time alerts to safeguard against over-spending and maverick spending;

  • Establish pre-purchase compliance with corporate spending policies at the front-end in combination with optimized MIS reporting on the back-end;

  • Gain efficiencies by simplifying the reconciliation process through the use of Virtual Numbers and Limited Use Numbers to uniquely identify each transaction.



About MasterCard

MasterCard Worldwide advances global commerce by providing a critical economic link among financial institutions, businesses, cardholders and merchants worldwide. As a franchisor, processor and advisor, MasterCard develops and markets payment solutions, processes approximately 22 billion transactions each year, and provides industry-leading analysis and consulting services to financial-institution customers and merchants. Powered by the MasterCard Worldwide Network and through its family of brands, including MasterCard®, Maestro® and Cirrus®, MasterCard serves consumers and businesses in more than 210 countries and territories. For more information go to www.mastercard.com.

About Fifth Third Bank

Fifth Third Bancorp is a diversified financial services company headquartered in Cincinnati, Ohio. The Company has $113 billion in assets, operates 16 affiliates with 1,309 full-service Banking Centers, including 103 Bank Mart® locations open seven days a week inside select grocery stores and 2,358 ATMs in Ohio, Kentucky, Indiana, Michigan, Illinois, Florida, Tennessee, West Virginia, Pennsylvania, Missouri, Georgia and North Carolina. Fifth Third operates four main businesses: Commercial Banking, Branch Banking, Consumer Lending, and Investment Advisors. Fifth Third also has a 49% interest in Fifth Third Processing Solutions, LLC. Fifth Third is among the largest money managers in the Midwest and, as of December 31, 2009, has $187 billion in assets under care, of which it managed $25 billion for individuals, corporations and not-for-profit organizations. Investor information and press releases can be viewed at www.53.com. Fifth Third's common stock is traded on the NASDAQ® National Global Select Market under the symbol "FITB." Member FDIC







Visa Inc. to Present at the Goldman Sachs Technology and Internet Conference

Visa Debit logoImage via Wikipedia
SAN FRANCISCO, Feb. 11 /PRNewswire-FirstCall/ -- Visa Inc. (NYSE: V) announced today that Byron Pollitt, Chief Financial Officer, will present at the Goldman Sachs Technology and Internet Conference in San Francisco on Thursday, February 25, 2010. The fireside chat will begin at 9:40 a.m. Pacific Time and last for approximately 40 minutes.



A listen-only audio webcast and replay will be accessible for 30 days on the Investor Relations web site at http://investor.visa.com.



About Visa Inc.



Visa operates the world's largest retail electronic payments network providing processing services and payment product platforms. This includes consumer credit, debit, prepaid and commercial payments, which are offered under the Visa, Visa Electron, Interlink and PLUS brands. Visa enjoys unsurpassed acceptance around the world and Visa/PLUS is one of the world's largest global ATM networks, offering cash access in local currency in more than 170 countries. For more information, visit www.corporate.visa.com.





Discover settles Morgan Stanley suit for $775 million

NEW YORK (Reuters) - Discover Financial Services (DFS.N) paid Morgan Stanley (MS.N) $775 million to settle claims related to sharing proceeds from an antitrust suit against credit card networks Visa Inc (V.N) and MasterCard Inc (MA.N), according to a regulatory filing on Friday.



The settlement came after Discover won $2.75 billion in a separate suit which accused the rival card networks of harming its business by preventing banks that issue MasterCard and Visa cards from also issuing Discover cards.







Taiwantrade Collaborates with PayPal to Start Online Electronic Transactions

Image representing PayPal as depicted in Crunc...Image via CrunchBase
 TaiwantradeTAIPEI, Taiwan--(BUSINESS WIRE)--Starting from March 2010, Taiwantrade--Taiwan’s national e-commerce trade portal--will collaborate with PayPal, the largest international online payment provider, to offer online electronic transaction service to Taiwantrade’s domestic paid members. Overseas buyers will be able to purchase sample products from the Taiwanese suppliers through PayPal payment system.



A business-to-business online trade platform and operated by Taiwan’s biggest trade promotion organization--Taiwan External Trade Development Council, Taiwantrade carries the most abundant amount of sourcing information on Taiwan’s local suppliers. It is anticipated that beginning from March after the PayPal online payment system is introduced, overseas buyers can directly select the sample products displayed by the Taiwanese manufacturers on Taiwantrade and make transnational payments online. At the same time, PayPal will provide complete online order tracking and complaint functions, allowing parties in disagreement a window to resolve their disputes.



PayPal is a leader in international online payment systems, offering a variety of payment methods for buyers to choose, such as credit card, debit card and bank account transfer, which is currently being used in 190 markets and 24 currencies around the world. PayPal’s collaboration with Taiwantrade has successfully opened the company’s door to the Taiwan market and is strongly supported by the Taiwan government. The alliance is predicted to bring a 14% growth in sales value for Taiwan’s small and medium enterprises.







Mobile and Online to Drive What’s Next In Payments



PayPal’s Scott Thompson and Wells Fargo’s Mike McCoy discuss the changing POS experiences driven by new channels, in exclusive PYMNTs.com interviews




BOSTON--(BUSINESS WIRE)--In its continuing series of exclusive interviews with CEO’s from leading payments industry players, PYMNTS.com captured insights from Scott Thompson, PayPal and Mike McCoy, Wells Fargo, both predict mobile as the industry game changer. Thompson, CEO of Paypal, predicts that “mobile is going to happen in a huge way… [and that it’s] a pretty interesting paradigm change if the point of sale is actually in your hand, not in the merchant’s hand.” Mike McCoy, President of Wells Fargo Card Services agrees saying, “there will be a lot of developments in the mobile channels as well as online.”

“mobile is going to happen in a huge way… [and that it’s] a pretty interesting paradigm change if the point of sale is actually in your hand, not in the merchant’s hand.”



Editor's Note:  The "paradigm shift" that Mr. McCoy speaks of, namely, placing the point of sale in the consumers hand, first happened with an eCommerce transaction.




Unfortunately, the forces that be decided to teach those "hands" to "type" instead of "swipe."  Thus our credit/debit card numbers were were "handed" right over to hackers. The good news is that according to all reports, unlike a dog, you CAN teach an old hand new tricks.  The great news is that there is a PCI 2.0 Certified PIN Entry Device handily available from HomeATM.


Rounding out this week’s interviews, PYMNTS.com profiled Moneris’ (processor of more than 2.5 billion credit and debit card transactions a year, for over 350,000 merchant locations) President, Greg Cohen and InstaMed’s (the industry leading healthcare payments network and platform) CEO, Bill Marvin, the full interviews can be found here:



http://pymnts.com/captains-of-the-industry-scott-thompson-on-what-s-next-with-paypal/;

http://www.pymnts.com/captains-of-the-industry-mike-mccoy-on-what-s-next-with-wells-fargo;

http://pymnts.com/moneris-president-of-u-s-business-greg-cohen-on-what-s-next/?tsc;

http://www.pymnts.com/ceo-series-bill-marvin-on-what-s-next-with-instamed



PYMNTS.com promotes the companies, products and people that drive "what's next" in payments, worldwide. PYMNTS.com is a joint venture between Berkshire Hathaway's Business Wire and Market Platform Dynamics. In the two months since its launch, PYMNTS.com has assembled a very large and highly engaged community of relevant (and senior) industry executives and opinion makers across the payments ecosystem who regularly click on its newsletter, visit the site, and spend a lot of time there. PYMNTs.com has become the "hub" for payments innovation for those whose core business is payments and for those who view payments as central to their own commerce capabilities.



For information on PYMNTS.com contact info@PYMNTS.com. You can also follow PYMNTS.com on Twitter at http://twitter.com/PYMNTS and join the PYMNTS Linked In group.



About Market Platform Dynamics (MPD):

MPD is a management consulting firm that ignites catalyst businesses by leveraging new technologies, business models and pricing strategies. MPD has a wealth of experience within industries that are characterized by complex platform-centered ecosystems, including payments, mobile/telecoms, digital and advertising-supported media, and software-based businesses.



MPD works with both incumbents and new entrants, offering a unique lens into the dynamics that shape the competitive playing field. In addition to traditional consulting-based services, MPD’s Catalyst Ventures provides intellectual and human capital to new firms. MPD’s experts include economists, econometricians, product development specialists, and strategic marketers who apply cutting-edge business theory and statistical methods to the practical problems of building and growing a profitable catalyst business. MPD is headquartered in Cambridge, MA, and has offices in London and Hong Kong.



For more information visit www.marketplatforms.com.



About Business Wire



Business Wire, a Berkshire Hathaway company, is utilized by tens of thousands of member companies and organizations worldwide to functionally enhance and communicate investor relations and public relations content to target audiences. As a recognized disclosure service in the United States, Canada and a dozen European countries, Business Wire facilitates the simultaneous flow of market-moving press releases from corporations to financial markets and their audiences, including regulatory authorities, media, investors, financial information systems and consumer news services. Business Wire also handles XBRL tagging, document formatting and regulatory filing into EDGAR, SEDAR, FSA and other systems.



Founded in 1961, Business Wire has dual headquarters in San Francisco and New York, with 30 bureaus in cities including Los Angeles, Chicago, Boston, Miami, Paris, Frankfurt, London, Brussels, Tokyo, Toronto and Sydney and reciprocal offices throughout the world. Business Wire's patented NX data platform supports XML, XHTML and XBRL code that enhances news release interactivity, social media sharing and search engine optimization. More information about Business Wire and its services is located on its website at www.BusinessWire.com.



Thursday, February 11, 2010

Voltage Security Completes Independent Security Review

Conforms To Visa Best Practices for Data Field Encryption; Format-Preserving Encryption Meets Recommendations for End-to-End Encryption



PALO ALTO, Calif. - PIN Payments News Blog -  February 11, 2010 - Voltage Security™, the global leader in end-to-end data protection, today announced that Cryptographic Assurance Services, LLC (CAS), a leader in cryptographic compliance consulting, has completed an independent security review of Voltage's innovative Format-Preserving Encryption used in numerous end-to-end encryption implementations around the world. Voltage End-to-End Encryption, part of the Voltage SecureData(tm) product line, conforms to the complete list of Visa’s global industry best practices for data field encryption, published on October 5th, 2009. The Visa best practices are designed to further the payment industry's efforts to develop a common, open standard while providing guidance to encryption vendors and early adopters. Data field encryption, also known as end-to-end encryption, protects card information from the swipe to the acquirer processor so that the merchant is no longer processing or transmitting card data in the "clear."



CAS was asked to evaluate Format-Preserving Encryption (FPE) as a mode of the Advanced Encryption Standard (AES). CAS evaluated the mathematical model on which it was based and the associated proofs of security. CAS also reviewed a source-code instantiation of FPE provided by Voltage Security. CAS identified applicable compliance regimes and assessed FPE against them.



In its finding, CAS noted the large body of cryptographic research on which FPE is based, accumulated over decades, and the strength of the mathematical proofs and cryptanalysis. CAS concluded that FPE as implemented in the form of the AES mode FFX3 meets the compliance criteria for PCI DSS v1.2 encryption requirements and for Visa’s Data Field Encryption requirements, making Voltage Security’s Format-Preserving Encryption solutions suitable for use by organizations needing to comply. AES mode FFSEM is a sub mode of AES mode FFX and included in this assessment.



The complete report is available at www.voltage.com/security-review, registration required.



About Cryptography Assurance Services



CAS is a team of security professionals with over 50 years of combined experience. The CAS experience covers a wide range of technologies addressing confidentiality, integrity, authentication and non-repudiation with emphasis on cryptography and key management. CAS has been, and is still today, involved in developing X9, ISO and other industry security standards and providing assurance services to gain compliance to such standards.



About Voltage Security



Voltage Security, Inc., an enterprise security company, is an encryption innovator and global leader in end-to-end data protection. Voltage solutions, based on next generation cryptography, provide end-to-end encryption, tokenization, masking and stateless key management for protecting valuable, regulated and sensitive information based on policy. Voltage products enable reduction in PCI audit scope with rapid implementation and the lowest total cost of ownership in the industry through the use of award-winning cryptographic solutions, including Voltage Identity-Based Encryption™ (IBE) and a new breakthrough innovation: Format-Preserving Encryption™ (FPE). Offerings include Voltage SecureMail™, Voltage SecureData™, Voltage SecureFile™ and the Voltage Security Network™ (VSN), an on-demand managed service for the extended business network.



As a service to the industry and general public, the company maintains the Voltage Data Breach Index and Map which is continuously updated with global data breach information: www.voltage.com/data-breach. The Company has been issued several patents based upon breakthrough research in mathematics and cryptographic systems. Customers include Global 1000 companies in banking, retail, insurance, energy, healthcare and government. To learn more about Voltage customers and sign up for the customer news letter please visit www.voltage.com/customers.







###





32% of Computers with AV Protection are Infected

Help Net Security published a story on a recent SurfRight report that anti-virus solutions don't stop infection from malware...
A SurfRight report shows statistics that give credibility to the lately popular opinion that one anti-virus solution is no longer enough to be sure your computer isn't infected. The effectiveness of most anti-virus solutions relies still on the quality of the virus signatures, and sometimes on the heuristics capabilities of the programs. Aided by its partners, SurfRight had the idea of bundling up 7 anti-virus engines that have at their disposal an equal amount of anti-virus databases. They called it Hitman Pro 3....



Continue Reading






Todos Addresses Cambridge University Research Concerned with eCommerce Security

University of CambridgeImage via Wikipedia

Todos addresses Cambridge University research concerned with ecommerce security

A study by the University of Cambridge shows that 3D Secure (3DS) technology may boast more than the security it actually provides. According to the report’s authors, Steven Murdoch and Ross Anderson, concern has been expressed with the current approach to e-commerce security, saying that there have been many serious problems in the 3DS environment.





The study revealed that the main problems come from the reliance on static passwords and the need to authenticate users at the point when they first enter their password.


Todos technology has addressed this works within the 3DS environment to offer merchants and card issuer two-factor authentication solutions. This would replace the static password and be available to use on a Todos device or mobile application and a private PIN.



With the two-factor authentications, users can securely validate online transactions without disclosing any sensitive personal information.






Customer Sues Bank After Phishing Attack, MI-Based Business Lost $550,000 in Breach

Another lawsuit has been filed against a bank for not keeping their customers secure.  This particular one claims that the bank's authentication system was susceptible to phishing.  Comerica Bank and others can "ELIMINATE" the threat of phishing by switching from a "typing your banking credentials" environment to a "swiping your banking credentials" one.  They say practice makes perfect, but the practice of "typing" username/passwords is far from perfect. 



Customer Sues Bank After Phishing Attack

MI-Based Business Lost $550,000 in Breach
Bank Info Security's Managing Editor, Linda McGlasson, is reporting that:



A Michigan-based metal supply company is suing Comerica Bank, claiming that the bank exposed its customers to phishing attacks.



A lawsuit filed by Experi-Metal Inc. (EMI) in Sterling Heights, MI alleges that Dallas-based Comerica opened its customers to phishing attacks by sending emails asking customers to click on a link to update the bank's security software. EMI says even though the bank had two-factor authentication using digital certificates for its online banking portal, the phishing scam was able to circumvent these measures.



EMI contends that Comerica's actions opened its online bank account to a successful phishing attack where more than $550,000 was stolen from the company's bank accounts and sent overseas.



Continue Reading at Bank Info Security











Chip and PIN is Broken: Cambridge's Ross Anderson Comments

Chip and PINImage via Wikipedia

Chip and PIN is Broken

February 11th, 2010 at 18:09 UTC by Ross Anderson







There should be a 9-minute film on Newsnight tonight showing some research by Steven Murdoch, Saar Drimer, Mike Bond and me. We demonstrate a middleperson attack on EMV which lets criminals use stolen chip and pin cards without knowing the pin.









Our technical paper Chip and PIN is Broken explains how. It has been causing quite a stir as it has circulated the banking industry privately for over 2 months, and it has been accepted for the IEEE Symposium on Security and Privacy, the top conference in computer security. (See also our FAQ and the press release.)





The flaw is that when you put a card into a terminal, a negotiation takes place about how the cardholder should be authenticated: using a pin, using a signature or not at all.



This particular subprotocol is not authenticated, so you can trick the card into thinking it’s doing a chip-and-signature transaction while the terminal thinks it’s chip-and-pin.  The upshot is that you can buy stuff using a stolen card and a pin of 0000 (or anything you want). We did so, on camera, using various journalists’ cards. The transactions went through fine and the receipts say “Verified by PIN”.


It’s no surprise to us or bankers that this attack works offline (when the merchant cannot contact the bank) — in fact Steven blogged about it here last August.



But the real shocker is that it works online too: even when the bank authorisation system has all the transaction data sent back to it for verification. The reason why it works can be quite subtle and convoluted: bank authorisation systems are complex beasts, including cryptographic checks, account checks, database checks, and interfaces with fraud detection systems which might apply a points-scoring system to the output of all the above. In theory all the data you need to spot the wedge attack will be present, but in practice? And most of all, how can you spot it if you’re not even looking? The banks didn’t even realise they needed to check.



This attack is both academically and practically significant. We get reports weekly from different victims of phantom withdrawals, and these include large numbers of stolen cards used to make purchases in the window between theft and the cancellation of the card. Currently these victims are denied refunds by their banks, but this attack could explain some of the frauds we are seeing. The fact the receipt says “PIN Verified” when actually it wasn’t raises a whole load of legal and evidential questions which call into question the banking industry’s claim that their systems work (and log) properly. Merchants will be none too pleased either; the system no longer protects their interests but only those of the issuing bank.



There’s been some confusion, possibly even misinformation, about our attack and its effects. Carte Bancaire in France were so concerned that they briefed the press way in advance of our plans for publication. We can set the record straight on a few things:



  • the attack applies to cards used online (where the merchant POS contacts the bank) as well as offline;

  • the attack works regardless of the amount of money spent (not just for small value amounts that are below floor limit);

  • the attack doesn’t work once a card has been cancelled by the bank — just like stolen cards in the past can only be used for a certain window of time once the cardholder discovers the loss;

  • the attack doesn’t work at ATMs (cash machines);

  • the failure applies to bank card schemes based on EMV – the most widely deployed standard for smartcard payments. Older national smartcard schemes may or may not be vulnerable; we don’t know.



So what went wrong? In essence, there is a gaping hole in the specifications which together create the “Chip and PIN” system. These specs consist of the EMV protocol framework, the card scheme individual rules (Visa, Mastercard standards), the national payment association rules (UK Payments Association aka APACS in the UK), and documents produced by each individual issuer describing their own customisations of the scheme. Each spec defines security criteria, tweaks options and sets rules – but none take responsibility for listing what back end checks are needed. As a result, hundreds of issuers independently get it wrong, and gain false assurance that all bases are covered from the common specifications. The EMV specification stack is broken, and needs fixing.



We’re really worried that if something isn’t done to fix this problem, and the many others we’ve found in EMV, that other regions adopting it (like the USA) are going to make the same mistakes again and again – and that means customers stay vulnerable.



That’s why again we’re arguing that Chip and PIN is broken. We don’t want people keeping their money in shoe boxes – we want the problems fixed. That means getting decent governance for the system that involves all the stakeholders – banks, regulators, merchants and customers.





Flaw Calls Entire Architecture of Chip and PIN Into Question - Video Report

Flaw 'calls entire architecture' of chip and pin into question

The BBC's Newsnight reveals a serious flaw in the chip and pin system uncovered by Cambridge University researchers which could allow criminals to make bank card payments without knowing the correct pin number.

Watch Susan Watts' full report on Newsnight on Thursday at 10.30pm on BBC Two, then afterwards on the BBC iPlayer and Newsnight website.

Get a Free Olympic Team USA Fleece

Support TeamTeam USA sent me a request to post this on the PIN Debit Blog and I am glad to oblige...



Hi John



Tomorrow, February 12, the world will gather to watch top athletes from around the globe compete in the Winter Olympic Games in Vancouver. Athletes from Team USA, who have been training their entire lives will take the stage to represent our country. I'm writing with the hope that you could share the news about Team USA with the readers of PIN Debit News Blog.



Anyone who registers on Teamusa.org will have access to the latest info and will receive exclusive updates throughout the games. I've put all that information including some very cool Team USA widgets and banners into this social media news release here:


Social Media News Release



Sign up to experience the insider’s view of the 2010 Olympic Winter Games in Vancouver!



TeamUSA

Be part of Team USA for 18 incredible days of competition!

  • Receive exclusive updates during the Winter Games


  • Get the inside scoop, event by event


  • Hear directly from our Olympic athletes as they chase their dream


  • Photo and video highlights, right to your desktop



  • Victory in Vancouver is a state-by-state, hometown-by-hometown effort to help the U.S. athletes who are our fellow Americans and neighbors achieve their dreams of winning top honors at the 2010 Olympic Winter Games in Vancouver, Canada!

  • It's been almost 80 years since Team USA won the most gold medals at the Olympic Winter Games, and they're ready to do it again. Your gift today can bring the United States to Victory in Vancouver!

  • Be a part of this historic bid for Olympic glory with your gift to the U.S. Olympic Committee.




  • Receive this Team USA fleece jacket FREE with a donation of $20 or more.

  • Proudly display your support for Team USA with this U.S. Olympic fleece jacket!


fleece offer
  • Warm, soft and rugged

  • Dark warm grey

  • Heavy-duty full length zipper with Team USA pull

  • Made of breathable and fast drying fleece

  • Roomy hand warmer pockets

  • Double-stitched hems

  • Beautifully embroidered with the U.S. Olympic 5-ring logo in full color



Shipping and handling included!




Available in four sizes: Medium, Large, X-Large and XX-Large - but supplies are limited, so act today!

Sixth Ring Membership

  • The Sixth Ring is an elite group of individuals who spearhead the efforts of the U.S. Olympic Committee to send the best, most talented athletes to the Olympic Games.

  • Become a member of the Sixth Ring today and lead the team to victory!







Credit Card Fraud Now Comprises 75% of ID Crime Cases

Until we stop "typing" and start "swiping" we will continue to see this trend continue.  This, from a story published at eCreditDaily.com,






Credit Card Fraud Surging in I.D. Theft Cases, Study Says

Credit card fraud surged in 2009 as the No. 1 form of rising identity theft, and it now comprises 75 percent of I.D. crime cases, according to a survey of 5,000 adults by Javelin Strategy & Research, the California-based research firm.



The credit card portion of I.D. fraud is up from 63 percent in 2008, Javelin’s study found.



Editor's Note:  The Consumer Version of Javelins Report is free and can be obtained by clicking the link at the bottom of this post. 



The overall number of identity theft victims in the United States rose 12 percent to 11.1 million last year, the firm’s findings show.  Total losses from identity fraud climbed 12 percent to $54 billion, up from $48 billion in 2008. The mean theft amount – per victim – slightly decreased to $4,841, but out-of-pocket consumer losses were $373, down from $498 in 2008, Javelin said.



“The average consumer cost is actually dropping because businesses are shouldering more of that actual fraud amount in order to protect individuals,” said James Van Dyke, Javelin president and founder. This is Javelin’s seventh annual identity fraud report.   Survey respondents reported more credit card fraud, followed by debit card fraud — 33 percent, down from 35 percent. The survey also showed an increase in stolen checking account numbers and health insurance documents.
96 pages; 67 charts/graphs

21 pages; 8 charts/graphs







iCharge: Europe's Version of iPhone Card Reader

TechCrunch Europe writes about iCharge, a European version of Square.  Doesn't do Chip and PIN.  Like Square, it uses SSL encryption instead of encrypting the data at the maghead to ensure security. 



iCharge – Jack Dorsey gets some Euro heat
by Steve O'Hear on February 11, 2010


Steve O'Hear writes:



It’s practically an identical pitch to Square, although iCharge looks to be slightly further behind. The self-funded company, founded by “experienced serial entrepreneurs and experts from the credit card industry” sometime in 2009, will run a limited trial with select retailers this summer. A wider launch isn’t scheduled until the third quarter of 2010. Square on the other hand is currently in private beta and plans to launch in early 2010.



The begin using iCharge, merchants will need to purchase the smartphone-compatible card reader and register with the iCharge service. Credit cards can then be swiped and the card info is sent to the connected iPhone/Android application.





A big part of iCharge’s pitch inevitably centers around security. All data transfers utilize SSL encryption,and credit card numbers are checked against a database of known stolen credit cards. And in the future, iCharge says it will integrate further safety features, such as “buyer name and image verification via social networks, as well as storing the GPS location where the transaction took place”, thus providing more protection for the retailer.



But who’s going to protect buyers?



All of this democratising credit card processing technology may seem great but consider this:



"Put a fake Square or iCharge device in the hands of a rogue trader, and a card reader attached to a phone running the ‘open’ Android OS seems like a fool-proof way to clone somebody’s credit card.




Just a thought.


PULSE and Woodforest Financial Group Sign Exclusive, Long-Term Agreement for PIN Point-of-Sale Debit Services

Cardholder Access to National ATM Network Also Included in Agreement


HOUSTON & THE WOODLANDS, Texas--(BUSINESS WIRE)--PULSE, one of the nation’s leading PIN debit/ATM networks, has extended and expanded its long-term relationship with Woodforest Financial Group for PIN point-of-sale (POS) debit and ATM services.



Under terms of the agreement, PULSE will be the exclusive network provider of PIN POS debit services to Woodforest Financial Group and its bank affiliates – Woodforest National Bank and Woodforest Bank. In addition, PULSE will provide the banks’ cardholders with access to PULSE’s nationwide network of ATMs.



“PULSE has provided ATM and PIN debit services to Woodforest for more than 25 years, and we are very pleased to extend and further develop our relationship,” said Dave Schneider, President of PULSE. “Being chosen to provide PIN debit network services by an innovative institution like Woodforest demonstrates our ability to deliver the acceptance, transaction processing services and customer support necessary to meet the institution’s PIN debit needs.”
Woodforest Financial Group is a privately owned community bank holding company headquartered in The Woodlands, Texas. Through its bank affiliates, Woodforest Financial Group services over 850,000 accounts from more than 725 branches located throughout 17 states.



“We have long relied on PULSE as a trusted debit network to serve our cardholders, and we are looking forward to continuing our relationship,” said Robert E. Marling, Jr., Chairman and Chief Executive Officer of Woodforest Financial Group. “With debit playing an increasingly important role in how consumers spend and manage their money, working with a network that possesses the expertise in PIN debit that PULSE does is critical.



“PULSE’s ability to deliver reliable electronic payment services to our cardholders, along with the responsiveness and outstanding customer service we expect, were deciding factors in continuing our mutually successful relationship,” added Marling.



About PULSE



PULSE, a Discover Financial Services company, is a leading debit/ATM network, serving more than 4,400 banks, credit unions and savings institutions across the United States. The network links cardholders with ATMs and POS terminals at retail locations nationwide. Through its global ATM network, PULSE provides worldwide cash access for Diners Club and Discover cardholders through hundreds of thousands of ATM locations. The company is also a source of electronic payments research and is committed to providing its participants with education on emerging products, services and trends in the payments industry. For more information, visit www.pulsenetwork.com.



About Woodforest Financial Group, Inc. and Its Family of Companies




Celebrating 30 years of banking success, Woodforest Financial Group, Inc. is a privately owned community bank holding company that includes Woodforest National Bank and Woodforest Bank in its family of companies. Together, they currently service over 850,000 accounts from more than 725 branches located throughout Texas, North Carolina, Ohio, Maryland, Pennsylvania, Virginia, West Virginia, Illinois, Indiana, South Carolina, Kentucky, Alabama, Louisiana, Mississippi, New York, Georgia and Florida. For more information, visit www.woodforest.com.





Disqus for ePayment News