Showing posts with label 3-D Secure. Show all posts
Showing posts with label 3-D Secure. Show all posts



MoBeePay(TM) Officially Announces a Revolutionary Mobile eCommerce Application





CHICAGO, March 15 /PRNewswire/ -- The MoBeePay iPhone application (other versions coming soon) allows buyers and sellers to connect and transact business in seconds without having to go through a time-consuming, risky payment process. Unlike PayPal, MoBeePay removes the need for a web based store and moves the transaction anywhere a merchant or consumer desires whether in the digital or the physical world.



Sellers register their products with MoBeePay and receive MoBeeTags (data matricies) and or MoBeeCodes (product codes) from MoBeePay, which are stored in the MoBeeHive (cloud). Buyers merely point their iPhone camera at the MoBeeTag in a magazine, on a billboard, or any print ad. Once the MoBeeTag is captured by the app the data is securely sent to the MoBeeHive. The MoBeeTag is compared, verified, and then the purchase is completed instantly if the user has signed in to their MoBeePay account.



If a user has not signed in they will be prompted to either sign in or sign up for an account directly in the MoBeePay app. The seller is notified of a successful purchase and the merchandise is shipped directly to the consumer from the manufacturer or retailer to the address on file, or in the physical world, handed to the buyer. Buyers who are unable to capture an accurate image are also able to enter a MoBeeCode as an alternative. This MoBeeCode or MoBeeTag can also be sent via SMS or MMS to the MoBeeHive if the user does not have an app compatible phone.



Like Square™ or VeriFone's PAYware™, MoBeePay will soon be offering a MoBeeMerchant application with hardware (MoBeeSwipe) that will enable mobile merchants or small retailers to accept credit and debit purchases at card present rates by plugging the MoBeeSwipe into an earjack.



Utilizing the same MoBeeTags with MoBeeMerchant, merchants can avoid the need for costly POS systems while still enjoying the benefits of an electronic transaction and inventory management system at competitive merchant discount rates.



MoBeePay was developed by Kent Mages and Kenneth Mages and has multiple patents pending. All MoBee terms herein are trademarked.



To see a demo visit www.mobeepay.com and let us know that you're interested.



About MobeePay:



MobeePay is the world's first mobile commerce application that allows anyone with a cell phone to complete purchases anywhere anytime and/or instantly open a merchant account on the web or in the physical world for free.



SOURCE MoBeePay Back to top RELATED LINKS

http://www.mobeepay.com





































Ever see an ad in a magazine for something you really want only to forget what the item was hours later? Ever walk by a store after it’s closed and see something you would love to buy in the window, but forget what it was the next day? With MoBeePay you can satisfy that need to buy with just a snap of your camera.



It’s 2010, why should you need to remember an ad, repeatedly enter your card number for different retailers, waste time filing out forms or speaking with sales people? Just log in to your MoBeePay account once and you’re done. We handle the billing and shipping so you don’t have to. Snap one of our MoBeeTags and that brand new piece of merchandise will be billed and shipped in the blink of an eye, or rather the snap of a shutter.



Use anywhere you see a MoBeeTag and pass on that cool new product to friends via social networking sites like twitter or Facebook. Check back soon to learn more and to sign up for you own MoBeePay account. Just leave your email address and you’ll be the first to know when we go live.



Would you like to know more?
Sign up for our newsletter.




Posted by John B. Frank Monday, March 15, 2010 0 comments

Merchant Risk Councils Platinum Day - Afternoon Sessions
by Allen Weinberg - Glenbrook Partners Payments Views

Allen Weinburg, from Glenbrook Partners, who is blogging about the Merchant Risk Council's Las Vegas conference, wrote an article in Payment Views entitled: "Is Now the Time For Online PIN Debit?"

Mike Strada, from Chase Paymentech predicts that PIN Debit on the Internet will be the most widely used payment mechanism on the web by 2012.  I agree
.

Allen also talks about 4 solutions, and whether 3D Secure might be just as good, if not a better solution. I took a moment out of my morning to leave a comment ascertaining that the answer is probably yes...for all but one.

Allen WeinbergIs Now the Time for Online PIN Debit?

This session was presented by MikeStrada from Chase Paymentech. Mike is a fan of online PIN debit,especially the notion of giving merchants more choices. His discussionfocused on the different options the 12 North American debit networksare exploring.

Several of the debit networks are exploring PIN debit, some aren’t.ACCEL, NYCE, PULSE and STAR are doing PINless debit for utility andother low risk payments. Mike explained that these are the 4 networksthat are exploring PIN debit on the Internet. Three of these four (allexcept STAR) have recently announced PIN debit pilots.


Mike maintains that PIN debit forecommerce transactions could provide some incremental sales lift formerchants, especially since 14% of debit cards are “ATM only” – i.e.,they don’t have a MasterCard or Visa logo on them and thus can’t beused for general ecommerce transactions.
Mike explored the pros and cons of the four alternatives:
  • Acculynk (formerly ATM Direct, previously owned bynow-defunct Pay By Touch). ACCEL, NYCE and PULSE have all signed LOIsto do pilots with Acculynk. Mike thinks two more debit networks willannounce pilots within the next 90 days.
  • Safe-Debit (the same name of the program NYCE wentto market years ago using a CD ROM token). This iteration is usingVerient’s platform to redirect the user to the customer’s home bankingsite for authentication. In this case, the cardholder is sent a onetime PAN for use at the merchant site. Hoping to do a pilot in firsthalf of 2009. This, of course, requires a redirect which scares a lotof merchants due to the increased risk of abandoned shopping carts.
  • Claerity – technology allows consumer to registercell phone number with their DDA FI. The bank, via the network, sendsone time password back to cell phone which the shopper enters onmerchant checkout page. Network compares the onetime password sent tocell phone with the one issued to the consumer. Not clear who will bearthe cost of the SMS message. Hoping for a 2009 pilot, but unclear if ontrack.
  • Home ATM – Canadian firm distributes USB PIN padthat has a mag-stripe card reader and encrypts data. Has a distributionagreement with Microsoft, but no announced pilots.
Mike acknowledged one of the big issues that Glenbrook encounterswith our merchant clients – critical mass and the challenge of gettingonline merchants adopting two or three (forget four or more) differentprocesses. Our clients tell us they’ll consider it when the networksadopting a particular approach/technology bring critical mass ofcardholders in aggregate. My sense is that STAR has critical mass untoitself. The next 3 largest networks (assuming Interlink and Maestrowon’t play) would need to converge on a solution to bring critical massto market. Just my opinion, but Mike doesn’t think standardization willhappen in the foreseeable future, and Paymentech has decided to moveforward anyway.

Mike/Chase Paymentech is predicting that be the end of 2010, most ofthe major networks will implement online debit products (excluding, ofcourse, Interlink and Maestro), with transaction pricing somewhere inbetween physical POS interchange and online Visa/MasterCardinterchange.

Mike also predicted that by 2012, online PIN debit could be the mostwidely used payment mechanism on the Internet.


The operating rules forhandling online PIN debit transactions haven’t been worked out, butthey’re working on it. He acknowledges that the rules really should be,and probably will be standardized across networks.

ChasePaymentech has agreed to do a pilot with Acculynk (and is looking for merchants to participate).

Of course there’s the fraud risk associated with these new products(Mike acknowledged it, but didn’t spend much time on this area).


Mike feels the consumer proposition is one of safety, security, and identity theft protection.

One question I have is whether 3D Secure technology could do just aswell as the above four products/technologies mentioned above. Mikethought that it probably could, but he wasn’t aware that any of thedebit networks had considered that path (could mitigate merchantadoption problem).

The merchants in the audience were somewhat skeptical on a number offronts. For example, how to deal with split shipments that span theauthorization time frames. They worried about consumer valueproposition and recalled all the issues they encountered with 3DSecure, particularly how the banks/issuers didn’t do as good a job asthey needed to educating their cardholders.

{ 1 comment… read it below or add one }


John B. Frank 03.11.09 at 5:50 am

Your comment is awaiting moderation.

You questioned whether 3D Secure Technology could do just as well asthe four products/technologies mentioned above. You pose an interestingquestion, but I want to point out that you cannot lump those fourtogether, as there is one key distinction. 1 uses a hardware device.The other 3 are software-based.

Which leads me to ask a pertinent question… How is it even“possible” to “securely” process a PIN Debit transaction WITHOUTHardware? (a magnetic stripe reader and PED) If a software applicationis utilized, then, by definition, it is a Card Not Present transaction.Thus a software based approach “cannot ” be a pure PIN Debit play…asthe card “must” be present in order to process the track data locatedon the magnetic stripe.

Remember…all PIN-based transactions “require” the submission ofvalid track data in order for the PIN to be properly decrypted. Withouttrack data, PIN submission becomes unnecessary and the transaction isbetter submitted as a manually-entered credit card transaction (withouta PIN), therefore 3D Secure would be just, if not more, effective.

For a true PIN Debit transaction to occur, a developer mustimplement PIN support as part of the submission process. Without trackdata, it becomes impossible to encrypt or decrypt PIN numbers (becausethe magnetic stripe data is used as part of PIN encryption/decryption).If track data is not submitted, a debit card transaction becomesimpossible and the transaction becomes a manually-entered credit cardtransaction.

That said, I would have to agree with Allen when he says there’s afraud risk associated with these new products (the lone exception beingthe one who utilizes a hardware “SwipePIN” device capable of not onlyproviding: E2EE, 3DES DUKPT, but also encrypting the Track 2 data aswell.) Track2 = PAN+Separator+Expiry Date+ServiceCode +Pvk Index+ PVV +CVV

Is it a coincidence that the event is called “The Merchant RiskCouncil” and although Mike Strada “acknowledged the risk of fraud… “hedidn’t spend much time on it?”

PN Debit card transactions require the availability of two (unlessyou combine them into one) hardware device(s): a PIN pad and a magneticstripe reader. Unless both a PIN pad (which is configurable with aworking key) and a magnetic stripe reader are both available andoperational, these debit card transaction examples cannot be applied asa PIN Debit card transaction requires both track data and an encryptedPIN to proceed.

Therefore, the only logical conclusion is that a Hardware device isrequired, not optional. What’s the big deal with a hardware deviceanyway? Did you ever have to charge your cell-phone…sometimes ahardware accessory is necessary to protect the Holy Grail. (PIN’s)

Otherwise the Heartland Breach will pale in comparison to what willhappen if people start putting their PIN’s into a software-basedapplication. The writing has never so clearly been written on any wall.

Where am I wrong here? Where is Avivah Litan wrong? Where are theSociety of Payment Security Professionals wrong? I’m dying to know,because I was a founding shareholder in Pay By Touch and could havebought ATMDirect out of the PBT bankruptcy “cheap.”.

You mean to tellme that PayPal will fork out nearly $1 BILLION for Bill Me Later butsaid “later” when it came to forking out $600K for ATMDirect?  If so,and PIN Debit is the most widely used payment mechanism on the internetby 2012, (as Mike Strada/ChasePaymentech predicts) then not evenbidding on ATMDirect will go down as one of the biggest mistakes inPayPal/Ebay history. (and mine)  But I think we're both fine...

TAGS: , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , ,







Reblog this post [with Zemanta]

Posted by John B. Frank Wednesday, March 11, 2009 0 comments

Editor's Note: The more I learn about securing a transaction on the web, the more I realize how unsafe many transactions actually are. Here's an interesting article in the Register regarding Visa's supposedly more program designed to fool cardholders into thinking their transactions are more secure. They call it "Verified by Visa" but first it has to verified by consumers, which means it can be then verified by Hackers.

"VbyV login credentials
make it easier for crooks to make purchases online while simultaneously making it harder for consumers to deny responsibility for a fraudulent transaction".

Since card information is can be bought online for as low as $2.50, "Stolen Card Info Plunges to $2.50 in Black Market" and obtaining a DOB is so easy a caveman could do it, it's looking like VbV is more of a marketing ploy than of any real value when it comes to protecting the security of an online transaction. What I found even more interesting was Visa's declination to comment about the story which the Register tells us at the end of this article:

VbyV password reset is childishly simple • The Register

Both VbyV and SecureCode are based on 3DSecure, a name that hints at the introduction of some kind of three-factor authentication scheme. But unlike robust authentication techniques, hackers don't have a hardware token generating one-time passwords to worry about - it's just more of the same.

And since card details + CVV number is no longer considered as secure enough then it's hard to see how card details + CVV number + VbyV login is any more robust.

Much was made of how easy it was for a hacker to reset Sarah Palin's webmail account password and gain illicit access to emails, but resetting passwords for Verified by Visa - which supposedly makes online transactions more secure is arguably even easier. To reset Palin's email account a hacker needed to know the Republican VP candidate's birth date, her zip code and the answer to a secret question on where she met her husband. Resetting a Verified by Visa password, by contrast, requires only card details (got $2.50?) and a date of birth.

Register commenter Anthony explains. Barclays Verified by Visa (VbV) allows anyone who has the credit card in their hands to set a new password for VbV with just the card details and the card owner's date of birth. Since the latter is trivial to discover for most people, this adds almost no additional security to the process.

Register reader Jusme reports the same issue. Verified by Visa is one of the reasons I no longer use Barclaycard. Pretty much every time I had to use it the password was not recognised and I had to "reset it", which just meant entering my DOB and a new password, hardly very secure.

Online shoppers who buy goods and service with participating retailers are asked to submit a VbyV or SecureCode password to authorise transactions. These additional checks are typically submitted via a website affiliated to a card-issuing bank but with no obvious connection to a user's bank.

Punters aren't informed up front that a merchant has signed up to Verified by Visa. Sites used to authenticate a VbyV or SecureCode password routinely deliver a dialogue box using a pop-up window or inline frame, making it difficult to detect whether or not a site is genuine.

The appearance of phishing attacks hunting for Verified by Visa passwords are among the reasons some punters are wary of the technology. Once obtained by fraudsters, either by direct phishing attack or through other more subtle forms of social engineering trickery,

An anonymous commenter to our original stories agrees:
Verified by Visa and Mastercard SecureCode are there purely to protect the banks, not the card holder. They offer zero additional protection to the consumer, but allow the bank to claim that transactions using purloined credit card credentials were really made by the card holder. It is as simple as that.
The issue has been noted, and commented on in the blogosphere as far back as June, but has received little attention in the mainstream media, despite the obvious security implications.

Visa and MasterCard ought to be able to defend the password reseting regime they have established, but neither organisation responded to our request for comment at the time of going to press.®

Reblog this post [with Zemanta]

Posted by John B. Frank Friday, October 24, 2008 1 comments

September 23, 2008 by Gill Montia

Story link:
Cardholders flock to secure online payment methods

UK payment services association, Apacs, has reported a major increase in the volume of credit and debit card holders taking advantage of measures that can prevent online shopping fraud.

According to Apacs, over 25 million cards are now registered with secure online payment systems, Verified by Visa and MasterCard SecureCode. Cardholder registration in August was up 150% over the year and had increased by nearly 600% on August 2006. The process of signing up is simple and can be completed on the websites of card providers.

The schemes offer enhanced protection against the unauthorised use of a card and provide state of the art online security without the need for additional software.

Online shopping card fraud was estimated at £223.8 million in 2007, when it formed around 77% of total card-not-present fraud losses in the UK. Last year’s figure was up from 45% from 2006, when Internet fraud losses stood at £154.5 million and accounted for 73% of total card-not-present fraud losses.
Reblog this post [with Zemanta]

Posted by John B. Frank Tuesday, September 23, 2008 0 comments

Payments Industry News Blog

Search the PIN Debit Blog by Subject

Kapersky Calls for Mass Adoption of Card Readers

Kapersky Calls for Mass Adoption of Card Readers