Showing posts with label Microsoft. Show all posts
Showing posts with label Microsoft. Show all posts



Chip and PIN 'not fit for purpose', says Cambridge researcher

Wikinews ... said that there was no evidence the attack was in use and emphasized that card fraud had fallen with the introduction of chip and PIN.



Biz Break: Microsoft vs. Google vs. Apple: phone OS on Monday, maps today

Today: Microsoft is expected to introduce its new mobile operating system next week. Google rolls out new maps features, a day after Bing Maps enhancements by Microsoft. Read article »



Google Sees Facebook, Amazon, Kayak As Competitors

Wall Street Journal The Internet search giant on Friday filed its 2009 annual report, which for the first time named social networks like Facebook Inc., e-commerce sites like ...



Discover to Pay $775 Million to Morgan Stanley

Wall Street Journal But Riverwoods, Ill., Discover contended that Morgan Stanley had breached the spinoff agreement by meddling in the Visa-MasterCard settlement. ...



Mobile operators unite on global apps platform

The world’s largest mobile operators have joined forces to launch an open international applications platform, marking the largest unified move to date by the operator community into the mobile apps space. The so-called ‘Wholesale Applications Community’ will combine 24 of the world’s largest mobile carriers, including America Movil, AT&T, Bharti Airtel, China Unicom, Deutsche Telekom, KT, mobilkom Austria, MTN Group, NTT Docomo, Orange, Orascom Telecom, Telecom Italia, Telefonica, Telenor, TeliaSonera, SingTel, SK Telecom, Sprint, VimpelCom and WIND. The four operators in the Joint Innovation Lab (JIL) mobile apps initiative – Vodafone, China Mobile, SoftBank and Verizon Wireless – are also included. The group serves a combined 3 billion mobile customers across the globe. Industry association the GSMA has backed the move. Read More 



CEO Series: Jack Dorsey Reveals What's Next with Square

Will Square spell the death of cash? In an exclusive interview, Twitter-vet Jack Dorsey gives PYMNTS.com the skinny on Square. Dorsey answers security concerns and explains how Square has redesigned payments. Listen to the NEXTcast interview



SEO Series: Twitter Vet Jack Dorsey on Why Square is What's Next

When buzz began bubbling up around Square about a month ago, the industry took notice. Many charged that was due mainly in part because the driving force behind Square was the co-founder of Twitter, Jack Dorsey. Many industry insiders, like MagTek CEO Mimi Hart, raised security concerns around where the consumer's data was encrypted. There have been a number of devices to hit the market recently. Most notably was VeriFone's PAYware Mobile iPhone payments device. In a recent video interview with Tech Crunch, Dorsey was asked for his reaction to VeriFone's announcement as seen on PYMNTS.com. In the announcement, VeriFone CEO Douglas G. Bergeron said, "Banks and processors are concerned about the security issues of unapproved merchants using unregulated software and insecure fobs to accept card payments." When asked if he thought Bergeron was taking a swipe at Square, Dorsey took the high road and explained that Square would be going through the same PCI compliance measures as VeriFone or any other device would. Whenever Dorsey has demoed the device, he has made it clear that the device is just a small component of what Square is about. He has said that he and his Square-mates are interested in redesigning the payments experience. PYMNTS.com asked "Paying with Plastic" author and industry expert David S. Evans to speak with Dorsey about why Square is "what's next" in payments.



ICEMAN GETS 13 YEARS FOR MASSIVE CARD DATA THEFT

A Californian hacker known by the Internet alias 'Iceman' has been sentenced to 13 years in jail for stealing nearly two million credit card numbers. More on this story: http://www.finextra.com/news/fullstory.aspx?newsitemid=21086



2010 Identity Fraud Study: Threats and Trends

BankInfoSecurity.com For insight on the study results and what they mean to organizations across industry, James VAN DYKE of Javelin discusses: What organiztions and ...



Mobile Commerce: Experts Offer Strategy for Smaller Merchants

Practical Ecommerce Mobile commerce is a small fraction of this total. But as mobile usage becomes mainstream, and as a variety of devices expand the mobile web,



NOKIA PARTNERS INDIA'S YES BANK ON MOBILE FINANCE PILOT




The world's biggest handset manufacturer Nokia is teaming up with India's Yes Bank on a commercial mobile financial services pilot in Pune. More on this story: http://www.finextra.com/news/fullstory.aspx?newsitemid=21089



Global banking and payments tech provider opens Manila service center

Manila Bulletin ... nine million loyalty accounts, 125 million debit cards, 301500 ATMs and nearly two million POS locations through its NYCE EFT/PIN-debit network. ...



Online Banking Report Publishes New Issue “Online & Mobile Banking Forecast ...

Earthtimes (press release) Lastly the report lists the top 25 innovations of the decade topped by the invention of simple online payments by PayPal ten years ago and the advent of



TSYS Aims to Tap Growing Debit Trend with Its New Hybrid Card

Digital Transactions Verient Inc., a startup company with technology to secure online PIN-debit transactions, also is recruiting card issuers to use its platform for letting









Posted by John B. Frank Tuesday, February 16, 2010 0 comments

Information Cards (protected by a PIN) look to be a logical replacement to passwords.  Microsoft, Google and Oracle are among the founding members.  So what exactly is an information card?  Here's a brief overview from the Information Card Foundation: (ICF)

Information Cards are the digital, online equivalents of your physical identification credentials such as a drivers license, passport, credit card, club card, business card or a social greeting card. Users control the distribution of their personal information through each Information Card. Information Cards are stored in a user’s own online wallet (called a “selector”) and “handed out” with a mouse click just like a physical ID card.

Information Cards can be issued to users by organizations for general or specific use. Users can also create their own Information Cards as a shortcut to avoid the endless process of filling out web forms. But more importantly, the infastructure behind the cards allows for trusted sources (a bank, a credit union, a government office, etc.) to verify specific information (“claims”) made by a user. In other words, Information Cards give users the ability to make claims about themselves, verified by qualified 3rd parties, while using the Internet.

Here's an excerpt from an article from yesterday's NY Times "Goodbye Passwords You Aren't a Good Defense" talking more about Information Cards:

Password-based log-ons are susceptible to being compromised in any number of ways. Consider a single threat, that posed by phishers who trick us into clicking to a site designed to mimic a legitimate one in order to harvest our log-on information. Once we’ve been suckered at one site and our password purloined, it can be tried at other sites.

The solution urged by the experts is to abandon passwords — and to move to a fundamentally different model, one in which humans play little or no part in logging on. Instead, machines have a cryptographically encoded conversation to establish both parties’ authenticity, using digital keys that we, as users, have no need to see.  In short, we need a log-on system that relies on cryptography, not mnemonics.

As users, we would replace passwords with so-called information cards, icons on our screen that we select with a click to log on to a Web site. The click starts a handshake between machines that relies on hard-to-crack cryptographic code. The necessary software for creating information cards is on only about 20 percent of PCs, though that’s up from 10 percent a year ago. Windows Vista machines are equipped by default, but Windows XP, Mac and Linux machines require downloads.  And that’s only half the battle: Web site hosts must also be persuaded to adopt information-card technology for sign-ons.

It is the author of the NY Times article that we won’t make much progress on information cards in the near future because of what he calls "wasted energy and attention devoted to a large distraction, the OpenID initiative". OpenID promotes “Single Sign-On”: with it, logging on to one OpenID Web site with one password will grant entrance during that session to all Web sites that accept OpenID credentials.

Support for OpenID is conspicuously limited, however. Each of the big powers supposedly backing OpenID is glad to create an OpenID identity for visitors, which can be used at its site, but it isn’t willing to rely upon the OpenID credentials issued by others. You can’t use Microsoft-issued OpenID at Yahoo, nor Yahoo’s at Microsoft.

Why not? Because the companies see the many ways that the password-based log-on process, handled elsewhere, could be compromised. They do not want to take on the liability for mischief originating at someone else’s site.

Kim Cameron, Microsoft’s chief architect of identity, is an enthusiastic advocate of information cards, which are not only vastly more secure than a password-based security system, but are also customizable, permitting users to limit what information is released to particular sites. “I don’t like Single Sign-On,” Mr. Cameron said. “I don’t believe in Single Sign-On.”

Microsoft and Google are among the six founding companies of the Information Card Foundation, formed to promote adoption of the card technology. The presence of PayPal, which is owned by eBay, in the group is the most significant: PayPal, with its direct access to our checking accounts, will naturally be inclined to be conservative. If it becomes convinced that these cards are more secure than passwords, we should listen.

BUT perhaps information cards in certain situations are convenient to a fault, permitting anyone who happens by a PC that is momentarily unattended in an office setting to click quickly through a sign-on at a Web site holding sensitive information. This need not pose a problem, however.

“Users on shared systems can easily set up a simple PIN code to protect any card from use by other users,” Mr. Cameron said.  The PIN doesn’t return us to the Web password mess: it never leaves our machine and can’t be seen by phishers.

Logging on to a site should entail a cryptographic conversation between machines, saving us from inadvertently giving away the keys.

Posted by John B. Frank Monday, August 11, 2008 0 comments

A deal with a payment processing firm has sparked speculation the firm is to launch its own branded checkout service.


Microsoft has signed an agreement with a payment processing firm that experts have said could be a precursor to it launching an online checkout service. The agreement with Symmetric Systems will give the software giant access to the firm's online transactional platform, VitalPay.

VitalPay provides regulatory-compliant payment services, including mail and telephone order facilities and card-not-present transactions, to retailers and merchants, as well as travel and airline companies.

Microsoft
refused to comment on why it had struck the deal with the firm or how it would link Vital Pay's capabilities with its own. But the software vendor has a variety of point-of-sale, customer relationship management (CRM) and web-based software offerings that could potentially integrate an online payment facility with.

It does not have its own payment facility, which could provide a way of capturing the internet consumer according to Martha Bennett, research director of financial services technology at
Datamonitor.

"It's a pretty appropriate deal when you look at it in a wider context," Bennett told IT PRO. "Microsoft has been pretty desperate to capture the online consumer, if you look at recent activities concerning Yahoo. MSN isn't really a main competitor in search and Passport was a disaster. And, apart from the Internet facility on the X-box, it has been an also-ran when it comes to capturing Internet consumers."


She also said it was technically feasible for Microsoft to link with VitalPay to create a potential rival to Google's Checkout and Papal, particularly given its customer base of retailers using its Dynamics retail software suite. "The integration would be nice to have, but it will only be any good if it brings the merchants with it," she said.

Zemanta Pixie

Posted by John B. Frank Friday, June 6, 2008 0 comments

Payments Industry News Blog

Search the PIN Debit Blog by Subject

Kapersky Calls for Mass Adoption of Card Readers

Kapersky Calls for Mass Adoption of Card Readers