Showing posts with label Twitter. Show all posts
Showing posts with label Twitter. Show all posts













SearchFinancialSecurity.com











Financial services firms face social media compliance challenges

Marcia Savage, Site Editor



Brokerages and other financial services firms turning to sites like Facebook and Twitter for marketing and customer outreach face a number of thorny social media compliance issues. Earlier this year, the Financial Industry Regulatory Authority (FINRA), which oversees U.S. securities firms, released Regulatory Notice 10-06.  The notice provides guidance on how FINRA rules governing public communications apply to use of social media sites by financial firms and their employees for business purposes.



Read the full story


Enhanced by Zemanta

Posted by John B. Frank Wednesday, June 30, 2010 0 comments

Jack Dorsey, co-founder of Twitter.Image via Wikipedia
Finextra Reports that Jack Dorsey's Square is back to...Square One?



Square roll-out delayed over security concerns




Much-hyped payments start-up Square has been forced to delay shipping its product that turns mobile phones into payment card readers because of emerging fraud concerns, with founder Jack Dorsey admitting parts were released "before they were fully baked".



Unveiling his new firm to much fanfare in December, Twitter founder Dorsey predicted Square would be available for customers in the US early this year.



Now, in a letter to customers (see below), he admits "we've let our excitement get the best of us" and says "we realize the amount of time we've taken to ship our Square readers has been frustrating, sometimes confusing, and has generated a number of questions".  The start-up initially suffered from hardware shortages but says this has been resolved with manufacturers in China.



However, a new problem has emerged. According to a letter to users from the Square support team: "We need to strengthen our underwriting infrastructure so that we can handle the huge demand for readers and still manage the risk of chargebacks and fraud."



Dorsey says Square initially moved to negate the risks by setting transaction limits but these have been set too low according to customers, prompting "rethinking and expanding" of the underwriting infrastructure.



The letter provides no details on when the product may be ready to ship, with Dorsey signing off: "We thank you for your continued patience as we work to deliver a utility you can use every day and for allowing us the time to get it right."



Finextra verdict: Reality bites for Square. Overly-hyped by the starry-eyed Silicon Valley tech press, Jack Dorsey and Co are discovering the hard way that payments processing is not as easy or as simple as it might first appear. Innovation has its place, but in the money-changing business it has to be backed up by a resilient infrastructure and water-tight contracts. There's no place for a fail-whale in the payments sphere.



Editor's Note:  
Want PIN Transaction Capability?  Take a look at our SLIM POS with a built-in PCI Certified PIN Entry Device. (below)  





Conduct Secure End-to-End-Encrypted PIN Debit Transactions with our SLIM PCI Certified PIN Entry Device


Here's a copy of the letter sent by Jack Dorsey:


"Dear Square user,



We announced Square with the phrase: "0 to $60 in under 10 seconds."



Square's goal is to enable people to accept payments immediately, everywhere. We realize the amount of time we've taken to ship our Square readers has been frustrating, sometimes confusing, and has generated a number of questions. When we announced the company last December, we estimated Square would be ready in the U.S. sometime in early 2010. Since then, we've let our excitement get the best of us and have released parts of Square before they were fully baked.



A recent email from our support team to a Square user sums up where we are:



Until recently, we were facing a big hardware shortage, but that is now resolved (we sent our co-founder Jim to China for a couple weeks to arrange better manufacturing, and that did the trick). The problem has transitioned to something we've been working on simultaneously, a credit processing and risk issue. We need to strengthen our underwriting infrastructure so that we can handle the huge demand for readers and still manage the risk of chargebacks and fraud. This is the last thing preventing us from shipping readers as fast as we'd like, and we have pretty much the entire team working on it.



The way we are handling the risk of chargebacks and fraud is through transaction limits, but we have received feedback that those limits are too low. We are rethinking and expanding our underwriting infrastructure to address this issue. As soon as we finish, we will send you an email to confirm that you would like us to run a credit check (or you can cancel your request to process cards with Square which will securely remove your personal information). We will then ship your free card reader and activate your account to accept card payments.



We thank you for your continued patience as we work to deliver a utility you can use every day and for allowing us the time to get it right.



Jack Dorsey

Square CEO"
Enhanced by Zemanta

Posted by John B. Frank Monday, June 21, 2010 0 comments

Security Watch is reporting on one of the many reasons Kapersky Labs is calling for "mass adoption" of peripheral card readers for all Internet Banking users...browsers are just too dangerous and thus, simply put, websites cannot be trusted.



Twitter Attack Pushes Banking Trojan








Tripe DES DUKPT End to End Encryption vs. Typing sensitive data into a box in a browser
Attackers are targeting Twitter users with a Trojan stealing online banking credentials, according to researchers.



"The initial Trojan is downloaded to the victim machine by a malicious Java archive file," explained Dmitry Bestuzhev of Kaspersky Lab. "It has several malicious features, for example: spreading through USB devices; it disables Windows task manager, the regedit application and also notifications from Windows Security Center. Also it creates a copy of itself in the system with the name of Live Messenger. The criminals even included an anti-virtualization feature. The worm checks if the hard drive of infected system is virtualized or not. If found to be in a virtual system, the malicious code won't be executed."
The malicious links being tweeted out come with the message "haha this is the funniest video ive EVER SEEN!" Researchers at F-Secure noticed the attack as well, and said the links in the tweets point to a page under pc-tv.tv.
"This malware is very harmful since credit cards and online banking credentials are in the game," Bestuzhev blogged. "Please, be really careful especially with trend topics (searches) since in many cases they are being used by criminals."


Reblog this post [with Zemanta]

Posted by John B. Frank Friday, May 21, 2010 0 comments

Security Watch is reporting on one of the many reasons Kapersky Labs is calling for "mass adoption" of peripheral card readers for all Internet Banking users...browsers are just too dangerous and thus, simply put, websites cannot be trusted.



Twitter Attack Pushes Banking Trojan








Tripe DES DUKPT End to End Encryption vs. Typing sensitive data into a box in a browser
Attackers are targeting Twitter users with a Trojan stealing online banking credentials, according to researchers.



"The initial Trojan is downloaded to the victim machine by a malicious Java archive file," explained Dmitry Bestuzhev of Kaspersky Lab. "It has several malicious features, for example: spreading through USB devices; it disables Windows task manager, the regedit application and also notifications from Windows Security Center. Also it creates a copy of itself in the system with the name of Live Messenger. The criminals even included an anti-virtualization feature. The worm checks if the hard drive of infected system is virtualized or not. If found to be in a virtual system, the malicious code won't be executed."
The malicious links being tweeted out come with the message "haha this is the funniest video ive EVER SEEN!" Researchers at F-Secure noticed the attack as well, and said the links in the tweets point to a page under pc-tv.tv.
"This malware is very harmful since credit cards and online banking credentials are in the game," Bestuzhev blogged. "Please, be really careful especially with trend topics (searches) since in many cases they are being used by criminals."


Reblog this post [with Zemanta]

Posted by John B. Frank 0 comments




www.Twitter.com/HomeATM
For Veteran Social Marketers, Twitter Is Tops



According to eMarketer, Facebook is the top social site for marketers just getting started in the space, but as they gain knowledge and improve techniques the social marketing mix changes.



Full Article




To follow the Payments Industry News Blog on Twitter, click the following link:



www.Twitter.com/HomeATM

Posted by John B. Frank Friday, April 30, 2010 0 comments




www.Twitter.com/HomeATM
For Veteran Social Marketers, Twitter Is Tops



According to eMarketer, Facebook is the top social site for marketers just getting started in the space, but as they gain knowledge and improve techniques the social marketing mix changes.



Full Article




To follow the Payments Industry News Blog on Twitter, click the following link:



www.Twitter.com/HomeATM

Posted by John B. Frank 0 comments



Last week, Blippy, a Twitter for purchases, created quite a stir when it was revealed that the company had exposedthe credit card numbers of several users.

The company's co-founder, Philip Kaplan, sought to downplay the severity of the mistake but as more and more individuals cozy up to the growing number of services that encourage 'oversharing' of financial-related information online, a number of parties involved with commerce will be affected.
Here's how this could play out.

Credit Card Holders & Issuers

In attempting to reassure Blippy users that the company's faux pas was "a lot less bad than it looks", Blippy co-founder Philip Kaplan wrote:
While we take this very seriously and it is a headache for those involved, it’s important to remember that you’re never responsible if someone uses your credit card without your permission.  That’s why it’s okay to hand your credit card over to waiters, store clerks, and hundreds of other people who all have access to your credit card numbers.
Unfortunately, Kaplan apparently hasn't read a cardholder agreement lately. In practice, credit card issuers rarely hold their cardholders liable for purchases that are truly unauthorized. But that doesn't mean that they can't.




Reblog this post [with Zemanta]

Posted by John B. Frank Monday, April 26, 2010 0 comments



Last week, Blippy, a Twitter for purchases, created quite a stir when it was revealed that the company had exposedthe credit card numbers of several users.

The company's co-founder, Philip Kaplan, sought to downplay the severity of the mistake but as more and more individuals cozy up to the growing number of services that encourage 'oversharing' of financial-related information online, a number of parties involved with commerce will be affected.
Here's how this could play out.

Credit Card Holders & Issuers

In attempting to reassure Blippy users that the company's faux pas was "a lot less bad than it looks", Blippy co-founder Philip Kaplan wrote:
While we take this very seriously and it is a headache for those involved, it’s important to remember that you’re never responsible if someone uses your credit card without your permission.  That’s why it’s okay to hand your credit card over to waiters, store clerks, and hundreds of other people who all have access to your credit card numbers.
Unfortunately, Kaplan apparently hasn't read a cardholder agreement lately. In practice, credit card issuers rarely hold their cardholders liable for purchases that are truly unauthorized. But that doesn't mean that they can't.




Reblog this post [with Zemanta]

Posted by John B. Frank 0 comments

You can bet your "Bippy" that it was only a matter of time before "Blippy" exposed your PAN's (primary account numbers).  Now, I've just learned (from Mashable.com) that they can be "Googled" (see below)  



How could "anyone" NOT see this coming?  Now that I mention it, why does "anyone" still think you can type your PAN's into boxes on websites? You just can't do it.  Again, my favorite definition of insanity is the act of doing the same thing over and over again expecting different results.  You Type...The Bad Guys Swipe.  You Swipe, Your NOT the bad guys type.  It's that simple.



Here's what I had to say back in January when I first heard about Blippy: (the full post is below)  


When Blippy, which lets you twitter credit/debit card purchases rolled out earlier this month, my eyes rolled as well.







Click to Enlarge




BLIPPY CREDIT CARD DETAILS EXPOSED ON GOOGLE - MASHABLE



Nearly 200 credit card transactions shared on social networking site Blippy  have been exposed - with full credit card numbers included - in Google search results, according to Mashable.



More on this story: http://www.finextra.com/news/fullstory.aspx?newsitemid=21323





When Blippy, which lets you twitter credit/debit card purchases rolled out earlier this month, my eyes rolled as well. Maybe because I still don't get Twitter. Somebody Tweets "I'm at Peet's" and frankly, it won't be more interesting finding out how much they spent there and what card they used. Who cares? Answer: The bad guys! 




Social networking sites have been identified as a nesting ground for purveyors of malware and phishing techniques, thus financial information gathering. It isn't difficult for them to round up needed information, but why make it easy for them by signing up to have your purchases show up as "blips" on the bad guys radar screens? I was waiting for someone else to see the naked emperor before saying anything. Cyveillance has spoken...



Blippy
, could be a valuable tool for cyber criminals, warns Cyveillance




Blippy, a Spear Phisher’s Dream




This month, a service called Blippy was rolled out to the general public. In a CNN article this week, Blippy was described as a “financial version of twitter.com”, where users’ credit card transactions are posted to the internet much like the short tweets that people post to twitter.



On twitter, users post up to 140 characters on any topic they wish to discuss. On Blippy, a posting displays how much a person paid for a recent purchase. In the image below for example, we see that Michael Arrington of TechCrunch paid $112.64 at Amazon for a SanDisk 16GB 60MB/s Extreme Compact Flash Card.




Read more: http://pindebit.blogspot.com/2010/01/blippy-do-you-really-want-your-card.html#ixzz0lwY41HWK





Reblog this post [with Zemanta]

Posted by John B. Frank Friday, April 23, 2010 0 comments

You can bet your "Bippy" that it was only a matter of time before "Blippy" exposed your PAN's (primary account numbers).  Now, I've just learned (from Mashable.com) that they can be "Googled" (see below)  



How could "anyone" NOT see this coming?  Now that I mention it, why does "anyone" still think you can type your PAN's into boxes on websites? You just can't do it.  Again, my favorite definition of insanity is the act of doing the same thing over and over again expecting different results.  You Type...The Bad Guys Swipe.  You Swipe, Your NOT the bad guys type.  It's that simple.



Here's what I had to say back in January when I first heard about Blippy: (the full post is below)  


When Blippy, which lets you twitter credit/debit card purchases rolled out earlier this month, my eyes rolled as well.







Click to Enlarge




BLIPPY CREDIT CARD DETAILS EXPOSED ON GOOGLE - MASHABLE



Nearly 200 credit card transactions shared on social networking site Blippy  have been exposed - with full credit card numbers included - in Google search results, according to Mashable.



More on this story: http://www.finextra.com/news/fullstory.aspx?newsitemid=21323





When Blippy, which lets you twitter credit/debit card purchases rolled out earlier this month, my eyes rolled as well. Maybe because I still don't get Twitter. Somebody Tweets "I'm at Peet's" and frankly, it won't be more interesting finding out how much they spent there and what card they used. Who cares? Answer: The bad guys! 




Social networking sites have been identified as a nesting ground for purveyors of malware and phishing techniques, thus financial information gathering. It isn't difficult for them to round up needed information, but why make it easy for them by signing up to have your purchases show up as "blips" on the bad guys radar screens? I was waiting for someone else to see the naked emperor before saying anything. Cyveillance has spoken...



Blippy
, could be a valuable tool for cyber criminals, warns Cyveillance




Blippy, a Spear Phisher’s Dream




This month, a service called Blippy was rolled out to the general public. In a CNN article this week, Blippy was described as a “financial version of twitter.com”, where users’ credit card transactions are posted to the internet much like the short tweets that people post to twitter.



On twitter, users post up to 140 characters on any topic they wish to discuss. On Blippy, a posting displays how much a person paid for a recent purchase. In the image below for example, we see that Michael Arrington of TechCrunch paid $112.64 at Amazon for a SanDisk 16GB 60MB/s Extreme Compact Flash Card.




Read more: http://pindebit.blogspot.com/2010/01/blippy-do-you-really-want-your-card.html#ixzz0lwY41HWK





Reblog this post [with Zemanta]

Posted by John B. Frank 0 comments





Popular social networking site Twitter is being used to control botnets, according to Jose Nazario, who is a Senior Security Researcher from Arbor Networks. Botnets are computers infected with malware that allows them to be commandeered by hackers. Nazario says that he stumbled upon one such Twitter account, though it has since been reported and taken down.



The key challenge of building botnets, for hackers, has always been in how to control them. Years ago, this used to be done via IRC channels, where infected computers would visit in order to receive their commands. These have proven to be relatively easy to track down though.



By switching to Twitter, hackers are leveraging not only on the server infrastructure of the social networking site, but also the publicly-known APIs used for the posting and viewing of tweets. And compared to earlier methods that saw hackers putting down money to purchase domains for their bots, creating a user account in Twitter costs them nothing.



Finally, using Twitter also makes it difficult for anti-malware applications to differentiate between a legitimate visit and the behavior of an infected workstation. Talking about the use of Twitter to host a botnet, Nazario said to The Inquirer, "I wouldn't call it rocket science, but it's effective."



For more on this story:- check out this article at The Inquirer















Reblog this post [with Zemanta]

Posted by John B. Frank Thursday, August 20, 2009 0 comments

Twitter Users - Want to Tweet a Post from the PIN Payments Blog? Feel free...and now it's easy!
Just look for the "Twit This" Icon located at the bottom of each and every Post and Simply Click to Tweet!

Posted by John B. Frank Friday, March 6, 2009 0 comments

Payments Industry News Blog

Search the PIN Debit Blog by Subject

Kapersky Calls for Mass Adoption of Card Readers

Kapersky Calls for Mass Adoption of Card Readers