| Financial services firms face social media compliance challenges | ||
| Marcia Savage, Site Editor Brokerages and other financial services firms turning to sites like Facebook and Twitter for marketing and customer outreach face a number of thorny social media compliance issues. Earlier this year, the Financial Industry Regulatory Authority (FINRA), which oversees U.S. securities firms, released Regulatory Notice 10-06. The notice provides guidance on how FINRA rules governing public communications apply to use of social media sites by financial firms and their employees for business purposes. Read the full story | ||
Square roll-out delayed over security concerns
Much-hyped payments start-up Square has been forced to delay shipping its product that turns mobile phones into payment card readers because of emerging fraud concerns, with founder Jack Dorsey admitting parts were released "before they were fully baked".
Unveiling his new firm to much fanfare in December, Twitter founder Dorsey predicted Square would be available for customers in the US early this year.
Now, in a letter to customers (see below), he admits "we've let our excitement get the best of us" and says "we realize the amount of time we've taken to ship our Square readers has been frustrating, sometimes confusing, and has generated a number of questions". The start-up initially suffered from hardware shortages but says this has been resolved with manufacturers in China.
However, a new problem has emerged. According to a letter to users from the Square support team: "We need to strengthen our underwriting infrastructure so that we can handle the huge demand for readers and still manage the risk of chargebacks and fraud."
Dorsey says Square initially moved to negate the risks by setting transaction limits but these have been set too low according to customers, prompting "rethinking and expanding" of the underwriting infrastructure.
The letter provides no details on when the product may be ready to ship, with Dorsey signing off: "We thank you for your continued patience as we work to deliver a utility you can use every day and for allowing us the time to get it right."
Finextra verdict: Reality bites for Square. Overly-hyped by the starry-eyed Silicon Valley tech press, Jack Dorsey and Co are discovering the hard way that payments processing is not as easy or as simple as it might first appear. Innovation has its place, but in the money-changing business it has to be backed up by a resilient infrastructure and water-tight contracts. There's no place for a fail-whale in the payments sphere.
Editor's Note: Want PIN Transaction Capability? Take a look at our SLIM POS with a built-in PCI Certified PIN Entry Device. (below)
We announced Square with the phrase: "0 to $60 in under 10 seconds."
Square's goal is to enable people to accept payments immediately, everywhere. We realize the amount of time we've taken to ship our Square readers has been frustrating, sometimes confusing, and has generated a number of questions. When we announced the company last December, we estimated Square would be ready in the U.S. sometime in early 2010. Since then, we've let our excitement get the best of us and have released parts of Square before they were fully baked.
A recent email from our support team to a Square user sums up where we are:
Until recently, we were facing a big hardware shortage, but that is now resolved (we sent our co-founder Jim to China for a couple weeks to arrange better manufacturing, and that did the trick). The problem has transitioned to something we've been working on simultaneously, a credit processing and risk issue. We need to strengthen our underwriting infrastructure so that we can handle the huge demand for readers and still manage the risk of chargebacks and fraud. This is the last thing preventing us from shipping readers as fast as we'd like, and we have pretty much the entire team working on it.
The way we are handling the risk of chargebacks and fraud is through transaction limits, but we have received feedback that those limits are too low. We are rethinking and expanding our underwriting infrastructure to address this issue. As soon as we finish, we will send you an email to confirm that you would like us to run a credit check (or you can cancel your request to process cards with Square which will securely remove your personal information). We will then ship your free card reader and activate your account to accept card payments.
We thank you for your continued patience as we work to deliver a utility you can use every day and for allowing us the time to get it right.
Jack Dorsey
Square CEO"
Related articles by Zemanta
- Jack Dorsey: Square Preparing for Credit Risks (readwriteweb.com)
- iPhone mag-stripe reader stalled (go.theregister.com)
- Square's mobile credit card reader hits speed bump (mobile.venturebeat.com)
- Dorsey Delivers 50,000 Squares, Eyes Global Domination [Video] (techcrunch.com)
- Square Delays Mass Roll-Out, Admits They Began Before Things Were "Fully Baked" (techcrunch.com)
- Jack Dorsey's Square Roll Out Delayed over "Security Concerns" (pindebit.blogspot.com)
Twitter Attack Pushes Banking Trojan
Attackers are targeting Twitter users with a Trojan stealing online banking credentials, according to researchers. "The initial Trojan is downloaded to the victim machine by a malicious Java archive file," explained Dmitry Bestuzhev of Kaspersky Lab. "It has several malicious features, for example: spreading through USB devices; it disables Windows task manager, the regedit application and also notifications from Windows Security Center. Also it creates a copy of itself in the system with the name of Live Messenger. The criminals even included an anti-virtualization feature. The worm checks if the hard drive of infected system is virtualized or not. If found to be in a virtual system, the malicious code won't be executed." The malicious links being tweeted out come with the message "haha this is the funniest video ive EVER SEEN!" Researchers at F-Secure noticed the attack as well, and said the links in the tweets point to a page under pc-tv.tv."This malware is very harmful since credit cards and online banking credentials are in the game," Bestuzhev blogged. "Please, be really careful especially with trend topics (searches) since in many cases they are being used by criminals." |
Twitter Attack Pushes Banking Trojan
Attackers are targeting Twitter users with a Trojan stealing online banking credentials, according to researchers. "The initial Trojan is downloaded to the victim machine by a malicious Java archive file," explained Dmitry Bestuzhev of Kaspersky Lab. "It has several malicious features, for example: spreading through USB devices; it disables Windows task manager, the regedit application and also notifications from Windows Security Center. Also it creates a copy of itself in the system with the name of Live Messenger. The criminals even included an anti-virtualization feature. The worm checks if the hard drive of infected system is virtualized or not. If found to be in a virtual system, the malicious code won't be executed." The malicious links being tweeted out come with the message "haha this is the funniest video ive EVER SEEN!" Researchers at F-Secure noticed the attack as well, and said the links in the tweets point to a page under pc-tv.tv."This malware is very harmful since credit cards and online banking credentials are in the game," Bestuzhev blogged. "Please, be really careful especially with trend topics (searches) since in many cases they are being used by criminals." |
![]() |
| www.Twitter.com/HomeATM |
According to eMarketer, Facebook is the top social site for marketers just getting started in the space, but as they gain knowledge and improve techniques the social marketing mix changes.
Full Article
To follow the Payments Industry News Blog on Twitter, click the following link:
www.Twitter.com/HomeATM
![]() |
| www.Twitter.com/HomeATM |
According to eMarketer, Facebook is the top social site for marketers just getting started in the space, but as they gain knowledge and improve techniques the social marketing mix changes.
Full Article
To follow the Payments Industry News Blog on Twitter, click the following link:
www.Twitter.com/HomeATM
The company's co-founder, Philip Kaplan, sought to downplay the severity of the mistake but as more and more individuals cozy up to the growing number of services that encourage 'oversharing' of financial-related information online, a number of parties involved with commerce will be affected.
Credit Card Holders & Issuers
While we take this very seriously and it is a headache for those involved, it’s important to remember that you’re never responsible if someone uses your credit card without your permission. That’s why it’s okay to hand your credit card over to waiters, store clerks, and hundreds of other people who all have access to your credit card numbers.
The company's co-founder, Philip Kaplan, sought to downplay the severity of the mistake but as more and more individuals cozy up to the growing number of services that encourage 'oversharing' of financial-related information online, a number of parties involved with commerce will be affected.
Credit Card Holders & Issuers
While we take this very seriously and it is a headache for those involved, it’s important to remember that you’re never responsible if someone uses your credit card without your permission. That’s why it’s okay to hand your credit card over to waiters, store clerks, and hundreds of other people who all have access to your credit card numbers.
You can bet your "Bippy" that it was only a matter of time before "Blippy" exposed your PAN's (primary account numbers). Now, I've just learned (from Mashable.com) that they can be "Googled" (see below)
How could "anyone" NOT see this coming? Now that I mention it, why does "anyone" still think you can type your PAN's into boxes on websites? You just can't do it. Again, my favorite definition of insanity is the act of doing the same thing over and over again expecting different results. You Type...The Bad Guys Swipe. You Swipe, Your NOT the bad guys type. It's that simple.
Here's what I had to say back in January when I first heard about Blippy: (the full post is below)
When Blippy, which lets you twitter credit/debit card purchases rolled out earlier this month, my eyes rolled as well.
![]() |
| Click to Enlarge |
BLIPPY CREDIT CARD DETAILS EXPOSED ON GOOGLE - MASHABLE
Nearly 200 credit card transactions shared on social networking site Blippy have been exposed - with full credit card numbers included - in Google search results, according to Mashable.
More on this story: http://www.finextra.com/news/fullstory.aspx?newsitemid=21323
Social networking sites have been identified as a nesting ground for purveyors of malware and phishing techniques, thus financial information gathering. It isn't difficult for them to round up needed information, but why make it easy for them by signing up to have your purchases show up as "blips" on the bad guys radar screens? I was waiting for someone else to see the naked emperor before saying anything. Cyveillance has spoken...
Blippy, could be a valuable tool for cyber criminals, warns Cyveillance.
Blippy, a Spear Phisher’s Dream
On twitter, users post up to 140 characters on any topic they wish to discuss. On Blippy, a posting displays how much a person paid for a recent purchase. In the image below for example, we see that Michael Arrington of TechCrunch paid $112.64 at Amazon for a SanDisk 16GB 60MB/s Extreme Compact Flash Card.
Read more: http://pindebit.blogspot.com/2010/01/blippy-do-you-really-want-your-card.html#ixzz0lwY41HWK
You can bet your "Bippy" that it was only a matter of time before "Blippy" exposed your PAN's (primary account numbers). Now, I've just learned (from Mashable.com) that they can be "Googled" (see below)
How could "anyone" NOT see this coming? Now that I mention it, why does "anyone" still think you can type your PAN's into boxes on websites? You just can't do it. Again, my favorite definition of insanity is the act of doing the same thing over and over again expecting different results. You Type...The Bad Guys Swipe. You Swipe, Your NOT the bad guys type. It's that simple.
Here's what I had to say back in January when I first heard about Blippy: (the full post is below)
When Blippy, which lets you twitter credit/debit card purchases rolled out earlier this month, my eyes rolled as well.
![]() |
| Click to Enlarge |
BLIPPY CREDIT CARD DETAILS EXPOSED ON GOOGLE - MASHABLE
Nearly 200 credit card transactions shared on social networking site Blippy have been exposed - with full credit card numbers included - in Google search results, according to Mashable.
More on this story: http://www.finextra.com/news/fullstory.aspx?newsitemid=21323
Social networking sites have been identified as a nesting ground for purveyors of malware and phishing techniques, thus financial information gathering. It isn't difficult for them to round up needed information, but why make it easy for them by signing up to have your purchases show up as "blips" on the bad guys radar screens? I was waiting for someone else to see the naked emperor before saying anything. Cyveillance has spoken...
Blippy, could be a valuable tool for cyber criminals, warns Cyveillance.
Blippy, a Spear Phisher’s Dream
On twitter, users post up to 140 characters on any topic they wish to discuss. On Blippy, a posting displays how much a person paid for a recent purchase. In the image below for example, we see that Michael Arrington of TechCrunch paid $112.64 at Amazon for a SanDisk 16GB 60MB/s Extreme Compact Flash Card.
Read more: http://pindebit.blogspot.com/2010/01/blippy-do-you-really-want-your-card.html#ixzz0lwY41HWK
Popular social networking site Twitter is being used to control botnets, according to Jose Nazario, who is a Senior Security Researcher from Arbor Networks. Botnets are computers infected with malware that allows them to be commandeered by hackers. Nazario says that he stumbled upon one such Twitter account, though it has since been reported and taken down.
The key challenge of building botnets, for hackers, has always been in how to control them. Years ago, this used to be done via IRC channels, where infected computers would visit in order to receive their commands. These have proven to be relatively easy to track down though.
By switching to Twitter, hackers are leveraging not only on the server infrastructure of the social networking site, but also the publicly-known APIs used for the posting and viewing of tweets. And compared to earlier methods that saw hackers putting down money to purchase domains for their bots, creating a user account in Twitter costs them nothing.
Finally, using Twitter also makes it difficult for anti-malware applications to differentiate between a legitimate visit and the behavior of an infected workstation. Talking about the use of Twitter to host a botnet, Nazario said to The Inquirer, "I wouldn't call it rocket science, but it's effective."
For more on this story:- check out this article at The Inquirer
Twitter Users - Want to Tweet a Post from the PIN Payments Blog? Feel free...and now it's easy!
Just look for the "Twit This" Icon located at the bottom of each and every Post and Simply Click to Tweet!







