The Airline Industry, thanks to First Data may now consider HomeATM's PIN Based Platform as their primary payment choice

HomeATM recently signed a deal with Universal Air Travel Plan (UATP) and if anyone was wondering why the Airline Industry is interested in HomeATM's platform, you need to look no further than this mornings announcement that Frontier filed for Chapter 11.

Many will blame the high cost of gasoline, but in fact, the majority of the blame (according to Frontier themselves) is their credit card processor, First Data.

Follow this link to read the letter sent by Frontier's CEO, Sean Menke to it's employees in it's entirety. Otherwise, here's a pertinent excerpt of that letter:

This week, I was notified by our credit card processor that, as of Friday, April 11, due to "current economic conditions, the rise in fuel costs and the other bankruptcies around the industry," they intended to start withholding 50 percent of the credit card funds received from the sale of Frontier tickets.

If they went ahead and did this, tens of millions of dollars owed to us by our customers would have been withheld by the credit card processor, First Data. This would have drained our available cash almost immediately and would have made it impossible for us to continue normal operations.

Therefore, we decided to file Chapter 11 in an effort to fight this unwarranted step by the credit card processor so that we can continue to position the Company for long term success.I want to emphasize to each of you that this was very sudden and unexpected. We are the victims of a credit market that is very fragile and the tolerance for risk is extremely low. As I have stated many times recently, our executive management team has been working diligently and tirelessly to extend our
runway by securing additional cash to bolster our balance sheet. We were successfully making progress on a number of fronts that would position us well for the future and with the protection of the bankruptcy court, we plan to continue to pursue those opportunities.
It's simply amazing to me that a card processor, in order to mitigate "their" risk, instills immediate danger into a company's "very existence" by having control over funds that were not theirs to begin with. The time has apparently come for airlines to position PIN Debit, (not as an alternative payment), but as their primary payment mechanism. Here's more from Bloomberg...

Frontier took the step after its credit-card processor, First Data Corp., began withholding proceeds from ticket sales, the Denver-based carrier said in a statement today. First Data told Frontier April 8 it would retain half the proceeds of bankcard sales and increase collateral to $130 million from $54.5 million, according to a statement by Frontier Vice President Edward Christie filed with the U.S. Bankruptcy Court in Manhattan. If First Data's hold on proceeds went unchecked, ``it would have put severe restraints on Frontier's liquidity and would have made it impossible for us to continue normal operations.'' Menke said. First Data is based in Greenwood Village, Colorado.

I'll include more detail in next week's blog posting(s) but suffice it to say that PIN Based Transactions not only "eliminate the reserve" instituted by credit card processors, but also "lowers the transaction rate" (Interchange Fees) significantly.

Airlines are on the very brink and the issue of credit card reserves is going to explode in this space (if not in their face, as it has for Frontier) if the airlines industry doesn't start taking the necessary steps required to switch their payment choice over to the lower cost, more secure PIN Based transactional methodology that "their partner" HomeATM offers.

First Data actions today could not have driven this point home (or should I say HomeATM) any more clearly.

Posted by John B. Frank Friday, April 11, 2008 0 comments

Interestingly, the brick and mortar world, (the one chock full of PCI Standard compliance demands), seems less secure than the Online world. Yet online retailers pay exhorbitantly higher fees than brick and mortar retailers. Card Not Present transactions are certainly higher risk transactions, but HomeATM's Internet PIN Debit platform, combined with their PIN Entry Device (PED) could cut risk significantly and thus save online retailers 100 basis points off their Interchange fees.

In yet another breach, this one from Advanced Auto Parts, Retail Wire questions whether or not we should move to Chip and PIN based transactions.

Here's the discussion in today's Retail Wire...

And yet again, an American retailer and its customers go down the road of data theft. In this case, the retailer is Advance Auto Parts and the most recent hack affected 56,000 of its shoppers in eight states - Georgia, Indiana, Louisiana, Mississippi, New York, Ohio, Tennessee and Virginia. Luckily, the customers from the stores in question represent a small portion of the total shoppers that frequent the chain's 3,261 stores across the country.

The discovery of the breach, as with those at other retailers, has prompted Advance to reassess its security measures. Others, at the same time, are once again questioning if Payment Card Industry (PCI) compliance standards are either fair or effective.

In a recent interview with RIS News, Dave Hogan, senior vice president and chief information officer with the National Retail Federation (NRF), expressed the view that more secure forms of payment such as "Chip & Pin" were available and proven in reducing fraud. He suggested that card associations should "provide (at no cost to the merchant) card readers that can accept these new types of cards."

Mr. Hogan also took issue with the amount of data that merchants are required to keep by banks. He called on financial institutions to "state that 'Retailers have the option to no longer store credit card data and they will not be penalized for not keeping credit card data."

To read the Retail Wire discussion, click here. I'm sure it will garner a lot of responses. Here is one from Evan Shuman, former eWeek contributor and StoreFrontBackTalk Editor:

To answer your question, yes, Hogan's concerns are quite reasonable. Much of this, though, is a lot of agreement on the easy issues. There are few who truly argue with the following:

1) PCI is not perfect and retailers who are fully compliant are still fully vulnerable. Even PCI's backers agree with this. PCI was never intended to be perfect security. PCI was never intended to be anything beyond a good starting point.

2) PCI has absolutely improved retail security today. Again, this is pretty much done unanimous. It's not gone nearly far enough, but any movement forward is good.

3) Banks are, for the most part, much better choices than retailers to store sensitive payment data. Again, no one ultimately quarrels with this. The issue involves infrastructure, politics and business costs. To make this transition would require tons of agreement from people who are not motivated to make such agreements. So arguing that it's better doesn't help much if it can't be done given the powers that be.

4) Chip and PIN is more secure than what much of the U.S. is doing. True. But Chip and PIN--as it's deployed in the U.K.--also has many issues. Making the transition would be costly, would meet with substantial infrastructure resistance AND it would still retailers far more exposed than is desirable. For the same extreme effort and cost, we could probably come up with a more secure approach.

It's also true that if all retailers strictly adhered to the common-sense rules (no default passwords, examine traffic logs routinely and seriously, strictly enforce procedures, etc.), we'd also be far better off.

This, however, doesn't address the Hannaford scenario where--based on currently available information--we have a retailer that indeed appeared to abide by all of the rules and still got burned by some aggressive cyber thieves. That's the more rare but far more frightening scenario.

Evan Schuman, Editor, StorefrontBacktalk.com

Posted by John B. Frank 0 comments

I was speaking with Ken Mages, the founder and CEO of HomeATM and George Gendron, HomeATM's President regarding ATMDirect's questionable press release (Smoke, Mirrors and Patents) last Sunday, and the notion of calling them on their bluff came up.

Additionaly, we discussed an article written by Digital Transaction News, whereby Rajiv Grover, an investor in ATMDirect said. “Our intention is to own Internet PIN debit transactions.”

Remember...I took at close look at ATMDirect when it went up for auction and when I began digging into ATMDirect's business my conclusion was that the asset value of the associated personal property (i.e. servers, networking equipment, computers and office equipment) was worth (in an eBay resale) between $500,000 and $750,000.

Freshly armed with this information I decidedly looked at their associated, and I use this term very loosely here, "intellectual property" which solely consisted of a single patent. (not 25 global patents as stated in ATMDirect's recent press release)

In what I consider to be a "more than bold" statement, the new owners of ATMDirect went on to say: "Over the course of the next 90 to 120 days, ATM Direct is set to contract with a major, publicly held acquirer to sign merchants, receive certifications from a couple of major electronic-funds transfer networks, and sign a number of large merchants...

This leads me to my point. I have a "common sense" question that I'd like to pose here. By the way, it's the same question I posed to myself when I decided not to move forward in my attempt to acquire ATMDirect.

But before posing the question, I would ask that you first take a look at the numbers shown in the graphic on the left. (to get a bigger picture of my point, click the picture and focus on the "debit". Okay, now on with my ponderings...

For a measly $600k, wouldn't one, or even you, think that PayPal, BillMeLater, Amazon, First Data, Heartland, CyberSource, (the list goes on forever) would have been interested in acquiring the assets of ATMDirect? If any of those aforementioned companies could have "Owned PIN Debit on the Internet," a $94 BILLION dollar market for only $600k, doesn't your common sense dictate that they would have been involved?

For obvious reasons ALL were glaringly absent.

Thus the only logical assumption that a pragmatic person can make is that there's nothing there. Which brings me back to the beginning of this post.

I was talking with both the CEO/Founder and President of HomeATM, and the notion of calling them on their bluff (Myth'd it By That Much...) came up.

The fairest and most arbitrary way would be to challenge them to an old-fashioned showdown which was dubbed during the course of our conversation, a "PIN-OFF."

HomeATM would be willing to have the "PIN Off" supervised by a knowledgeable, non-partisan entity. One suggestion among many as a "fair and balanced" arbitrator was John Stewart" the Editor in Chief of Digital Transactions Magazine.

Will you, ATMDirect accept? I think the real question is: Will ATMDirect even "be able" to accept? If so, will ATMDirect be able to do so "securely" without any glitches? That is the gist of the challenge.

My take is they won't. It's too "Rocky" a road for them to travel. They know that it's simply a case of the Contender vs. the Pretender...

...Everlast versus Never...mind...I think you get the picture!

However, I've been known to be wrong before, so...ATMDirect, prove me wrong! If you don't think that HomeATM would "PIN U" into the proverbial corner, feel free to accept the invitation to an offical PIN Off by emailing me at: ATMDirect Hereby Accepts

Posted by John B. Frank Thursday, April 10, 2008 0 comments

A study shows that in 2007 organizations were much less likely to be subject to fraud from electronic payments than from checks, including ACH debit (26 percent), corporate cards (13 percent), ACH credit (4 percent) and wire transfer (3 percent). Most fraud is caused by thieves using credit cards. 89 percent of organizations that experienced consumer electronic payments fraud claim that credit cards were used.

More than one-third experienced ACH fraud and one-quarter claim they were subject of signature debit card fraud. PIN debit cards were not frequently used to commit fraud.

Two-thirds of organizations that experienced ACH and/or card payments fraud registered financial losses and 71 percent of these organizations state that the loss was caused by online commerce.


63 percent reported financial losses from in-person transactions, while 46 percent were subject to fraud because they accepted fraudulent ACH and/or card payments over the phone.


Data was published by the Association for Financial Professionals


In a related story, SEPA stated it's concern regarding the potential of fraudulent activity as it moves forward...

Sepa fraud risk warning for businesses
Laissez-faire attitude adds to confusion over payments...

As Europe starts to adopt pan-continental payments systems, UK payments takers are ill-equipped to deal with the exposure to fraud this change might bring. The Single Euro Payments Area (Sepa) directive came into operation at the beginning of the year and Faster Payments protocols are due to go live in May.

But UK organizations in the utilities, telecoms and insurance sectors are not anticipating any change in processes or systems to introduce fraud countermeasures following the introduction of Sepa Sepa allows organizations to offer services easily across the Euro area - but this also means fraudsters can bury their trails across a number of countries. A survey of 43 companies in the utilities, telecoms and insurance sectors, from newly rebranded Experian Payments (formerly Eiger Systems), found 98 per cent are not planning to change their security policies, even though three-quarters have some business overseas.

These sectors were chosen as a sample because they rely heavily on the automated direct debit payments Sepa seeks to streamline. A significant majority (86 per cent) said they had yet to even assess the payment fraud risk of Sepa, while 15 per cent of the insurance companies questioned believed there was a negligible risk.

Gartner research VP of banking and investment services Alistair Newton said: "There is often a difficulty in assessing the value of data on payment fraud, because of the disparity in how it is measured from organisation to organisation. The important angle here is that there is clearly a lack of visibility around payment fraud at a corporate level."

Cheat Sheet: Sepa

Back in 2000, European political big wigs got together in Lisbon. By the end of their jaunt in the sun, they decided the EU would be one of the world's leading knowledge-based economies by 2010 - a plan that has become known as the Lisbon Agenda.

Out of this stemmed the idea to support innovation and the idea of a single market by making it easier and cheaper to move money around the EU.

The EC decided that cross-border payments should cost no more than domestic payments and in 2002 the European Payments Council (a group of banks) sketched plans for how this would be done.

Thus the Single European Payments Area (Sepa) was born.

What will it mean?
Basically it means fewer charges on transactions and purchases. On the consumer side of things, if Sepa comes into being by 2010, it could mean you'll be able to buy things on your card in another European country and pay nothing more than you would domestically.

On the business side, it'll basically mean the same thing but moving money around should be as cheap as it is domestically. This means banks will have to sharpen up their IT systems, to replace manual processes with automatic ones in order to bring down costs.

Sepa will also mean that European-wide card issuers can compete with domestic card firms. Sepa is probably going to be built around EuroPay MasterCard Visa (EMV) card technology to ensure security and interoperability at the acceptance point. How will it happen?

Aye, there's the rub. The thing is the banks don't really know what they should do as wise men at the EC in Brussels haven't issued any strict guidelines. A lot has been left to interpretation.

Saying that, Voca, the payments organisation formally known as Bacs, is already revamping its infrastructure to accommodate future demands of Sepa. Analysts have also predicted banks will have to spend money quite fast to hit the 2010 deadline.

After all, making all European businesses and all banks sing from the same song sheet isn't going to be easy.

What should I do to be to prepare for Sepa?
Basically, get ready to buy technology and think Europe-wide.

Is it all smooth sailing?
As mentioned, it could cost a lot for banks to get up to scratch but the benefits will be that banks can compete for customers anywhere in Europe.

Posted by John B. Frank Tuesday, April 8, 2008 0 comments

On the right sidebar you'll find a "search this blog" option. Simply type in your request and it will search not only this blog, but give you additional options for the search parameters. For example...type in ATMDirect and4 the results will appear on the top of the most recent post.

Posted by John B. Frank Monday, April 7, 2008 0 comments

The many people who subscribed to my Pay By Touch Blog over the past couple years know that I was a big advocate for ATMDirect, more specifically, a methodology designed to offer Internet Retailers a lower cost, more secure PIN Debit payment solution.

In fact, in one specific post I did in June of '06 I mentioned that I really believed that ATMDirect might have been a Pay By Touch Cash Cow.

That is why, when Pay By Touch announced they were selling their non-core assets, including ATMDirect, I decided to take a close look at it. Thus, I signed the requisite non-disclosure and PBT forwarded me the confidential information that they forwarded to others who may have been interested in procuring ATMDirect's assets.

I also spoke to former Pay By Touch executives who informed me that some of the claims made by the former owner of ATMDirect regarding their patents were, "misleading" or at least "overblown." So I looked at their patents, no...let's make that "patent" since only one is issued (the rest are only applied for,) as well as other key ingredients and, frankly, came away rather unimpressed.

How unimpressed? Let's just say that my vision of ATMDirect as a "cash cow" took on a new form...(which I graphically illustrate on the right)


I knew that Pay By Touch had (been duped?) paid $30.5 million only two years previously, and that now it could be had for somewhere around $500k-$750k. Even though there
were several IBM Blade Servers worth about $1.5 million, I decided to pass as I wasn't in the used blade server resale business.

On Friday, I mentioned that I was going to do a post discussing how ATMDirect is bluffing their way through the PIN Debit Card game. They sure made it easy for me. as yesterday, while I was watching the Cubs game, I got an e-mail alert regarding a press release from ATMDirect.

Here's the link, followed by the portion of the press release that, in my view, is blatantly misleading. Bluffs only work when you don't have to show your cards, but when you say you have a Four Aces, you better have four and not one.

As you read the following, keep in mind that ATMDirect (or should I say ATM-Indirect.) has been issued ONE patent...and that I saw everything that ATMD had to offer and was simply not interested.

Frankly, one word sums up this press release...Unbelievable!


###

Accullink, LLC Acquires Pay by Touch Internet PIN Debit "Patents"


Accullink, LLC is pleased to announce the acquisition of Pay By Touch's "suite of 25 global Internet PIN Debit patents".

These "
patents" enable, for the first time, a software-only solution for PIN based payment transactions on the Internet. "The patents" are being commercialized through Accullink, LLC subsidiary ATM Direct. Their solution provides a compelling alternative payment method for consumers and merchants.

Atlanta, GA, April 06, 2008 --(
PR.com)-- Accullink, LLC, an Atlanta based investor group, has acquired Pay by Touch's suite of 25 global patents that enable a software-only solution for PIN based payment transactions on the Internet. Accullink, LLC is commercializing the patent suite through its subsidiary ATM Direct, a leading alternative payment provider.

I'll have more to say on this subject later on. By the way...if anyone from ATMDirect disputes anything I've stated in this post, I would invite them to feel free to contact me and set the record straight. johnbfrank@gmail.com

Posted by John B. Frank 0 comments

PIN Debit for the Internet...which Avenue should Online Retailers Take?


VERSUS


Posted by John B. Frank Friday, April 4, 2008 0 comments

Payments Industry News Blog

Search the PIN Debit Blog by Subject

Kapersky Calls for Mass Adoption of Card Readers

Kapersky Calls for Mass Adoption of Card Readers