Bank Info Security posted a story suggesting that the Comerica/EMI lawsuit will bring security to the forefront.  It's about time.  Usernames and Passwords should have been eliminated long ago.  We say it's time to authenticate the online banking session the same way you authenticate an ATM transaction.  Swipe your Card and Enter Your PIN.  Talk about secure.  Our technology 3DES DUKPT End-to-End-Encrypts the data at the mag-head thus preventing the data from EVER being in the clear.  If it's trusted to dispense $200.00 at 2:00 in the morning 2000 miles away from home, it can be trusted to authenticate the online banking session.



In fact, it's even safer.  No threats from skimming devices or hidden cameras come into play.  By eliminating typing you eliminate the behavior that makes for a phishing environment.  What good would it do to "lure" a consumer and tell them to type their username and password if they banked at an institution that instructed them to swipe their card and enter their PIN?   Want to be the leader in online banking?  Be the leader in online banking security first.  The worlds only PCI 2.0 Certified PIN Entry Device designed specifically for eCommerce use. 







Industry Experts: 'This Litigation Raises the Stakes'


Banking/security leaders continue to debate the merits of the lawsuit between Dallas-based Comerica Bank and its customer, Experi-Metal Inc. (EMI), a Michigan-based metal supply company that claims the bank exposed its clients to phishing attacks.



But already industry analysts say there are some key lessons learned that other institutions can draw from this case.



Read Entire Article





Thanks for Visiting - Bookmark us or Add to your Favorites and Find Out What's Going on Tomorrow in the Payments Industry





Posted by John B. Frank Monday, March 1, 2010 0 comments





Smart Card Talk : February 2010 : Volume 15 : Number 2






Smart Card Talk Logo



Executive Director’s Letter » Member Profile » Feature of the Month »
From the Alliance Office » Event Calendar » Members in the News »

Executive Director’s Letter

Dear members and friends of the Alliance,

February 2010 has been an active month on many fronts for the U.S. smart card industry. It has been so busy, we couldn’t stop long enough to get you the February monthly newsletter until early March! What has been so important to keep everyone busy? The answer is summed up in three letters–EMV. Fresh off the heavily viewed webinar (over 317 viewers) that the Smart Card Alliance presented in January, Top Ten Reasons U.S. Should Consider EMV, it seems as if the discussion really started to heat up in February.



The month began with an announcement that some people feared might shake the confidence of the entire payments industry. Researcher Ross Anderson and his colleagues at Cambridge University declared that “chip & PIN was broken” as a result of the discovery of a surprise flaw in the way EMV chip cards communicate with chip & PIN terminals when offline PIN verification is requested. Anderson and his U.K. security experts were deemed heroes by the hacker community, but their claims that this flaw was a serious problem for EMV issuers were quickly rebuked by the U.K. Card Association, EMVCo and other industry experts. However, the report raised attention about the prospect of chip cards in the U.S. The fact that this attack did not involve the security of the chip itself and that this fraud is also detectable by the industry’s systems, did nothing to dampen the enthusiasm among U.S. industry stakeholders for either contact or contactless EMV chip for the U.S. market.





Member Profile

Thales e-Security Inc. – Interview with Jose Diaz, Director, Technical and Strategic Business Development

This month Smart Card Talk spoke with Jose Diaz, Director, Technical and Strategic Business Development, Thales e-Security Inc. Jose has worked with the Thales (formerly Racal) group for over 30 years. Currently, he works on enterprise and government global strategy focusing on payment systems. He has over 10 years experience in payment systems security including five years in a technical sales capacity for the Latin America and Caribbean region. His background includes over 17 years working in product development and communication system design with four patents for his work in digital communications. Jose holds a master’s degree in electrical engineering from the University of Miami.







Feature of the Month

Prepaid Cards and the Transit Industry

For the past several years, transit agencies have been moving away from cash-based fare collection systems to contactless smart card-based systems. In most cases, the cards issued have been closed loop payment cards; that is, cards that can only be used to pay transit fares. Recently, in an effort to both reduce the costs associated with administering these systems and make the systems more convenient for customers, transit agencies are considering accepting contactless bank cards at points of entry, eliminating the need for customers to buy a transit-specific card.

As banks continue the process of converting credit and debit cards to include contactless features, a large number of transit riders will be able to use these new cards on transit systems. However, transit agencies have a long-standing mandate to serve all constituencies in their service areas. Any movement to adopt financial industry products, such as bank cards, would therefore require that all riders be able to obtain such a card conveniently. Because some segments of a transit agency’s ridership may not qualify for a credit or debit card or may be uninterested in establishing a relationship with a bank, transit agencies should consider promoting the use of prepaid cards that can operate like a bank card but be available to anyone.





New CSCIP Accreditations





Congratulations to the first group of LEAP members who have successfully completed the requirements for professional accreditation as Certified Smart Card Industry Professionals.


  • Deborah Baxley, Keypoint

  • Edgar Betts, Smart Card Alliance

  • Dana Blegen, Paragon Application Systems

  • John Fessler, Exponent, Inc.

  • Dale Grogan, LifeMed Card, Inc.

  • Bryan Ichikawa, Unisys

  • Brad McGoran, Exponent, Inc.

  • John McKeon, IBM

  • Barry Mosteller, Oberthur Technologies

  • Ken Pantin, The Bank of New York Mellon

  • Neville Pattinson, Gemalto

  • Myles Roberts, FAA

  • Michael H. Smith, Montner & Associates, Inc.

Click here for more information about LEAP and CSCIP certification program.




Thanks for Visiting - Bookmark us or Add to your Favorites and Find Out What's Going on Tomorrow in the Payments Industry

Posted by John B. Frank 0 comments

 Global Commercial Payments Summit February 26-27, 2009











Commercial Payments International News - March 1, 2010
Summit210banner



Invapay



New Agenda Posted for CPI’s Upcoming Global Commercial Cards and Payments Summit

Commercial Prepaid Opportunities Highlighted at Prepaid Expo USA

Steve Abrams Retires from MasterCard Worldwide

MasterCard Partners Recognized for Prepaid Programs

Bank of America Merrill Lynch to Bring Electronic Bank Account Management to Corporates

Bottomline Technologies Acquires Bank of Americas Commission Payments Service

First Data’s Money Network Extends Electronic Payroll Distribution Service

Sterling Commerce Extends B2B Integration to Mobile Devices




CPI Founding Sponsors
MasterCard
Spendvision
J.P. Morgan



Industry Partners

Visa

Invapay


Thanks for Visiting - Bookmark us or Add to your Favorites and Find Out What's Going on Tomorrow in the Payments Industry

Posted by John B. Frank 0 comments

MobileBanking.com Website Enables More Consumers to Benefit from On-the-go Financial Services —

ATLANTA, March 1 /PRNewswire-FirstCall/ -- Firethorn Holdings, LLC, a Qualcomm company (Nasdaq: QCOM), has expanded its mobile banking solution to allow consumers to now manage their checking, savings and credit card accounts with more than 3,700 U.S. financial institutions using a single mobile application.  Consumers can now go to www.mobilebanking.com to download the updated Mobile Banking application directly to their mobile devices and enroll their accounts with these newly added financial institutions.  The application is available on a variety of smartphones and feature handsets offered by wireless operators working with Firethorn.



"Until recently, users of Firethorn's Mobile Banking solution could only access their accounts if their financial institution was an integrated Firethorn provider," said Ben Ackerman, vice president of product strategy at Firethorn.  "Our goal is to deliver a comprehensive, relevant and secure mobile banking experience to all consumers, which is why we are delivering this new solution."  



One of the Mobile Banking application's newest features gives users the ability to securely access their enrolled financial accounts from more than 3,700 financial institutions using a single login PIN number on their mobile device, in addition to the secure access they previously had to financial institutions working with Firethorn.  Once logged in, consumers can check their financial account balances, see their latest transactions, and track if payments have cleared.  Financial institutions providing integrated Firethorn services may offer additional transactional capabilities, such as bill pay and funds transfer, as well as the ability to receive and view rewards and offers.  A full list of providers is available at www.mobilebanking.com/providers.



"Firethorn conducted extensive research to better understand consumers' lifestyles, needs and behaviors," continued Ackerman. "In response, we have expanded our Mobile Banking offering so that consumers can access critical account information at more banking institutions, enabling them to make well informed financial and purchase decisions while on the go."



To learn more about the new Mobile Banking experience, please visit www.mobilebanking.com.



About Firethorn

Firethorn Holdings, LLC, is providing an important link in the mobile commerce ecosystem. With its expertise in the mobile domain, Firethorn is creating an exciting mobile revenue channel that will bridge relationships among consumers, retailers, wireless operators and financial institutions.  Firethorn's innovative technology creates easily accessible, branded and personalized mobile commerce channels that give consumers access to their accounts, offers and transactions while on the go.  For more information about Firethorn, visit www.firethornmobile.com.

Firethorn is a registered trademark of Firethorn Holdings, LLC.  Qualcomm is a registered trademark of Qualcomm Incorporated.





Thanks for Visiting - Bookmark us or Add to your Favorites and Find Out What's Going on Tomorrow in the Payments Industry

Posted by John B. Frank 0 comments

Smart Card Alliance 2010 Payments Summit Highlights


PRINCETON JUNCTION, N.J., MARCH 1, 2010 – Contactless payment is now the de facto standard for U.S. transit fare collection systems, and will likely become a principal market driver for the expansion of bank-issued contactless cards. But that is just one of many factors building interest in the United States around chip cards for payments, according to experts presenting at the Smart Card 3rd Annual Payments Summit. The event was held February 23rd – 25th, 2010 in Salt Lake City, Utah.



Contactless in Transit



Contactless fare systems installed by U.S. transit operators will help pave the way for broader contactless acceptance here and elsewhere in the world.

  • Charlie Craven, vice president, American Express: "Transit can be a great help to drive acceptance of contactless around the world. Daily use of the cards in transit will help consumers understand the benefits of contactless." He also cited an American Express study that showed there are 118 contactless or mobile pilots worldwide.

  • Des Docherty, vice president, Visa, pointed out that in New York City all 13,000 taxicabs accept contactless and over the next few years all of the MTA buses and transit systems will too, concluding: "If I'm a merchant within that footprint, doesn't it make sense for me now to start implementing?"

  • Oliver Manahan, vice president, MasterCard: "We have 12 U.S. airports deploying contactless PayPass acceptance." MasterCard has issued 70 million PayPass cards worldwide, most of them in the U.S.

Representatives from transit agencies in Toronto, Philadelphia, Los Angeles, Utah, San Francisco Bay Area, and New York City reported on their current contactless fare collection systems and plans. Steve Frazzini, chief officer of AFC program management, New York City Transit, reported that an expanded open payments pilot that will include New York City Transit, PATH and New Jersey transit is targeted to start mid-year and will include a service area that includes 1.4 million riders.



Mobile Payments
Mobile payments are very exciting to everyone, including retailers, and is regarded as another important driver that will continue expanding the contactless market. Retailers are motivated by the other mobile applications that complement mobile payment such as coupons, loyalty programs and location-based services that drive people into their locations.
  • Mohammad Khan, ViVOTech: “The Holy Grail will be when tens of millions of NFC mobile phones show up in the U.S. The whole industry will move then. That won't happen over the next 12 months, but it will absolutely happen over the next 36 months."

  • Jennifer Garcia, Discover Financial Services, reported on the successful test of Discover Zip contactless stickers and said there's no reason to wait for NFC phones: “Our pilot confirmed stickers are a simple and easy bridge solution to the NFC logjam.”

  • Dave Wentker, head of proximity payments, Visa: “The future of NFC is bright.”

International Traveler EMV Card



Several industry experts predicted that the next U.S. chip-based bank card would be an EMV card for international travelers who increasingly find situations where they cannot use their magnetic stripe card when abroad, particularly in Europe. 



Merchant Acceptance



Merchant acceptance of contactless cards today, and their receptiveness to eventually using chip cards for security reasons, were actively discussed topics in several sessions.



Dodd Roberts, president of the Merchant Advisory Group (MAG), an organization of large U.S. retailers, made a strongly reasoned call to action for all of the stakeholders to sit together and finalize a strategy. Focusing on security, Roberts argued that retailers are willing to invest, but what is holding them back is confidence in a technology roadmap that has an end point agreed upon by all the stakeholders.  Putting up a slide that showed a winding U.S. payment technology path that included end-to-end encryption, tokenization, contactless and EMV technology, Roberts said, "You have merchants out here on this road and everyone is in different places and trying to figure out what they invest in, why and when.”  When asked what it would take to get retailers on board, Roberts answered, "If I'm that retailer, I know at some point in the future I have to invest to be EMV capable. I see that as a foregone conclusion. To move that up in my timeline, I'd need to know everyone is on board—here's the timeline, here's the roadmap, here's where you are going and here's the date."



Roberts drew parallels to the Program Management Office established by all of the stakeholders in Canada as they planned their migration to EMV. He said it's a good idea to establish something like that in the U.S., and invited all of the other stakeholders to come together and agree on one plan.



One reason for the step approach was presented succinctly by Robert Carr, CEO of Heartland Payments Systems. Though fully supportive of EMV as the ultimate end point, he argued that the industry can’t get there fast enough, pointing out that Canada’s ‘fast’ EMV implementation took eight years.   Carr has worked toward the goal of making Heartland the most secure payment processor in the world, and has moved toward end-to-end encryption because it is a solution that his company could get to market quickly and unilaterally, though they have tried to make it a standard.  Carr also worked to foster information sharing on attack vectors used by criminals through a new organization he helped to create, the Payments Processing Information Sharing Council. In the past, this information was not shared in the industry, and created a situation where criminals could repeat the same attacks on different organizations. In Carr’s view, being secure should be a competitive advantage, but knowing how criminals are attacking the industry should not be.



The Payments Summit brings together members of the Smart Card Alliance’s Contactless and Mobile Payments Council and Transportation Council. These councils include representatives from transportation authorities, issuing banks and payment brands, retailers, mobile technology suppliers, chip and card manufacturers, terminal manufacturers, payments processors, and transit and payment systems integrators.



About the Smart Card Alliance



The Smart Card Alliance is a not-for-profit, multi-industry association working to stimulate the understanding, adoption, use and widespread application of smart card technology.  Through specific projects such as education programs, market research, advocacy, industry relations and open forums, the Alliance keeps its members connected to industry leaders and innovative thought. The Alliance is the single industry voice for smart cards, leading industry discussion on the impact and value of smart cards in the U.S. and Latin America. The Smart Card Alliance also offers the Leadership, Education and Advancement Program (LEAP) and Certified Smart Card Industry Professional (CSCIP) program for individuals who are involved in the smart card industry. For more information please visit http://www.smartcardalliance.org.



###







Thanks for Visiting - Bookmark us or Add to your Favorites and Find Out What's Going on Tomorrow in the Payments Industry





Posted by John B. Frank 0 comments

  • Offer available to all online banking customers between March 1-April 30, 2010

  • Offer includes both local and international bank transfers

  • Bank committed to increasing ease of access to customers

As further evidence of its commitment to providing its customers relevant and convenient services, Emirates NBD, the largest banking group in the Middle East in terms of assets, announced today that it will be offering its online banking customers free telegraphic transfers.



The promotion will run from March 1–April 30, 2010, and is valid for all local and international bank transfers that are conducted via BankNet, Emirates NBD’s comprehensive online banking system.



“At Emirates NBD, our customers are our priority, and we remain committed to making banking a convenient experience for them. As pioneers of online banking in the UAE, we are delighted to introduce our new promotion that will enable our customers to make local and international transfers with no extra fee,” said Suvo Sarkar, Executive Vice President and General Manager, Retail Banking, Emirates NBD. “Emirates NBD’s BankNet is a complimentary, user-friendly service that is extremely efficient, offering our customers the option to conduct their banking needs from the comfort of their home.”



With no queues, no fees and 24-hour availability, BankNet is the ideal solution for customers wishing to conduct secure, fast and easy transactions without stepping into a branch, allowing them to view their account details, transfer funds, open accounts and order chequebooks and ATM/debit cards online.



“With 16 payment partners, including Etisalat, Du, SALIK, DEWA, RTA, Emaar Properties, Air Arabia and many others, banking with Emirates NBD is always convenient and hassle-free,” Sarkar said.



Other banking solutions offered by Emirates NBD include its new mobile banking facility, the latest addition to Emirates NBD’s numerous existing information technology channels, which also include online, telephone and PDA banking.



Thanks for Visiting - Bookmark us or Add to your Favorites and Find Out What's Going on Tomorrow in the Payments Industry

Posted by John B. Frank 0 comments

http://www.rsaconference.comDiverse Keynote Lineup Includes Technologists Steve Wozniak and Craig Newmark, U.S. Secretary of Homeland Security Janet Napolitano and White House Cybersecurity Coordinator Howard Schmidt
RSA Conference 2010

SAN FRANCISCO--(EON: Enhanced Online News)--Information security professionals and business leaders from around the world convened today to open the 19th annual RSA® Conference being held at San Francisco’s Moscone Center. Taking place March 1-5, RSA Conference 2010 provides information security professionals with the best educational opportunities and access to the most important issues through interactions with peers, industry luminaries and emerging and established companies.

“Most Innovative Company at RSA Conference 2010”
Continuing its tradition of informative and compelling speakers, this year’s Conference includes a notable lineup of featured speakers, including:

  • Janet Napolitano, Secretary of the U.S. Department of Homeland Security

  • Howard Schmidt, White House Cybersecurity Coordinator

  • Robert S. Mueller, III, Director of the Federal Bureau of Investigation

  • John P. Donoghue, Ph.D., Director of the Brown Institute for Brain Science, Brown University

  • Dr. Peter Warren Singer, Senior Fellow and Director of the 21st Century Defense Initiative, Brookings Institution

  • Herbert (Hugh) Thompson, Ph.D., Program Committee Chair and Advisory Board Member, RSA Conference and Chief Security Strategist, People Security

  • Craig Newmark, Founder, Craigslist

  • Bob Sullivan, Technology Writer, MSNBC.com

  • Steve Wozniak, Co-Founder, Apple Computer, Inc. and Chief Scientist, Fusion-io

  • Art Coviello, Executive Vice President of EMC Corp. and President of RSA, The Security Division of EMC

  • Scott Charney, Corporate Vice President for Trustworthy Computing, Microsoft Corp.

  • Enrique Salem, President and CEO, Symantec Corp.

  • Philippe Courtot, Chairman and CEO, Qualys Inc.

  • David DeWalt, President and CEO, McAfee Inc.

  • Dave Hansen, Corporate Senior Vice President and General Manager, Security Business Unit, CA Inc.

  • Al Zollar, General Manager, IBM Tivoli Software

  • Phil Dunkelberger, President and CEO, PGP Corp.

  • James Bidzos, Executive Chairman, VeriSign Inc.

“For nearly 20 years, RSA Conference has been the best place for information security professionals from around the world to engage in thought-provoking discussions on issues that affect our industry and the world at large,” said Sandra Toms LaPedis, Area Vice President and General Manager of RSA Conference. “As cyber warfare, cloud security and protecting the enterprise in the face of consumerization and mobility emerge as new challenges for IT departments, our attendees rely on RSA Conference for practical insights and real-world answers to these issues.”

Some of the highlights at RSA Conference 2010 include:

  • Innovation Sandbox – Taking place on Monday, March 1, this half-day interactive program is devoted to highlighting technological breakthroughs and solutions that are designed to help security practitioners tackle emerging security issues facing the industry. Innovation Sandbox features the “Most Innovative Company at RSA Conference 2010” contest, “Idea Exchange Whisper Suites” showcasing new R&D breakthroughs from laboratories around the country, interactive white board sessions facilitated by renowned information security experts, an “Ask the Experts" session and a "Successful Entrepreneur Panel."

  • The Cryptographer’s Panel – On Tuesday, March 2, at 10:30 a.m., pioneers in the cryptography field will come together for an engaging discussion about the latest advances in cryptography, research areas to watch in 2010 and practical insights that continue to be drawn from lessons learned over the last three decades.

  • Big Brother Panel – On Wednesday, March 3, at 2 p.m., this keynote panel will bring conflicting viewpoints to the stage in a contentious discussion about the role government plays in our daily lives. As increasingly sophisticated cybercrime cartels defeat the security of the enterprise, this panel will examine how governments can defend corporations and civilians against these threats without impinging on civil liberties and privacy rights.

  • Responsible Disclosure Panel – On Wednesday, March 3, at 10:40 a.m., researchers, vendors and customers will convene to discuss the role each constituency plays in the responsible disclosure debate. Questions addressed during this session include what responsibilities does each of these groups owe the other? Do researchers owe the consumer anything? Should software consumers help researchers identify vulnerabilities? And finally, what is the vendor's responsibility to both groups?

A complete RSA Conference 2010 agenda can be found at: http://www.rsaconference.com/2010/usa/agenda-and-sessions.htm.



About RSA Conference

RSA Conference helps drive the global information security agenda with annual events in the U.S., Europe and Japan. Throughout its 19-year history, RSA Conference consistently attracts the best in the field, creating opportunities to learn about information security’s most important issues through face-to-face and online interactions with peers, luminaries and emerging and established companies. More information on events, online programming and the most up-to-date news pertaining to the information security industry can be found at www.rsaconference.com.

RSA and the RSA Conference logo are either registered trademarks or trademarks of EMC Corporation in the United States and/or other countries. All other marks are trademarks of their respective companies.





Thanks for Visiting - Bookmark us or Add to your Favorites and Find Out What's Going on Tomorrow in the Payments Industry

Posted by John B. Frank 0 comments

Payments Industry News Blog

Search the PIN Debit Blog by Subject

Kapersky Calls for Mass Adoption of Card Readers

Kapersky Calls for Mass Adoption of Card Readers