Skip to main content

Home/ Open Intelligence / Web 3X (Social + Mobile)/ Group items tagged Security

Rss Feed Group items tagged

Marc-Alexandre Gagnon

Researchers Uncover 'Massive Security Flaws' In Amazon Cloud [28Oct11] - 0 views

  • Amazon's cloud services are vulnerable to attack via a "massive security gap" that enables hackers to access user accounts and data, a team of German researchers has revealed.
  • Security researchers from Ruhr-University Bochum (RUB) found that Amazon (NSDQ:AMZN) Web Services was vulnerable to different methods of attack, including signature wrapping and cross site scripting, Those security holes have since been closed.
  • But similar security holes may still be open in other cloud infrastructure offerings, the RUB team found.
  • ...7 more annotations...
  • "Using different kinds of XML signature wrapping attacks, we succeeded in completely taking over the administrative rights of cloud customers," said RUB researcher Juraj Somorovsky in a statement. "This allowed us to create new instances in the victim's cloud, add or delete images."
  • The researchers suggested that many cloud offerings are vulnerable to signature wrapping attacks, due to a deviation between performance and security when dealing with Web services.
  • Along with cross scripting attacks, the researchers uncovered gaps in the AWS interface and in the Amazon online story through which executable script code could be smuggled, or open to cross-site scripting attacks. Through the attack, the RUB security team was able to access customer data.
  • "We had free access to all customer data, including authentication data, tokens, and even plain text passwords," said RUB researcher Mario Heiderich. "It's a chain reaction. A security gap in the complex Amazon shop always also directly causes a gap in the Amazon cloud."
  • Along with Amazon's public cloud offerings, the RUB security crew also found single wrapping attack and cross site scripting vulnerabilities in private cloud services, including open-source cloud play Eucalyptus Systems. Eucalyptus also immediately closed the security gap when notified by RUB researchers.
  • "A major challenge for cloud providers is ensuring the absolute security of the data entrusted to them, which should only be accessible by the clients themselves," said Prof. Dr. Jorg Schwenk.
  • Somorovsky added: "Therefore it is essential that we recognize the security gaps in cloud computing and avoid them on a permanent basis.
Marc-Alexandre Gagnon

Isis selects Gemalto to manage mobile payments for NFC wallet - Tech News and Analysis - 0 views

  • Isis, the near field communication mobile wallet venture from Verizon, AT&T and T-Mobile, took another step forward with the announcement that it has selected SIM card maker and digital security specialist Gemalto as its trusted service manager (TSM) for the wallet. The deal means Gemalto will manage the secure element on Isis phones, overseeing the transfer of payment credentials from banks and payment services to the Isis wallet application on phones.
  • Gemalto will essentially hold the payment keys for Isis, controlling which service providers are able to tap Isis for contactless payments. It won’t participate in the actual transactions but will enable a host of applications, from payments to coupons and loyalty cards.
  • The deal is an important step for Isis, which is moving ahead toward a launch in the first half of 2012 in Salt Lake City and Austin before a larger nationwide roll out. The joint venture will compete with Google Wallet, which launched in September with partners Sprint, MasterCard and Citibank and First Data as its trusted service manager.
  • ...5 more annotations...
  • Gemalto is becoming a major player in the emerging market for TSMs. It has signed a deal to become the TSM for Deutsche Telekom and also Singapore’s nation-wide NFC system. It has also secured TSM deals with Barclaycard and Orange. Sebastian Cano, SVP Telecommucation for Gemalto, said the company has 45 NFC projects underway but the Isis deal would be the largest.
  • “The secure element will not be an open asset to allow people to write content to it or it will lose the first portion of it birth name,” said Hughes. “Any suggestion that a secure element is an SDK that sits on top of an open OS is a fanciful argument.”
  • I asked Ryan Hughes, the CMO of Isis, about the situation and he declined to comment on the Verizon situation. But he said that the secure element must be managed by a TSM and the owner of the device, which will be the carriers in the case of Isis. Creating a completely open situation where any company or developer can access the secure element would not be safe or practical, he said.
  • The deal is interesting because it follows word last week that Google Wallet has not been enabled to run on the Galaxy Nexus, Google’s flagship Android device which is expected to go on sale soon with Verizon. Verizon said it has not blocked the NFC application but is working on commercial talks with Google, which many have interpreted as Verizon holding back the wallet until its own Isis payment tool is available.
  • That suggests to me that we shouldn’t expect to see Google Wallet instantly enabled on Isis phones. It can still happen eventually and Verizon makes it sound like it’s just a matter of working things out with Google. But each Isis carrier will be able to decide what service provider gets access to their secure element, and it looks like it will not be a free-for-all. That makes sense on some level for security reasons but my hope is that ultimately, Isis members won’t find reasons to keep Google Wallet or other competing applications off their phones for too long. The NFC wallet market is just emerging and it will be good to have competition and options for consumers.
Marc-Alexandre Gagnon

Mobile payment apps work to make wallets obsolete - 0 views

  • Late last month, I ordered the beverage at Sightglass Coffee in SoMa, grabbed it from the counter and walked out without cracking my wallet.
  • Nobody chased me down because, when I first approached the cafe, the Card Case app on my iPhone detected the store's perimeter and automatically switched on. It broadcast my picture to the barista, who could then tap my pre-entered credit card number to cover the bill. The phone never had to leave my pocket.
  • It felt a lot like buying in the one-click environments of iTunes or Amazon, which is to say it didn't feel like buying at all. Square, the San Francisco startup behind the app, has come close to replicating the frictionless online buying experience in the brick-and-mortar world.
  • ...28 more annotations...
  • "What we wanted to focus on was removing the mechanics of the transaction and building the relationship between the merchant and customer," said Megan Quinn, director of products at Square, which occupies space at the Chronicle building at Fifth and Mission streets.
  • But, of course, Square isn't the only company working hard to crack the nut of mobile payments - and they all face considerable challenges.
  • Google, Visa, MasterCard, VeriFone, eBay's PayPal division and a joint venture among AT&T, Verizon and T-Mobile are attacking the problem in various ways. In most cases, those businesses are going a different direction than Square, employing near field communications (NFC) technology that allows people to tap their phone near a terminal to make a payment.
  • Done right, mobile payments can accelerate the monetary exchange, while streamlining the issuance, acceptance and storage of receipts, coupons and loyalty cards. Down the road - once consumer and retail use reaches critical mass - the hope is that people will be able to leave their wallets at home altogether.
  • But there's a chicken and egg paradox: Customers won't start using mobile payments in great numbers until they're accepted in great numbers, and retailers don't have a huge incentive to roll these systems out until customers are clamoring to pay this way.
  • There are only about 150,000 retailers nationwide that accept payments over MasterCard's NFC-based Paypass readers. Google's Wallet payment app works with this system, and industry rumors suggest the next iPhone might as well.
  • Square, which has so far focused on small merchants has about 20,000 that accept Card Case.
  • Another big challenge is human inertia. To get people to download apps, key in credit card numbers and transform a habit they're very comfortable with, mobile payments will have to represent more than a little improvement over what they do today.
  • "You have to offer them a compelling reason to do it," said David Mangini, an IBM executive focused on mobile payments. "At a very, very minimum ... it has to be just as convenient, just as broadly accepted and just as safe."
  • One of the big knocks on basic NFC payments is that tapping a phone near a reader doesn't represent a whopping improvement over swiping a card. In addition, merchants have little to gain by replacing one expensive payment infrastructure with another, some observers say.
  • "It doesn't upset the status quo," said Nick Holland, senior analyst at Yankee Group. "It doesn't really change the original business model and it all goes through the same rails."
  • Receipts, deals Google argues that its NFC-based Wallet app is a big step forward for a few reasons. A single tap replaces not just the payment, but also the exchange of receipts, coupons and loyalty points.
  • On top of that, Google believes it's tying together the on- and off-line retail worlds, by allowing consumers to move the deals they spot on the Web into the Wallet app, where they can redeem them in the real world. Google Wallet also advertises nearby deals when users open up the app.
  • "For the consumer, it's really about tap, pay and save," said Osama Bedier, vice president of payments at Google. "On the merchant side, it's about closing the loop on that advertising."
  • This is a critical goal for Google, too, as it experiences slowing growth in online advertising - 93 percent of commerce still occurs offline, according to Forrester Research
  • For its part, Square steers around the limitations of NFC - as well as the various roadblocks of wireless carriers and credit processing networks - by leveraging the powers of the Internet to process payments. The credit card information is stored online, in Square's secure cloud, not on the device itself.
  • Square, which started by providing small attachments that allow merchants to swipe credit cards using mobile devices, acts as the merchant of record for its customers. This allows the businesses to quickly start accepting credit cards without going through the usual drawn out and expensive process of applying for a merchant account. But it also clearly puts more risk onto Square's shoulders.
  • Square turned on the hands-free feature on its Card Case app, which takes advantage of the so-called geofencing capabilities in the latest version of Apple's mobile software, in an upgrade to the app in November. The feature is only available on Apple devices to date
  • Quinn said "automatic tabs" represents an obvious improvement over traditional payments and it's quickly driving user growth (though the company doesn't disclose user numbers).
  • In addition, retailers have seen revenue leap as much as 20 percent since integrating the app. It drives traffic by highlighting nearby establishments, and the ease of payment encourages customer loyalty, the company says. Tips also tend to go up.
  • Is it safe? But the question that has dogged Square - and indeed hangs over much of the mobile payment space - is security.
  • Early last year, VeriFone CEO Douglas Bergeron blasted Square - its attention-grabbing young competitor - for what he called serious security flaws. In an online video, he argued that any bad actor could use the Square dongle and an easy-to-create app to skim credit card numbers.
  • Square CEO Jack Dorsey, also the co-founder of Twitter, defended the company's security practices in a letter. He also highlighted the inherent insecurity of credit cards, noting that any sketchy waiter is equally free to steal your information.
  • Meanwhile, Quinn argued that Card Case is actually more secure than credit cards because it only works if you're in the location and your face matches the picture that pops up on the merchant's screen.
  • The radio technology behind NFC has taken some security lumps, too.
  • Late last month, a security researcher at a Washington, D.C., conference used a wireless reader she bought on eBay to highlight some weaknesses of radio frequency identification, Forbes reported. She pulled the critical data from an RFID-enabled credit card through a volunteer's clothing, encoded that data onto a blank card and put it to use onstage.
  • Holland said that any new form of payment inevitably creates new forms of fraud. The challenge will be to educate consumers and merchants about how to minimize the risks.
  • "Clearly, having a device always with you and connected is a very inviting target for criminals," he said. "Any safe is only as strong as the key."
Marc-Alexandre Gagnon

OPENWAYS ANNOUNCING: Mobile Key DUAL© with Pure NFC™ in Cooperation with Nord... - 0 views

  • The best of mobile technologies are now combined to offer hoteliers the most advanced front desk bypass solution that is 100% deployable today, 100% future proof, 100% compatible with the major electronic locks and 0% dependent on Mobile Phone Operators/Carriers
  • Modern travelers are expecting self-service options to make their journey easier. Who did not dream to one day be able to arrive at the hotel and go straight to the room without having to go through the burden of the check-in process? Thanks to Mobile Key by OpenWays, guests can already choose to proceed straight to their room upon arrival and securely open their door with their cell phone. They are no longer forced to wait in line at the front desk – unless they want to.
  • 100% Deployable Today / 100% Future Proof / Truly Ubiquitous "Mobile Key works TODAY with ALL cell phones worldwide. With NFC (Near Field Communication) enabled cell phones gradually hitting the market in larger volumes during 2012 and 2013, we are pleased to announce Mobile Key DUAL© with Pure NFC™," said Pascal Metivier, Founder and CEO of OpenWays. "Mobile Key DUAL© combines the established and highly ubiquitous CAC™ (Crypto Acoustic Credential) technology with both RFID and NFC technologies so we can offer the only 'fully deployable today' while 'fully future proof' solution to our customers. Thanks to Mobile Key DUAL©, hoteliers can offer today a mobile-based front desk bypass solution to all their guests while being sure that the investment they are making is made for the long run."
  • ...10 more annotations...
  • In 2010, Nordic Choice Hotels was first to try mobile NFC key technology in hotels: It was an important learning experience that helped identifying needed improvements and changes
  • “When Nordic Choice Hotels conducted an NFC key pilot in 2010 at our Clarion Hotel Stockholm property we learned that mobile keys are the future for hospitality. We also learned of some limitations to the technology and it was decided not to expand the trial,” said Svein Krakk, Nordic Choice Hotels CIO. “Indeed the pilot we ran was very educative and helped us identify several areas that needed to be improved in order to make NFC viable within a hospitality environment.
  • “The No. 1 priority for Nordic Choice Hotels is to provide freedom of choice for our guests," Krakk said. "Freedom to choose the phone you prefer, to use any mobile operator, to use mobile keys or ordinary keys independently or in combination. We started looking for alternative technologies addressing some of the shortcomings of the pilot. First the user interface needed to be improved. With the latest generation of NFC phones it is not very easy for the end user to figure out how to position the phone vis à vis the lock reader. We also wanted a solution that bypassed the SWP protocol which is designed to make the solution mobile operator and mobile carrier dependant. The pilot was limited to one mobile operator. More than 1,500 mobile operators / carriers exist around the world and our guests could come from anywhere, so offering a solution that works only with one or a few carriers would be pointless.”
  • Hotelier’s independency and cost control are key "Equally important, the SWP standard drives the cost and complexity if implementation towards areas that hoteliers do not like," he said. "It implies a long list of fees to pay to the mobile phone carriers and it places our brands and hotels in a state of dependency that is not acceptable. In addition, we felt that using a solution that would make us dependant on one lock vendor only was not a good idea."
  • A good mobile front desk bypass solution must be guest centric, supported by a strong business case and must be deployable for real "In 2010, we also tested the Mobile Key solution by OpenWays with CAC™ technology," Krakk said. "We appreciated that it was compatible with all cell phones worldwide, that it was easy to use and that it was mobile carrier independent. Equally important, the pilots conducted were great successes both from a technology and a guest satisfaction stand point. As a result, we decided to deploy Mobile Key by OpenWays in several hotels and we are continuing as we speak. "We also decided to challenge OpenWays to think about the next steps and to include NFC as part of their strategy," he added. "Obviously, we wanted an NFC solution that would be free of the identified shortfalls but also would allow us to eventually offer more services to our guests in the years to come. We do realize that it will take years before NFC phones reach any form of critical mass, nevertheless we want to be sure to deploy and invest in the most future-proof platform while our dependency on both mobile carriers and lock vendors would be minimal. As a result, OpenWays proposed to us Mobile Key DUAL© with Pure NFC™. We were immediately seduced with the open architecture of the OpenWays solution. We were thrilled with the idea to offer a DUAL platform allowing us to leverage all mobiles today with the CAC™ technology while building an infrastructure for when NFC will be reaching critical mass. We are now looking forward to go live with several hotels this year."
  • Mobile Key DUAL© with Pure NFC™ is very unique: The solution is protected by 26 patent filings and patents; It allows OpenWays' customers to deploy globally without having to ever worry about knowing if their guests have the right phone or the right carrier; And, it works with all phones and all carriers. "Pure NFC™ allows adding NFC features while still being fully carrier and lock provider independent," Metivier said. "It is highly secured and operates on trusted networks. It leverages modern cryptology combined with highly secured OTP (One Time Password) principles. Implementation costs are significantly lower than with the sole SWP protocol and significant engineering efforts were invested in making the user interface intuitive. This was achieved with the design of very specific RFID antennas designed to provide high reading performances with the next generation of NFC handsets. Other areas of focus were ergonomics and human factors. With NFC, what appears to be a good idea -- because you simply have to wave your phone to a lock to open it -- can sometime be a very bad idea when you truly analyse user behaviours and expectations."
  • A solution compatible for both new build and existing hotel locks Like Mobile Key by OpenWays, Mobile Key DUAL© with Pure NFC™ can be applied to existing hotel locks and/or major renovations. New locks that are factory made with the OpenWays module built in can be provided by the major electronic lock vendors.
  • A solution that works with ALL cell phones and ALL Smartphones With Mobile Key by OpenWays, all smartphones can receive an app and leverage any data network (2G, 3G, 4G and even the hotel WiFi network) to use Mobile Key. The same is true for hotel staff who use our “Mobile key for Master Keys” that offers much more security (real time master key management) and flexibility than traditional plastic cards.
  • A “green” solution that contributes to reduced waste Mobile Key is green. The more guests use their mobile phones as room keys, the less plastic key cards will end up spoiling the environment. Today everyone is concerned about the planet, and hoteliers want to allow their guests to contribute to waste reduction programs. Because Mobile Key by OpenWays is only made with data, it is the cleanest room key a hotelier can offer. "With Mobile Key DUAL© with Pure NFC™, we are making a giant step forward and confirming our global leadership in key management via Mobile phone," Metivier said. "Mobile Key DUAL© with Pure NFC™ is a solution that is going to be 'new for long time' and will be also applied to many other market segments outside the hospitality industry, such as residential, commercial buildings, university campuses, and more. "We would like to thank our partners Nordic Choice Hotels, Nokia, NXP, KABA SAFLOK and Ariane systems that are making these first 2012 deployments possible," he said.
  • About OpenWays | OpenWays is a global solution provider of mobile-based access-management and security solutions. With offices in Chicago, Las Vegas, Seoul and in Europe, OpenWays provides technology solutions allowing for the secure issuance and delivery of access rights and keys process via any cell phone operating on any network. The OpenWays solution is truly unique as it is built on the concept of credential dematerialization. The OpenWays mobile room key solution works on ALL the 6 billion cell phones in service in the world today. For more information, please contact Barb Worcester at +1 440 930-5770 or email barbw@prproconsulting.com. More information can be found by visiting www.OpenWays.com.
Dan R.D.

How Facial Recognition Technology Can Be Used To Get Your Social Security Number [01Aug11] - 0 views

  • Those freaked out by facial recognition technology have fresh fodder: a study from Carnegie Mellon University in which researchers were able to predict people’s social security numbers after taking a photo of them with a cheap webcam.
  • For those participants who had date of birth and city publicly available on their account, the researchers could predict a social security number (based on the work from their 2009 study). The researchers sent a follow-up survey to their student participants asking them whether the first five digits of the social security number their algorithm predicted was correct. One problem with this part of the study was that “60% of the CMU students were foreign and don’t have social security numbers,” said Acquisti. Though researchers were still able to tell them all about their interests and favorite movies based on what they got from their Facebook profile pages.
Dan R.D.

Google's Catch 22 - Security vs. Transparency [29Apr10] - 0 views

  • So I think that one of the biggest problems that Google has, taking Google as probably the best example of someone trying to build a reputation currency, is that as soon as Google gives you any insight into how they are building their reputation system it ceases to be very good as a reputation system. As soon as Google stops measuring something you created by accident and starts measuring something you created on purpose, it stops being something that they want to measure. And this is joined by the twin problem that what Google fundamentally has is a security problem; they have hackers who are trying to undermine the integrity of the system. And the natural response to a problem that arises when attackers know how your system works is to try to keep the details of your system secret—but keeping the details of Google’s system secret is also not very good because it means that we don’t have any reason to trust it. All we know when we search Google is that we get a result that seems like a good result; but we don’t know that there isn’t a much better result that Google has either deliberately or accidentally excluded from its listings for reasons that are attributable to either malice or incompetence. So they’re really trapped between a rock and a hard place: if they publish how their system works, people will game their system; if they don’t publish how their system works it becomes less useful and trustworthy and good. It suffers from the problem of alchemy; if alchemists don’t tell people what they learned, then every alchemist needs to discover for themselves that drinking mercury is a bad idea, and alchemy stagnates. When you start to publishing, you get science—but Google can’t publish or they’ll also get more attacks.Read more at craphound.com
  •  
    If Google publishes their secrets then security is compromised. If Google doesn't publish then users trust in them diminishes. If we will never know how Google measures value, then we will never know if there can be a better way?
Dan R.D.

SecureIDNews | Easier, better identitiy on the horizon - 0 views

  • The first of these changes is BYOD (Bring Your Own Device) computing. BYOD is a much better term than “consumerization” and really portrays the meaning that many of us are buying smart phones, tablets or laptops to use them on a work network. The tension this creates is predictable.
  • In 2012 and beyond, we’re going to see more and more different devices coming into the workplace.
  • If you use PayPass, Tap & Go, or other contactless credit cards, that’s NFC. In fact, NFC hardware already is appearing in smart phones and tablets. There are relatively few devices with NFC today, but there will be more in 2012.
  • ...5 more annotations...
  • The next of these changes is increased security on mobile devices.
  • Just a few weeks ago, Forrester Research said, “It’s time to repeal Prohibition” about Macs in the workplace, but the real changes are going to come from the smartphones and tablets.
  • Together, three trends lead to an Internet of Things, where smart phones use NFC to make statements about the physical world. For example, there has already been an art exhibition that lets visitors vote for their favorite display by tapping with their smartphone. But more importantly, there’s an Internet of Secure Things coming. You will be able to use your smartphone to badge in to work, unlock your PC, start your car or motorcycle (the prototype of that is already working), as well as merely pay for things.
  • Together, three trends lead to an Internet of Things, where smart phones use NFC to make statements about the physical world. For example, there has already been an art exhibition that lets visitors vote for their favorite display by tapping with their smartphone. But more importantly, there’s an Internet of Secure Things coming. You will be able to use your smartphone to badge in to work, unlock your PC, start your car or motorcycle (the prototype of that is already working), as well as merely pay for things. It isn’t going to all happen in 2012, but we are likely to look back at 2012 as the year when it took off.
  • It isn’t going to all happen in 2012, but we are likely to look back at 2012 as the year when it took off.
Marc-Alexandre Gagnon

Verizon begins testing new mobile payment solution - 0 views

  • Vantiv, a provider of mobile payment solutions, announced a new point-of-sale product on Friday that it will be rolling out in partnership with Verizon Wireless. The product, which is currently in field testing, includes custom tailored applications and an Android-based point-of-sale solution for accepting payments. The applications will be available in Verizon’s Private Application Store for Business. “Merchants and consumers are seeking greater mobility, control and timely access to data,” said Bill Weingart, Chief Product Officer of Vantiv. “We’ve teamed with Verizon to combine our payment and security expertise with Verizon’s ability to tailor development of mobile technologies to address those needs.” Verizon Wireless is also a member of ISIS, an initiative in which it has partnered with AT&T and T-Mobile to provide customers with NFC-based mobile payment options. Vantiv’s full press release follows after the break.
  • Vantiv Introduces Next Generation Mobile Payment Solution Teams with Verizon to Develop and Deliver More Flexibility and Opportunity for Merchants to Grow Their Businesses CINCINNATI, Jan. 31, 2012  — Vantiv, LLC (formerly Fifth Third Processing Solutions, LLC), a leading integrated payment processor, today announced that its customers will be the first to use an innovative point-of-sale device and system that will help merchants more effectively conduct business.
  • Vantiv is conducting a field trial of a new mobile payment solution developed in collaboration with Verizon. The new solution is architected on the Android operating system and features end-to-end, secure point-of-sale payment capabilities and business applications using Verizon’s Private Application Store for Business. As a result, Vantiv customers can tailor point-of-sale applications to meet their needs while taking advantage of remote device management.
  • ...8 more annotations...
  • Whether service professionals are meeting with customers at home or sales associates are interacting with visitors at a retail location, the new Vantiv solution is part of Vantiv’s overall strategy to address customers’ growing mobile payment needs.
  • “Merchants and consumers are seeking greater mobility, control and timely access to data,” said Bill Weingart, Chief Product Officer, Vantiv. “We’ve teamed with Verizon to combine our payment and security expertise with Verizon’s ability to tailor development of mobile technologies to address those needs.”
  • The Vantiv mobile payment solution serves merchants who require mobility, convenience and security and addresses many business needs through a value-added suite of applications including accounting, payroll, workforce management, loyalty, inventory and customer relationship management (CRM). Having complete business control in a packaged, intuitive and flexible platform is a significant differentiator in the realm of tablets, and allows merchants to conduct data enriched customer interactions and transactions, anytime and anywhere.
  • JKrete Supply in Mason, Ohio is among the first Vantiv customers to participate in the field trial.
  • “This technology gives me more flexibility and makes it easier to serve my customers,” said Jay Rhoden, Owner, JKrete Supply. “Having the option of being mobile takes my business to a whole different level. I have everything I need at my fingertips. I can sell my products anywhere I go at any time. Vantiv tailored this product to meet my needs; it is clear they listened to customer demand.”
  • “Verizon, through our Private Application Store for Business, is leading the charge to work with innovative companies to develop industry-specific mobile solutions,” said Chandan Sharma, Vice President and Global Managing Director of Verizon’s financial services practice. “The ability to customize enterprise tablets and applications has been characterized as a potential ‘game changer,’ and we look forward to working with Vantiv and its customers to advance the playing field for mobile commerce.”
  • The capabilities were featured in a Tab Times article “The 10 most important tablet trends, products, and stories at CES 2012.”
  • For more information on Vantiv and to view more information on the Vantiv mobile payment solution visit us at www.vantiv.com .
Marc-Alexandre Gagnon

Trade Your Wallet for Wireless - 0 views

  • People fed up with the proliferation of credit cards, IDs and key cards that fill their wallets to bulging may soon have an alternative. New technology could bundle such functions into just one item: your cell phone.
  • Near Field Communication technology, jointly developed by Sony and Royal Philips Electronics, lets wireless devices connect to other devices nearby and transfer data, from payment information to digital pictures. Samsung Electronics and Philips say they are developing cell phones with embedded NFC chips that could double as debit cards or electronic IDs. The companies plan to begin field trials toward the end of the year.
  • Such phones are already available in Japan and Korea, where users can charge their phones with virtual cash, then wave them near NFC-enabled machines to buy anything from a soda to lunch. But it remains to be seen how Americans will react to the devices, which are not yet available outside Asia, said wireless technology analyst Allen Nogee of In-Stat/MDR.
  • ...8 more annotations...
  • "Americans seem to be more skeptical of new technology like this," Nogee said, largely because of security and privacy concerns.
  • However, Nogee said the systems seem to have adequate security measures -- like requiring personal identification numbers, so thieves could not make purchases -- and could provide consumers with added protections in some cases.
  • "In theory, merchants will have wireless devices they can bring to you," he said. "When you buy something in a restaurant, you have to give them your card. They go off with your card and could be writing down your number. With this, they'd bring a portable device to your table and (the transaction) would be encrypted."
  • But Nogee said some apprehension about privacy might be well-founded.
  • "A carrier, if they wanted to, could know exactly where you are any time of day, who you're calling, and now they can know what you're purchasing and where," Nogee said. "So if you tie all these things together, that's quite a lot of information available on you."
  • Payments are not the only potential use for the technology. Philips and Samsung have suggested NFC devices could also work as mobile transit passes for users who would swipe their phones to get access to public transportation, and as secure building-access keys and electronic business cards. The technology could also let users swap digital music, photos or other files between devices.
  • Don't go throwing away your wallet just yet, though. The companies have not set a date for when the phones will be for sale in the United States. And even if security and privacy worries are allayed, the technology will need to be widely usable for consumers to adopt it. That means NFC devices from different manufacturers must be interoperable and integrated to work with the credit card infrastructure.
  • To that end, Nokia, Philips and Sony formed the Near Field Communication Forum in March to promote implementation and standardization of NFC technology. Philips is also working with Visa to encourage support of the technology.
Marc-Alexandre Gagnon

Global Payments First to Bring VeriFone PAYware Mobile for iPhone to Canada - 0 views

  • SAN JOSE – September 15, 2010 – VeriFone Systems, Inc. (NYSE: PAY), today announced that Global Payments Inc.,(NYSE: GPN), leader in electronic payment processing services, will distribute and support VeriFone’s PAYware Mobile secure card payment system in Canada. Global Payments is the first payment processor to offer Canadian customers VeriFone’s unique card processing solution for the iPhone mobile digital device.
  • Global Payments will begin immediately to make the PAYware Mobile card encryption sleeve available to merchants. VeriFone’s sleek and durable card reader slips over iPhone 3G and 3GS to accommodate secure card swipes and allow individuals and businesses with new or existing merchant accounts to qualify for lower-cost “card present” transaction fees.
  • “VeriFone has created a market-leading mobile payment solution that will expand electronic card acceptance to a broad range of merchants and small businesses for which a payment-enabled, multipurpose smartphone is the best option for electronic payment transactions,” said Jeff J. McGuire, Vice President, Product Development and Marketing for Global Payments Canada. “We’re delighted to be first to introduce this first-class payment solution for iPhone into the Canadian market.”
  • ...4 more annotations...
  • “We look forward to working with Global Payments to introduce PAYware Mobile in Canada,” said VeriFone Executive Vice President Jeff Dumbrell. “Merchants and other small businesses are eager to use VeriFone’s solution to adapt their iPhones for card payment acceptance anywhere, anytime.”
  • The VeriFone system currently incorporates a secure mag-stripe card encryption reader for iPhone and a PA-DSS validated App; an EMV version of the card encryption reader is anticipated soon. An English language version of the PAYware Mobile app for Canada is available for immediate download, with a French version planned for later this year.
  • The PAYware Mobile card encryption sleeve incorporates VeriFone’s end-to-end encryption technology and ensures secure payment processing. It incorporates a stylus for signature capture and a mini-USB port for charging the iPhone while the ergonomic reader is attached.
  • Users also gain access to the PAYware Connect gateway, a fully customizable and reliable gateway service that's ideal for small businesses. Details of all iPhone payment transactions are available in real-time within the Merchant Portal on the payment gateway, which also enables businesses to consolidate payment reporting from multiple PAYware Mobile-equipped iPhones.
Dan R.D.

10/03/31 Malicious Tweet Links - Shortened URL Security Threat on Twitter Overblown? - ... - 0 views

  • URL-shortening sites are often criticized as an easy way to snare unsuspecting users into clicking malicious links - but a new report says it's not that common
  • wrote about their dangers in 3 Ways Twitter Security Falls Short), Zscaler's Julien Sobrier found otherwise.
  • The experiment only looked for malicious sites such as phishing sites, malware, etc., and did not include spam.
  • ...1 more annotation...
  • Results reveal on only 773 links led to malicious content; a mere .06 percent, according to Sobrier. Bit.ly represents 40 percent of all links, and roughly the same proportion of malicious links, according to Sobrier. Another shortening site, TinyUrl, represents only 5 percent of all URLs and 6 percent of all malicious sites. "It does not look like bit.ly's phishing and malware protection is making it any safer than other URL shorteners," Sobrier said in a blog posting on the research.
D'coda Dcoda

Orange customers can now pay for goods in UK stores with their mobiles [21May11] - 0 views

  •  
    today, Orange and Barclaycard officially launched 'Quick Tap', which is the UK's first contactless mobile phone payments service. The service is designed for small purchases of under £15, and contactless readers will be available at over 50,000 UK stores. You'll know that a store has the special reader when it displays the contactless payments symbol, and Pret A Manger, Eat and Subway are among the outlets to have signed up already. Quick Tap uses a secure SIM-based approach to mobile payments, and Orange customers will require a 'Quick Tap' enabled handset. The scheme launches with a Quick Tap enabled version of the Samsung Tocco Lite, and the device will be available on pay as you go and pay monthly price plans. More handsets are expected to follow from a selection of manufacturers. Barclaycard, Barclays debit or Orange Credit Card users can transfer funds of up to £100 simply and securely onto the handset's Quick Tap app, after which the phone is ready to make payments of £15 and under in a single transaction.
Dan R.D.

An "Open" Perspective on Near Field Communications [22Jun11] - 0 views

  • Currently NFC is seen as one of the most exciting areas in our industry in terms of revenue generation: projections show up to 700 million NFC-enabled mobile phones will be sold by 2013, according to Jupiter Research. At Nokia, however, we would argue that the industry's current focus on secure NFC may be at the expense of realizing the potential of open NFC. As pioneers in NFC technology, and as a founder of the NFC Forum, Nokia believes that open NFC will have a far greater impact on consumer behavior and the NFC ecosystem than secure NFC will. Open NFC has the potential to spur a vast number of business opportunities for developers, retailers, advertisers, electronics manufacturers and others.
  • NFC tags, which cost only a few cents, offer huge potential for advertisers, retailers and others to reach, reward and stay in touch with their customers. These tags can be promoted at any location, including a phone retail point, a coffee shop, or even at the local supermarket, with immediate and measurable results.
  • Open NFC will benefit consumers on a much larger scale and get people familiar with using their device for NFC interactions, before secure NFC reaches a high level of penetration. As more and more NFC phones come to the market in 2011 and 2012, open NFC will change the way consumers interact with each other and open up a host of opportunities for developers both large and small.
  • ...1 more annotation...
  • As more and more NFC phones come to the market in 2011 and 2012, open NFC will change the way consumers interact with each other and open up a host of opportunities for developers both large and small. We believe that developers will embrace the opportunity offered by open NFC in creating apps for sharing information, reading tags, joining social networks and more. And this open NFC opportunity will be realized long before secure NFC takes off.
Marc-Alexandre Gagnon

Sage Mobile Payments Handles Credit Cards, Signatures And Taxes - 0 views

  • “While other vendors are fighting over no monthly fees, but higher processing costs for mobile transactions, we’re still saying ‘no’ to mobile transaction surcharges,” said Hammermaster. “With Sage Mobile Payments, businesses have the option to pay no more than they would to process regular credit or debit card transactions on a standard credit card terminal.” 
  • Enhancements built into Sage Mobile Payment 2.0 include an updated user interface, signature capture capabilities, a tax and tip calculator, and a free Sage Mobile “app store” download.
  • “In 2011, 25 percent of worldwide mobile PC shipments were tablets, and upwards of 75 percent U.S. small and midsized businesses plan to purchase tablets in the next year,” said Greg Hammermaster, president of Sage Payment Solutions, the payments division for Sage. “Mobility has truly become a must-have in today’s business world. Businesses using Sage Mobile Payments have a great opportunity to expand their sales and customer service opportunities, and with the confidence of a commercial-grade mobile payments solution. Sage Mobile Payments will help businesses evolve into this next phase of mobile payments.”
  • ...3 more annotations...
  • New Sage Mobile Payments 2.0 features:One Merchant Account — Businesses can now use their existing Sage Merchant ID (MID) account to add mobile payments to their existing payment solution, and at the same low processing rate.Updated User Interface on Smart Phones — The new, completely intuitive, colorful user interface makes processing payments easier than ever.Signature Capture — Businesses can give customers peace of mind knowing a signature is required to complete their transaction. With the swipe of a finger, a signature is captured to complete a sale. A signed receipt is emailed to both the business and their customer.Tax And Tip Calculator — Businesses no longer need a separate calculator to determine tax due and tips; Sage Mobile automatically calculates both.‘App Store’ Download — By going to the Android Marketplace or Apple’s iTunes store, businesses can download the Sage Mobile application at no cost. Then, once they have called Sage to set up their merchant account, they can start accepting mobile payments.
  • Businesses using Sage Mobile Payments can benefit from increased chances to close sales; anytime, anywhere transactions; a secure and PCI compliant payment processing environment; real-time authorizations for expedited cash flow; and minimal cost.Sage has been providing businesses and organizations with electronic payment systems for more than 20 years. Visit Sage Payment Solutions online at www.sagepayments.com.
  • Sage North America today announced the launch of Sage Mobile Payments 2.0, the latest version of its Payment Card Industry (PCI) compliant mobile payments product. Sage Mobile Payments comes bundled with a Sage merchant account, and allows businesses to cost effectively and securely process credit and debit card transactions on mobile devices, like cell phones and tablets, including Apple’s iPad, across all major wireless carriers. Version 2.0 focuses on enhancing the customer experience through new features designed to save businesses time and increase the security of their transactions.
Marc-Alexandre Gagnon

How does Netswipe work? | Jumio - Netswipe - 0 views

  • How does Netswipe work? Camera + Credit Card = Secure payment Jumio’s patent pending technology turns the camera of a computer or mobile device into a card reader. The most secure form of online payment possible. Step 1 Scan your card with your webcam or phone camera. Actual card needed. (online card present transaction) Step 2 Enter security (CVV) code to complete transaction. You’re done. Netswipe – the online card present transaction, a new technology product from Jumio.
  • How Netswipe uses the webcam as a credit card reader Your webcam or phone camera is turned on during the payment process to scan your credit card and verify its authenticity. Hold the credit card in front of your camera as illustrated below. Jumio’s Netswipe scans and verifys your card details. No details are stored upon completion of the payment and the camera will be turned off automatically.
D'coda Dcoda

Android Security Practices? [20May11] - 0 views

  • "Smartphone security recommendations seem to boil down to Windows-like practices: install an antivirus, run updates, and don't execute apps from untrusted sources. On my own computers, running Linux, I choose to only install (signed) packages from the distribution's or well-known repositories, or programs I can check and compile myself, or run them as a dedicated user — and I don't bother with an antivirus. What rules should I adopt on my soon-to-be-bought Android device? Can I use it purely with open-source apps and still make the most of it? Are Android's fine-grained permissions (accessing the network, contacts...) reliable? Can apps be trusted not to scan your files and keyboard for passwords and emails? What precautions do security-conscious Slashdotters take to keep control of their phones?"
  •  
    Q&A see answers at site.
D'coda Dcoda

Verifying Passwords By the Way They're Typed [19May11] - 0 views

  • "There are good passwords and bad passwords, but none of them are totally secure. Researchers at the American University of Beirut, Lebanon, are working on strengthening an approach to password security that's not just about what you type, but how you type it (abstract)." Note that the actual paper appears to be behind some crappy paywall: hopefully the research exists elsewhere on-line.
D'coda Dcoda

A significant security hole has been discovered in Google's Android operating system [2... - 0 views

  • A significant security hole has been discovered in Google’s Android operating system for smartphones, which can allow attackers to gain access to users’ personal information without their permission. The flaw, which was discovered by three research assistants at Ulm University in the southern part of Germany, affects approximately 97% of Android users. In a recent blog post, the researchers found that users of Android devices running versions 2.3.3 and below could be susceptible to attack when they are connected to unencrypted Wi-Fi networks. Anyone else on that network could gain access to, modify or delete Android users’ calendars, photos and contacts.
1 - 20 of 113 Next › Last »
Showing 20 items per page