• Home
  • Subscribe
  • About
  • Archives
  • Search
  • Views
  • Bookstore
  • Careers
  • Consulting
  • Education

Security

Welcome to the News View for "Security".

Here, on one page, you'll find all of the articles on Payments News for Security listed in date sequence beginning with the most recent article at the top of the page.

Click here for a complete listing of what's available in the Payments News Archive - organized by both posting date and subject category.

Subscribe to Payments News!

June 24, 2008

TowerGroup Worries about Nonbank Personal Finance Web Sites

Tags » Personal Financial Management, Security, TowerGroup

In a new report titled "The Impact of Online Personal Finance Offering: The Good, the Bad, and the Ugly", TowerGroup analyst George Tubin finds the capabilities of new non-bank online personal finance web sites are of interest but raises concerns about whether the sites have "adequate fraud prevention capabilities to protect both the consumer and the bank from account takeover and identity theft."   » Continue Reading

May 29, 2008

Attacking NFC Mobile Phones

Tags » Contactless Payments, Mobile Payments, Near Field Communication (NFC), Security

In a post titled "Attacks on NFC mobile phones demonstrated", Dancho Danchev writes for ZDNet on last week's presentation by Collin Mulliner icon_PDF_small.gif at the EUSecWest conferece in London.

May 23, 2008

Trusteer Partners with ING DIRECT

Tags » Identity Theft, ING Direct, Privacy, Security

ING DIRECT has announced that it has partnered with Trusteer to become the first US bank to offer Trusteer’s Rapport consumer Identity Theft protection software free to all of its customers.   » Continue Reading

May 20, 2008

Unisys Security Index Finds Bank Customers Concerned

Tags » Banking Industry, Card Fraud, Data Security, Identity Theft, Privacy, Security

The latest U.S. results of the Unisys Security Index find that Americans are more concerned than they were seven months ago about national security issues and health epidemics and are increasingly concerned about financial security issues and worries about identity theft.   » Continue Reading

Accenture's Payments Innovation Showcase

Tags » Biometrics, Innovation, Mobile Banking, Mobile Payments, Security, SEPA

Accenture has announced that it has opened a new facility at its research and development technology lab in Sophia Antipolis, France, dedicated to innovation in the rapidly growing global payments industry. The facility, called the Accenture Payments Innovation Showcase, focuses on original research and development in all facets of the payments business, including mobile communications and other point-of-sale technology, bank-to-corporate connectivity, processing, process models, biometrics, regulation such as the Single Euro Payments Area (SEPA) initiative, and security.   » Continue Reading

May 13, 2008

Summer Reading Recommendations: Payments Security

Tags » Data Security, Glenbrook, Online Banking, PCI Compliance, Security

Two important new books about security - and payments security in particular - arrived on my desk this week.

The first book - the second edition of Ross Anderson's Security Engineering - provides fascinating insights into all of those things that are often overlooked when designing secure systems. Anderson provides a comprehensive survey of the issues, the nature of successful attacks, with serious recommendations on how to simply do better across a range of security applications. This is a big book - not exactly suited for reading on the beach - but important nonetheless! Rated 4.5 out of 5 stars by Amazon.com reviewers.

The second book - Zero Day Threat by Byron Acohido and Jon Swartz - provides real insights into the threats that attackers are exploiting to gain the necessary information to take over online banking, PayPal, brokerage, and other accounts. If "know your enemy" makes sense to you, then you'll find Zero Day Threat of great interest. Zero Day Threat is 5-star rated by Amazon.com reviewers.

Both of these books have just been added to the first page of the Payments News Bookstore on Amazon.com.

April 10, 2008

Securing Online Banking

Tags » Authentication, Online Banking, Security

Brian Krebs writes for his Security Fix blog at the Washington Post about changes to the banking code in the UK that stress that online banking customers have the responsibility to keep up-to-date anti-virus, anti-spyware, etc. software installed on their computers - and wonders why more US banks don't make available hardware tokens to secure online access (the way PayPal optionally does).

March 31, 2008

Vast Majority of Americans Feel Safe Online

Tags » ECommerce Payments, Online Banking, Security

Nearly 90 percent of Americans say they feel safe online despite the rising tide of spyware, phishing and other badware threatening Internet users, according to a new poll sponsored by StopBadware.org, a consumer protection initiative aimed at combating dangerous software.   » Continue Reading

March 27, 2008

TJX Agrees to Settle FTC Charges

Tags » Data Security, Merchants, PCI Compliance, Security

The Federal Trade Commission has announced that TJX has agreed to settle charges that it engaged in practices that, taken together, failed to provide reasonable and appropriate security for sensitive consumer information. The settlements will require that TJX implement comprehensive information security programs and obtain audits by independent third-party security professionals every other year for 20 years. Full details available here.   » Continue Reading

October 29, 2007

Visa's New Payment Application Security Mandates

Tags » Data Security, Merchants, PCI Compliance, Security, Visa

Jaikumar Vijayan writes for Computerworld about last week's announcement by Visa of new payment application security mandates. "Basically, they require any company that accepts payment card transactions to ensure that all third-party payment applications they use to store, process or transmit cardholder data comply with a set of minimum security requirements from Visa."

October 24, 2007

Mobile Banking Security

Tags » Mobile Banking, Security

Aite Group has published a new report titled "Mobile Banking Security: The Black Cloud Attached to the Silver Lining" that it says "investigates security vulnerabilities for mobile banking, both now and in the near future, focusing on the methods that are being deployed to mitigate risk over this emerging channel."   » Continue Reading

September 11, 2007

PCI Security Standards Council to Manage PED Requirements

Tags » Banking Industry, Debit Cards, PCI Compliance, PCI Security Standards Council, Point of Sale (POS), Security

Taking on an expanded role, the PCI Security Standards Council has announced that it has also assumed responsibility for the PIN Entry Device (PED) Security Requirements that were previously administered under the auspices of JCB, MasterCard International and Visa International.   » Continue Reading

June 07, 2007

PULSE EFT Association Encourages Electronic Payment Security Practices

Tags » Card Fraud, Debit Cards, Identity Theft, Pulse, Security

The PULSE EFT Association has launched its annual nationwide effort encouraging consumers to review and practice safety tips when using their ATM/debit cards. New to the network’s ATM/Debit Card Safety Awareness Month campaign this June is an increased focus on privacy and fraud protection.   » Continue Reading

May 02, 2007

New Javelin Report on Mobile Banking Security

Tags » Mobile Banking, Security

Javelin Strategy & Research has announced new report titled "Mobile Banking Security: The Call for Technology Standards and Proactive Security Messaging" (PDF).   » Continue Reading

April 25, 2007

Navigating the Payment Card Industry - Data Security Standard

Tags » Data Security, PCI Compliance, Privacy, Security

Sarah D. Scalet writes for CSO Magazine about the Payment Card Industry - Data Security Standard (PCI-DSS) standard - calling it "corporate America's most ambitious effort yet to prove that it can self-regulate."

April 23, 2007

RSA Enhances Portfolio of PCI Compliance Solutions

Tags » Data Security, PCI Compliance, Security

RSA has announced "an expanded Payment Card Industry Data Security Standard (PCI DSS) Solution portfolio, a suite of products and services that help enable customers to answer the most challenging IT security technology challenges associated with the PCI DSS. As part of the RSA PCI Solution, RSA also announced a new blueprint for promoting compliance by discovering data and infrastructure, assessing risk, enacting remediation and ensuring sustained controls."   » Continue Reading

April 21, 2007

First Data Security Chief Calls for PCI DSS Changes

Tags » Data Security, First Data Corp., PCI Compliance, Security

Robert Westervelt reports for SearchSecurity.com on comments made by First Data's Chief Information Security Officer Phil Mellinger regarding the Payment Card Industry Data Security Standards (PCI DSS) in which he calls for "an overhaul to eliminate subjectivity and ease restrictions to get more merchants to meet the standard."

April 12, 2007

Securing Your Mobile Wallets

Tags » Mobile Banking, Mobile Payments, Security

Elena Malykhina blogs for Information Week about what banks and their partners are doing to secure mobile banking services.

April 11, 2007

Data Breaches and Consumer Buyer Behavior

Tags » Data Security, Merchants, PCI Compliance, Security

Javelin Strategy & Research has published a new report on data breaches - examining consumer attitudes and the TJX security issue. The study concludes that "77% of consumers intend to stop shopping at merchants that suffer from data breaches. Retailers and merchants are viewed by 63% of consumers as the least secure when protecting consumer’s data, compared with processors (16%), card networks like Visa or MasterCard (5%) and issuers (5%). When little is known about a data breach, half of all consumers automatically consider the merchants where they shop to be at fault. However, 85% will reward merchants who are perceived as security leaders with increased purchases."   » Continue Reading

March 29, 2007

TJX Intruder Had Retailer's Encryption Key

Tags » Data Security, Merchants, PCI Compliance, Security

Evan Schuman reports for eWeek's Channel Insider on more details about the recent TJX payment card data breach.

TJX - The Largest Payment Card Data Breach Ever Reported

Tags » Data Security, Merchants, PCI Compliance, Security

Jenn Abelson reports for the Boston Globe on the TJX data breach reported earlier - saying the breach involved "at least 45.7 million credit and debit card numbers" stolen over a period of several years. The data was provided by the company in a 10-K annual report filing with the SEC yesterday.

March 18, 2007

Protect Your Own Identity

Tags » Identity Theft, Security

Diana Ransom writes for the Wall St. Journal about the techniques one should follow to minimize the chances of identity theft by electronic means - especially if you're using a wireless router in your home or business.

March 09, 2007

VeriFone Launches Payment Security Web Site

Tags » Data Security, PCI Compliance, Security, Verifone

VeriFone has launched a new payment security web site at www.secureretailpayments.com. "VeriFone developed this web site to help retailers better understand the confusing set of payment industry standards. The web site includes white papers, links to industry standards, news updates and information about VeriFone products."

February 08, 2007

Massachusetts Attorney General Leading Investigation Into TJX Data Breach

Tags » Data Security, PCI Compliance, Security

Massachusetts Attorney General Martha Coakley has announced that "her office is leading a multi-state civil investigation into the recently disclosed security breach at TJX Companies. The Consumer Protection Division of the Attorney General's Office is investigating the breach, which was disclosed last month by the Framingham-based company, and particularly what security measures the company took to protect consumer information."   » Continue Reading

February 06, 2007

An Interview With RSA's Art Coviello

Tags » Authentication, Data Security, Security

Joris Evers of CNET News.com interviews RSA president Art Coviello during this week's annual RSA Conference being held in San Francisco. Coviello comments that "if you look at the three biggest Internet banks in the country, they way they have responded to the FFIEC recommendation for having strong authentication in online transactions, each one is using a different type of RSA technology."

January 30, 2007

Data Security Firms Establish PCI Security Vendor Alliance

Tags » Data Security, PCI Compliance, Security

Eight data security companies have announced the formation of The Payment Card Industry Security Vendor Alliance – (PCI SVA). According to the group, "PCI SVA will assist members of the payment card industry and the PCI Security Standards Council -- composed of merchants, banks and point-of-sale vendors – in educating the business community on the requirements and business value of the Payment Card Industry (PCI) Data Security Standard, a global benchmark intended to improve security throughout the entire payment card transaction process."   » Continue Reading

Entrust Introduces $5 Hardware Security Token

Tags » Authentication, Security

Entrust has announced the launch of a new, five dollar one-time-password (OTP) hardware security token along with news that Expedia will become the first company to deploy the new Entrust token.   » Continue Reading

January 25, 2007

Annals of Data Breaches

Tags » Data Security, Financial Regulators, PCI Compliance, Security

James C. McGrath and Ann Kjos of the Payment Cards Center of the Federal Reserve Bank of Philadelphia have published a conference summary report for a conference held at the bank last September.   » Continue Reading

January 24, 2007

Massachusetts Banks Reporting Fraud Has Occurred Re: TJX Breach

Tags » Card Fraud, Data Security, Merchants, Security

The Massachusetts Bankers Association said today that "several banks across the Bay State have reported incidents of fraud due to the recently disclosed data breach by the TJX Companies. The fraudulent use of debit and credit card data has thus far been used to make purchases in Florida, Georgia, and Louisiana in the U.S., and Hong Kong and Sweden overseas."   » Continue Reading

January 18, 2007

TJX Security Breach

Tags » Card Fraud, Data Security, Merchants, Security

The TJX Companies yesterday announced that "it has suffered an unauthorized intrusion into its computer systems that process and store information related to customer transactions."   » Continue Reading

January 09, 2007

Outsourcing As An IT Security Solution

Tags » Data Security, Security, TowerGroup

TowerGroup reports that enterprise security today has become an everyday concern from the corner office to the boardroom -- and financial services institutions are finding it increasingly difficult to manage security in-house and asserts that now is the time for financial institutions to consider outsourcing the IT portions of security.   » Continue Reading

January 05, 2007

FDIC Spotlights Importance Of Bank Incident Response Programs

Tags » Data Security, Financial Regulators, Privacy, Security

The Federal Deposit Insurance Corporation's latest quarterly Supervisory Insights newsletter features an article titled "Incident Response Programs: Don't Get Caught Without One". From the abstract: "A security incident can damage corporate reputations, cause financial losses, and foster identity theft, and banks are increasingly becoming targets for attack because they hold valuable data that, when compromised, allow criminals to steal an individual's identity and drain financial accounts. To mitigate the effects of security breaches, organizations are finding it necessary to develop formal incident response programs (IRPs). This article highlights the importance of IRPs to a bank's information security program and provides information on required content and best practices banks may consider when developing effective response programs."

January 02, 2007

New Developments And Trends In The Law Of Information Security

Tags » Data Security, Privacy, Security

Thomas J. Smedinghoff writes us with news about a new paper he's written titled "Where We're Headed — New Developments and Trends in the Law of Information Security" that's available online. Smedinghoff is a partner at the law firm of Wildman Harrold, in Chicago, and a member of the firm's Privacy, Data Security, and Information Law Practice. In the paper, he writes that "three legal trends are rapidly shaping the information security landscape for most companies." These include a continuing expansion of the duty to provide security, the emergence of a legal standard for compliance - a definition of "reasonable security", and the imposition of a duty to warn.

October 10, 2006

Symantec, VeriSign Deliver Stronger Identity Protection For Consumers

Tags » Authentication, ECommerce Payments, Identity Theft, Online Banking, Security

Symantec and VeriSign have announced plans to deliver "security solutions to combat the growing threat of consumer identity theft and fraud on the Internet." Symantec plans to offer support for the VeriSign Identity Protection (VIP) Authentication Service, which allows consumers to utilize one-time passwords to protect their online identity.   » Continue Reading

September 18, 2006

EMC Completes RSA Security Acquisition

Tags » Authentication, Data Security, Security

EMC has announced it has completed the acquisition of RSA Security. EMC also announced it has signed a definitive agreement to acquire Network Intelligence, a privately-held company in the security information and event management market. EMC says "the acquisition of RSA and Network Intelligence joins market leaders which together will create the new information security division of EMC."   » Continue Reading

September 15, 2006

Top Five Causes of Data Security Compromises

Tags » Data Security, PCI Compliance, Security, Visa

Visa USA and the U.S. Chamber of Commerce have announced their assessment of the five leading causes of data security breaches and offered immediate, specific prevention strategies for each.   » Continue Reading

September 06, 2006

Survey: E-Crime Incidents Declining Yet Impact Is Increasing

Tags » Data Security, Law Enforcement, Security

CSO Magazine has released the results of the 2006 E-Crime Watch survey, revealing a decline in security events, yet an increase in the financial and operational losses caused by such electronic crime incidents.   » Continue Reading

August 28, 2006

Security Engineering - The Book

Tags » Data Security, Security

Ross Anderson of the University of Cambridge (UK) Computer Laboratory has made available his book "Security Engineering" (PDFs - by chapter) for download onlline. Anderson's book is an important reference to many aspects of designing and operating secure systems and it's great that he and his publisher are making it available online.

August 04, 2006

A Look At Identity Based Encryption

Tags » Bank Technology, Security

Paul Korzeniowski writes for Investor's Business Daily about "identity-based encryption" - a new approach that simplifies the management of encryption keys by using something like an email address (an identity) as the basis for a public encryption key. Korzeniowski reports that Ferris Research did a cost comparison between the IBE and PKI approaches and found that an IBE system costs one-fourth as much to operate as a traditional PKI-based approach.

August 03, 2006

Sizing Up Security: Are U.S. Banks Trailing U.K. Banks?

Tags » Authentication, Online Banking, Security

From Bank Technology News: "If best practices are indeed what the U.S. banking industry seeks with regard to online security, they'll likely find some of the answers across the pond. The irony is that U.K. banks, whose cultures are inherently more formal and ultra-conservative, are taking a much more open approach to online security and the challenges that they face than U.S. banks."

July 31, 2006

Updated FFIEC Information Security Booklet

Tags » Data Security, Financial Regulators, Security

The Federal Financial Institutions Examination Council (FFIEC) has released an updated Information Security Booklet (PDF), which replaces the booklet issued in December 2002. The Information Security Booklet is one of 12 that, in total, comprise the FFIEC IT Examination Handbook. The FFIEC also released an Executive Summary (PDF) that contains a high-level synopsis of each of the 12 booklets and describes the handbook development and maintenance processes.

June 29, 2006

EMC To Acquire RSA Security

Tags » Authentication, Data Security, Security

It's official, EMC this afternoon announced that it is acquiring RSA Security in an all-cash transaction valued at slightly less than $2.1 billion.   » Continue Reading

Sale Of RSA Said To Be Near

Tags » Authentication, Bank Technology, Security

Andrew Ross Sorkin and John Markoff report for the New York Times that RSA Security is in the late stages of negotiating a sale of the company - with EMC reported as one of the potential bidders to acquire the company.

June 12, 2006

Visa, Verified Identity Pass In Marketing Deal

Tags » Authentication, Biometrics, Security, Visa

Visa USA has announced an agreement with Verified Identity Pass, Inc. to offer discounted memberships for Clear, Verified ID's Registered Traveler Program, to select Visa Signature and Visa Traditional Rewards cardholders. According to Visa, "Clear members receive fast access through security checkpoints by verifying their biometric information in specially-designed Clear lines, enabling time-pressed travelers to quickly move through long lines and experience a more hassle-free travel experience."   » Continue Reading

June 07, 2006

MasterCard, Fraternal Order of Police Hold Security Seminars

Tags » Card Fraud, MasterCard, Merchants, Security

MasterCard has announced it is partnering with the Fraternal Order of Police to deliver a "multifaceted program to educate business owners about how to stop fraud before it happens, protect cardholder data and deliver peace of mind to their customers. The program is aimed at furthering collaboration on data security throughout the payment system and helping merchants keep cardholder data safe and secure."   » Continue Reading

June 06, 2006

CyberSource Protects Against Payment Data Theft

Tags » CyberSource, ECommerce Payments, PCI Compliance, Security

CyberSource has announced the launch of a new service enabling eCommerce merchants to process electronic payments without the risk of storing or even handling sensitive account information. With CyberSource's Payment Data Management, CyberSource, not the merchant, manages sensitive customer information such as credit card numbers and related transaction data. CyberSource handles and stores all payment data on behalf of the merchant in security-certified processing centers that connect directly with the banking network. As a result, consumer payment information is safer, merchant risk decreases, and merchant compliance with card association security rules can become simpler and faster.   » Continue Reading

May 25, 2006

Barclays Launches New Anti-Fraud Initiative

Tags » Banking Industry, Barclays, Card Fraud, Online Banking, Phishing, Security

Barclays has announced it is launching a "new online anti-fraud initiative and becoming the first bank to offer free anti-virus software to its customers. Customers will also be offered an innovative text message service notifying them of new payees on their online account, helping to cut occurrences of fraud attacks."   » Continue Reading

May 23, 2006

Americans Want Congress to Do More to Protect Them Online

Tags » ECommerce Payments, Security

The Cyber Security Industry Alliance (CSIA) has released the results of its semi-annual survey dedicated to measuring the American public's confidence in the security of the nation's digital infrastructure.   » Continue Reading

May 22, 2006

New Edge Networks, Chase Paymentech Tighten Security

Tags » Chase Card Services, Merchant Acquirers, Merchants, PCI Compliance, Security

New Edge Networks has announced it is tightening privacy and security on bankcard transactions through new network interconnections to Chase Paymentech Solutions LLC. The new connections provide end-to-end compliance with Payment Card Industry (PCI) security standards.   » Continue Reading

May 16, 2006

Credit Card Security Rules To Get Update

Tags » PCI Compliance, Security

Joris Evers writes for CNET News.com about an update to the Payment Card Industry (PCI) Data Security Standard, expected this summer based on comments from Tom Maxwell, director of e-Business and Emerging Technologies at MasterCard International.

May 13, 2006

Consumers Losing Trust in Online Banking

Tags » Online Banking, Security

Ed Sutherland reports for InternetNews.com that US consumer concerns about online banking security is slowing the growth of online banking.   » Continue Reading

April 24, 2006

RSA Security Acquires PassMark Security

Tags » Authentication, Identity Management, Online Banking, Phishing, Security

RSA Security has announced that it has acquired PassMark Security, a privately held company based in Menlo Park, that "delivers robust software-based authentication to millions of users worldwide, through some of the largest consumer-facing financial institutions."   » Continue Reading

April 13, 2006

Triple DES Upgrades May Introduce New ATM Vulnerabilities

Tags » ATM, Debit Cards, Security

In a press release today, Redspin, an independent auditing firm based in Carpinteria, CA, suggests that the recent mandated upgrades of ATMs to support triple DES encryption of PINs has introduced new vulnerabilities into the ATM network environment - because of other changes that were typically made concurrently with the triple DES upgrades.   » Continue Reading

March 15, 2006

Study Says Chips In RFID Tags May Be Vulnerable To Viruses

Tags » Contactless Payments, Security

New York Times reporter John Markoff covers recent research by a group of European computer researchers who have demonstrated inserting a software virus into RFID tags.   » Continue Reading

March 14, 2006

Fraud Management Technologies Introduces FraudAlert

Tags » Authentication, Identity Management, Phishing, Security

Australia-based Fraud Management Technologies has announced FraudAlert, a new software or hosted solution designed to reduce the rate of increasingly sophisticated online fraud while protecting the convenience and ease of use of online banking and retailing.   » Continue Reading

March 09, 2006

ICBA, Microsoft Team Provide Data Security Resources for Community Banks

Tags » Data Security, Security

The Independent Community Bankers of America and Microsoft have announced they are teaming up to help community banks manage the security of their technology infrastructures and battle emerging security risks.   » Continue Reading

March 06, 2006

Magnetic Card Counterfeits

Tags » Card Technology, Security

Brian Krebs of the Washington Post reports in his Security Fix blog about how various hotel key cards are having their magnetic stripes re-encoded by fraudsters for use as bank cards.

February 26, 2006

Keyloggers Replace Phishers

Tags » Online Banking, Phishing, Security

Phishing is already passé among global cybercriminals - according to Tom Zeller Jr.'s article "Cyberthieves Silently Copy as You Type" in Monday's New York Times.   » Continue Reading

February 23, 2006

CardSystems Solutions Settles FTC Charges

Tags » Data Security, Financial Regulators, Identity Theft, Pay By Touch, Privacy, Security

The Federal Trade Commission has announced that CardSystems Solutions, Inc. and its successor, Solidus Networks, Inc., doing business as Pay By Touch Solutions, have agreed to settle Federal Trade Commission charges that CardSystems' failure to take appropriate security measures to protect the sensitive information of tens of millions of consumers was an unfair practice that violated federal law.   » Continue Reading

February 22, 2006

Strict Liability For Breaches Of Personal Data

Tags » Data Security, Identity Theft, Security

Mark Rasch writes for SecurityFocus about a recent lawsuit in Minnesota (PDF) in which a victim who was included in a data breach of a financial service provider's 550,000 customer database sued the company for breach of contract, breach of fiduciary duty and negligence.   » Continue Reading

February 19, 2006

Multimedia Tool To Beat Identity Theft

Tags » Identity Theft, Phishing, Security

Joseph Pellicciotti reports for the Northwest Indiana Times on a new presentation available online from the FDIC. Titled "Don't Be an On-line Victim: How to Guard Against Internet Thieves and Electronic Scams", the presentation is designed to educate consumers about the steps they can take to protect themselves from identity theft and what they can do if they've become victims.

February 15, 2006

ID Analytics, PassMark Security To Partner

Tags » Authentication, ECommerce Payments, Identity Management, Online Banking, Security

ID Analytics and PassMark Security have announced a partnership to bring the power of authentication and identity risk scoring to online banking and e-commerce. The combined offering will help more companies determine the risk associated with each log-in and safeguard legitimate customers from identity fraud while transacting online.   » Continue Reading

February 14, 2006

Microsoft: Fostering A Trust Ecosystem Online

Tags » Authentication, ECommerce Payments, Identity Management, Online Banking, Security

Microsoft's Bill Gates keynoted today's RSA Conference by focusing on Microsoft's vision for a more secure online future. Included in that future is a "trust ecosystem" that engenders trust and accountability between people and businesses online.   » Continue Reading

February 13, 2006

A Look At VeriSign's VIP

Tags » Authentication, ECommerce Payments, Identity Management, Online Banking, Security

Peter Pollack writes for Ars Technica on his views of the newly announced VeriSign VIP service - both pro and con.   » Continue Reading

VeriSign Introduces VeriSign Identity Protection (VIP)

Tags » Authentication, ECommerce Payments, Identity Management, Online Banking, Security

VeriSign has announced the launch of VeriSign Identity Protection (VIP), a program designed to "help provide identity protection for consumers who conduct business online." VeriSign said that VIP is supported by several online companies including PayPal, eBay and Yahoo!. In addition, SanDisk has announced plans to support VIP by manufacturing and distributing OATH compliant USB mass-storage and trusted flash devices and Motorola plans to enable this technology on consumer mobile devices.   » Continue Reading

February 11, 2006

ChoicePoint's Recovery

Tags » Credit Scores, Data Security, Identity Management, Identity Theft, Privacy, Security

Bill Husted writes from tomorrow's Atlanta Journal-Constitution about what a difference a year has made to suburban Atlanta-based ChoicePoint.   » Continue Reading

February 03, 2006

Boston Globe Grapples With Credit Card Blunder

Tags » Card Payments, Security

Svea Herbst-Bayliss reports for Reuters on the credit card security breach by the Boston Globe that was reported earlier this week.   » Continue Reading

February 01, 2006

Financial Institutions Face Significant Security Breach Costs

Tags » Banking Industry, Data Security, Security

Tracey Vispoli, vice president, Chubb & Son, cautioned bankers about the potential costs associated with a security breach at a recent American Bankers Association conference.

"For many financial institutions, a network security breach involving the release of confidential customer information is not a matter of if, but when. It's time for financial institutions to further tighten their data security controls and to prepare for the potentially significant financial cost of this risk."
  » Continue Reading

Financial Institution Shared Assessments Program

Tags » Banking Industry, Security

Robert Guth reports for the Wall St. Journal on a new banking industry initiative called the Financial Institution Shared Assessments Program expected to be announced today to guard customers against security breaches.

Marketing Payment Card Security

Tags » Authentication, ECommerce Payments, MasterCard, Security, Visa

Eric Dash reports for the New York Times on the "vastly different approaches" being taken by Visa and MasterCard in marketing their security initiatives to consumers and merchants.   » Continue Reading

January 30, 2006

Unisys Identifies Banking Industry Trends

Tags » Banking Industry, Security

Unisys has announced their view of the top trends affecting the banking industry in 2006.   » Continue Reading

January 27, 2006

Japan: Banks Implement Consumer Tokens

Tags » Authentication, Bank Technology, Identity Management, Security

RSA SecurIDRSA Security has announced that Japan Net Bank and Sumitomo Mitsui Banking Corporation have selected RSA SecurID strong authentication tokens to better protect online banking customers in Japan. Japan Net Bank will be the first to deliver two-factor authentication tokens to over one million online banking customers.   » Continue Reading

January 26, 2006

Choicepoint Settles Data Security Breach Charges

Tags » Financial Regulators, Privacy, Security

The Federal Trade Commission has announced that ChoicePoint, Inc., which last year acknowledged that the personal financial records of more than 163,000 consumers in its database had been compromised, will pay $10 million in civil penalties and $5 million in consumer redress to settle FTC charges that its security and record-handling procedures violated consumers’ privacy rights and federal laws.   » Continue Reading

January 25, 2006

Visa: Consumers Worried About Personal Information

Tags » Privacy, Security, Visa

Visa International has released the results of new global survey of consumer attitudes concluding that the theft or loss of personal and financial information is the No. 1 concern of consumers worldwide (64 percent). A media backgrounder on the survey results (PDF) is available online.   » Continue Reading

January 12, 2006

Credit Card Rivals to Unite in Data Protection Effort

Tags » MasterCard, Security, Visa

Eric Dash reports for the New York Times on efforts by Visa and MasterCard to create a private group that would set new industrywide security standards.

January 11, 2006

Javelin Updates Online Banking Safety Scorecard

Tags » Authentication, Identity Management, Identity Theft, Online Banking, Security

Javelin Strategy & Research has released its second annual Online Banking Safety Scorecard which ranks 28 banks on their consumer-facing online identity fraud prevention, detection and resolution capabilities with respect to how well the banks protect consumers and allow consumers to protect themselves.   » Continue Reading

MasterCard Announces New Merchant Security Initiatives

Tags » MasterCard, Merchants, Privacy, Security

MasterCard has announced several new merchant-related initiatives: incentives for merchants to adopt MasterCard SecureCode payer authentication, free network vulnerability scans of merchant systems, and new education for merchants on security and data protection issues. MasterCard has also launched a new merchant website focused on security at www.mastercardsecurity.com.

January 08, 2006

Rethinking Online Banking

Tags » Authentication, Online Banking, Security

Forrester's Martha Bennett has written a new research report titled "Online Banking Security: Give Customers More Control And Reassurance" saying that banks are failing to take into account the customer's needs with their approaches to online banking security practices.   » Continue Reading

Bank Offshoring: Putting Data At Risk?

Tags » Banking Industry, Privacy, Security

Patrik Jonsson writes for the Christian Science Monitor about the potential risks to customer and bank data associated with banks offshoring certain jobs.   » Continue Reading

January 04, 2006

CSO: Keeping Secrets Secret

Tags » Security

Simson Garfinkel writes for CSO Magazine on techniques to securely protect data - and let you sleep at night.

All of the following approaches protect the data in the database against both outside attackers and malicious insiders. That's because these tactics work by either eliminating or scrambling sensitive information so that it no longer poses a security risk.
  » Continue Reading

Bank of America Expands SiteKey To Northe