Quantcast StorefrontBacktalk - Techniques, Tools, and Tirades about Retail Technology and E-Commerce
E-Mail Us
Trick Or Treat? New PCI Version To Be Here By Halloween
May 16th, 2008

By this Halloween, the PCI Council will unveil the first major revision of the PCI DSS payment card security program in two years. But with the council not releasing any true details about the changes, nervous retailers are truly wondering “Trick or Treat?”

Robert Russo, general manager of the PCI Council and a man who never met an acronym he didn’t like (when we chatted, he tried turning QA into a verb—and he frighteningly got darn close), is trying to play down the significance of the new version, describing the modifications as “minor changes.” Read more.

Blueprint for Growth & Innovation:

The Power of a Valued Partner.

Selecting a strategic partner has become more critical than ever to growing retail organizations. Discover, and learn what to look for in a business partner that will position your organization for growth and innovation. Click here for this free white paper on the Power of a Valued Partner.
Dave & Buster’s Data Breach Indictment: Apps Crash For The Bad Guys, Too
May 16th, 2008

It was April 2007 when a pair of cyberthieves from the Ukraine and Estonia set out to try and grab payment card data from the 49-store Dave & Buster’s restaurant chain. But according to a federal indictment and a U.S. Secret Service affidavit unsealed May 12, 2008, the pair quickly discovered that software can be an equal-opportunity crasher.

“As a result of a defect in the software program for the packet sniffer, the packet sniffer automatically deactivated whenever the compromised (Dave & Buster’s) POS servers rebooted in the normal course of the operation of the servers,” the indictment said. “Therefore, in order for the packet sniffers to capture data from the compromised D&B POS servers on an ongoing basis, the defendants had to regularly reactivate the packet sniffers.” This group might even have had a hand in the TJX incident. Read more.

In E-Commerce Satisfaction: Netflix, QVC On Top; PCMall, Home Depot On Bottom
May 15th, 2008

That which keeps consumers satisfied seems to be part of an E-Commerce site’s culture, as top (and bottom) players tend to show little movement, year to year. The latest results from measurement firm ForeSee Results seem to reinforce that.

Several of the top sites this year (Netflix, QVC, Amazon, DrsFosterSmith, Shutterfly and Newegg) changed only a few percentage points—and often less—from last year’s numbers. The percentage change for those at the bottom of the list (PCMall, PCConnection, Efollet, Bidz and Home Depot) is even smaller. ForeSee CEO Larry Freed said that a score of 80 percent or higher is “a really good score,” in the 70s “is in the average realm today” and anything below the 70s needs some serious work. Netflix came in at 86 percent, QVC at 84 percent and Amazon at 83 percent, while Home Depot and Bidz were both 69 percent, Efollet was at 68 percent and PCMall (the lowest) was at 67 percent.

Delegation Can Be Good, And A Half-Dozen Other Security Tips
May 15th, 2008

From his perch in the world of security, Guestview Columnist David Taylor sees delegation as a good thing. Some of the retailers with the best strategies have figured out how to “deputize” internal audit, HR, data owners and store managers and give them specific things to do, from employee education to access monitoring to policy enforcement.

These leaders also tend to be more successful at getting business units and other departments to share the cost of PCI compliance with IT. Read more.

U.S. Watched 11.5 Billion Web Videos In March
May 14th, 2008

For e-tailers who still think that Web video may be a fad, consider this stat: In March 2008, U.S. Internet users watched 11.5 billion online videos. That’s a 13 percent gain from the prior month and a 64 percent gain from the identical month the prior year, according to Comscore.

In March, Google Sites once again ranked as the top U.S. video property with more than 4.3 billion videos viewed (38 percent share of all videos), gaining 2.6 share points versus the previous month. YouTube.com accounted for 98 percent of all videos viewed at Google Sites. Fox Interactive Media ranked second with 477 million videos (4.2 percent), followed by Yahoo Sites with 328 million (2.9 percent) and Viacom Digital with 249 million (2.2 percent).

Google Pushes Aside Yahoo For #1 Slot
May 14th, 2008

Thanks in no small part to soaring traffic on YouTube, Google for the first time took the top slot in American consumer reach in April 2008, besting Yahoo.

But it took that top slot just barely, reaching 141 million Americans in April. Yahoo ranked second with 140.6 million visitors, followed by Microsoft Sites with 121.2 million visitors.

TJX Gets 99.5 Percent Signoff With MasterCard Banks
May 14th, 2008

When TJX announced a MasterCard agreement last month to pay $24 million for data breach costs stemming from the industry’s worst payment card data breach, it was contingent on at least 90 percent of the banks agreeing.

No surprise, but TJX made that acceptance rate with room to spare, coming in at 99.5 percent, the retailer announced May 14.

Applying Internet Security To RFID
May 14th, 2008

NeoCatena Networks has in the wings a product designed to stop fraudulent or bad tag data from getting into the system from the supply chain.

Applying Internet-level security to RFID is something that has not gone very far, according to this RFID Update story about the anticipated rollout. NeoCatena Networks is developing RF-Wall, an appliance to be installed between RFID readers or controllers and middleware servers, edge servers or host applications in networked RFID systems. The product acts as a firewall that authenticates RFID tags prior to allowing their data to pass into enterprise systems and also scans input to detect and block malware. RF-Wall works by using the unique tag ID to create a digital signature.

FTC To Hold Contactless Hearing In Seattle
May 14th, 2008

Retailers focused on contactless payment might want to circle July 24, 2008, on their calendar. That is when the U.S. Federal Trade Commission will hold a hearing in Seattle “to explore the growth of contactless payment systems and the implications for consumer protection policy.”

Here are the details of the FTC’s hearing along with a link to submit comments electronically. There are lots of legitimate pros and cons on this issue, but the panel should at least understand the merchant’s perspective.

Macys Shutting Down Bloomingdale’s Catalogue
May 12th, 2008

Guess this is what the cliché-afflicted would call a “sign of the times.” Macys is killing the Bloomingdale’s catalog while Amazon.com is selling copies of Bloomingdale’s 1886 catalog for $12. (Can you imagine the number of out-of-stocks in that thing?)

Current Bloomie’s owner Macys is killing the classic catalog “by early 2009″ to focus more on its Web site and “reduce redundancies” (corporatespeak for pinkslip panic). A Macys statement even came up with a politically correct reason to zap the catalog: “Eliminating the paper catalog is also consistent with our sustainability and environmental policies of communicating more with customers electronically and less in paper.”

Arrests Made In California Debit-Card Skimming Scam
May 12th, 2008

California authorities have arrested two men in connection with another retail card-reader switch scam, an effort that police say brought in about $225,000 from 222 victims who swiped their debit cards at a regional grocery chain.

The arrests were in connection with the debit-card thefts at California grocery chain Lunardi’s, where police say the pair swapped out part of the card-reader with a skimmer, according to this San Jose Mercury News story. It was unclear whether the data was collected by piggybacking on the store’s network, wirelessly or if thieves retrieved the data by re-swapping the machines later. The Lunardi’s store that was hit is based in Los Gatos. The paper also reported that a nearby Los Gatos Arco gas station suffered a very similar debit-card breach a couple of weeks earlier.

Self-Checkout Psychology: Losing The Customer’s Trust
May 9th, 2008

With the many new self-checkout offerings being introduced this week from the likes of IBM, NCR and Fujitsu, it’s not a bad idea to focus on what will truly decide whether these machines do anything to help retailers.

To state the obvious: It’s getting consumers to use them. I say it’s obvious, but one wouldn’t guess that based on what the vendors were saying this week. Read more.

Self-Checkout: It’s Not Just For Lanes Anymore
May 9th, 2008

With the nation’s largest casino town as its backdrop, IBM and NCR gambled that the ho-hum growth in self-checkout can become a winner if the systems are moved away from the front-of-the-store checkout lanes and moved back toward the deli, bakery and even in the middle of the cereal aisle. All in all, I’d rather take my chances at rolling a 10 the hard way.

Las Vegas was hosting the 2008 Food Marketing Institute and Marketechnics show, which felt like self-checkout central this week. Read more.

The Home Depot Self-Checkout Machine That Wouldn’t Take “No” For An Answer
May 9th, 2008

Trying to collect some innocuous-sounding information from self-checkout customers, a self-checkout system at a Maryland Home Depot instead accidentally got itself embroiled in a privacy controversy.

The story began on May 8 when a woman visited a Baltimore Home Depot to buy a few odds and ends, including plants, pots and tile sealer. Read more.

The Data Breach Librarian Actually Gets Paid
May 9th, 2008

The Florida librarian and data breach victim who successfully took Wells-Fargo and Sprint Nextel to small claims court was paid this week, something that some data breach observers doubted would ever happen.

Theodore Karantsalis had filed the lawsuit for several reasons, but one was to prove that consumers would fare far better—faster, easier and more money—in small claims court than as one of many in some class-action litigation. Read more.

Twitter Dead Last In Social Network Uptime
May 9th, 2008

With its sites being unavailable for barely one hour over four months, MySpace has the best uptime of any major social networking site and Twitter (more than 37 hours of downtime during the same period) has the worst. Those stats come courtesy of Pingdom’s periodic uptime surveys, which tracked some 16 social networking sites from January 1 through April 30 of this year.

Not only was Twitter’s 37 hours and 16 minutes of downtime the worst in the group, it was almost double the amount of downtime from the second worst-performing site (Reunion.com, with 18 hours and 55 minutes of downtime). But even Twitter’s numbers amounted to an uptime that sounded good: 98.72 percent. Pingdom’s Peter Alguacil said those percentages can be misleading. Read more.

The Dangers Of Choosing The Wrong Wireless Approach
May 9th, 2008

London-based Marks & Spencer is the RFID tag champ. Attaching 350 million a year to items of clothing, they even blow past Wal-Mart when it comes to tagging individual items. Unfortunately, each and every one of those tags might have used the wrong technology.

The exec “who has been running the program said to me a year ago, ‘I’d love Nokia to say we have a way for people to walk into this door, wave their phone over a suit and take it home,’” said IDTechEx Chairman Peter Harrop. “But he said, ‘I think I’ve chosen the wrong frequency.’” Read more.

Opposition To Tokenization A Lot More Than Token
May 9th, 2008

GuestView Columnist David Taylor this week discovered that there’s a lot more than token opposition to tokenization.

One of the concerns is that companies have already spent money on encryption. The most popular reason for not implementing tokenization is that companies have already implemented data encryption and key management systems costing hundreds of thousands of dollars, and either they did not feel they needed tokenization or they were unwilling to be perceived by upper management as “changing course” by recommending the removal of the data they just spent all this money to protect. Read more.

Microsoft Gives Up Yahoo Pursuit
May 3rd, 2008

Microsoft on Saturday (May 3) gave up its efforts to acquire Yahoo, declaring such an effort too expensive.

“Despite our best efforts, including raising our bid by roughly $5 billion, Yahoo! has not moved toward accepting our offer,” Microsoft CEO Steve Ballmer said in a letter to Yahoo CEO Jerry Yang. “After careful consideration, we believe the economics demanded by Yahoo! do not make sense for us, and it is in the best interests of Microsoft stockholders, employees and other stakeholders to withdraw our proposal.” Read more.

Rite Aid Cuts Deal For Visually Impaired Web, POS Support
May 2nd, 2008

Rite Aid on May 1 announced an extensive set of E-Commerce and POS changes to accommodate visually-impaired consumers, admittedly under an implied litigation threat from advocacy groups.

The $24 billion 5,000-store pharmacy chain joins an expanding list of national retailers who have agreed to make such changes, including 7-Eleven, RadioShack, Safeway, Trader Joe’s and Wal-Mart. The most prominent retailer who has fought such efforts is Target, whose legal battle continues. Read more.

Beware Of Mobile Customers Who Are Not Where You Think They Are
May 2nd, 2008

As retailers continue to experiment with mobile commerce, one potential problem is when mobile customers prove to be truly mobile. Let’s say a national chain sends an E-mail blast to the cellphones of 10,000 Boston-area customers, inviting them to visit the store for a free sample on Wednesday. The chain limits the offer to the Boston area through area code and other data.

But it just so happens that there’s a huge convention in San Jose that day of the Society Of People Who Live In Boston. Your San Jose locations get flooded with people asking for their free gift, leading to a lot of baffled employees and angry customers. This observation comes courtesy of a colleague who has far too much time on his hands to think up such things.

Do Retailers Really Maintain A Secure Environment?
May 2nd, 2008

This wonderful piece comes courtesy of that time-honored daily newspaper tradition, the police blotter. You really should read the details in this story in New York’s Saratogian newspaper, but the essence is that a woman walks up to an ATM at a Hannaford’s grocery store. (Just what Hannaford needs right now. More police-oriented publicity.)

She connects a laptop to the ATM until an alarm goes off, at which point she packs up and leaves. Turns out that she worked for the ATM company, but the story asks why no one bothered to ask her what she was doing. Indeed, it’s a fine question. How many retailers have strict file access procedures, but would likely let a stranger plug a laptop into equipment without any questions? No, please, don’t answer that question. It’s too depressing to hear.

Number Of 10-Year-Olds On Social Sites Soaring
May 2nd, 2008

Like it or not (place this father defiantly in the “not” category), children are using the Internet’s social network sites at a younger age, with retail marketers hovering close by. How young?

New stats show 17 percent of boys aged 10-12 used such sites last year, which is more than double the 8 percent who used social sites in 2006, according to the Harris Poll. For 10-12-year-old girls, the figure is 27 percent, more than 2-and-a-half times the prior year’s 11 percent. In the 13-15-year category, boys jump to 46 percent and girls jump to 54 percent. Oddly enough, that 54 percent for 13-to-15-year-old girls actually dropped three percent from 2006.

NRF Group Offers Payment Consistency Guidelines
May 2nd, 2008

With an eye on retailers having to juggle payment systems between many varied environments–far beyond merely online and in-store–a National Retail Federation division this week introduced a set of guidelines called the Retail Transaction Interface, which it has dubbed “the first service-oriented architecture service interface schema and technical specification for the retail industry.”

“By making existing POS transaction functions available as SOA Services, RTI will enable the business logic behind these services to be easily reused for other customer and associate touch-points such as self checkout, fuel at grocery stores, kiosks, shop on the web, store within a store, portable shopper, mobile line buster and other complementary store solutions,” said a statement from the NRF’s Association for Retail Technology Standards (ARTS). Execs with Big Lots and BJ’s Wholesale Club represented retailers in a committee dominated by tech vendors.

Best Buy Using IT To Try And Limit Geek Squad Snooping
May 2nd, 2008

With a privacy invasion trial about to begin, Best Buy’s IT department will be conducting more frequent remote audits of the chain’s Geek Squad tech support department.

“Using powerful mainframes at Best Buy’s headquarters in Richfield, the company now scans several hundred Geek Squad computers each night to see if customer data is stored appropriately,” said a story in the May 1 edition of the Minneapolis Star-Tribune. “Previously, these audits were done only several times a year.” Best Buy is also setting up a system where customer files can only be viewed by the file names, without personal content. In addition, the retailer has now banned thumb drives by its Geek Squad technicians.

Search Through Blog Blurbs
Search Through All Stories
Quickly catch-up on the latest in E-Commerce and Retail Tech with our free weekly newsletter, with urgent bulletins as news merits.
StorefrontBacktalk will never sell your E-mail address to anyone at anytime.
Evan Schuman is the former retail technology editor for eWEEK.com, PCMagazine, CIOInsight and retail reporter for RISNews and Consumer Goods Technology. Having covered IT issues for 21 years - and other stuff like legal affairs, politics, Wall Street and the environment for about eight years before that - Schuman is in a good position to gripe about technology trends and sometimes accidentally make a good point.
Trick Or Treat? New PCI Version To Be Here By Halloween
By this Halloween, the PCI Council will unveil the first major revision of the PCI DSS payment card security program in two years. But with the council not releasing any true details about the changes, nervous retailers are truly wondering "Trick or Treat?"
In E-Commerce Satisfaction: Netflix, QVC On Top; PCMall, Home Depot On Bottom
That which keeps consumers satisfied seems to be part of an E-Commerce site's culture, as top (and bottom) players tend to show little movement, year to year. The latest results from measurement firm ForeSee Results seem to reinforce that.
Delegation Can Be Good, And A Half-Dozen Other Security Tips
From his perch in the world of security, Guestview Columnist David Taylor sees delegation as a good thing. Some of the retailers with the best strategies have figured out how to "deputize" internal audit, HR, data owners and store managers and give them specific things to do, from employee education to access monitoring to policy enforcement.
Dave & Buster's Data Breach Indictment: Apps Crash For The Bad Guys, Too
It was April 2007 when a pair of cyberthieves from the Ukraine and Estonia set out to try and grab payment card data from the 49-store Dave & Buster's restaurant chain. But according to a federal indictment and U.S. Secret Service affidavit unsealed May 12, 2008, the pair quickly discovered that software can be an equal-opportunity crasher.
TJX Gets 99.5 Percent Signoff With MasterCard Banks
When TJX announced a MasterCard agreement last month to pay $24 million for data breach costs stemming from the industry's worst payment card data breach, it was contingent on at least 90 percent of the banks agreeing. No surprise, but TJX made that acceptance rate with room to spare, coming in at 99.5 percent.
Applying Internet Security To RFID
NeoCatena Networks has in the wings a product designed to stop fraudulent or bad tag data from getting into the system from the supply chain.
FTC To Hold Contactless Hearing In Seattle
Retailers focused on contactless payment might want to circle July 24, 2008, on their calendar. That is when the U.S. Federal Trade Commission will hold a hearing in Seattle "to explore the growth of contactless payment systems and the implications for consumer protection policy."
Macys Shutting Down Bloomingdale's Catalogue
Guess this is what the cliche-afflicted would call a "sign of the times." Macys is killing the Bloomingdale's catalog while Amazon.com is selling copies of Bloomingdale's 1886 catalog for $12. (Can you imagine the number of out-of-stocks in that thing?)
U.S. Watched 11.5 Billion Web Videos In March
For e-tailers who still think that Web video may be a fad, consider this stat: In March, U.S. Internet users watched 11.5 billion online videos. That's a 13 percent gain from the prior month and a 64 percent gain from the identical month the prior year, according to Comscore.
Google Pushes Aside Yahoo For #1 Slot
Thanks in no small part to soaring traffic on YouTube, Google for the first time took the top slot in American consumer reach in April, besting Yahoo. But it took that top slot just barely, reaching 141 million Americans in April. Yahoo ranked second with 140.6 million visitors.
Arrests Made In California Debit-Card Skimming Scam
California authorities have arrested two men in connection with another retail card-reader switch scam, an effort that police say brought in about $225,000 from 222 victims who swiped their debit cards at a regional grocery chain.
Self-Checkout Psychology: Losing The Customer's Trust
With the many new self-checkout offerings being introduced this week from the likes of IBM, NCR and Fujitsu, it's not a bad idea to focus on what will truly decide whether these machines do anything to help retailers.
Self-Checkout: It's Not Just For Lanes Anymore
With the nation's largest casino town as its backdrop, IBM and NCR gambled that the ho-hum growth in self-checkout can become a winner if the systems are moved away from the front-of-the-store checkout lanes and moved back toward the deli, bakery and even in the middle of the cereal aisle. All in all, I'd rather take my chances at rolling a 10 the hard way.
The Home Depot Self-Checkout Machine That Wouldn't Take "No" For An Answer
Trying to collect some innocuous-sounding information from self-checkout customers, a self-checkout system at a Maryland Home Depot instead accidentally got itself embroiled in a privacy controversy.
The Data Breach Librarian Actually Gets Paid
The Florida librarian and data breach victim who successfully took Wells-Fargo and Sprint Nextel to small claims court was paid this week, something that some data breach observers doubted would ever happen.
Twitter Dead Last In Social Network Uptime
With its sites being unavailable for barely one hour over four months, MySpace has the best uptime of any major social networking site and Twitter (more than 37 hours of downtime during the same period) has the worst.
The Dangers Of Choosing The Wrong Wireless Approach
London-based Marks & Spencer is the RFID tag champ. Attaching 350 million a year to items of clothing, they even blow past Wal-Mart when it comes to tagging individual items. Unfortunately, each and every one of those tags might have used the wrong technology.
Opposition To Tokenization A Lot More Than Token
GuestView Columnist David Taylor this week discovered that there's a lot more than token opposition to tokenization. One of the concerns is that companies have already spent money on encryption.
Microsoft Gives Up Yahoo Pursuit
Microsoft on Saturday (May 3) gave up its efforts to acquire Yahoo, declaring such an effort too expensive. "Despite our best efforts, including raising our bid by roughly $5 billion, Yahoo! has not moved toward accepting our offer," Microsoft CEO Steve Ballmer said in a letter to Yahoo CEO Jerry Yang.
Rite Aid Cuts Deal For Visually Impaired Web, POS Support
Rite Aid on May 1 announced an extensive set of E-Commerce and POS changes to accommodate visually-impaired consumers, admittedly under an implied litigation threat from advocacy groups. The $24 billion 5,000-store pharmacy chain joins an expanding list of national retailers who have agreed to make such changes, including 7-Eleven, RadioShack, Safeway, Trader Joe's and Wal-Mart.
Beware Of Mobile Customers Who Are Not Where You Think They Are
As retailers continue to experiment with mobile commerce, one potential problem is when mobile customers prove to be truly mobile. Let's say a national chain sends an E-mail blast to the cellphones of 10,000 Boston-area customers, inviting them to visit the store for a free sample on Wednesday.
Number Of 10-Year-Olds On Social Sites Soaring
Like it or not (place this father defiantly in the "not" category), children are using the Internet's social network sites at a younger age, with retail marketers hovering close by. How young? New stats show 17 percent of boys aged 10-12 used such sites last year, which is more than double the 8 percent who used social sites in 2006, according to the Harris Poll.
Do Retailers Really Maintain A Secure Environment?
This wonderful piece comes courtesy of that time-honored daily newspaper tradition, the police blotter. A woman walks up to an ATM at a Hannaford's grocery store. She connects a laptop to the ATM until an alarm goes off, at which point she packs up and leaves.
NRF Group Offers Payment Consistency Guidelines
With an eye on retailers having to juggle payment systems between many varied environments—far beyond merely online and in-store—a National Retail Federation division this week introduced a set of guidelines called the Retail Transaction Interface.
Best Buy Using IT To Try And Limit Geek Squad Snooping
With a privacy invasion trial about to begin, Best Buy's IT department will be conducting more frequent remote audits of the chain's Geek Squad tech support department.
Microsoft Leaning Toward Going Hostile To Get Yahoo
Microsoft is "leaning toward going hostile in its pursuit of Yahoo," with an announcement "likely" on May 2.
Which Do You Want, Buddy? Compliance Or Security?
GuestView Columnist David Taylor this week suggests that, today, only a small minority of retailers says that they are getting much value from their security investments. Examples abound: Intrusion alerts that are ignored due to lack of staff, firewalls with rules that are out of date, intrusion detection systems that have not been tuned to minimize the false positives and encryption keys that are never changed. Fixing this stuff is not expensive, but it's not fun either.
Cash Usage Rising Sharply In Britain
British retailers are seeing a resurgence in cash purchases, mostly due to a weak economy and consumers who are "nervous about borrowing or spending on debit cards," according to a new report from the British Retail Consortium (BRC). But the question remains whether the consumer reactions that are pushing cash usage in the U.K. are likely to be replicated in other parts of the world.
Google's New Technique To See Pictures, Rather Than Merely Read Captions
Google says it has concocted a better way of searching for Web images, one that involves image-recognition to "see" what the image depicts as opposed to just reading the accompanying text. This technique, called Visual Rank, has tremendous potential to shake up E-Commerce, which heavily relies on product images.
Hannaford CIO: We Need To Spend Millions, Go Well Beyond PCI
Hannaford CIO Bill Homa, overseeing a data breach probe that exposed some 4.2 million payment cards, said this week that his grocery chain needs to go well beyond PCI to try and be secure, an effort he predicted would cost his department millions of dollars "but not tens of millions."
Pizza Hut Delivering A Web Virtual Waiter
Pizza Hut is taking the "other people who bought also liked" approach mastered by Amazon.com and is trying to apply it to pizza and breadsticks and their own Web site. The service initially sounded like an ordinary Web upsell package, but a demo of the service suggested it might be more sophisticated than that.
Javelin Report: Retailers Have No Reason To Support Contactless Payment
Although contactless payment has tremendous potential to advance payments and set the stage for mobile commerce, it's suffering from benign neglect from both retailers and the card brands—and banks, too. That according to a new contactless payment report from analyst firm Javelin Strategy & Research.
The Few. The Proud. The Incredibly Retail Geeky
The E-Commerce folk over at the National Retail Federation—Shop.org—are not so quietly putting out feelers for a new VP gig to pull in other e-tailers.
Wal-Mart Makes RFID Privacy Promises To Arkansas State Legislators
Wal-Mart executives this week promised Arkansas legislators that any product with a radio tag would be clearly labeled, as the retail giant tries to put the inventory-tracking devices on all products sold at Sam's Clubs by 2010.
Is This Retail Payment Data Breach A Trend?
Police near Canton, N.Y., are investigating a payment card data breach at a local retail chain that sounds oddly similar to the Hannaford and other related recent breaches. Is this a coincidence or a gang focused on retail data?
Startup Promises Hard-To-Duplicate RFID Chips
A difficult to duplicate RFID chip? That's the claim of an RFID startup, which is using MEMs resonators to create a unique signal, or "voiceprint," which can't be cloned and can be used to authenticate the chip.
EBay's PayPal Gets Into In-Store
EBay's PayPal is following the path set by other alternative payment players and is starting to appear in physical stores. It's not a huge chain, but it's a start. Moosejaw Mountaineering and its seven stores will now accept PayPal and the chain is also starting to use in-store kiosks to display online customer reviews.
Did Someone Forget To Tell Amazon About The Recession?
We've been seeing a bizarre trend this national recession. It seems to be hitting hard the companies that expected to be hit, the ones that cut back spending in anticipation of the downturn. Lo and behold, after cutting back on customer service and marketing programs, they see revenues fall. Did they correctly predict the sales drop or did they unintentionally cause the sales drop?
Is Starbucks' Continuing Traffic Plunge Payback For Web Weakness?
Starbucks on April 23 cut back its financial projections for the year, citing continuing declines in its store traffic, especially in California and Florida. This is announced just a few weeks after Starbucks said it would shake up its Web presence.
China Becoming A Very Dominant POS Player
China POS shipments soared some 19 percent last year, figures that show China's retailers quickly becoming some of the biggest POS purchasers in the world, according to a new global POS report from consultancy IHL Group.
The Secret To Protecting All That Is Confidential
GuestView Columnist David Taylor this week argues that one of the hardest parts of extending PCI controls to other confidential data is the application of Identity and Access Management (IAM) that crosses applications and platforms, without encountering the "analysis paralyses" that comes with trying to implement Single Sign-on.
A Trio Of Credit Card Conundrums
If there's one thing that the last year of credit card catastrophes has made undeniable it's that mixing credit cards, retailers, banks and card brands is unpredictable and a lot more complex than anyone wants to believe. With that in mind, StorefrontBacktalk has been asking retailers, lawyers and other experts (and gadflies) for their favorite credit card security issue brain teasers. How many can you figure out?
Retailers Wrestling With How To Use Consumer-Generated Video
When North Face—a unit of the $7.2 billion VF Corp. and a major manufacturer of athletic gear and clothing—officials started looking at the tidal wave of consumer-generated Web videos being created, they saw consumer passion. It's the same kind of passion that exists in sports enthusiasts, which is who the retailer needs to reach.
Top E-Commerce Complaint: Web Images That Don't Look Like The Product
E-Commerce customers have several complaints about online buying, but the top concerns are Web images that don't match the real thing and sites that make it difficult to easily ask any questions, according to a late March Opinion Research Web survey of 1,092 consumers.
Waiter? Stylus, Please
One of the most annoying parts of many a casual restaurant outing is at the end, when you just want to say "Check, please" and all wait staff seems to sense this and decide instead to join the Waitress Relocation Program. Microsoft has created a device that permanently sits on the table.
NRF Lobbying Group Opposes Behavioral Advertising Warning
The National Retail Federation's Shop.org is lobbying the U.S. Federal Trade Commission to not flag consumers when their shopping behaviors are being tracked online, arguing that it would merely serve to frustrate those consumers.
More Than 10 Billion U.S. Web Videos Watched In February
In case there are two or three of you who are still skeptical about whether Web video will have an impact, consider these new figures. In February, U.S. Internet users viewed more than 10 billion online videos, which represents a 3 percent gain versus January (despite February being two days shorter) and a 66 percent gain versus February 2007, according to ComScore.
Extending PCI Standards To Protect All Confidential Data
GuestView Columnist David Taylor this week questioned why PCI doesn't protect non-payment card information, such as Social Security numbers. Any security consultant will tell you that it's important to have a data classification scheme. Although it makes a nice spreadsheet, we have seen only a few leading-edge merchants and banks that actually attempt to enforce it and use it to drive access controls. Why? Taylor has concluded that it's for a single strategic reason: "Data classification is boring."
PA-DSS Formally Unveiled
The PCI Security Standards Council on April 15 officially rolled out version 1.1 of the Payment Application Data Security Standard (PA-DSS). The specifics of the standard were spelled out last November and this is just the expected formal unveiling.
A Kiosk That Toys With Long-Term CRM Rewards
A DVD rental kiosk outfit has rolled out a kiosk that keeps track of orders and awards free videos for frequent shoppers. The idea of a kiosk that has a long-term memory and an active CRM component is a wonderful next step (OK, a baby step) for intelligent kiosks.
A 600-Foot Passive RFID System?
RFID vendor Mojix has rolled out a new RFID system that it says can read passive, Gen2-standard tags from 600 feet away; cover 250,000 square feet of area; and pinpoint tag location in 3D.
Walmart.com Wants Its Own Online Customer Forums
Wal-Mart is pushing to create online communities for its customers, where Wal-Mart employees can sit on the sidelines, take notes and be influenced, or so suggests the chief marketing officer for online operations at the world's largest retailer.
GuestView Column: Many QSAs Do Not Have The Background, Expertise To Assess PCI
GuestView Columnist Joel Weise—the chief technologist for Sun Microsystems GSS Security Program Office—argues that although there are many qualified security assessors (QSAs), "a few who simply do not have the background and expertise in systems security manage to distort the original intent of PCI."
$5 Billion Blockbuster Wants To Buy $12 Billion Circuit City
Blockbuster is trying to acquire Circuit City--a chain that is reporting twice its annual revenue--by offering a 50 percent per-share premium, Blockbuster announced early on April 14.
eBay's Australia Experiment: Ban All Payment Methods Other Than PayPal
As of June 17, anyone in Australia buying from eBay online will be told: "PayPal" or "Forget It, Pal." With the exception of in-person pickups and cash-on-delivery, plus a handful of large-ticket items, sellers will be required to offer eBay-owned PayPal as a payment method by May 21, in anticipation of the June 17 ban on anything else.
Advance Auto Parts Breach Included Unencrypted Payment Data From 2001
Unencrypted customer credit card information dating back to 2001 was among the customer payment data stolen from as many as 56,000 customers of Advance Auto Parts, according to one company official, who added that the chain is not PCI compliant.
McDonald's Mobile Trial Raises Question: Who Owns The Data?
A group of 109 McDonald's restaurants in the Salt Lake City region are doing a mobile commerce trial, with participating consumers getting free iced coffee. Although those 109 stores are barely one coffee bean's worth, given the $22.8 billion chain's 31,377-store network, the trial is interesting both for its capabilities and for how much data-control McDonald's was willing to give up.
Hannaford Kills TV Commercials After Station Reports On Data Breach
Saying only that a TV station's news coverage of its data breach was too "aggressive," the Hannaford grocery chain has canceled its commercials from the Portland, Maine, CBS affiliate. The station, which announced Hannaford's decision on its own news site, said the chain declined to site any errors or problems with the coverage.
Best Buy Change Sees 10X Increase In CRM Participants
When Best Buy removed annual fees from its bonus card, the company yielded about 10 times the number of shoppers opting to sign up for its rewards program.
European Commission Cracking Down On Search Engine Privacy
The European Commission is cracking down on search engine data-retention, with a new proposed rule that search engines should delete personal data about their customers within six months.
Forrester: E-Commerce Dollars Growing But Cannibalization A Big Factor
E-Commerce is growing sharply—much more rapidly than in-store sales. It grew some 21 percent, to $175 billion last year, crediting E-Commerce with six percent of all retail sales, according to new figures from Forrester Research.
The Dangers Of Manual PCI Reviews
Guest Columnist David Taylor sees manual reviews as one of most serious threats to retail security. As one security manager put it: "We are so far behind in tracking down the alerts, we could have been breached a month ago and still not know it."
RFID Prototype Aircraft Delays Not An RFID Issue
With reports out this week that Boeing's much-celebrated upcoming aircraft—the 787 Dreamliner—would be again delayed because of technology problems, some wondered if the delays involved
the plane's extensive RFID experiments. Not so, says Boeing.
ISPs Tracking User Activity Much More Than Is Generally Known
ISPs have been quietly expanding their use of deep-packet inspection. They are capturing everything a user does—to the point where "at least 100,000 U.S. customers are tracked this way, and service providers have been testing it with as many as 10 percent of U.S. customers, according to tech companies involved in the data collection."
Sears Online Soaring 20 Percent
The Web world defies prediction—or does it? Conventional wisdom would have the new up-and-coming retailers faring better online, while the old-style bigbox merchants lag behind. And yet, Starbucks has had far more online troubles than it should have while Sears is soaring online.
Piggly-Wiggly Trying To Recreate The Grocery Layout
Focusing on recent improvements in refrigeration technology, the 115-store Piggly Wiggly is pledging to radically revamp its store. The grocery chain is shaking up product positioning issues—all frozen foods are kept together, for example—that have been considered sacrosanct for decades.
Microsoft To Yahoo: Accept Buyout Now Or It Will Be Hostile And For Less Money
Microsoft's board has given Yahoo's board three weeks to either agree to a takeover deal or it will go hostile. In a Saturday letter from Microsoft CEO Steve Ballmer to the Yahoo board, Ballmer strongly hinted that if the deal goes hostile, the original $44.6 billion offer would be reduced.
Virtually Instant Card-Swipe Encryption Device To Be Unveiled Next Week
Amidst the sea of security announcements slated for the RSA Conference next week is a card swipe device that claims almost instant encryption of cards, avoiding the problem of card data being grabbed before encryption. Such claims are commonplace, but the VeriShield Protect from Verifone is making claims that—if ultimately proven true—would significantly advance retail payment security.
Home Depot CIO Steps Down
Home Depot CIO/EVP Bob DeRodes has resigned and will leave the $77 billion home improvement chain "at the end of the year," according to a statement Home Depot issued Thursday. DeRodes will continue to run IT until he leaves, the statement said, as the chain starts a search for his replacement.