Natural News Store

Showing posts with label Barclays. Show all posts
Showing posts with label Barclays. Show all posts

Wednesday, March 18, 2009

The Real AIG Scandal: It's not the bonuses. It's that AIG's counterparties are getting paid back in full.

By Eliot Spitzer
Posted Tuesday, March 17, 2009, at 10:41 AM ET

American International Group Inc. Click image to expand.

Everybody is rushing to condemn AIG's bonuses, but this simple scandal is obscuring the real disgrace at the insurance giant: Why are AIG's counterparties getting paid back in full, to the tune of tens of billions of taxpayer dollars?

For the answer to this question, we need to go back to the very first decision to bail out AIG, made, we are told, by then-Treasury Secretary Henry Paulson, then-New York Fed official Timothy Geithner, Goldman Sachs CEO Lloyd Blankfein, and Fed Chairman Ben Bernanke last fall. Post-Lehman's collapse, they feared a systemic failure could be triggered by AIG's inability to pay the counterparties to all the sophisticated instruments AIG had sold. And who were AIG's trading partners? No shock here: Goldman, Bank of America, Merrill Lynch, UBS, JPMorgan Chase, Morgan Stanley, Deutsche Bank, Barclays, and on it goes. So now we know for sure what we already surmised: The AIG bailout has been a way to hide an enormous second round of cash to the same group that had received TARP money already.

It all appears, once again, to be the same insiders protecting themselves against sharing the pain and risk of their own bad adventure. The payments to AIG's counterparties are justified with an appeal to the sanctity of contract. If AIG's contracts turned out to be shaky, the theory goes, then the whole edifice of the financial system would collapse.

But wait a moment, aren't we in the midst of reopening contracts all over the place to share the burden of this crisis? From raising taxes—income taxes to sales taxes—to properly reopening labor contracts, we are all being asked to pitch in and carry our share of the burden. Workers around the country are being asked to take pay cuts and accept shorter work weeks so that colleagues won't be laid off. Why can't Wall Street royalty shoulder some of the burden? Why did Goldman have to get back 100 cents on the dollar? Didn't we already give Goldman a $25 billion capital infusion, and aren't they sitting on more than $100 billion in cash? Haven't we been told recently that they are beginning to come back to fiscal stability? If that is so, couldn't they have accepted a discount, and couldn't they have agreed to certain conditions before the AIG dollars—that is, our dollars—flowed?

The appearance that this was all an inside job is overwhelming. AIG was nothing more than a conduit for huge capital flows to the same old suspects, with no reason or explanation.

So here are several questions that should be answered, in public, under oath, to clear the air:

What was the precise conversation among Bernanke, Geithner, Paulson, and Blankfein that preceded the initial $80 billion grant?

Was it already known who the counterparties were and what the exposure was for each of the counterparties?

What did Goldman, and all the other counterparties, know about AIG's financial condition at the time they executed the swaps or other contracts? Had they done adequate due diligence to see whether they were buying real protection? And why shouldn't they bear a percentage of the risk of failure of their own counterparty?

What is the deeper relationship between Goldman and AIG? Didn't they almost merge a few years ago but did not because Goldman couldn't get its arms around the black box that is AIG? If that is true, why should Goldman get bailed out? After all, they should have known as well as anybody that a big part of AIG's business model was not to pay on insurance it had issued.

Why weren't the counterparties immediately and fully disclosed?

Failure to answer these questions will feed the populist rage that is metastasizing very quickly. And it will raise basic questions about the competence of those who are supposedly guiding this economic policy.

Eliot Spitzer is the former governor of the state of New York. (And politically assassinated because he dared to get in the way of the very bankers that are looting our nations treasury.)

http://www.slate.com/id/2213942/

Tuesday, March 3, 2009

Barclays cards make contact with RFID tech

Beware the man in the middle…

By Tom Espiner

Published: 3 March 2009 07:59 GMT

Barclays Bank has rolled out a contactless Visa debit card.

As of yesterday, Barclays customers getting new or replacement cards will receive ones containing RFID technology. This contactless technology will allow them to use the debit card for transactions of up to £10, without entering a PIN.

Owners will still be able to use the debit cards for chip and PIN transactions and for bank machine withdrawals.

The protocol behind the contactless technology has not been made available to academic security researchers, Cambridge University researcher Steven Murdoch said on Monday.

Murdoch said: "The problem with the UK contactless system is that it's secret, which means we have to reverse-engineer it to point out vulnerabilities."

"Contactless payment has been rolled out but any security vulnerabilities will be pointed out after the banks can do anything about it," he told silicon.com sister site ZDNet UK.

Murdoch said that while security researchers were restricted from viewing the protocol, people with malicious intent would be able to examine it.

"I'm sure crooks will have a copy of the spec," he said. "People can get hold of a copy if they sign a contract saying they will not make any reports [about the protocol]. Any criminals could get hold of a copy of the specification but academics are at a disadvantage."

A Barclays spokesperson told ZDNet UK on Monday that there had been extensive third-party testing of the contactless system, and said that security risks around contactless payments had been mitigated.

"Contactless is designed for small transactions, while users will periodically be asked for a PIN," said the spokesperson. "The card uses dynamic data authentication - in which a unique secret code is generated to authenticate each transaction - while the chip contains different information than the magnetic strip, to prevent cloning."

Tests have concluded that it would not be economically viable for criminals to subvert the system, the Barclays spokesperson added. "The cost of intercepting the information doesn't justify how much could be made out of the information," said the spokesperson.

Cambridge University researchers have said they have serious security concerns about chip-and-pin payment systems. Researchers Ross Anderson, Saar Drimer and Murdoch published a paper on Thursday detailing security flaws in the Chip Authentication Programme (CAP) used for UK payments cards. The main problem they identified is that online card payment systems using readers had been optimised for usability, to the extent of sacrificing security.

The researchers said they had found design errors in CAP, including a failure to ensure "freshness of responses". Murdoch said that there were no assurances in the system that card responses were not old or generated in advance, allowing for a man-in-the-middle attack.

"The lack of freshness could be exploited through a fake chip and PIN terminal in a shop," said Murdoch. "The bank asks for a response from a card reader that it hasn't seen before but that response could be hours or even days old."

In addition, authentication tokens are reused between point-of-sale and online banking transactions, Murdoch added. This effectively opens up the possibility of a man-in-the-middle attack online, he said.

Apacs, a UK trade association for the payments industry, said that it was familiar with the report by the Cambridge researchers. "The report hasn't said anything we are unaware of," a spokesperson for the group said. "It's important to bear in mind that those banks that have deployed two-factor authentication have reported a fall in fraud losses."

The spokesperson added that the Cambridge University researchers tested security to a different set of requirements to banks. "Banking industry requirements are usability - that card processes are easy for customers to understand and that cards are easy to transport," said the spokesperson.

Original article: Barclays rolls out contactless debit card from ZDNet UK

http://www.silicon.com/financialservices/0,3800010322,39401765,00.htm