Vulnerabilities / Threats // Insider Threats
5/12/2010
11:09 AM
50%
50%

Fiserv Demos ZashPay, iPad Banking

Rich-media interfaces and P2P payments promise to transform online and mobile banking.

At the Finovate conference in San Francisco Tuesday, technology provider Fiserv demonstrated a prototype of its online banking and payment application for the Apple iPad, including a preview of ZashPay, a person-to-person (P2P) payments service launching early this summer.

"We demonstrated a full online banking and payment application, all in a downloaded iPad app," said Erich Litch, SVP & GM, consumer services, Fiserv, in a phone interview. "It's a rich online banking experience with personal financial management tools, budgeting, goals, online payments, messages, managing personal payments, transfers and self-service."

Instead of the multi-layered approach of a Web site containing perhaps 100 different hierarchically organized pages, the iPad app compresses the entire online banking experience to a single, easy-to-navigate layer. "You can swipe, from component to component, things like alerts, pending payments, account balances, goals and payments," said Litch.

As an alliance partner of Microsoft, Fiserv is also developing rich-media Microsoft Silverlight applications for web and mobile deployment, according to Litch.

With its iPad demo, Fiserv also previewed ZashPay, which will enable consumers to send money to anyone using only an e-mail address or mobile phone number. "ZashPay will be accessible through the online banking sites of participating banks and credit unions and will use consumers' existing financial accounts rather than require them to sign up for and fund a third party account," stated Litch in a statement.

Senders will be able to transfer funds in as little as one business day to recipients having an account at a participating financial institution. From the outset, ZashPay will be available to a network of more than 3,100 financial institutions and 16 million consumers that already use Fiserv's CheckFree RXP online bill payment service. Other recipients will be able to claim their money at the ZashPay site. Confirmation of payment will be made to the sender via e-mail or text message.

Although the company would not disclose what it charges participating banks for the service, Fiserv has identified $0.50 as the optimal price for a transfer, comparable to the cost of a postage stamp. Participating financial institutions will be able to set their own fee structures based on market demand, customer segmentation or other factors.

Transactions will be processed through the Fiserv payment network, which in 2009 processed 1.35 billion online bill payments with over $600 billion in transaction value. By comparison, PayPal processed $71 billion in transactions in 2009.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2009-5027
Published: 2014-12-26
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2010-2062. Reason: This candidate is a reservation duplicate of CVE-2010-2062. Notes: All CVE users should reference CVE-2010-2062 instead of this candidate. All references and descriptions in this candidate have been removed to pre...

CVE-2010-1441
Published: 2014-12-26
Multiple heap-based buffer overflows in VideoLAN VLC media player before 1.0.6 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted byte stream to the (1) A/52, (2) DTS, or (3) MPEG Audio decoder.

CVE-2010-1442
Published: 2014-12-26
VideoLAN VLC media player before 1.0.6 allows remote attackers to cause a denial of service (invalid memory access and application crash) or possibly execute arbitrary code via a crafted byte stream to the (1) AVI, (2) ASF, or (3) Matroska (aka MKV) demuxer.

CVE-2010-1443
Published: 2014-12-26
The parse_track_node function in modules/demux/playlist/xspf.c in the XSPF playlist parser in VideoLAN VLC media player before 1.0.6 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty location element in an XML Shareable Playlist Format...

CVE-2010-1444
Published: 2014-12-26
The ZIP archive decompressor in VideoLAN VLC media player before 1.0.6 allows remote attackers to cause a denial of service (invalid memory access and application crash) or possibly execute arbitrary code via a crafted archive.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.