Saturday, July 26, 2008

Battles and Bids Over Pay by Touch


Pay By Touch, with revenues of approximately $70 million and at its height some 750 employees, has grown mainly through acquisition. Between 2005 and 2007, it bought at least six companies, including rival biometrics firm BioPay, and CardSystems Solutions, an Arizona-based credit-card payment processor. In December, 2006, Pay By Touch paid $100 million in cash and stock to acquire original loyalty marketer S&H Solutions, the 110-year old company behind S&H green stamps.

With its fingerprint payment technology slow to pay off, Pay By Touch this year started focusing on other lines of business. It signed grocers including Ohio's Dorothy Lane Markets and Harps Food Stores of Arkansas to a loyalty marketing program aimed at offering personalized coupons and deals to consumers who scanned their fingerprints with an in-store kiosk. Consumers who joined the program received personal offers and coupons based on purchasing history. Another line of business aimed at using fingerprints to help make check-cashing more secure had gained some traction with small banks.

Control Battles

But the company still needed more cash to fund operations. Last February, Pay By Touch raised $163 million from three hedge funds—Plainfield, Och-Ziff Capital Management (OZM), and Farallon Capital Management. Plainfield secured its portion of the loan, worth about $50 million, with Pay By Touch shares owned personally by company founder Rogers. Those shares amount to a 20% ownership stake in Pay By Touch but carry "supermajority" voting rights that give the holder control of 64% of the voting shares, enough to control the company.

The loan agreement calls for Plainfield to assume control of Rogers' shares in the event of a default. On Oct. 15, Plainfield's court complaint declared Pay By Touch in default because it failed to deliver its 2005 audited financial results by an Aug. 31, 2007, deadline. That set off a volley of lawsuits and legal moves. Having assumed Rogers' voting power, Plainfield created a new board of directors for Pay By Touch, reinstating two directors that Rogers had suddenly fired on Oct. 11, and a third who had resigned on Oct. 12.

On Oct. 18, Pay By Touch's Delaware lawyers disputed the validity of Plainfield's action, citing a technicality in the company's bylaws. Plainfield then issued a new order that would have seated Plainfield's new board on Nov. 1. But late on the night of Oct. 31, four Pay By Touch employees filed an involuntary petition aimed at forcing the company into bankruptcy. Rogers has also sought personal bankruptcy, in a case filed in the same court on the same day. Rogers didn't respond to an e-mail seeking comment, and Pay By Touch declined to make him available for an interview.

Usually a bankruptcy filing stays other pending litigation, but the judge in the bankruptcy case has allowed the Delaware case to proceed. A Delaware judge has issued a status quo order, forcing the company into management under the care of a temporary custodian and a temporary board of directors. A trial over control of the company in Delaware is set for Dec 21.


For More Info

New DNS exploit now in the wild and having a blast


About two weeks ago, we covered the release of a DNS security fix meant to patch a vulnerability in the system that matches domain names with IP addresses. The flaw had been discovered by security researcher Dan Kaminsky some months earlier but, at the time, details on the exploit were being kept secret. That information has since leaked thanks to an accidental blog post by someone at Matasano Security. Fast forward four days, and hackers, enterprising little children that they are, have released an exploit aimed squarely at the vulnerability.

This would be less of an issue if the widely released patch from two weeks ago had been fully deployed, but a number of companies or ISPs don't seem to have gotten the memo. Accordingly to Kaminsky, some 52 percent of DNS servers are still vulnerable to the attack. This is a marked improvement from the 86 percent vulnerability rate in the days immediately following the patch's release, but it's still far too high, especially with dangerous code now squirreling its way across the Internet. Patch deployment is not an instant process, even if the company is on the ball, but we'll hopefully see the number of patched DNS servers skyrocket in the next few days.

Some publications have dubbed the attack Metasploit, but that term refers to the open-source Metasploit Framework that was used to develop it. As for the exploit itself, it's a new variation on a classic DNS poisoning theme. It disrupts the normal translation functions of a DNS server, causing it to redirect users to websites other than the ones they intended to visit. A poisoned DNS server, for example, could send someone to www.RussianMalware.com when they had actually typed www.google.com into the address bar. DNS poisoning isn't new—vulnerabilities have existed for over a decade—but the one Kaminsky discovered increases the power of a successful attack.

Kaminsky has now detailed the methodology of a standard DNS poisoning attack and provides additional information on the vulnerability he discovered. As he describes it, a DNS lookup request is essentially a race between a good guy and a bad guy, each of whom possess certain advantages. The good guy knows when the race begins, and he knows the secret code that's been sent along with that request in order to verify that the response coming back is actually authentic. The bad guy doesn't have this code, but he actually decides when the request goes out, and he knows about the request before the good guy does.

Normally, the good guy wins the vast majority of these races, and the bad guy is forced to race again and again in an attempt to guess the right authentication value before the good guy provides correct information. What Kaminsky discovered, and what the new hack exploits, is a vulnerability in the recursive nature of the DNS system. DNS is designed to "bump" your request along until it reaches a server that can answer the client's request. If you ask www.DNSTarget.com for a location it doesn't know, DNSTarget.com can refer you to A.DNSTarget.com, B.DNSTarget.com, and so on, until it finds the requisite information. A.DNSTarget.com is what's called an "in-bailiwick" relative to DNSTarget.com—the information that comes back from that server is automatically trusted and passed on.

Therein lies the problem. Instead of launching an attack straight at www.dnstarget.com and losing 99 percent of the time, the bad guy attacks one of the recursive in-bailiwick servers and then feeds it false information. The in-bailiwick server communicates that data back to DNSTarget.com, which then caches the response—that way, it doesn't need to look the information up again. Problem is, the server has cached poisoned information and doesn't know it. Until that information drops out of the server's cache, the bad guy has effectively won the race.

For More Info