On MovieTome: P.Diddy reviews HANCOCK…this is good
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers, News.com
Posted on ZDNet News: May 16, 2006 1:40:00 AM

SAN FRANCISCO--Proposed new security rules for credit card-accepting businesses will put more scrutiny on software, but let them off the hook on encryption.

The update to the Payment Card Industry (PCI) Data Security Standard, due this summer, responds to evolving attacks as well as to challenges some businesses have with the encryption of consumer data, Tom Maxwell, director of e-Business and Emerging Technologies at MasterCard International, said here Monday.

The proposed update includes a requirement to, by mid-2008, scan payment software for vulnerabilities, Maxwell said in a presentation at a security conference hosted by vulnerability management specialist Qualys. Currently, merchants are required to validate only that there are no security holes in their network. "There is an increase in application-level attacks," Maxwell said.

While security stands to benefit from a broader vulnerability scan, another proposed change to the security rules may hurt security of consumer data, critics said. The new version of PCI will offer merchants more alternatives to encryption as a way to secure consumer data.

"Today, the requirement is to make all information unreadable wherever it is stored," Maxwell said. But this encryption requirement is causing so much trouble for merchants that credit card companies are having trouble dealing with requests for alternative measures, he said.

In response, changes to PCI will let companies replace encryption with other types of security technology, such as additional firewalls and access controls, Maxwell said. "There will be more-acceptable compensating and mitigating controls," he said.

While PCI is good in principal, relaxing encryption requirements is not, said Paul Simmonds, a representative of the Jericho Forum, a group of companies that promotes open security technologies. "It basically means that if you hack the system, you get the data," he said. "I can't think of a good alternative for encryption."

The challenge with encryption is that older payment systems were not built to support the scrambling technology, said Qualys CEO Philippe Courtot. "Encryption is the ultimate measure of security, but the current applications have not been designed with encryption in mind," Courtot said

The PCI security standard was developed by MasterCard and Visa and went into effect last year. It aims to reduce the risk of an attack by mandating the proper use of firewalls, message encryption, computer access controls and antivirus software. It also requires frequent security audits and network monitoring, and forbids the use of default passwords. Retailers that don't comply may face penalties, including fines.

  • Talkback
  • Most Recent of 22 Talkback(s)
Online Super Payment Gateways
I have worked in the real time payment gateway industry for twelve years I have become accustomed to the security vulnerabilities of our system. It keeps us all employed!!

Then along comes thes... (Read the rest)
Posted by: fooj Posted on: 03/09/07 You are currently: Logged In | Log out
Another thing... DarbyOhara   | 05/16/06
Many lawyers ARE the criminals... kokuryu   | 05/17/06
Time for an upgrade jheine   | 05/16/06
Furthermore... techboy_z   | 05/16/06
Another thing... BlazeEagle   | 05/17/06
How about making it the law Shelendrea   | 05/16/06
Hey, silly... techboy_z   | 05/16/06
=-p Shelendrea   | 05/16/06
This is ILLEGAL kokuryu   | 05/17/06
SMB encryption and access controls schwana   | 05/16/06
Active Discussion group for PCI Data Security Standard - pciFile.ORG QDSP   | 05/16/06
Solve the real problem - Merchants never needs my credit card drorharari   | 05/17/06
'The Credit' redtalmage   | 05/17/06
'The Credit' drorharari   | 05/17/06
Already available kokuryu   | 05/17/06
Citi has "Virtual Account Numbers" JED!   | 05/18/06
great news for hackers eaze   | 05/17/06
I Have Had My Account Attacked Twice hal3650@...   | 05/18/06
Credit Cards not needed for on-line purchases jack@...   | 06/21/06
Online Super-Gateways - Your Thoughts?? fooj   | 09/14/06
Bank of America Boycott Credit Cards KheshireKat   | 02/28/07
Online Super Payment Gateways fooj   | 03/09/07

What do you think?

advertisement
advertisement