Showing posts with label PCI. Show all posts
Showing posts with label PCI. Show all posts

Friday, April 7, 2017

Security Threats Facing Online Payment Gateways


[Guest Post by Arthur Jones]
Most experts agree: it is a brave new world for payment gateway providers, which presents both opportunities and challenges. For nearly a decade, cyber security professionals have been warning about the ongoing rise of cybercrime. Agencies like the FBI regularly put out reports detailing the threats to the financial services industry, in particular. As outlets like TechRepublic have reported, this trend is only going to continue, and we may see record levels of cybercrime activity this year.
What kind of threats can we expect to face for online payment gateways? Let’s look at some major security challenges and how they may be addressed payment gateway providers as they continue to innovate and remain competitive in the marketplace.
Information Attacks
It is safe to say that a data breach is one of the most serious threats for payment gateways. Attacks like these can come in many different forms, and because they are smaller and require fewer resources, they are easier to carry out and occur much more frequently. If an attacker gets their hands on sensitive financial information, the losses can be catastrophic, putting companies at the risk of irreparable damage to customer trust.
There are many ways for attackers to breach a system. Phishing attacks consist of fake emails that can trick users into opening harmful links and installing malware or giving up sensitive information. Such attacks can open up system vulnerabilities, giving attackers access to valuable information.
Untrustworthy insiders can also get access to sensitive information and compromise security systems from within the business. Or hackers can gain access to sensitive systems through security breaches in compromised hardware and software.
Credit Card Fraud
Payment gateway providers may be concerned about threats to their internal data systems, but there are external threats to take into account as well. Attackers use skimming devices and other technologies all of the time, which can steal credit card information wherever a credit card is used. After this sensitive information is acquired, attackers can commit credit card fraud wherever they please, which can go undetected until banks or card holders notice suspicious activity related to any compromised accounts.
This is a sort of “death by a thousand cuts” threat for payment providers, as constant small attacks on credit card holders’ information can result in the gradual erosion of customer trust.
DDoS Attacks
Distributed denial of service (DDoS) attacks are a little trickier to deal with, as they can be very powerful and destructive on a systematic level. DDoS attacks are becoming more sophisticated, in that the attackers are finding specific structural weaknesses in internet infrastructure, and then exploiting those weaknesses to bring down large and powerful institutions. Additionally, the expanding internet of things (IoT) makes it much easier for attackers to use internet-connected devices like appliances, TVs, security cameras, and other machines to flood servers with requests, which crashes them.
Typically, only the largest financial institutions are targeted by these attacks. However, hackers are increasingly attacking broader internet structures like the DNS system, which can crash a wide range of businesses’ websites that are using the infrastructure. Fortunately, large attacks such as these have been less frequent, and most payment gateway companies will not have to deal with attacks like these as much. Nevertheless, a downed server poses a threat for payment gateway providers if they’re not able to process transactions in a timely manner.
Safer Transactions
It is important for cyber security professionals, payment gateway providers, and other financial services businesses to continue to develop secure technologies to protect their systems and data. The most promising avenues include advanced encryption, tokenization, and authentication methods, which go a long way towards cutting down on common cyber-attacks. The Payment Card Industry Data Security Standard (PCI DSS) is a powerful industry-wide tool to increase security with, and innovation in this field is welcome as well. Further, proper employee training can go a long way to reduce risk exposure. Ultimately, payment gateway providers and other tech and financial services businesses who innovate in these areas will come out stronger in the future.


Author Bio: Arthur Jones is a consultant for Allied Wallet. He is an innovator in eCommerce services and everything a company needs for success including a global payment gateway system, a prepaid affiliate debit card program, and much more. Arthur has extensive experience in the eCommerce and merchant services industry, and regularly writes about it for interested readers.


IMAGES:

Monday, September 28, 2015

The Chips Are Down

By now, most consumers who use credit cards have found that replacements for their old plastic have arrived with embedded chips in them. And most merchants have been receiving a barrage of calls for months from processing companies trying to convert them using the need for new chip-enhanced terminals as a selling point. A recent article in the NY Times highlighted the issue. This is a real thing that merchants and consumers alike need to pay attention to as the United States catches up to most of the rest of the world regarding the security of credit and debit payment systems.

Why This Is Important

Fraud protection is one of the main reasons that the chip is an important addition to the credit card. Stripes contain easily duplicated magnetically encoded information about the card and the card holder. For this reason, it has been very easy for criminals to steal this information using a small swiping mechanism and subject consumers to identity theft. These tiny devices have been embedded in the payment terminals built into gas station pumps, or used by waiters or waitresses at restaurants who take the card in order to swipe it in a payment station out of view. There are plenty of ways that the information can be stolen off of a magnetic stripe. But not so easily from a chip.

The main reason is that the chip is actually a small computer with encoded data that must communicate with a distant server in order to authorize the charge or debit. It does this by changing its code every time it is used. This may sound complicated, and it may take a second or two longer than swiping a magnetic stripe does, but it offers a nearly impossible to steal or duplicate transaction process. This is why card brands adopted the chip years ago virtually everywhere else. The USA is always a bit slow to catch up on this sort of technology due to the heavy regulations in place for all things financial and the reticence of major companies to engage in huge spending upgrades any earlier than they have to. But the benefits are going to be huge with regard to identity theft.

What This Means To Merchants

The basic thing that merchants need to be aware of is that they will now be responsible for identity theft issues that come from using duplicated magnetic stripes. If a cardholder provides a striped card, the merchant must verify the cardholder's identity or risk being liable for the transaction. This should be standard protocol anyway, but the processing companies are offering cheap or free upgrades to chip-enabled terminals to specifically avoid the costs associated with identity theft and they are going to be very serious about ensuring that merchants use this new tool. On the flip side, the protections involved with chip-based transactions should be higher than the old ones were with the stripe-based transactions.

Monday, March 10, 2014

New PayAnywhere (Free) Tablet Storefront Solution Is Here

First the good news: North American Bancard (NAB) has a new PayAnywhere branded mobile tablet-based processing program which offers the placement of a free counter-top system and some great new options built around a 10 inch Android tablet (plus an additional mobile card reader for phones or tablets). It is one of the most affordable processing solutions on the market that takes advantage of mobile solutions at highly competitive rates with a future-ready, upgradable combination of hardware and software. It will become EMV compliant and is consistently being updated on the software side to take advantage of the latest technology while offering more enhancements to merchants. The program is very similar to the previous Phone Swipe Tablet Program which NAB been providing, but without the high volume requirements.

Processing of Visa, MasterCard, Discover, American Express and the new PayPal card are all available with Next Day Funding and a lower swiped rate than Square or any "Pay As You Go" style programs, and still without additional transaction fees.

Having stated the good news, you might expect that there is bad news to counter it. But there isn't, at least not in the sense of anything new about the processing industry. Instead, there is the caveat that merchants still must deal with the same basic pricing and service of typical merchant accounts, including the PCI responsibilities and standard fees. Moreover, however, this program is not a "one size fits all" solution. If merchants are not processing over $5,000 in monthly charges, there is a good chance this program is not for them. On the other hand, it could save the right merchants a lot of money, offer a forward-thinking alternative to standard terminals and increase both productivity and profits. All will be revealed after the jump...

Monday, September 30, 2013

PCI DSS 3.0: The end of store and forward on mobile?

It is time for new PCI changes to get implemented. Last February (2013), the PCI Security Standards Council released a document on mobile payment security guidelines. While it is not the most entertaining read in the history of guidelines, it does shed light on some of the changes we are going to see implemented in the industry over the coming year. In November, expect to see a new set of regulations being handed down, to be fully implemented by the star of 2014. But most processors, not wanting to find themselves caught in the awkwardness of being out of compliance when the date hits, attempt to get on the bandwagon as early as possible and will demand the same of their merchants.

Sunday, September 22, 2013

PCI Program Update for North American Bancard Merchants

A notice came out today, September 17th, 2013, from the folks over at North American Bancard, which also provides the Phone Swipe and PayAnywhere products in the mobile processing field. Merchants who are on the mobile "Pay As You Go" plan (also known as Option B for Phone Swipe) should note that this information will not apply directly to their accounts, since those types of accounts have the compliance fees rolled into their higher percentage along with all other incidental costs (which is why Phone Swipe may be so much more cost-effective for merchants who do under $2,500 per month).

Here is an excerpt from the NAB correspondance:

"The monthly fee for PCI non-compliant merchants will be increasing from $6.95 to $14.95. This increase is effective for Global merchants and for First Data merchants. Your merchants will continue to receive messages on their statements notifying them when PCI billing will occur.

Note that the annual PCI compliance-related fees will not be increasing. Those fees will remain the same as they have for the past three years: $79 for all main accounts ($99 if non-compliant) and $19.95 for each additional account with the same Tax ID number and/or same Principal/Social Security Number ($24.95 if non-compliant). We are proud to say that these annual fees continue to be lower than those of our top competitors despite the fact that our compliance programs offer significantly better levels of protection and that our costs for the programs continue to increase."

NAB, just like most payment processors, sends their merchants notices regarding Payment Card Industry security standards and compliance issues in the merchants' monthly processing statements. Frequently merchants forget to check their statements for these announcements, which may also include rate or fee increases due to higher percentages being charged by Visa, MasterCard or Discover, that the processor might pass along to the merchant. It is essential that merchants remember to check their monthly statements, not only to verify that they are not being overcharged or billed for something that they do not understand, but to ensure that they are up to date on any changes or responsibilities regarding their accounts.