Showing posts with label PCI Compliance. Show all posts
Showing posts with label PCI Compliance. Show all posts

Friday, April 7, 2017

Security Threats Facing Online Payment Gateways


[Guest Post by Arthur Jones]
Most experts agree: it is a brave new world for payment gateway providers, which presents both opportunities and challenges. For nearly a decade, cyber security professionals have been warning about the ongoing rise of cybercrime. Agencies like the FBI regularly put out reports detailing the threats to the financial services industry, in particular. As outlets like TechRepublic have reported, this trend is only going to continue, and we may see record levels of cybercrime activity this year.
What kind of threats can we expect to face for online payment gateways? Let’s look at some major security challenges and how they may be addressed payment gateway providers as they continue to innovate and remain competitive in the marketplace.
Information Attacks
It is safe to say that a data breach is one of the most serious threats for payment gateways. Attacks like these can come in many different forms, and because they are smaller and require fewer resources, they are easier to carry out and occur much more frequently. If an attacker gets their hands on sensitive financial information, the losses can be catastrophic, putting companies at the risk of irreparable damage to customer trust.
There are many ways for attackers to breach a system. Phishing attacks consist of fake emails that can trick users into opening harmful links and installing malware or giving up sensitive information. Such attacks can open up system vulnerabilities, giving attackers access to valuable information.
Untrustworthy insiders can also get access to sensitive information and compromise security systems from within the business. Or hackers can gain access to sensitive systems through security breaches in compromised hardware and software.
Credit Card Fraud
Payment gateway providers may be concerned about threats to their internal data systems, but there are external threats to take into account as well. Attackers use skimming devices and other technologies all of the time, which can steal credit card information wherever a credit card is used. After this sensitive information is acquired, attackers can commit credit card fraud wherever they please, which can go undetected until banks or card holders notice suspicious activity related to any compromised accounts.
This is a sort of “death by a thousand cuts” threat for payment providers, as constant small attacks on credit card holders’ information can result in the gradual erosion of customer trust.
DDoS Attacks
Distributed denial of service (DDoS) attacks are a little trickier to deal with, as they can be very powerful and destructive on a systematic level. DDoS attacks are becoming more sophisticated, in that the attackers are finding specific structural weaknesses in internet infrastructure, and then exploiting those weaknesses to bring down large and powerful institutions. Additionally, the expanding internet of things (IoT) makes it much easier for attackers to use internet-connected devices like appliances, TVs, security cameras, and other machines to flood servers with requests, which crashes them.
Typically, only the largest financial institutions are targeted by these attacks. However, hackers are increasingly attacking broader internet structures like the DNS system, which can crash a wide range of businesses’ websites that are using the infrastructure. Fortunately, large attacks such as these have been less frequent, and most payment gateway companies will not have to deal with attacks like these as much. Nevertheless, a downed server poses a threat for payment gateway providers if they’re not able to process transactions in a timely manner.
Safer Transactions
It is important for cyber security professionals, payment gateway providers, and other financial services businesses to continue to develop secure technologies to protect their systems and data. The most promising avenues include advanced encryption, tokenization, and authentication methods, which go a long way towards cutting down on common cyber-attacks. The Payment Card Industry Data Security Standard (PCI DSS) is a powerful industry-wide tool to increase security with, and innovation in this field is welcome as well. Further, proper employee training can go a long way to reduce risk exposure. Ultimately, payment gateway providers and other tech and financial services businesses who innovate in these areas will come out stronger in the future.


Author Bio: Arthur Jones is a consultant for Allied Wallet. He is an innovator in eCommerce services and everything a company needs for success including a global payment gateway system, a prepaid affiliate debit card program, and much more. Arthur has extensive experience in the eCommerce and merchant services industry, and regularly writes about it for interested readers.


IMAGES:

Sunday, October 30, 2016

Troubleshooting Chip-Based Transaction Terminals

The following is a guest post from Brian Thompson at Transaction Services:

With the recent rollout of chip-based credit and debit cards with next-generation security precautions, many merchants have found themselves coping with the troubleshooting that comes with new technology alongside trying to educate customers about the transition to the new technology. Between that and the uneven nature of the upgrade, it can be very difficult to make transactions go smoothly and to keep your registers moving at a regular pace. Here are a few tips and tricks to help you get the most out of your terminal so that you can concentrate on helping your customer.

Connecting the Terminal


Most companies these days are opting for high-speed transaction terminals because they can piggyback on the data connection your company already pays for, and on top of that they also run much more quickly and with fewer dropped attempts. If you’re trying to make a new terminal work, it’s important to start by troubleshooting the basic connection and testing it before you open for the day. To do that, follow these steps:

  • Check to be sure that you have the data cable plugged into the appropriate port.
  • Look at the indicator lights for the model. If any are not lit, consult the owner’s manual to see what to do next.
  • If the terminal still does not work, reboot it by shutting it down and unplugging it for thirty seconds or so before powering it up and letting it initialize itself.
  • Last but not least, confirm that the internet connection itself is working correctly by checking to see if a connected PC or mobile device can access the internet through it.

Troubleshooting Your Digital Services


Sometimes, the connection and the hardware are both in great shape, but it is still impossible to get information through. This tends to happen when high-speed terminals are put on the same connection as a VOIP communication device. For technical reasons, VOIP tends to complicate the ability of the terminal to perform downloads. When that happens, you may need to connect the terminal to an analog phone line to let it download the new software it needs via dial-up.

To coexist well with VOIP services, it is important to know how to switch between VOIP and regular data connections on the device and to use the actual data connection for downloads and transactions. The reason is because the VOIP service will not provide the same kind of network connectivity that an analog phone uses, and the terminal is not able to make use of its analog data connection to send a signal along VOIP. Instead, it needs the regular data connection that other computers use.

The simplest way around this is to connect the high-speed terminal directly to the router instead of going through a VOIP device, but if that is not possible, then the next best choice is to remember to switch from voice to data when you are attempting to process transactions or downloads.

Wrap-Up



There are a variety of other issues that might pop up besides those with digital services, including problems stemming from needing to dial an outside line to use an analog phone system. To find out how to troubleshoot those specific problems, consult your terminal manufacturer’s literature. That way, you will have all the information you need to successfully implement your chip reader.


This guest post by Brian Thompson has been provided by our friends at Transaction Services.
Brian Thompson is a business man who means business.  He has helped several companies thrive in the business world, and in his spare time writes for several blogs.
Follow him on Twitter @Biz_Gab

Monday, September 28, 2015

The Chips Are Down

By now, most consumers who use credit cards have found that replacements for their old plastic have arrived with embedded chips in them. And most merchants have been receiving a barrage of calls for months from processing companies trying to convert them using the need for new chip-enhanced terminals as a selling point. A recent article in the NY Times highlighted the issue. This is a real thing that merchants and consumers alike need to pay attention to as the United States catches up to most of the rest of the world regarding the security of credit and debit payment systems.

Why This Is Important

Fraud protection is one of the main reasons that the chip is an important addition to the credit card. Stripes contain easily duplicated magnetically encoded information about the card and the card holder. For this reason, it has been very easy for criminals to steal this information using a small swiping mechanism and subject consumers to identity theft. These tiny devices have been embedded in the payment terminals built into gas station pumps, or used by waiters or waitresses at restaurants who take the card in order to swipe it in a payment station out of view. There are plenty of ways that the information can be stolen off of a magnetic stripe. But not so easily from a chip.

The main reason is that the chip is actually a small computer with encoded data that must communicate with a distant server in order to authorize the charge or debit. It does this by changing its code every time it is used. This may sound complicated, and it may take a second or two longer than swiping a magnetic stripe does, but it offers a nearly impossible to steal or duplicate transaction process. This is why card brands adopted the chip years ago virtually everywhere else. The USA is always a bit slow to catch up on this sort of technology due to the heavy regulations in place for all things financial and the reticence of major companies to engage in huge spending upgrades any earlier than they have to. But the benefits are going to be huge with regard to identity theft.

What This Means To Merchants

The basic thing that merchants need to be aware of is that they will now be responsible for identity theft issues that come from using duplicated magnetic stripes. If a cardholder provides a striped card, the merchant must verify the cardholder's identity or risk being liable for the transaction. This should be standard protocol anyway, but the processing companies are offering cheap or free upgrades to chip-enabled terminals to specifically avoid the costs associated with identity theft and they are going to be very serious about ensuring that merchants use this new tool. On the flip side, the protections involved with chip-based transactions should be higher than the old ones were with the stripe-based transactions.

Monday, September 30, 2013

PCI DSS 3.0: The end of store and forward on mobile?

It is time for new PCI changes to get implemented. Last February (2013), the PCI Security Standards Council released a document on mobile payment security guidelines. While it is not the most entertaining read in the history of guidelines, it does shed light on some of the changes we are going to see implemented in the industry over the coming year. In November, expect to see a new set of regulations being handed down, to be fully implemented by the star of 2014. But most processors, not wanting to find themselves caught in the awkwardness of being out of compliance when the date hits, attempt to get on the bandwagon as early as possible and will demand the same of their merchants.

Sunday, September 22, 2013

PCI Program Update for North American Bancard Merchants

A notice came out today, September 17th, 2013, from the folks over at North American Bancard, which also provides the Phone Swipe and PayAnywhere products in the mobile processing field. Merchants who are on the mobile "Pay As You Go" plan (also known as Option B for Phone Swipe) should note that this information will not apply directly to their accounts, since those types of accounts have the compliance fees rolled into their higher percentage along with all other incidental costs (which is why Phone Swipe may be so much more cost-effective for merchants who do under $2,500 per month).

Here is an excerpt from the NAB correspondance:

"The monthly fee for PCI non-compliant merchants will be increasing from $6.95 to $14.95. This increase is effective for Global merchants and for First Data merchants. Your merchants will continue to receive messages on their statements notifying them when PCI billing will occur.

Note that the annual PCI compliance-related fees will not be increasing. Those fees will remain the same as they have for the past three years: $79 for all main accounts ($99 if non-compliant) and $19.95 for each additional account with the same Tax ID number and/or same Principal/Social Security Number ($24.95 if non-compliant). We are proud to say that these annual fees continue to be lower than those of our top competitors despite the fact that our compliance programs offer significantly better levels of protection and that our costs for the programs continue to increase."

NAB, just like most payment processors, sends their merchants notices regarding Payment Card Industry security standards and compliance issues in the merchants' monthly processing statements. Frequently merchants forget to check their statements for these announcements, which may also include rate or fee increases due to higher percentages being charged by Visa, MasterCard or Discover, that the processor might pass along to the merchant. It is essential that merchants remember to check their monthly statements, not only to verify that they are not being overcharged or billed for something that they do not understand, but to ensure that they are up to date on any changes or responsibilities regarding their accounts.