advertisement
advertisement

Top Stories


advertisement

Security / Fraud


Yes, Virginia, We Really Do Need A QIR Program

May 16th, 2012

Integrators and resellers seem to be resisting a program that would provide stronger enforcement over, well, integrators and resellers. PCI Council General Manager Bob Russo talked with PCI Columnist Walter Conway about the resistance (the program is “sorely needed”), the pricing and the nature of the training. And given the number of industry insiders Russo worked with to create the program, he bristled at the suggestion that the Council worked in a vacuum on this one.

Russo said the training will be an online course so nobody should have to travel, Conway writes.

Read more...

advertisement

A Better Way To Search StorefrontBacktalk

May 16th, 2012

With more than 3,000 stories, columns and GuestViews in the content database here at StorefrontBacktalk, we thought it was time to do a little upgrading. Starting this week, readers (both free and Premium) can search for stories by limiting the search to just the story’s headline—as opposed to the headline and the full text. (Note: Right below the search bar, readers can choose HED Only or Story And Hed.)

The ability to isolate a search to the headline can be useful in two ways. If you happen to remember that the headline mentioned Target, for example, you need not see every story that mentioned Target (or even used the word “target”). The second way is practical. If you want a story that is primarily about tokens—and not a story that merely mentions the word somewhere—the headline-only search can be helpful.


advertisement

MasterCard Aims To Take Mobile Wallet Rivals Apart

May 9th, 2012

What Google, PayPal and ISIS are trying to assemble in mobile payments, MasterCard wants to dismember. On Monday (May 7), the number-two payment-card brand unveiled a mobile wallet and an E-Commerce payment system that are designed to cut out any middlemen horning in between customers and retailers and payment networks.

Ironically, while MasterCard’s PayPass Wallet for NFC-equipped phones got most of the attention, that’s still largely a pipe dream—MasterCard hasn’t even talked any mobile operators into giving it access to the NFC chip. But the online payments effort will offer tokenization to reduce PCI scope for E-Commerce. The bad news: You can probably forget about any interchange relief.

Read more...

advertisement

Best Buy Facebook “Joke” Points Out The Risks Of Handling Smartphone Repairs

May 9th, 2012

Corporate data security policies have always been a challenge. In recent years, thumbdrives, corporate telecommuting and smartphones have made such controls problematic. But the assumption has always been that the data being protected was on the hard-disks or RAM of various systems.

A Best Buy incident this month, however, is a grim reminder that saved passwords or tokens can expose employees to sensitive data—and capabilities—far beyond the bits and bytes of that device.

Read more...

advertisement

32-Point Font Might Save Your IT Career

May 9th, 2012

It’s you versus the sales guy in an epic battle over your IT career. The sales guy has a polished presentation about the features and benefits of his products and services. You have a status report. The sales guy has access to unlimited resources to make your business partners’ wildest dreams come true. You have one really great guy who you’ve overworked to the point that you carry a ton of personal shame.

The sales guy says, “Yes. Yes. Yes.” You say, “No. No. No.” In this surreal world, pens Retail Columnist Todd Michaud, you are watching your hard-fought IT career be dismantled by an onslaught of companies that shake your hand and look you in the eye as they pitch your demise one product and service at a time. And you had better buckle-up, Buttercup; it’s only going to get worse.

Read more...

Level 3 PCI Compliance Increases Slightly, Even As Its Population Grows

May 9th, 2012

The latest PCI compliance stats—out this week—show trivial changes from the prior report, with Level 2 and Level 3 retailers slightly increasing compliance. Level 2 went from 91 percent at the end of December 2011 to 92 percent as of March 31, 2012, and Level 3 also increased by 1 percent, from 58 percent to 59 percent.

With changes as small as 1 percent, it’s hard to determine what, if anything, caused the change. The number of Level 2s dropped slightly (from 1,066 to 1,060), so it’s possible a couple of the chains that left might have had compliance issues.

Read more...

P2PE: No Cakewalk for Merchants, But There May Be No Alternative For Reducing Scope

May 9th, 2012

When the PCI Council released version 1.1 of its Point-to-Point Encryption (P2PE) Testing Procedures late last month (April 27), it forced an interesting question: Will P2PE be the only way to remove encrypted data from a merchant’s PCI scope?

Writes PCI Columnist Walter Conway: Current PCI Council guidance (FAQ 10359) holds that encrypted data can be out of a merchant’s PCI scope “if, and only if, it has been validated that the entity that possesses encrypted cardholder data does not have the means to decrypt it.” The important word here is “entity.” That is, the ability to decrypt the data must rest with some unrelated third party. With the emergence of P2PE, could this scoping guidance be revised to where the only appropriate “entity” is an approved P2PE provider?

Read more...

“Careless” Systems Integrators Now Directly Under PCI DSS

May 2nd, 2012

Mistakes made by careless or incompetent payment application installers or system integrators have led to far too many data breaches over the years. In each case, even though the reseller or integrator made the mistake, the merchant bore the ultimate responsibility.

Unfortunately, system resellers and integrators formerly fell in a governance gap in PCI, and their actions were outside the PCI Council’s jurisdiction. PCI Columnist Walter Conway says “were,” because that situation is about to change.

Read more...

Walmart’s Online Cash Creates New Fraud Problem

May 2nd, 2012

When Walmart launched its E-Commerce cash program on April 26, did it open the door to evil-minded rivals by giving them the means to falsely lock up merchandise? That is just one example of the many implications behind Walmart’s move to enable people to use cash to make online purchases.

Beyond new security holes on the risk side, the reward side is equally huge. While everyone seems to have focused on the general unbanked audience, a much more interesting prospect for this program is teenagers. Plus, this is sort of an anti-showrooming move, where online shoppers are being lured into the stores. Revenue sharing between Walmart channels is also a point of nervousness with this program. And a store’s inability to cancel such online orders—even if the customer then finds the item on the shelf—is problematic, too. This is a rare example of the kinds of compromises—between online and in-store operations—chains must make these days.

Read more...

Sears’ Move Into IT Services: A Baffling Step If You Think Of Sears As A Retailer

April 25th, 2012

Sears on Tuesday (April 24) launched a service to provide managed technology services for “brick-and-mortar enterprises across all industry verticals.” It is a move partly aimed at Amazon’s cloud service, with Sears promising much more customization and hand-holding. For many retail observers, this was a baffling step, another non-strategic distraction at a time when the 119-year-old retailer needed to do nothing more than focus on selling more products in its stores.

For Sears, though, the move made fiscal sense. With all of those dollars invested in IT systems—with more capacity than Sears needs—why not, in effect, lease out some of it? Put another way: Turn IT from a pure cost-center to a mostly cost-center that generates at least some revenue.

Read more...

E-Nightmare: Minors May Not Have To Pay For Downloads

April 25th, 2012

In Mark Rasch’s legal column this week, he points out that online purchases by minors are a potential legal nightmare and that a federal judge is now deciding the retail issue. But what if the case goes against retailers? Frighteningly, the way many digital purchases are processed makes it all but impossible to comply with the law.

How could iTunes refund an already listened to song or an already played game? That’s not merely a business/profit question. From an IT perspective, there is often no mechanism to do it. What might start out as a legal problem will almost instantly morph into an IT problem.

Read more...

Angry Nerds: The iTunes Youth Legal Nightmare

April 25th, 2012

It’s not just those birds that are angry these days. The process by which Apple allows teens, pre-teens and even toddlers to download free apps, and then purchase game currencies within these free apps, may have landed the computer giant in hot water—with both parents and at least one federal district court in San Jose.

The case revolves around a longtime legal reality: Minors cannot agree to a contract. If they pretend to agree, it’s non-binding and can’t be enforced, writes Legal Columnist Mark Rasch. But what if an adult gives the child their password and permission to make a purchase? It’s still the child doing it and the contract, therefore, probably can’t be enforced.

Read more...

Turning Back Office Into A Game, IT Style

April 25th, 2012

Why is it that the same people who will easily spend hours playing Angry Birds each week won’t spend an extra hour improving their retail operations? Saving money just isn’t sexy or fun. It’s boring, and that’s the biggest problem.

After many years in retail operations, Retail Columnist Todd Michaud is still surprised how little traction well-developed back-office applications receive. You would think that saving money on inventory, labor or marketing expenses would be all the motivation that a retail owner or general manager would need, but that rarely seems to be the case. That got Michaud thinking about some of the new social applications, like Foursquare, and what makes them successful: Gamification.

Read more...

Home Depot’s SEO Furor

April 18th, 2012

What began as a Home Depot effort this month to get installers to boost the chain’s Web traffic has morphed into a strange SEO Google mess, with a Home Depot E-mail encouraging those service providers to use invisible links on their sites.

This is not merely an issue of violating the rules of a major search engine. A lot of these partners—carpet installers, for instance—have minimal E-Commerce teams, which means they rely on partners such as Home Depot for E-Commerce guidance. And when chains give advice that is false and endangers the ranking of the sites of those partners, it is a problem.

Read more...

Wal-Mart MoneyCard Break-In Offers Lessons For New Payment Tactics

April 18th, 2012

As retailers accelerate payment experiments, a recent Wal-Mart experience with a well-established approach offers a cautionary tale. A Buffalo, N.Y., woman this month walked into her local Wal-Mart, gave an associate $1,000 in cash and asked for it to be loaded onto a Walmart MoneyCard, in preparation for a vacation. A couple days later, the customer discovered that the money had been removed by a thief in another country.

The fact that it was a thief who stole the funds is undisputed. However, the immediate next actions of Wal-Mart and Green Dot—which manages MoneyCard for Wal-Mart—is a textbook example not of what should not be done, but how it shouldn’t be done.

Read more...

7-Eleven’s New Age-Verification Provides Proof For Police, But Is Far From Perfect

April 18th, 2012

7-Eleven on Monday (April 16) started a new age-check system, one that provides digital proof that a specific person’s credentials were checked at a specific date and time. This will provide the nation’s largest convenience-store chain with a new independent way to fight back when police say that an underage customer’s driver’s license had never been checked.

But it won’t address many of today’s age-ID problems, including waiving license checks if the associate thinks the person is old enough, license photos often being bad enough to fool weak authenticators, and under-age consumers using the driver’s license of an older sibling. Still, 7-Eleven has crafted ways to deal with some of those gotchas with the new system.

Read more...

Stealing From A Wal-Mart? Better Not Drive A Rental

April 17th, 2012

A pair of accused Wal-Mart thieves in North Carolina learned a valuable lesson last week: If you’re going to shoplift from the world’s largest retailer, it’s not a great idea to drive to the heist in a rental car.

It seems that as they exited the Havelock Wal-Mart with multiple yet-to-be-paid-for HP desktop computers, store officials did not stop them, but they did jot down their license plate number. Police found that it was from a car rental company, which happened to be able to remotely shut down the engine. And GPS was involved, too. Yep, this was a dual-shoplifter takedown, ultra-geek style.

Read more...

Appellate Court Limits Computer Fraud And Abuse Act

April 12th, 2012

In a major decision limiting corporate use of the federal Computer Fraud and Abuse Act (CFAA), the U.S. Court of Appeals for the Ninth Circuit on Tuesday (April 10) said the law is intended to address true cybertheft and other criminal hacking efforts and nothing else. At issue was whether companies could threaten employees with federal prosecution for violating company policies, such as playing games on a company computer.

Beyond the fact that retailers have to deal with many of these employee issues, the potentially bigger retail impact of this ruling is how it would strengthen prosecutions of actual cyberthieves, who tend to work where they shop.

Read more...

New Jersey Giftcard Law Is Much More Complicated For Retailers Than Even Its Critics Believe

April 12th, 2012

The great New Jersey giftcard exodus continues. On April 5, Blackhawk Network and InComm announced they’ll pull their giftcards from New Jersey retailers to avoid a new state law requiring them to collect and store the purchaser’s ZIP code. (American Express giftcards are already gone from the state.) Their complaint: It’s an IT project that’s all cost and no business benefit. But in a merged-channel world, that’s not the only problem with the new law.

In fact, what lawmakers probably thought was a simple idea runs into a buzzsaw of complexities—and the IT project is the easiest part of the problem.

Read more...

Secret Service’s Home Depot Arrests Add To Self-Checkout Woes

April 12th, 2012

When the U.S. Secret Service arrested five men last week on charges that they stole hundreds of items from the self-checkout areas of 74 Home Depots in six states, it certainly didn’t help the security reputation of self-checkout. This comes after Costco detailed its own self-checkout thefts and several chains abandoned self-checkout, citing theft as one key reason.

Some self-checkout advocates concede that these types of self-checkout thefts are very real, but that they are often the result of sloppy self-checkout deployments, with some stores not activating all security functions, using insufficient staff around self-checkout, not bothering with security cameras and ignoring other self-checkout best practices.

Read more...

Best Buy Planned Outages Due To Its Move To The Cloud

April 11th, 2012

The abrupt departure of Best Buy CEO Brian Dunn on Tuesday (April 10), because of his “personal conduct,” overshadowed something much more interesting that surfaced this week: the reason for Best Buy’s recent series of planned outages—one on March 28, another on April 8—is that the now-CEO-less retailer is moving its E-Commerce operations to the cloud.

The cloud move, like last fall’s quadrupling of the number of Best Buy IT project managers, is an effort to control IT costs without rolling back IT initiatives—absolutely critical in the face of Dunn’s inability to stem the chain’s loss of sales to Amazon. Amazon, ironically, is among those that Best Buy is writing checks to for its cloud efforts.

Read more...

Apple, PayPal Enjoy Unchartered Mobile Payment Legal Issues

April 11th, 2012

As Apple tries to position itself as the ultimate payment processor, the competition is heating up for which entity, and which technology, will be responsible for ensuring that retailers get paid. Although these choices may ultimately prove useful for both consumers and retailers, they present new privacy challenges to all participants.

As a result, pens Legal Columnist Mark Rasch, Apple, PayPal and a host of other payment processors may find the need to hire new teams of lawyers to help them comply with the inevitable subpoenas and discovery requests that will befall them.

Read more...

ISIS Collides With Magstripe’s Dominance

April 11th, 2012

ISIS is scaling back expectations for how much its mobile payment system will be used, even before it launches. Last week, ISIS Chief Marketing Officer Ryan Hughes told GigaOM, “We’re not trying to hit a home run, but get a bunt single.” That’s wise, given the very low levels of customer use for Google Wallet and PayPal’s Home Depot trial. In fact, ISIS’s expectations may still be too high, considering what happened to Chip-and-PIN, contactless in the U.S.

After all, even the hottest things in retail-chain POS today—iPads and iPods outfitted with sleds—still only handle one type of payment device: a magstriped card.

Read more...

Visa to Global Payments: Strike One, You’re Out

April 4th, 2012

When Visa removed, at least temporarily, Global Payments from its list of PCI-compliant service providers, it reflected a subtly different position than any card brand has taken in the past. And the decision has implications for every merchant and service provider.

The PCI Council states that no breached merchant or processor has been found to be PCI compliant at the time of the breach. PCI Columnist Walter Conway has never liked that statement. It seems to be either tempting fate or challenging the bad guys. Although it stopped short of promising a safe harbor, at least the statement acknowledged the possibility of suffering a data breach while still being PCI compliant. Visa’s suspension of Global Payments has swept aside that distinction.

Read more...

Costco Self-Checkout Trial Setback After Store Losses

April 4th, 2012

A two-year-old experiment at Costco to try self-checkout in a handful of stores has not gone well, with at least one Costco in Idaho pulling the systems out after finding—and attributing entirely to self-checkout—a $60,000 inventory loss in six months, said a Costco management source.

One of the problems with the Costco system in various stores was either inadequate or non-existent notification to customers when a purchase was rejected. If an item’s weight was different than expected, the system would void the purchase and not charge the customer. But many customers didn’t notice the item was rejected, so they placed it in their cart, took their payment-card receipt and left the store.

Read more...

Page 1 of 63123456102030Last »

Weekly, Monthly Newsletters

Quickly catch-up on the latest in E-Commerce and Retail Tech with our free weekly report, with urgent bulletins as news merits—along with our monthlies on Mobile, Security, In-Store, E-Commerce and CRM.
advertisement

Most Recent Comments

"Careless" Systems Integrators Now Directly Under PCI DSS

This exact issue has been bothering me for years, and I was JUST talking about it with someone only yesterday. This may well be my favorite article, mostly because I'm biased and have hated this particular problem forever. Read more...
Good article, but how does this have anything to do with the DSS? Read more...
Actually, the QIR program has a lot to do with the DSS (or PCI). Since merchants rely on their reseller or integrator to implement their PA-DSS validated application, these resellers and system integrators play a critical role in merchants achieving and maintaining PCI compliance. As far as I can tell, the QIR program is designed to help merchants stay compliant by making sure their payment applications are installed according to the PA-DSS Implementation Guide, for example ensuring default passwords are changed (and protected), that the data encryption keys are properly set and secured, that the merchant's data retention policy is set, that no sensitive cardholder data are stored, and often that a firewall is in place and properly configured. Read more...
Although this is a great move forward in pushing the issue of highly trained people, it is also a good marketing ploy for the council. It begs the question: How much do they stand to make? The problem for this is that for people (like myself) that are just starting out their own business venture, PCI has typically charged a premium for their training and certifications. This change will likely force those of us with less capital to spin into the abyss. I have more than 15 years in the security and compliance fields with heavy hitter certs like CISSP, CRISC, and Sec+. There should not be a guide but a free test or a pre-requisite of either the PCI cert OR other heavy hitter certs. I just don't want the good guys in small places to get flushed out. Read more...
The ETA recently launched the Certified Payment Professional program, which charges $425 for non-members to take the test, assuming they meet the 'experience' requirement, to PROVE they are a professional. And they'll have to take it every 3 years. Worthy program, but high cost. Plus, only a select few were allowed to be in the first class, and there are only 4 test windows per year currently. So being on the registry simply means, you were lucky enough to get picked, nothing to do with skill level. Read more...
@Cory: Thanks for your comment and question about the pricing of the QIR training. I raised that question in a conversation with Bob Russo last week, and I will address it in a follow-up column in a few days. While the pricing is not yet set, hopefully it will not be too great a burden for you or other integrators/resellers. We'll have to see, though. Read more...

Costco Self-Checkout Trial Setback After Store Losses

Not all self checkout works this way. One self checkout vendor is designed to work this way and it leaves a gaping security problem that can create this situation. There are 3 predominant providers of self checkout in the U.S. and this represents the lowest installed base provider of the 3 and their market share continues to shrink from reports I have seen. Read more...
Editor's Note; The vendor that Mark was referencing is IBM. His point is that other systems make it easier for any weight mismatches to require associate intervention--just like with alcohol or cigarettes or any other age-restricted item--rather than a more passive flag to the customer that the item was excluded. Read more...
Another angle on the challenges with self checkout which may come to the retail scene in the next year is the tap and go/NFC smart phones. Though these are all the rage in Japan, we have yet to adopt them in the U.S.. But that will change as the new phones emerge with the chips embedded this year. And the new demographic want to use this type of technology. A large retailer told us that NFC phone customers are getting their identities stolen, even though the self check-out requires proximity-- and they do not want to take responsibility for this occurrence in their stores, on their premises. So although they like the idea self check-out they are still experimenting with various approaches. Read more...
ed
For self checkout, item-level RFID or unique barcodes plus real-time tracking appears to be the missing component. Mail delivery companies use real-time tracking of mail with a barcode and assure delivery at a certain time. The public library embed books with RFID and track them through checkout. Retailers and SCO manufacturers are going to have to accept the fact they cannot rely on UPC and really need an item-level identifier that tract that specific product as a unique item from shelving to checkout. Read more...

Visa Yanks Global Payments' PCI Compliance. Catch-22 In Full Force

So PCI compliance can not guarantee that a provider will not be breached, but a breach is inherent evidence of non-compliance? Any comment from VISA as to whether they will continue to accept ROCs prepared by Trustwave? Seems like an inconsistent position. Read more...
Thu
Global Payments reported they were working toward being in compliance with PCI, despite already being on the list. In a backwards way, they admitted they were not previously in compliance. We can't really say that a breach is inherent in these type of situations without having a full investigation report. That's one reason why MasterCard is waiting to see what forensics finds before yanking them from their list. Read more...
In the past, Visa has stated, "No compromised entity to date has been found to be in compliance with PCI DSS at the time of the breach. In all cases, forensic investigations have concluded that compliance deficiencies have been a major contributor to the breach." This quote can be taken two ways. Either PCI is perfect and all-encompassing and compliance guarantees you won't be breached; or there are so many “gotchas” in PCI that no one can escape non-compliance. I personally believe that PCI is written in such a way — and interpretations among QSAs vary so much — as to make it impossible for anyone to be 100 percent compliant 100 percent of the time. Read more...
PCI, TSA, IRS - obviously none of these functions as intended or as promoted. I've said it before and I say it again, hackers are free of personnel, budget, expertise, infrastructure and time constrains. Nothing, NOTHING, is ever fully safe. Visa and its attorneys simply choose to hide behind the false sense of security of the PCI veil. Truth be known, Visa has probably been hacked. Anyone see the similarities between VISA and the wizard of OZ? Read more...
This begs the question, how does this decision by Visa affect Third Party Processors (TPA's)? Our TPA agreement has wording to the effect that we can only send CHD to PCI compliant processors and banks. Now that Visa has deemed GPS non-compliant, are we breaking our TPA agreement by allowing our customers to continue using GPS? Read more...

How About A Little Service Provider Responsibility Here, PCI-Wise?

I appreciate the one-sideness issue highlighted in this article. I also understand how card brands have a contractual link to merchants - but only rarely do with service providers. I'd find it virtually meaningless for the PCI requirement to mandate actions by the service provider, when they have no contracted responsibility to a commercial entity. That said, 12.8.4 places an obligation on the service provider to demonstrate compliance to their customer the merchant (or service provider, Acquirer etc). Is not the combination of these 2 requirements having the same outcome? Read more...
Lem
PCI is like banging your head on the wall. When you complete the SAQ, it feels good stopping. Read more...
Actually, service providers do have direct links to the card brands. For example, many have direct system connections/access points to the card networks. More importantly, all service providers validate their PCI compliance to the card brands. The brands (at least Visa and MasterCard) also post lists of compliant Level 1 Service Providers on their websites. My point was not so much about the card brands, though. I was observing that since PCI already has a number of requirements that only apply only to Service Providers and not to merchants, there is precedent for one more Service-provider-only requirement to cure the imbalance I noted. Read more...
Walt, I'd suggest that perhaps you have a limited concept of who would be considered a Service Provider under the guidelines that you've suggested. The fact is that most resellers/integrators do NOT have direct links to the card brands or the card networks. They may work with processors to board new merchants or provide support, but there is no contractual or legal obligation at all. Your comment that all service provides validate their PCI compliance is also way off base if you include resellers & integrators. The limited number of Level 1 Service Providers probably do validate their compliance, but the vast majority of resellers/integrators are not that big. Read more...

The Never-Ending Dance Of Contactless Security

ed
Contactless should require multi-factor authentication for financial transactions. However, multi-factor authentication will nullify the main benefit of contactless transactions which is speed. Is there really an improvement between a mag swipe and contactless tap if multi-factor authentication is required? Read more...
Contactless card transactions are verfied online, if there is fraud the bank with take the liablity. This does not happen with checks, bills. Oh and contactless is faster than any other form of payment and you do not have to check the takings at the end of the day: so faster service and a bit more secure. Read more...
MC
To contaftless. Not completly true that the bank will take the hit for a fraudulant contactless transaction. When paying at the fuel pump with contactless, you will have a defined pre-auth limit which is set by the issuer and obtain an online auth number. Even with the issuer providing real time auth, should the customer dispute the transaction, the liability and burden of proof still lies with the retailer in most circumstances. To the issuer they claim this is a "card not present" transaction if completed out of sight of the store attendant. Add that to the fact that that a gas station forecourt allows the hiding of the necessary fraudulant transaction supporting equipment inside a vehicle, it creates the anoynmous environment that fraudsters prefer to operate under. Read more...

The PayPal Problem: Will It Impact Retailers' PCI Scope?

For the foreseeable future, retailers are not going to be transacting exclusively against PayPal accounts. Therefore, with the assumption that the payments are stored, transmitted and processed through the same systems as "regular" CHD, there will be no change in scope. Merchants will have to protect the PayPal payment information with the same rigour as PANs/CV2s/tokens, but this isn't arduous because they are doing it right now. (Or should be.) Read more...
This is the problem with the notion of the high value token wording in September's guidelines. As you rightly point out an email address, mobile no. or even a name can be considered a high value token. Yet by their very nature these are all readily available in the public domain, so I find it hard for them to be considered as a high value token. Read more...
Will Visa be including in their V.me system the additional ability for online payers to source funds via a “debit” transaction from their banking account, rather than only by a credit card transaction as has been the case in the past because of the PIN requirement for such a “debit” transaction? After all, what’s the difference between a PIN, that Visa/MasterCard already hold, and a password required to access a secure online payments gateway? Read more...
The PayPal user information is much more "high value" because it can be used across merchants to initiate transactions. If I have it or gain access to it via a merchant compromise, there is nothing to stop me from using it at another merchant. A properly designed tokenization system should have rules that prohibit tokens obtained from one merchant to be used at another merchant and/or prohibit initiating transactions unless the PAN and authentication data has been previously received by that merchant. Read more...
A big difference with PINs(at least in the debit world) is that they should only be entered into an encrypting PIN Pad. The feeling goes that if I steal a card with a valid PIN I can go to an unattended device(ATM) and pull out money w/o having to present a legitimate card to a person. I suppose you could make the same case(which you did) regarding an online transaction w/ a password. Read more...
PayPal's plan of POS attack is to entice merchants with below-cost credit and debit card processing, which is an offer no retailer will refuse. The company will subsidize its losses from the card transactions with the very high-margin profits it enjoys when its users fund the sales amount from their bank accounts. On the other hand, whether the consumers will be won over is another question altogether. If it is to stand a chance, PayPal will need to make the checkout process as uneventful as possible. As it is, the customer is asked to enter his or her cell phone number, in addition to a PIN, before the transaction can be completed. That's unnecessary and excessive. Read more...

Tokens Are Not The Same As Encryption. Honest

I agree with all your points on how the technologies differ. The only possible disagreement I have is that you are very generous in giving PCI credit for distinguishing the differences between the two technologies and scope whereas I think they caused the confusion (or at least didn't help). Read more...
I tend to disagree that tokenisation and encryption are different - indeed, I see tokenisation as a form of bespoke encryption. Many of the arguments I hear about tokenisation being different from encryption leads to concerns about the security of encryption, or that encryption can be reversed. Although it is true that encryption can be reversed with the key, I strongly dispute the arguments about the security of encryption, and personally I put much more faith in an algorithm that has undergone many decades of community research, where the security (key) can be isolated in approved hardware, than in a bespoke solution I have no visibility or independent assurance of. Read more...
"High-value tokens are those that can be used to initiate a new card transaction." Personally, I didn't understand this part of the doc. Surely that's the point of a token, so I'm assuming they mean a token that can be used independently of a 'vault' type of service to initiate and complete a transaction. Otherwise, every token would be a High Value token. Services like Square's card case where a person's name can trigger a payment, or PayPal's where an email and password trigger a card payment. In these cases a name and email would be tokens and as they are initiating a card payment could be considered a High Value token. Read more...
I disagree with you on the point you made about there being no way from a PCI scoping perspective to compare tokenization guidance to encryption clarification. The parallel that I see is not between tokenization and encryption, but between the token and the encrypted data values themselves. Semantics? Maybe, but I believe there is a significant if not subtle difference between these two statements. Read more...
How can QSA be comfortable determining if something is out of scope, if he or she does not know how the system providing that benefit explicitly works in all conditions over its lifetime, especially if its distributed and may its functionality and risk profile may change over time and can be explicitly guaranteed? A QSA takes liability for such a de-scoping claim. Only proofs of security and evidence can stand behind that something seriously lacking in most of the debate. Read more...
Tokenization is a use case of data transformation, not a specific technology. Humans have been practicing tokenization using multiple methods for centuries and claiming that one method of data transformation is the "real" tokenization and not some other way doesn't make sense. Tokenization must be reversible. Read more...
Promises of incremental sales and the ability to target loyalty have been completely worn out by endless pitches of card services, hardware, software, etc etc etc... Another watershed way of getting mobile payments introduced is to shift merchant's payment modes from higher to lower cost products. I think ISIS has started down a path that completely misses that opportunity by partnering with incumbents who have zero interest in reducing merchant payment costs. Read more...

Want To Push Social Media? Have You Considered Using Your Stores?

What about if the retailer is in a shared space (e.g., a food court in a mall or college campus) where there may be limited space and possibly limited flexibility (e.g., power, comms, lease restrictions)? Or in airports, where I see more and more retailers. Would your recommendations hold for those locations, too? By coincidence, I was at a conference this week and sat next to the person charged with building brand awareness for a national food chain on college campuses -- and therefore with the student demographic -- nationwide. After reading your piece, I was wondering, would your recommendations would hold for them? As for airports, I could see one school of thought that says customers don't live there, so get them in and out. But I also could see where the particulars of this demographic could be sufficiently compelling to want to reach out. Read more...
I agree that there are even deeper levels of engagement that you absolutely could drive in the store (I love the idea of floating coupons by the way). I think what is most important is using the store to start a conversation that could be then continued online (rather than always trying to start a conversation online that culminates with a sale in the store). Read more...
I think the statement "Then there is the small fact that the retail operator doesn’t feed his family based upon how well his customers are engaged online" speaks loads. Read more...

Publix Buy-Online-Pick-Up-In-Store Trial Nixed: Grocery Shoppers Are Different

Your take on the customer's view is right, however I wonder whether supermarkets can go a _long_ way towards resolving it with easy, quick refunds? My partner unpacked our home-delivered fruit and veg box last week, and discovered bruised fruit. Took a picture, emailed the company, and within 10 minutes had a refund. Happy customer all round - the company cares, etc. This requires very careful thinking on the merchant's part about how to invest in this area of customer service. However, since it is equally easy for my partner's picture of bruised oranges to be uploaded to a social media site as it is to email the company, the downsides for NOT doing this are quite large. Read more...
What about the other non tangible benefits of shopping at the grocery store - it gets you out of the house and you get to interact with the staff. for many people this might be there only "human contact" in a day, or at least human contact that doesnt come with the stresses associated with family/work colleagues/customers. And of course, there is the primeval "hunting and gathering food" aspect. Read more...
ed
The last poster hit it head on - there is a primal "hunter" instinct of us humans preventing the buy groceries online model to take off. Food, clothing and shelter are the three things we humans go out and scavenge for and that is in our primal instinct. It appears the next logical step is to focus on items that do not interfere with our primal instincts such as prepackaged food or personal hygiene. Read more...

StorefrontBacktalk
Our apologies. Due to legal and security copyright issues, we can't facilitate the printing of Premium Content. If you absolutely need a hard copy, please contact customer service.