<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Heartland Taking Names And Kicking POS, With Visa&#8217;s Help</title>
	<atom:link href="http://storefrontbacktalk.com/securityfraud/heartland-taking-names-and-kicking-pos-with-visas-help/feed/" rel="self" type="application/rss+xml" />
	<link>http://storefrontbacktalk.com/securityfraud/heartland-taking-names-and-kicking-pos-with-visas-help/</link>
	<description>Techniques, Tools and Tirades about Retail Technology and E-Commerce</description>
	<lastBuildDate>Wed, 08 Feb 2012 16:02:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: Steve Sommers</title>
		<link>http://storefrontbacktalk.com/securityfraud/heartland-taking-names-and-kicking-pos-with-visas-help/comment-page-1/#comment-59819</link>
		<dc:creator>Steve Sommers</dc:creator>
		<pubDate>Thu, 23 Apr 2009 00:15:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.storefrontbacktalk.com/?p=2632#comment-59819</guid>
		<description>A VISA represenative speaking at the ETA show clarified this today. The merchant is responsible from his network and down stream -- meaning any POS, hardware or software that they host. Merchants must use &quot;approved&quot; gateways and processors but if the breach happens up stream -- meaning the gateway or processor -- then the merchant is not liable. Heartland is still an &quot;approved&quot; vendor (albeit on probation) so compliant merchants using Heartland are compliant.</description>
		<content:encoded><![CDATA[<p>A VISA represenative speaking at the ETA show clarified this today. The merchant is responsible from his network and down stream &#8212; meaning any POS, hardware or software that they host. Merchants must use &#8220;approved&#8221; gateways and processors but if the breach happens up stream &#8212; meaning the gateway or processor &#8212; then the merchant is not liable. Heartland is still an &#8220;approved&#8221; vendor (albeit on probation) so compliant merchants using Heartland are compliant.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PCI Guy</title>
		<link>http://storefrontbacktalk.com/securityfraud/heartland-taking-names-and-kicking-pos-with-visas-help/comment-page-1/#comment-58082</link>
		<dc:creator>PCI Guy</dc:creator>
		<pubDate>Tue, 31 Mar 2009 17:25:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.storefrontbacktalk.com/?p=2632#comment-58082</guid>
		<description>Considering all of the close scrutiny Heartland has now been subject to by VISA personnel, FBI, Secret Service, and Heartland&#039;s own staff and security consultants, their systems are now probably far more secure than most. So why on Earth did Visa decide to make a public spectacle of &quot;suspending&quot; Heartland? What benefit could possibly been achieved by doing that? Either VISA considers Heartland&#039;s systems secure enough to be safe for processing transactions, or not. If they are not secure enough then they should have been REMOVED from the list, not &quot;placed on probation&quot;.</description>
		<content:encoded><![CDATA[<p>Considering all of the close scrutiny Heartland has now been subject to by VISA personnel, FBI, Secret Service, and Heartland&#8217;s own staff and security consultants, their systems are now probably far more secure than most. So why on Earth did Visa decide to make a public spectacle of &#8220;suspending&#8221; Heartland? What benefit could possibly been achieved by doing that? Either VISA considers Heartland&#8217;s systems secure enough to be safe for processing transactions, or not. If they are not secure enough then they should have been REMOVED from the list, not &#8220;placed on probation&#8221;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Evan Schuman</title>
		<link>http://storefrontbacktalk.com/securityfraud/heartland-taking-names-and-kicking-pos-with-visas-help/comment-page-1/#comment-57572</link>
		<dc:creator>Evan Schuman</dc:creator>
		<pubDate>Wed, 25 Mar 2009 12:28:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.storefrontbacktalk.com/?p=2632#comment-57572</guid>
		<description>Editor&#039;s Note: The gray area here is Visa&#039;s use of the word &quot;probation&quot; and Visa&#039;s definition. It means that someone is off the PCI Compliant list, but it also means explicitly that retailers and still use them and be considered compliant. That probationed entity has to jump through a lot of testing hoops--and is put on notice that they need to fix everything quickly or they&#039;re out--but they are still qualified to accept transactions.
But regardless of how anyone might feel about this probation mode, Visa is within its rights to create it and to define it however it wants. Given that Visa--from the beginning--was explicit about what it meant, I have to side with Heartland on this one and say that the rivals (this time) were out-of-line. I don&#039;t have to agree with Visa&#039;s move (personally, I would have argued that if they wanted to have an impact, they should have cleanly removed them from the list. That would have sent a clear signal) to respect it and to argue that the industry has an obligation to abide by it.</description>
		<content:encoded><![CDATA[<p>Editor&#8217;s Note: The gray area here is Visa&#8217;s use of the word &#8220;probation&#8221; and Visa&#8217;s definition. It means that someone is off the PCI Compliant list, but it also means explicitly that retailers and still use them and be considered compliant. That probationed entity has to jump through a lot of testing hoops&#8211;and is put on notice that they need to fix everything quickly or they&#8217;re out&#8211;but they are still qualified to accept transactions.<br />
But regardless of how anyone might feel about this probation mode, Visa is within its rights to create it and to define it however it wants. Given that Visa&#8211;from the beginning&#8211;was explicit about what it meant, I have to side with Heartland on this one and say that the rivals (this time) were out-of-line. I don&#8217;t have to agree with Visa&#8217;s move (personally, I would have argued that if they wanted to have an impact, they should have cleanly removed them from the list. That would have sent a clear signal) to respect it and to argue that the industry has an obligation to abide by it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom Mahoney</title>
		<link>http://storefrontbacktalk.com/securityfraud/heartland-taking-names-and-kicking-pos-with-visas-help/comment-page-1/#comment-57568</link>
		<dc:creator>Tom Mahoney</dc:creator>
		<pubDate>Wed, 25 Mar 2009 12:04:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.storefrontbacktalk.com/?p=2632#comment-57568</guid>
		<description>Evan;

I certainly don&#039;t approve of advertising using Heartland&#039;s unfortunate position but you, or rather Heartland&#039;s competitors, raise an interesting point.

Merchants are required to be compliant.  Being compliant requires using a compliant processor.  Heartland is not, at least for now, compliant.  Therefore Heartland&#039;s merchants are not compliant.

Yes?  No?</description>
		<content:encoded><![CDATA[<p>Evan;</p>
<p>I certainly don&#8217;t approve of advertising using Heartland&#8217;s unfortunate position but you, or rather Heartland&#8217;s competitors, raise an interesting point.</p>
<p>Merchants are required to be compliant.  Being compliant requires using a compliant processor.  Heartland is not, at least for now, compliant.  Therefore Heartland&#8217;s merchants are not compliant.</p>
<p>Yes?  No?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

