MasterCard Note Causes Remote Key Injection Confusion
Written by Evan SchumanJust a few weeks after it roughed up Level 2 merchants with demand for on-site assessments, a dustup with MasterCard was causing confusion about their remote key injection policy. A Gartner report this week–carried by Computerworld–said that MasterCard was rejecting it.
MasterCard indeed changed its policy regarding using remote key injection to install new encryption keys on point-of-sale (POS) systems, but the change was only to ban when the hardware is not already PCI compliant. If it’s PCI compliant–which many are–then it’s not an issue. “Our customers and vendors can use Remote Key Injection services to upgrade the terminals if those services meet all aspects of the PCI Pin Security Requirements,” said a MasterCard clarifying statement issued Friday (July 10).
Leave a Reply
Our Comment SPAM system is getting very aggressive these days and has been blocking legitimate comments. If you post a comment and don't see it appear within 2 hours or so, can you please send a heads-up to customer-service@storefrontbacktalk.com? Ideally, please include the time you posted the comment. That will allow us to try and hunt for it. Thanks! P.S. We're working on fixing the system, but we don't want to lose any valuable comments in the meantime.
I have strong reservations about the 'individual' certification and posting of that information for merchants. Can you imagine the potential employee poaching that might occur? The implications when competitors can look up how many are certified with each of their competitors?
-Christine
