MasterCard Note Causes Remote Key Injection Confusion
Written by Evan SchumanJust a few weeks after it roughed up Level 2 merchants with demand for on-site assessments, a dustup with MasterCard was causing confusion about their remote key injection policy. A Gartner report this week–carried by Computerworld–said that MasterCard was rejecting it.
MasterCard indeed changed its policy regarding using remote key injection to install new encryption keys on point-of-sale (POS) systems, but the change was only to ban when the hardware is not already PCI compliant. If it’s PCI compliant–which many are–then it’s not an issue. “Our customers and vendors can use Remote Key Injection services to upgrade the terminals if those services meet all aspects of the PCI Pin Security Requirements,” said a MasterCard clarifying statement issued Friday (July 10).
Leave a Reply
Our Comment SPAM system is getting very aggressive these days and has been blocking legitimate comments. If you post a comment and don't see it appear within 2 hours or so, can you please send a heads-up to customer-service@storefrontbacktalk? Ideally, please include the time you posted the comment. That will allow us to try and hunt for it. Thanks! P.S. We're working on fixing the system, but we don't want to lose any valuable comments in the meantime.
Is there really an improvement between a mag swipe and contactless tap if multi-factor authentication is required?
-Ed
