PCI 1.2 To Let WEP Stay For Two More Years
Written by Evan SchumanBut the changes confirmed by the PCI Security Standards Council this week—which have been circulated among members for the last few weeks—provide few other substantive changes, delivering the mild tweaks and updates the council has publicly promised.
The document lists some 30 changes to the current PCI Version 1.1 and PCI officials promise that the official and final version—now slated for release on Oct. 1, a few weeks earlier than originally expected—will include yet more changes.
Still, the document provides a fairly detailed peek into the council's thinking. The most significant change is language that addresses the much-maligned WEP and tried to balance conflicting member interests, from those who argued that such a weak security approach should be banned as soon as possible and their opposite numbers, who spoke to the cost and effort that retailers would need to deploy to make the change.
This Story Is Only Available For Premium Subscribers. Click Or Login In Below To Read The Rest Of This Story.
Leave a Reply
Our Comment SPAM system is getting very aggressive these days and has been blocking legitimate comments. If you post a comment and don't see it appear within 2 hours or so, can you please send a heads-up to customer-service@storefrontbacktalk.com? Ideally, please include the time you posted the comment. That will allow us to try and hunt for it. Thanks! P.S. We're working on fixing the system, but we don't want to lose any valuable comments in the meantime.
I have strong reservations about the 'individual' certification and posting of that information for merchants. Can you imagine the potential employee poaching that might occur? The implications when competitors can look up how many are certified with each of their competitors?
-Christine
