<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Visa To Acquirers: Stop Forcing PAN Retention</title>
	<atom:link href="http://storefrontbacktalk.com/securityfraud/visa-to-acquirers-stop-forcing-pan-retention/feed/" rel="self" type="application/rss+xml" />
	<link>http://storefrontbacktalk.com/securityfraud/visa-to-acquirers-stop-forcing-pan-retention/</link>
	<description>Techniques, Tools and Tirades about Retail Technology and E-Commerce</description>
	<lastBuildDate>Wed, 08 Feb 2012 16:02:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: Howard Falcon</title>
		<link>http://storefrontbacktalk.com/securityfraud/visa-to-acquirers-stop-forcing-pan-retention/comment-page-1/#comment-80742</link>
		<dc:creator>Howard Falcon</dc:creator>
		<pubDate>Thu, 29 Jul 2010 13:27:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.storefrontbacktalk.com/?p=5704#comment-80742</guid>
		<description>Alex, your insight into PCI is outstanding.  I now don&#039;t feel like I am the only one that thinks that PCI is nothing more than the good old boys putting together another business to make a ton of money on forced fees.</description>
		<content:encoded><![CDATA[<p>Alex, your insight into PCI is outstanding.  I now don&#8217;t feel like I am the only one that thinks that PCI is nothing more than the good old boys putting together another business to make a ton of money on forced fees.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex Wieder</title>
		<link>http://storefrontbacktalk.com/securityfraud/visa-to-acquirers-stop-forcing-pan-retention/comment-page-1/#comment-78364</link>
		<dc:creator>Alex Wieder</dc:creator>
		<pubDate>Thu, 15 Jul 2010 15:31:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.storefrontbacktalk.com/?p=5704#comment-78364</guid>
		<description>I&#039;ve been saying it for years.. Why the &amp;$##$@(&amp; do merchants store ANYTHING? The only exception being subscription services that need to bill users periodically, and even that can be done differently, securely, and just as efficiently.

The convenience customers get for not having to present a credit card when they return something they bought is far out-weighed by the risk involved in trusting a stranger with your card&#039;s information.

PCI is just like the patriot act. Totally useless other than for PCI-certifying agencies, which are now making a ton of money charging for the privilege of having merchants answer ridiculous surveys &quot;correctly&quot;.

Alex</description>
		<content:encoded><![CDATA[<p>I&#8217;ve been saying it for years.. Why the &amp;$##$@(&amp; do merchants store ANYTHING? The only exception being subscription services that need to bill users periodically, and even that can be done differently, securely, and just as efficiently.</p>
<p>The convenience customers get for not having to present a credit card when they return something they bought is far out-weighed by the risk involved in trusting a stranger with your card&#8217;s information.</p>
<p>PCI is just like the patriot act. Totally useless other than for PCI-certifying agencies, which are now making a ton of money charging for the privilege of having merchants answer ridiculous surveys &#8220;correctly&#8221;.</p>
<p>Alex</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PCI Guy</title>
		<link>http://storefrontbacktalk.com/securityfraud/visa-to-acquirers-stop-forcing-pan-retention/comment-page-1/#comment-78361</link>
		<dc:creator>PCI Guy</dc:creator>
		<pubDate>Thu, 15 Jul 2010 15:05:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.storefrontbacktalk.com/?p=5704#comment-78361</guid>
		<description>I guess that means merchants will soon be required to switch to &#039;host-based&#039; processing systems, and deal with all the associated headaches, since the &#039;terminal-based&#039; transaction systems most merchants are currently using require storing PANs until the settlement batch is submitted. (Or does that not count as &#039;storage&#039;? Neither the PCI Council nor the card brands have been willing to clarify that point.)</description>
		<content:encoded><![CDATA[<p>I guess that means merchants will soon be required to switch to &#8216;host-based&#8217; processing systems, and deal with all the associated headaches, since the &#8216;terminal-based&#8217; transaction systems most merchants are currently using require storing PANs until the settlement batch is submitted. (Or does that not count as &#8216;storage&#8217;? Neither the PCI Council nor the card brands have been willing to clarify that point.)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pcidssguy</title>
		<link>http://storefrontbacktalk.com/securityfraud/visa-to-acquirers-stop-forcing-pan-retention/comment-page-1/#comment-78352</link>
		<dc:creator>pcidssguy</dc:creator>
		<pubDate>Thu, 15 Jul 2010 13:12:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.storefrontbacktalk.com/?p=5704#comment-78352</guid>
		<description>Rearranging the deck chairs…  While you must applaud Visa for coming out with a strong recommendation to improve the payment system, this particular action will do nothing to reduce the frequency of merchants getting breached.   PAN data has very limited value to the criminals.  You can’t make a counterfeit card with it.   The major threat to merchants today is the memory parsing malware that was identified by Trustwave back in 2008.  The way to protect against this threat is to secure the merchant’s network, a PCI-DSS requirement.  End to end encryption is starting to look like a promising security layer as well. 

A more meaningful recommendation for the acquiring banks would have been:  “Now that we’re past July 1 and all your merchants are running PA-DSS validated software, please make sure they install a commercial firewall and stop using their POS system for surfing the internet.”  

If this recommendation becomes an edict, it will create costly churn for the merchants, acquiring banks and technology providers that does nothing to stop the breaches.</description>
		<content:encoded><![CDATA[<p>Rearranging the deck chairs…  While you must applaud Visa for coming out with a strong recommendation to improve the payment system, this particular action will do nothing to reduce the frequency of merchants getting breached.   PAN data has very limited value to the criminals.  You can’t make a counterfeit card with it.   The major threat to merchants today is the memory parsing malware that was identified by Trustwave back in 2008.  The way to protect against this threat is to secure the merchant’s network, a PCI-DSS requirement.  End to end encryption is starting to look like a promising security layer as well. </p>
<p>A more meaningful recommendation for the acquiring banks would have been:  “Now that we’re past July 1 and all your merchants are running PA-DSS validated software, please make sure they install a commercial firewall and stop using their POS system for surfing the internet.”  </p>
<p>If this recommendation becomes an edict, it will create costly churn for the merchants, acquiring banks and technology providers that does nothing to stop the breaches.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

