Quantcast StorefrontBacktalk - PCI 1.2 To Let WEP Stick Around For Two More Years
E-Mail Us
PCI 1.2 To Let WEP Stick Around For Two More Years
Written by Evan Schuman
August 22, 2008
The new version of PCI due out in October will let the outdated WEP wireless security standard stick around for almost two more years, while also reducing the required frequency of firewall rule reviews.

But the changes confirmed by the PCI Security Standards Council this week—which have been circulated among members for the last few weeks—provide few other substantive changes besides delivering the mild tweaks and updates the council has publicly promised.

The document lists some 30 changes to the current PCI Version 1.1, and PCI officials promise that the official and final version—now slated for release on Oct. 1, a few weeks earlier than originally expected—will include yet more changes. (Were the omissions from PCI 1.2 even more important than what was included?)

Still, the document provides a fairly detailed peek into the council's thinking. The most significant change is language that addresses the much-maligned WEP and tries to balance conflicting member interests, from both those who argued that such a weak security approach should be banned as soon as possible and their opposite numbers, who spoke to the cost and effort that retailers would need to deploy to make the change.

"We needed to give people enough time to be able to comply. We wanted to make sure that there was enough time," said Bob Russo, the council's general manager. "There's a lot of expense for a merchant. We had feedback from some merchants that it would cause them some stress."

The new rule will say that "new implementations of WEP are not allowed after March 31, 2009" and that "current implementations must discontinue use of WEP after June 30, 2010."

Gartner security analyst Avivah Litan said the move is the right one, but quickly added that "they could have put out an amendment to upgrade this (WEP) requirement earlier. This is so long overdue that I don't know what the right word is."

PCI consultant Walter Conway, a former Visa VP, said the date compromise for WEP "reflects some business realities. I would have wanted the WEP changes; I would have wanted something much stricter and much sooner. I mean two years? I would have expected something stronger there."

Ed Adams, president of a security vendor called Security Innovation, said he had reviewed the changes and wanted to "criticize the council for caving in to vendor pressure more than anything else with the new changes. It's getting as bad as Capitol Hill filibustering and lobbyist groups setting new legislation."

David Taylor, a former Gartner analyst and currently the head of the PCI Knowledge Base, said some of the changes read as though they were "cutting some people a break."

For example, Taylor spoke of the section that requires annual visits to offsite storage sites. He mentioned a few concerns about that requirement.

"Because some of these locations are outside the U.S., it sounds like a travel burden for the merchant and a 'hospitality burden' for the service providers," Taylor said. "Also, a lot of banks and large merchants do visitation programs now. That's not how you find problems, by doing an annual tour of the facilities. It's done by asking lots of tough questions about process, reviewing procedures, etc. All you can see is that these places are physically locked down and that they are typically much more physically secure than retailers, so these visits won't prove anything."

An area that allowed retailers to not necessarily have video cameras watching every sensitive area is a mixed blessing, Taylor said.

"This will be a huge savings to some retailers who have been told by assessors to have cameras on every register, as well as in multiple places in the back office," he said. "That's all fine, I suppose, except that these tapes and discs are never reviewed until forensics people are brought in after a breach. Their main role has been to place blame, rather than to actually reduce the risk of a security breach. So this is a good thing that they're doing." (Taylor has a column in this issue pointing out that PCI has completely avoided addressing virtualization, and that he believes their silence ultimately will make no difference.)

Gartner's Litan said the changes were, for the most part, good, but they didn't address the key problems that have surrounded PCI. "A few things I was looking for were there, but it's kind of a yawner in terms of solving the real problems," Litan said. "This is good, it's an improvement, but the standard has never been the biggest issue."

Some of the other key changes:
  • Slightly softened the rule to maintain a firewall configuration, by reducing the required review frequency from once every three months to once every six months.
  • Clarified that a rule forbidding retailers from using "vendor-supplied defaults for system passwords and other security parameters" also applies to wireless. (Is someone suggesting that there existed professional retail IT security managers who made this argument with a straight-face? That someone actually argued—let alone believed—that vendor-issued default passwords are OK for anything, never mind a wireless deployment?).
  • "Removed requirement to disable SSID broadcast since disabling SSID broadcast does not prevent a malicious user from determining the SSID, as the SSID is broadcast over numerous other messaging/communication channels."
  • Deleted a reference in version 1.1 that said "Note: Systems commonly affected by viruses typically do not include UNIX-based operating systems or mainframes." The new version will "clarify that requirement for use of anti-virus software applies to all operating system types." (The bigger question is why the initial security standard felt compelled to encourage not protecting Unix and legacy systems.)
  • Softened the patching requirement section. The 1.1 version, for example, required retailers to "install relevant security patches within one month of release" and other specifics. The new version will add "flexibility to the patching requirement by specifying that a risk-based approach may be used to prioritize patch installation." (It's hard to argue that IT directors need to be able to make decisions based on specific circumstances. That said, installing relevant security patches within a month is hardly draconian. Said PCI's Russo: "In some cases, 30 days was too onerous.")
  • Specified that offsite storage locations must be visited at least annually.
  • In version 1.1, section 9.1.1 required retailers to "use cameras to monitor sensitive areas." Some assessors have interpreted that to require video monitoring of every POS station. The new rules will provide "flexibility in the requirement for cameras to allow organizations to select other appropriate access control mechanisms." It also clarified that the requirement to secure media applies to electronic and paper media containing cardholder data as well clarified destruction requirements for media containing cardholder data.
  • The new rules will "clarify that logs for external facing technologies (for example, for wireless, firewalls, DNS and mail) must be copied to an internal log server" and "provide flexibility and clarified that three months of audit trail history must be immediately available for analysis or quickly accessible (online, archived or restorable from backup)."
  • In the test process section, the 1.1 requirements specified that "quarterly external vulnerability scans must be performed by a scan vendor qualified by the payment card industry. Scans conducted after network changes may be performed by the company's internal staff." The new version wants to clarify that, regardless of whether the quarterly timing coincides with "after network changes," ASVs "must be used for quarterly external vulnerability scans."
  • The new rules will also specify "that both internal and external penetration tests are required and clarified that it is not required to use a QSA or ASV for penetration tests.

  • E-Mail StorefrontBacktalk Editor Evan Schuman at
    eschuman@storefrontbacktalk.com
    Search Through Blog Blurbs
    Search Through All Stories
    SFBT Twitter Feed
    Quickly catch-up on the latest in E-Commerce and Retail Tech with our free weekly newsletter, with urgent bulletins as news merits.
    StorefrontBacktalk will never sell your E-mail address to anyone at anytime.
    Evan Schuman is the former retail technology editor for eWEEK.com, PCMagazine, CIOInsight and retail reporter for RISNews and Consumer Goods Technology. Having covered IT issues for 21 years - and other stuff like legal affairs, politics, Wall Street and the environment for about eight years before that - Schuman is in a good position to gripe about technology trends and sometimes accidentally make a good point.
    Cyber Monday '08: The Butterfly Effect In Action
    Whether the wing flapping of a bug can eventually cause a tornado is debatable, but Cyber Monday 2008 should serve as a warning to E-tailers to avoid the lesson learned by Staples and Dell on Monday (Dec. 1): Don't ignore the butterfly effect.
    What Was Wal-Mart Thinking When It Made Key Site Changes On Black Friday?
    At about 6 AM on Black Friday, Wal-Mart's site went down for about an hour and then came up. But this time, it had moved its content pages to an outside service. Wal-Mart said it had been a scheduled change, a concept that Gareth Evans, head of client services at Web tracking firm Sitemorse, finds unlikely.
    Visa Card Holograms Shut Down POS Terminals
    In a trial of new holographic magnetic stripes for its payment cards, Visa found the cards "emitted an electrostatic discharge that caused POS terminals to shut down," according to a report in The Nilson Report, a respected credit card industry newsletter.
    Microsoft's Live Search Program Crashes On Black Friday
    Microsoft's Live Search cashback program—which gives rebates to those who comparison shop online and choose stores that are part of the program—was a bit too popular on Black Friday (Nov. 28) and crashed for several hours, leaving consumers with no cashback and a lot of anger.
    Sears.com Melts Down On Black Friday, But Costco, Walmart, Saks and Kmart Have Issues, Too
    Sears.com suffered the worst Web problems on Black Friday (Nov. 28), experiencing a series of complete site crashes for much of the day. Although no other major retailer came close, according to preliminary reports, many of the industry's largest merchants suffered site slowdowns or other Web problems, including Walmart, Kmart, Saks, Overstock, Amazon, Target, Kohl's, Costco and Buy.com.
    Visa Europe Testing A Reciprocal Authentication Card
    In a trial initially limited to the United Kingdom, Switzerland, Israel and Italy, Visa Europe is starting a trial this month of a card with an 8-digit alphanumeric display, 12-button keyboard and a long-life battery. The card has the ability to offer reciprocal authentication, which is designed to allow consumers "making transactions via phone or the Web a way to identify the party on the other end before transmitting identifying credentials."
    Black Friday Cyber Sales Up A Mere One Percent
    Black Friday (Nov. 28) E-Commerce sales hit $534 million, reflecting a one percent increase from last year's Black Friday, ComScore reported Sunday (Nov. 30).
    JCPenney Adds Merged Channel Twist, Including Wake-Up Calls
    A Web-generated wakeup phonecall to get customers to in-store early morning sales may not have a material impact on quarterly sales, but it's a creative touch for the E-Commerce site JCPenney relaunched right before Black Friday (Nov. 28). Even if the system's in-store inventory update isn't quite accurate.
    CRM Chutzpa: Best Buy Credit Card Thief Sought Loyalty Rewards
    A group of credit card thieves in Seattle tried to maximize their profits by using their stolen credit card data to open a loyalty card account with Best Buy, where they could get could extra benefits along with their stolen products, according to a federal indictment filed Nov. 19. One had tried a similar rewards scam with a Home Depot reward card and a Sears gift card.
    Tracking How Many Consumers Flee During A Site Meltdown
    Following a site meltdown by a major U.K. retailer this month, Internet traffic tracking firm Hitwise was able to document and make concrete what has always been assumed: Consumers abandon a retail site when it melts down faster than politicians vote for a tax cut.
    How Bleak Is The E-Commerce Picture? Mixed Messages
    Recently released numbers raise questions as to whether online will be much of a savior at all. New figures from eMarketer project that E-Commerce sales will top last year's numbers by some $5.6 billion, a 4.1 percent increase from $136.8 billion to $142.4 billion.
    PCI Fines: Nuisance Or A Ticket To ROI?
    Eduardo Perez of Visa has called its fines for non-compliance "nuisance" fines. In other words, the fines are not large enough to be a big financial burden to retailers but are large enough to get the CFO pissed off about having to pay them and maybe large enough to get a CEO to at least show up for a meeting to discuss PCI.
    Trying To Protect Payment Data When You Can't Even Find It All
    The IT struggle with knowing where all payment data is—let alone trying to enforce rules that pretty much try and keep it there—was the topic of a StorefrontBacktalk a podcast this week with our own PCI columnist, David Taylor, and security specialist J.D. Oder, the chief technology officer at Shift4.
    Is Price Comparison Dead? And, If So, Should We Celebrate?
    A Supreme Court decision from back in June 2007—intended to give consumer goods manufacturers greater control over their products' pricing—is fueling confusion, mistrust and runarounds among E-tailers trying to compete on price.
    Wal-Mart To Pay $1.4 Million Fine Because Of Price Change Database Problem
    Wal-Mart has agreed to pay $1.4 million to settle complaints that it overcharged customers in California. The Nov. 24 deal involved the mispricing of some 1,043 items over four years. Some of the problems happened because associates would make pricing changes to items in the store's register database but not in the aisle.
    PayPal To Use Cellphones To Authenticate Payments
    PayPal has come up with yet another payment-related use of a cellphone: to authenticate a non-mobile E-Commerce transaction. Customers of the payment giant "can now choose to receive a unique six-digit security code via text message to their mobile phones prior to logging in to their accounts," PayPal said.
    American Patriots Finding They Can't Rely On Barcodes
    There's an E-mail campaign that says consumers can identify American products by the first three digits of the barcode. In theory, this would allow people who only want to buy American products an easy way to do that. The only problem is that the trick doesn't always work, which means it could have the opposite effect.
    HP Finds Cutting Back Related Items Shown Boosts Sales
    When are related product lists helpful and when are they distracting? Is it an obviously useful upsell or is it doomed to the fate of the salesperson who shows a customer one too many choices? HP thinks it's often the latter and has sharply trimmed the number of related items it shows. And the company is claiming a 30 percent sales increase as a result.
    Amazon's Gift Card Future: Personal, But Not Too Personal
    Amazon.com, which arguably has one of the most extensive retail CRM databases and purchase recommendation engines, envisions a Catch-22 future for gift cards. The key is making them more personalized, more customized. And yet, anything that hints of privacy violations is off-limits. It's like a starving man being given the keys to a well-stocked food locker as long as he agrees not to eat anything.
    TiVo And Domino's Try E-Commerce Without The PC Or Phone
    As more retailers try to go where the customers are rather than getting them to come to the retailer, TiVo and Domino's are taking the next logical step with a TV-as-E-Commerce-Device approach.
    O, Kiosk, How Doth I Differentiate Thou?
    We make calls on PCs and surf the Web on our phones. The lines of separation are blurring fast. But in the world of retail technology, the difference between a kiosk and digital signage is one of the more difficult distinctions to make. How to describe that difference? To one CFO, the answer was obvious: A poem. In rhyming verse. Rhyming verse that is so bad it's almost good.
    Do You Have a Mobile Blindspot?
    The further employees get from corporate, and from corporate networks, the more likely they are to do things with their computer that security managers would rather they didn't. GuestView Columnist David Taylor asks if these people might be doing things (e.g., downloading malware) that could bring down your company?
    All Web Meltdowns Are Not Created Equal
    When file transfer site YouSendIt—with more than 100,000 paid users bringing in some $10 million this year—crashed on Monday (Nov. 17), it illustrated the kind of crash that should make retailers very concerned.
    Security Podcast: 12-Year-Old Data And Publishing Encryption Keys
    Podcast panelists debate card replacement problems, including inadvertently printing encryption keys on customer receipts and the refusal of the card brands to shorten how long expiration dates are valid. "We now have to worry about data that's been there as many as 12 years."
    Will Consumers Punish Retailers That Misuse CRM Data?
    A loyalty card that consumers can turn on and off could potentially usher in a consumer revolution of sorts, allowing the majority to punish merchants they see as misusing CRM data that has been entrusted to them. At least that's one scenario painted by the president of the company that is pushing the card.
    NRF Says Gift Card Spending To Drop
    Amidst an avalanche of hype about the desirability of gift cards this holiday season, the National Retail Federation on Tuesday (Nov. 18) predicted a six perfect drop in gift card sales this season, from $26.3 billion spent during last year's holiday season to a projected $24.9 billion for this season.
    What A Bond Villain's Datacenter Would Look Like
    Some 30 meters below solid bedrock underneath Stockholm, an abandoned nuclear bunker has been transformed into what could only be described as the world's coolest datacenter.
    E-Commerce Site Crashes To Soar This Holiday Season, With Upgrades, Partners And Discount Traffic The Likely Culprits
    Several factors are lining up—including rushed technology upgrades, more site handoffs for everything from mobile to social networking widgets and a surge in traffic from bargain hunters—that could easily make this holiday shopping season one of the crashiest in years, if not the crashiest. (Note to copydesk: I don't care if crashiest is not a word. It should be.)
    Sears Mobile Move Illustrates The Mobile E-Tail Challenge
    When Sears rolled out its mobile effort (Sears2go) this month, it illustrated the challenges for a retailer trying to craft a clean and stable mobile strategy at a time of extreme flux for the mobile space.
    "Store Locator" The Unsung Hero Of Web Analytics
    When E-Commerce execs try and understand abandoned shopping carts, they often overlook concrete clues. One of the best is whether shoppers clicked on the store locator link right before leaving. But deciding what to do about abandoned carts, that gets complicated. The innocuous-looking store locator is akin to waving a red cape in front of the face of an E-Commerce manager bull.
    How Much Do You Really Know About Your Security Consultant?
    The Web is overflowing with analysis of the TJX data breach disaster, but what's intriguing is the possibility that some of the indicted suspects may have worked as code writers in the light of day for some major companies, including Morgan Stanley.
    Would CRM Work If Customers Had An On/Off Switch?
    Equifax on Thursday (Nov. 13) announced an E-Commerce CRM and payment card that consumers can activate and deactivate based on how they feel about the site they are visiting. The only way such a card—dubbed the Equifax online identity card—will be successful is if it's adopted by a large number of retailers. And each of those retailers would have to be willing to surrender one of their most precious pieces of data: customer history.
    Site That Finds And Integrates Coupons With Low Pricing?
    We see tons of variations on the meta-search concept for E-Commerce, but this site seems to have hit on a truly practical combo: An engine that finds the lowest prices and simultaneously finds relevant coupons and then integrates the two.
    Visa's Global PCI Effort: Small Carrot, No Stick
    Visa, long the key driver of compliance with the PCI security standards, is helping to clear up merchant and service provider confusion regarding the global deadlines for PCI DSS compliance. But GuestView Columnist David Taylor notes some unusual phrasing and concludes that Visa wants to ease the compliance process to get more service providers outside the United States on board.
    Target, Best Buy Turn Gift Cards Into Literal Entertainment Devices
    Instead of making gift cards worthless once they're emptied, Target and Best Buy have opted for the other extreme: With enough micro electronics, the gift cards themselves might be worth more than the merchandise they can buy.
    Wal-Mart To RFID Crack Down On Chinese Suppliers By January
    Wal-Mart will insist that its Chinese suppliers comply with RFID tagging by January 2009. And given various recent safety problems reported from China, Wal-Mart is also requiring sub-contractor information be included with every tagged product.
    Best Buy's API Strategy Goes Beyond Social, Mobile
    Forced to try and boost revenue in a tight economy, Best Buy is pushing an aggressive plan—based partly on open APIs—to sell to customers wherever on the Web they're hanging out, rather than trying to get them to virtually travel to the retailer's online storefront.
    While U.S. Retailers Close Stores, World's Largest Mall Opens In Dubai
    While the headlines in the United States tell of store closings and expansions being back-burnered, it's a very different story in at least one part of the Middle East. In Dubai in the United Arab Emirates, Tuesday (Nov. 4) saw the world's largest mall opening ever.
    Ohio Man Pleads Guilty To $1 Million Barcode Scam
    The defendant pleaded guilty to heading a conspiracy that netted more than $1million by using phony UPC labels to obtain products and then sell them on eBay.
    One More Charged In TJX Breach
    Federal prosecutors have apparently accused a New York man of providing a sniffer program to help the TJX cyberthieves steal payment data. The fact that 25-year-old Stephen Watt has been charged with unlawful access to computers, wire fraud, aggravated identity theft and money laundering is not in dispute, nor is the fact that he has been accused of delivering a sniffer program to accused TJX mastermind Albert Gonzalez.
    RFID Market To Top $5.3 Billion This Year, Says ABI Research
    RFID sales globally will be more than $5.3 billion this year, with supply chain management, ID documents, ticketing and contactless payment drive shipments leading the way, according to a report released Monday (Nov. 3) by ABI Research.
    MasterCard Pushing NFC Mobile Program
    MasterCard's PayPass is ramping up its mobile program with an over-the-air provisioning service to supposedly make it easier for consumers to personalize their payment data on their mobile devices.
    PCI Avoidance Strategies
    Without a doubt, the most popular strategy for dealing with PCI compliance and data security is avoidance, writes GuestView Columnist David Taylor. Not unlike the game of "hot potato," which dates back to the pilgrims, the goal is to find someone who is willing to put up with the hassle of PCI compliance and then give that person all the credit card data.
    Costco's Embrace Of Online Customer Comments Illustrates How Innocuous They Are Now Viewed
    When Costco on Monday (Oct. 27) announced that it would support—for the first time—customer comments on its products, the move was less noteworthy for the $71 billion chain's late-to-the-party embrace than for what it says about the industry's acceptance of a once much-feared feature.
    The Old PCI Squeeze Play
    The position that there are far-reaching implications of the Payment Applications Data Security Standards (PA DSS) for the merchant community is hardly new, as they affect thousands of payment, infrastructure and business management applications. But GuestView Columnist David Taylor argues that some concerns raised by Jake Star, technology VP at HEI Hotels and Resorts, take this to the next level: the old squeeze-play level.
    Will Retail IT Be Spared The Recession?
    Although there is a little doubt that the United States is in for a very rough economic period over the next half-year or more, there is ample reason to believe that retail IT may escape mostly unharmed. Let's not get too optimistic here. "Mostly unharmed" doesn't mean escaping untouched. But it does mean that when large companies—especially retailers—have to suddenly make do with a lot fewer people, they need that good ole IT magic more than ever.
    Barnes & Noble E-Commerce Focuses On Experience
    The battle for booksales should be an online natural. But as Barnes & Noble discovered this week, the compelling, intimate experience of a physical bookstore is still proving elusive.
    Manufacturer Gets Creative To Meet Wal-Mart RFID Requirement
    Pet product maker Normerica opted for an unorthodox combo of smart boxes with embedded RFID tags and a mobile reader to comply with Wal-Mart's RFID requirement. The application was attractive because it reportedly involved "no significant retooling of its packing or shipping lines."
    Handheld RFID Reader Claiming 25-Foot Read Range, 400 Tags/Sec. Read Rate
    A Hong Kong RFID vendor is boasting about a new $1,950-$2,500 handheld UHF reader "with a read range exceeding 25 feet with standard dipole passive tags and a throughput reaching 400 tags per second." That claim is usually reserved for fixed readers, a very sharp claimed performance boost.
    Racial Slur Programmed Into POS At Genesco Store
    Genesco, which owns more than 2,000 stores operating as nine different chains including Johnston & Murphy, Dockers and Journeys, learned this week how POS receipt customization can be remarkably dangerous.
    Does The Rich Niche Twitch To A Different E-Commerce Itch? And If Ditched, Do They Switch?
    As the U.S. economy collapses (temporarily mind you, but a collapse nonetheless) and holiday sales contract, the one segment rumored to likely fare best is merchants selling to the highly affluent. But in what could be bad news for E-Commerce, those rich niche retailers tend to resist online sales more fervently than other E-tail segments.
    Could Software Allow Shelves To Look Back At Consumers?
    Technology that has been deployed to digitally watch—and analyze—how consumers interact with digital signage could also be used to interpret what they are doing while looking at a cereal shelf. Are they ignoring the product or are they picking it up, reading the label and then quickly putting it back?
    PCI Group Figures Out That The Word "Vendor" Is The Anti-Credibility
    The group originally called the PCI Alliance, which changed its name to the PCI Security Vendor Alliance on Tuesday (Oct. 21), has changed its name again—this time to the Payment Card Industry Security Alliance (PCI SA). Mercifully, it never bothered to change its URL, so it's still pcialliance.org.
    Big Lots Launches Its First E-Commerce Site With A "Deal Of The Day"
    When 1,361-store $4.6 billion chain Big Lots unveiled its first E-Commerce site Tuesday (Oct. 21), it decided to borrow a gimmick from its brick-and-mortars and re-create what it dubbed the stores' "treasure hunt atmosphere." Specifically, every morning, the chain plans to announce on the site a "deal of the day," which is a limited-inventory product at supposedly ultra-discounted rates.
    Holiday Online Sales To Grow This Year, But At A Much Slower Rate
    Two new reports paint a relatively slow growth picture for holiday E-tailers, although the projections are for double-digit growth this year. The dour side is that both projections are about half of the growth rate experienced last year.
    Could Japanese Mobile CRM Pilot Serve As Mobile Payment Prototype?
    A major Japanese mobile phone loyalty card trial slated to run from February through June of next year might prove to be a powerful prototype of how other countries might deploy mobile payment networks.
    When PCI Compliance Is A Competitive Advantage
    Companies are beginning to extend the protection of PCI-driven security controls to other confidential data, which is great, argues GuestView Columnist David Taylor. What is even better, he says, is that some service providers are finding they can leverage their PCI compliance to gain a competitive advantage.
    Australia's Woolworths Abandons RFID Plan To Trace Produce Crates
    Australia's Woolworths, which runs the country's largest supermarket chain, has given thumbs up to one RFID trial and thumbs down to another. "The overall cost for a company the size of Woolworths is still too high, and the return on investment for track and trace is just not enough for us to race ahead."
    Pizza Hut, Papa John's To Merge E-Commerce With Social Networks
    The very premise of E-Commerce is for E-tailers to create a beautiful site, where your customers come to shop. The latest trend, though, is to cut deals with your customers to buy from you anywhere but your site, whether it's on MySpace or Facebook social networking sites, from a cell phone, in the middle of a Google search or while watching a YouTube video.
    Study: Identity Thieves Swarm To English Speakers
    E-Commerce customers who speak English are "the most frequent victims of identity theft, twice the rate of France, Germany and Spain," according to a study released Tuesday (Oct. 21) by PayPal. The E-mail survey of 1,000 consumers was conducted this summer and examined six countries: the United States, Canada, France, Germany, Spain and the United Kingdom.
    Payment Authorization Terminal Sales Soar Worldwide
    As retailers across the globe modernize, the installed base of payment authorization terminals has soared almost 22 percent from 2006 to 2007. As happens typically in a growth segment such as authorization terminals, vendor consolidation has concentrated control—and, therefore, retail purchase options—into far fewer hands.
    Web Irony Of The Week: Sites That Sell Eyeglasses Have Weakest Support For Visually Impaired
    In their September stats, U.K. sites that sold eyeglasses and related vision aids fared among the very worst in one criteria: sites that are designed to be easily used by those with vision difficulties.
    Report: Power Attacks On Credit Cards Still A Major Threat
    It's hardly a new payment card security threat, but what has become known as differential power analysis (DPA) is still very much a threat on most payment smart cards. A DPA attack takes advantage of the electrical impulses inherent in any smart card.
    Circuit City Identical Online/Offline Pricing Plan Might Actually Work
    The Circuit City "one price promise" move could ultimately prove to be quite a clever piece of marketing. First, it will be trumpeted as a consumer advantage, even if it means that the price equality will be achieved by sometimes (all the time?) online pricing being raised to match the in-store price.
    Home Depot, McDonald's Pushing Non-Traditional Kiosk Trials
    Home Depot and McDonald's are both in the middle of non-traditional kiosk trials. McDonald's is on its fourth such trial, after having concluded that the first three simply didn't work well. Not too many retailers would opt for a fourth trial after three unsuccessful attempts. The non-traditional Home Depot kiosk trial is based more on the units themselves—small mobile units, some as tiny as 5-inches tall—and the size of the chain's planned kiosk commitment: Well north of $100 million for full deployment
    Wal-Mart, Amazon Learning That Product Downloads Are Harder Than They Look
    The last few weeks have not been kind to the product download efforts of retail giants. Last month saw Amazon inadvertently giving away tons of music and video downloads, courtesy of a glitch in Adobe's encryption approach. This month, it was Wal-Mart's turn.
    How Cloud Computing And Growing Franchisee Influence Are Hitting Retail IT
    Consider this: Is there a connection between a growing support for various cloud computing approaches and the increasingly active IT role that franchisees are taking? Yes, it's a wacky juxtaposition, but stay with me for a moment. There has been a steady noise coming from retail franchisees who are trying to drive more of their stores' IT strategy.
    New QA Review Toughens PCI Assessors
    When GuestView Columnist David Taylor wrote last week about PCI 1.2 changes, he received quite an earful from readers that some changes are having an even more strict impact.
    Is Wegmans' Self-Checkout Trial Truly For Customer Service?
    When supermarket chain Wegmans confirmed this month its first-ever self-checkout trial, it was billed as a customer service feature. That's technically true, but only in a very roundabout way.
    New European Card Data Theft Ring Raising China Questions
    A report this week from The Wall Street Journal
    about a European "credit-card fraud ring that funnels account data to Pakistan" and "uses untraceable devices inserted into credit-card readers that were made in China" sparked a lot of retail interest, but it's unclear how widespread or innovative the attacks were.
    Wine.com Federal Court Ruling Only The Beginning Of E-Commerce Changing Rules
    This is the latest volley in a federal court—and soon federal legislative—game of Internet taxation and control. Can states force E-Commerce sites to tax for them? Can municipalities police what gets sold in their communities, even via laptop or PDA?
    Home Depot Tackles A Supply Chain That Doesn't Recognize Geography
    "The systems were very poorly adjusted to reflect differences in locales," said CEO Frank Blake. "We are the single-largest less-than-truckload shipper in the United States. A lot of trucks are going to stores that aren't full. It's not efficient."