I have posited several times that compliance with the PCI DSS, with all of its idiosyncrasies and expense, has driven innovation in the payments space to a degree never before seen.  I even wrote a blog on the subject; How PCI Has Driven Innovation in Payments

However, over recent months, I have had the honour of working with several organisations who are throwing their hats in the ring, and trying to come up with ways to increase both the effectiveness of non-cash payments, but also the security.  Admittedly, these are still piggy-backing off credit cards, but the technologies are precursors to the demise of the card number itself. Basically;

If you don’t need a card number at the beginning of a transaction, why have a card OR a number in the first place?

Continue reading “How PCI Is Stifling Payments Innovation”

Have you all seen the ‘sneak peek‘ yet?

I have to admit, that with 3 YEARS to accept and process feedback, I was hoping for a little more in the way of progress.  I’m optimistic that way, but I really should have known better.

Many changes were proposed, lots of the them good, some of them naive and bordering on the comical, but any that made it through are so watered down as to be virtually irrelevant.  And we won’t get any more for 3 more years?

The standard is already behind the times, and is only going to become more so if it does not keep up with payments innovation, and show a better integration with the needs of the business. i.e. STAYING in business.

I have taken the table of changes out of the SSC’s document and added my own thoughts.  Unfortunately they are overwhelmingly negative, and at times my frustration is clear. Go here if you want to download it.

I do however want to make it clear that I’m not against the PCI DSS as much as I appear.  No standard has raised security awareness as much before, or since, and it’s the only one that puts its money where its mouth is.  While there is still some vagueness and room for interpretation, it’s a damned-sight better that just saying ‘use appropriate security based on good practices’ like most do.

The reason I stick to the negative is I’m assuming the positive is self evident, and all I really care about is addressing the gaps to where it should be.  As Ego says in Ratatouille; “In many ways, the work of a critic is easy. We risk very little yet enjoy a position over those who offer up their work and their selves to our judgment. We thrive on negative criticism, which is fun to write and to read. But the bitter truth we critics must face is that, in the grand scheme of things, the average piece of junk is more meaningful than our criticism designating it so.”

This applies every bit as much to my blogs.

I have only addressed the PCI DSS stuff, PA-DSS is not my thing.  If someone wants to take a stab at that, I’ll be happy to post it here as a guest blog.

 

 

Let’s just start with the basics, money;

There are ~1.5 BILLION credit cards in the US, and a replacement card is between $3 – $5. So you’re looking at an expense between $4.5 and $7.5 billion for that alone.Now add into that the cost of replacing ~10 million payment terminals to ACCEPT the new cards, at a cost of ~$50 – $100 each (at the VERY minimum), and that price-tag goes up by another $0.5 – $1 billion. Finally, every bank must replace / upgrade their back-end systems to PROCESS these new transactions, and I’m not even going to try to guess the cost (it’s a lot).

Yes this will be spread out of a number of years, but that’s like saying you’d like to get punched in the mouth a little bit at a time. No alternative is pleasant.

Cost aside, why would the banks make this expense when the main driving factor behind EMV is being negated on a daily basis by innovations in payment technology? Innovations such as mobile payment applications, and far more secure alternatives to the Chip & PIN itself, will drive the US to abandon their plans for EMV in favour of solutions that have a far longer shelf-life, are more secure, include Card-Not-Present (CNP) transactions (e.g. e-commerce), AND are not just a patch/fix to a 60+ year old technology.

The EMV concept itself was first put into real-world practice in France in 1992 – yes, 21 YEARS ago – and is now the de facto standard in over 100 countries globally. Except the US of course, who still rely on the magnetic strip first introduced by IBM in the 1960s.

This mag stripe method is the major cause of card-present (CP) fraud globally, which is why the US has been under increasing pressure to make the change. The issuing banks in the US, however, are very powerful in their own right, and have managed to delay things long enough to now have a valid reason to stop the plans altogether.

Good for them.

The need for PIN authentication will not go away any time soon, but the need for any payment terminal or payment application to ever SEE that number will. This is an enormous game-changer for both the banks, and the end users.

Chip & PIN transactions are cheaper than magnetic strip transactions for one reason; less fraud. However, you can’t use chip & PIN for e-commerce, where things like the CVV code, Verified by Visa, or 3-D Secure are used to similar, though limited, effect.

This restricts their usage to specific card brands, but this brave new world of innovation where the card brands are no longer the only game in town, a more ubiquitous PIN method is required that’s not only secure, but seamless, portable to legacy technologies, and affordable. Something like this; www.mypinpad.co.uk.

Suddenly:

  1. Expensive card-not-present transactions become cheaper card-present transactions saving millions for e-commerce;
  2. Legacy payment terminals that are not yet End of Life (EoL) can be kept, saving brick & mortar merchants millions;
  3. ATM payments become far less prone to fraud (under certain circumstances);
  4. Mobile payments become far more secure; and
  5. Liability shift is now firmly with the issuing banks

All of this is great stuff, and makes me wonder what’s next!

[If you liked this article, please share! Want more like it, subscribe!]

19-Dec-19: Clearly I was way off the mark here, but I still think it was a mistake!

If you came this far you did one of the following when you read the title:

1. Scoffed;

2. Screwed up your forehead in confusion, or;

3. Laughed.

Good, these all mean you’re cynical and therefore a perfect audience, so let me put you out of your misery; this is a story of unintentional cause and effect, and has started a trend that will not stop until credit cards as we know them are dead and buried.

About time too. 60+ year old technology in payments is akin to leaches in medicine (no offence card brands, but this analogy is particularly relevant).

When PCI was first drafted, it was very clear for whom it was geared; e-commerce organisations running Windows. How do you translate the configuration standard requirements (for example) to someone working on a mainframe. For Windows, you take out what you don’t need (hardening), for zOS, you build in only what you need. What about logging? Can syslog record everything you need in 10.2.X?

This is one of the most minor issues that drove organisations to seek alternatives to compliance, cost / effort / ROI, you name it, PCI is a burden any way you look at it. Yes, cardholder data should be protected, but enforcement of a single standard across all industry sectors and business types was never going to work.

At first, organisations became VERY creative in making their PCI burden go away. From outsourcing, to revamping all business processes in favour of truncated card numbers (except authorisation of course), to going back to cash only (not kidding). While almost EVERY merchant organisation should consider the first 2 anyway, it really didn’t help either retail, or e-commerce.

So the first foray into a technical ‘innovation’ was to make PCI go away for areas where they could not fix their systems to a degree that supported PCI compliance. Organisations started looking for alternatives to processing the full cardholder data; tokenisation was born (poetic licence, we’ve had forms of tokenisation for centuries). But this does nothing for authentication traffic which requires the fill account number.

Then came my personal favourite; Point to Point Encryption (P2PE), a.k.a. – and before the SSC decided to kibosh it – End to End Encryption (E2EE). The theory is very sound; encrypt the data for the point of interaction (usually a Pin Entry Device, or PED) all the way to the point of decryption, but the eventual PCI-approved solution is as complex as the DSS, limited (currently) to approved hardware devices, and requires a degree of certification few have even looked at.

A lot of organisations put their entire PCI programme on hold until such times as the P2PE standards were defined, and now that the first one (hardware/hardware) cannot apply to them, they continue to do nothing until such times as a hybrid standard is released.

So what you have here is; PCI forced the innovation, which in turn caused a justifiable delay in doing anything at all, which means that cardholder data is no better protected. Brilliant.

So P2PE, which had so much promise, is now stagnant. Organisations SHOULD have developed software solutions for legacy PEDs 3 years ago, which would have almost forced acceptance. But no-one did, and now it’s too late. How do you standardise a P2PE solution for an infinite number of scenarios? You don’t obviously, but with the advent of the next innovation, even PEDs themselves are becoming redundant…

We have the ultimate PCI and card brand killer; Mobile Applications / Mobile Payments. Still fairly new, growing exponentially – and to add the ultimate piece of irony – but cannot be PCI complaint unless the device was built for purpose. In other words, smart phones and tablets, by themselves, can never be PCI compliant. Not that this will stop their use.

Mobile payments, in all its forms, is already forcing the CARD BRANDS to innovate, or in the case of Visa, buy interest in vendors like The Square. But the SSC, as a standards only body, can never keep up. Eventually, as credit card numbers decline, so will the SSC and ALL it’s standards, and a replacement will be formed when people realise this massive drive for innovation has set us BACK in security…again.

That’s my final point of this blog; unless security is built in from the ground floor of this wave of innovation, the innovators will be directly responsible for the impossible-to-follow standards of the future.

As long as there are profit drivers, and Windows OS, I will always have a job…