As I stated in my previous article Target Breach: What Does This Say About Their QSA?, the more naive questions that inevitably follow a major breach like this revolve around a couple of things:

  1. What good is the PCI Data Security Standard if this kind of thing still happens, and;
    o
  2. What did the QSA do wrong?

Both of these questions are the WRONG questions to ask, and display an ignorance of good security practices, the PCI compliance assessment process, and the intent of the PCI standard itself.

First, the intent of the standard was never to prevent beaches from happening entirely, that’s impossible, so the intent was always to REDUCE the instances of breaches to a point that can be considered ‘best efforts’. Every other standard or security framework out there use phrases like ‘reasonable’ or ‘appropriate’, and make absolutely no effort whatsoever to help you figure out what these things mean in your environment.

PCI went the other way, and explicitly implied (by the very nature of the DSS) that if you implement all of the controls, that the resulting risk reduction was good enough. Not once did they ever say PCI compliance was actual security, and not once did they ever say that you should stop your security program AT compliance. The PCI DSS has always been, and will always BE a minimum set of controls around a single form of data, and should NEVER have been seen as enough security for your business.

So, ANY individual who is surprised when a company that has achieved compliance is breached, should do their homework before pointing fingers. Target was an enormously valuable prize for thieves, and warranted an effort far above anything PCI compliance, or maybe even good security, could have hoped to prevent.

As for the QSA, you just have to look at the assessment process itself to see that the PCI DSS should never be confused with either a comprehensive security framework, or even a reasonable assessment of compliance. Any standard that allows both sampling, AND point-in-time validation, can only ever be seen as scratching the surface, especially with an organisation the size, distribution, and complexity of Target. There is simply far too much that the QSA will not see in a given year to point fingers in that direction.

Sampling is a privilege, not a right, and has to be earned. You start at 100%, and work down from there, and to even allow sampling in the first place, a few things must be in place:

  1. Standardised Builds: Just because every Windows system is built from the same base image (for example), does not mean that all Windows systems can be sampled randomly. Every system function, location, admin team, etc. must be taken into account, and a justifiable cross section of systems included.
    o
  2. Centralised Maintenance/Management: For sampling to be valid, it must be shown that ALL systems in the environment are maintained identically. From patching, to updates, to anything else that affects the ‘like’ systems, uniformity must be demonstrated.
    o
  3. Centralised Monitoring: Unless all systems in the estate where sampling is proposed are monitored centrally, each distinct monitoring unit must be handled separately.

In other words, unless you can show how the systems are configured identically, managed identically, and monitored identically, sampling is not an option. Even with this in place, the potential gaps are significant.

As for the point-in-time aspect, even the cards brands themselves don’t understand that at the time of compliance, the assessment process allows validation evidence that’s 364 days old. There is nothing in the DSS, or any other document produced by the SSC, that states that validation evidence cannot be more than x days/months old.

Instead, it seems to be assumed that the RE-certification process, including evidence gathering, happens in the last few weeks of the compliance cycle. It simply does not work that way. Unless you provide a list of evidence / remediation requirements MONTHS in advance of your client’s compliance deadline, any surprises can either prevent re-compliance, and/or create significant internal re-tasking. So, generally, this will involve collecting evidence 6 months old at a minimum.

A lot can happen in 6 months.

As I stated at the end of my previous blog on the Target breach, the fault – IF there is any – lies with Target stopping their security program at just PCI compliance. If they didn’t stop there, and had gone above and beyond, then it’s just one of those things, hopefully a lesson learned, and we should all focus on something a little more constructive.

Like getting away from the use of credit cards for example…

[It’s clear that this topic has wayyyy too much material for just a blog, so at some point I’ll back this up with a white paper or some such. Please accept this as an amuse-bouche];

Today, the savvy buyer does their homework on all major retail expenses, ensures they have they the funds for it (debit or credit), and finds the best deal BEFORE buying.

The non-savvy, or impulse buyer, tends to get hosed, which may result in several things; the buyer either changes their minds and returns the item (and/or gets into financial difficulty), the merchant has a second-hand system to get rid of AND has the hassle of a charge-back, and the financial institution behind the payment runs the risk of non-repayment of the resulting bad debt.

While you’re never going to get away from consumers making bad decisions, you CAN make level the playing field, and make the experience for all parties less risky, more efficient, and potentially cheaper all round.

Two of the challenges we face today are:

  1. The vast majority of new businesses in the payments space are innovators, and have a very narrow focus. i.e. see a need, fill a need from a niche perspective. So if you’re looking around for those types of services, you have hundreds of small organisations from which to choose, and you either gamble, or wait until the market settles down and risk missing out entirely on a potential competitive edge.
    o
  2. Every player in the payments ecosystem is either a dependent, or in competition, leaving everyone worse off, especially the consumer. You just have to look at the number of e-wallets, coupons, or loyalty point systems to see that 99% of them are unsustainable. The corollary is that new innovations in the retail space are very slow to be adopted, if at all.

So how do you choose the right combination of payment services for YOUR business?

Choose the right one(s) and the benefits are clear and ongoing, choose the wrong one(s) and you’ve potentially damaged your brand reputation. How many times have you collected loyalty points (for example), and never had the opportunity to enjoy the benefits?

The biggest issue the payments ecosystem faces it that the true cost of an expense if rarely apparent up front, and your payment options are limited to the offers of either your existing financial institutions, or of the retailers themselves.  Instead, what if the banks made available enough information at the time of purchase for you to choose the RIGHT payment option?

Bob Mackman wrote a short white paper How to Pay: The Future for Mobile in m-Commerce, in which he posits that for a mobile application to;

…weigh up the advantages of each [payment method] by looking at things such as: available credit, due date, interest rates and any loyalty schemes and give them the pros and cons of each for this particular purchase at this moment in time. Perhaps putting them into an order of preference.

…that the background financial institutions would first need to provide;

“…direct access to the information from the bank and card accounts being used. If the providers made API’s available for even just some basic transactions then this would be possible.”

You can imagine how often his happens currently.

But, if the banks could see the amazing potential this provides, then this would not be the “pipe dream of a romantic“, as Bob puts it, but a reality in which anyone NOT providing these services is left behind.

Like most things, it’s not that easy. For this to truly work you have to consider all of the following and many more:

  1. Authentication – ALWAYS the primary consideration in payments
  2. Ratings & Reviews integration – against financial services, retailers, products etc.
  3. Big data analytics and customer profiling resulting in targeted displays / coupons based on instant access to metadata of preferences (e.g. material / colour / designer)
  4. Existing payment technologies – PEDs, EMV, NFC, e-wallets and so on…
  5. New[er] payment technologies – Bluetooth beaconing, geolocation, bio-metrics and so on…
  6. Payment choices / instant credit through existing financial institutions (which has dependencies on single purchase interest rates and unaffected credit ratings etc.)

So who’s going to be able to put this all together? No-one currently, but in much the same way that the enormous growth of telecoms options resulting in a spin-off industry of consultants providing consolidation / savings services, the soon to be exponential growth of payment technologies will spurn a new breed of consultant; the payments Service Provider Integrator (SPI).

From banks, to payment gateways, to ratings & reviews, to loyalty, to anti-fraud, the SPI will be able to seamlessly integrate all the niche providers into a whole-istic solution designed to meet an organisations goals.

Here I must stop, but this will continue in more detail in the pending white paper.

If you have any ideas around this stuff, please share, I’ll make sure to build it in.

 

Anyone who has read my blogs knows that I am very critical of credit cards and EMV as payment technologies. I am also equally critical of the card brands themselves for attempting to spread their use when there are so many other more convenient, safer, cheaper , and future-proofed options out there. With mobile applications, e-wallets, and whatever comes next, the piece of plastic with which we are all so familiar will die in its current form.

Then two products come along and I find myself having to adjust my thinking …somewhat. I still think the card brands are wrong, but I have reached my own internal compromise based on one difficult truth; I have become so enamoured with innovation, that I have lost touch with the only question that’s relevant;

Is it functional?

To me, there is no innovation without practical application, and no function without benefit and use. In other words, innovation is great, but if it’s not adopted, AND makes things better, it’s just a fad.

The two products that caused this revelation are pinCode and Coin:

pinCode is an awesome little product that covers a gamut of authentication mechanisms in a credit card sized token, and Coin allows you to load multiple credit / debit cards on – you guessed it – a credit card sized token.

Each has a fundamental flaw; pinCode cannot replace multiple cards, Coin does not authenticate payments.

Now imagine if you could combine the two.

You would no longer need multiple pieces of plastic you would have just one. Whether you load your credit cards, debit cards, branded, non-branded, or any other form of electronic payment information, it would now all be in one place, with authentication mechanisms built in that would cover every provider.  No more chip and PIN, pinCode takes care of that, and no more thick wallets, Coin takes care of that.

Added benefits;

  1. The bluetooth technology in Coin could be adapted for non-NFC contactless payments, as well as its existing security feature of alerting you if the card is more than x feet away
    o
  2. Backwards compatibility with magnetic stripe only terminals, but each bank could add authentication mechanisms with the pinCode functionality
    o
  3. Continued use of existing credit accounts, but now without the need to issue credit cards. The information contained on a credit card magnetic stripe or the EMV integrated circuit (IC) can just as easily be sent or downloaded as long as the authentication is sound
    o
  4. Chip and PIN would be unnecessary globally. Therefore no requirement for expensive payment terminals, leading to a massive expansion of payment technology to emerging markets / micro-merchants
    o
  5. Every bank can be its own payments scheme and neither the cards, payment terminals, or back-end systems are tied to any particular card brand or region
    o
  6. Your ‘credit card’ can now be used for multiple authentication requirements; from a physical security pass, to 2 factor authentication, to call centre mutual authentication
    o
  7. Carrying a ‘spare’ credit card is now so much simpler. As a frequent traveller, I not only have a spare credit card, I have FOUR spare credit cards just in case (Visa Credit, Visa Debit, MasterCard, Amex). Being able to replace all the credit cards with a vastly improved one, as well as not having to worry about it being stolen makes me drool

However, and back to my original point, this MAY end up prolonging the life of the card brands, but even I can’t deny that there are literally hundreds of millions of people who are already used to carrying little pieces of plastic. As long as this ‘interim innovation’ can instil more security, greater functionality, and perhaps a little more competition, then so be it.

Mobile applications and smartphones will rule the day eventually, and the combination described above will actually begin the process of educating people that electronic payments and phones will no longer be as separate as they are now.

This is the perfect gap-filler between present and future, and it all points back to where it began; authentication.

 

 

Apparently an announcement was made at the PCI SSC ‘s Community Meeting in Nice that “European Payment Services (EPS), [is] the first company to have a solution listed…“, this according to Tenable’s Jeffrey Man in his new article ‘What’s Wrong with P2PE‘.

I’m not going to go into why P2PE is dead from a PCI perspective, Jeff covered that better than I can, instead I’ll cover it from an innovation and real-world perspective that the SSC simply cannot / will not include in their presentations.

Why P2PE is pointless, and dead before it reached the gate:

  1. If you have read the P2PE assessment procedures (which were about 2 years too late in being released), you’ll know that they make the PCI DSS look like a nursery rhyme. EXTREMELY complicated, and ENORMOUSLY expensive to achieve certification. I was, however, very surprised that PED / payment terminal companies with significant resources (like VeriFone and Ingenico) didn’t get into a race to corner the market early, but now it makes sense;
    o
  2. P2PE done the SSC’s way still requires PTS and SRED compliant payment terminals, which are massively expensive, and whose days are numbered. Mobile payments, and whatever comes next will, thankfully, kill retail’s reliance on payment terminals and bring secure, non-cash, payment capability to every merchant world-wide, no matter how small, or large and distributed;
    o
  3. Chip & PIN (EMV) technology is tied to the terminals and to the use of credit cards, which along with payment terminals, are dying technologies. Credit cards are 60+ years old, and EMV was a very poor patch to fill a gaping hole in credit card security, so innovation will, and in some cases already has, replaced the need for both;
    o
  4. Retailers are simply not going to make the massive investment in replacing their payment terminal estates before they end of life (EoL) just because of a possible reduction in PCI scope. And why would they then spend a fortune in expensive devices, tie themselves into a single service provider, as well as limit themselves to credit card transactions? Answer; they wouldn’t, not unless they’re irretrievable stupid;
    o
  5. The entire payment space is finally recognising the fact that it’s bloated, inefficient, enormously outdated, and complex. Innovation will simplify it back to its basics, which it that it’s not ABOUT payments, it’s about authentication. I don’t care how I access my funds, whether they be debit or credit (both of which are provided by the bank anyway), I just want to do it whenever I want, wherever I want, and without risk.

Any protection the card brands provide related to fraud and consumer protection can be provided cheaper and probably better by the banks, and this, along with the demand for better customer service, will drive the banks to compete for our business as never before. Gone will be the days that they can act as though they are doing US a favour.

As for the SSC’s announcement, I can’t blame them for wanting to announce any kind of success, God knows the DSS v3.0 is nothing to write home about.

[If you liked this article, please share! Want more like it, subscribe!]

My penchant for dramatic titles aside, perhaps a more accurate – and less controversial – title would be; “Why The Card Brands SHOULD Secretly Hate Chip & PIN“, and the reason is simple; it’s in the way of their business.

The only reason chip and PIN (or EMV) is championed publicly by the brands is that it works, and has significantly reduced card present fraud (or face-to-face payments) in those areas that have mandated it, which is basically almost all the world’s industrialised nations except the US. If you want to know why I think the US will never adopt EMV, my thoughts are here; Why the US Will Not Adopt EMV (Chip & PIN)

The most basic and fundamental misunderstanding about EMV is that it’s a payment technology, it’s not, it’s an authentication technology.  And a very inefficient one at that.  The reason it reduces fraud is that anyone can swipe a credit card to buy something, but not everyone has the PIN number associated with that card to complete the transaction.

So the concept is sound, but the implementation is fatally flawed:

  1. It’s not a real-time authorisation, it’s performed offline by the PIN Entry Device (PED) – a.k.a. payment terminal – itself, therefore the PED must have a significant capability that is no longer required given recent innovations in authentication technologies
  2. The PEDs that are EMV capable are incredibly expensive as a result of 1. above (between £400 – $2,000 each), and are therefore out of the reach of the largest retail segment globally; the micro-merchant (e.g. corner store, street market vendor and the like)
  3. It has already been shown as vulnerable to attack. Yes, it was a VERY specific circumstance in which it was broken, and it’s still very difficult to do so, but the only reason it’s not further exploited is because thieves are lazy and there are still so many easier targets out there
  4. The PIN authorisation is only for card payments, it is not extensible to any other scenario where a similar mechanism would be desirable (logging into your bank online, Doctors access medical records etc.)
  5. You still have to carry a piece of plastic around with you, and credit cards are a dying non-cash payment technology

If you accept the above as true, then it’s relatively trivial to determine why the card brands must hate EMV:

  1. It will be very difficult to expand credit cards to regions that are either resisting EMV due to replacement costs (i.e. the US), or initial implementation costs (non-industrialised countries). They simply cannot introduce any card-dependent technology other than one that provides authentication capability
  2. Try telling a merchant in sub-Saharan Africa bringing home less than $1,000 a year that they need to spend a year’s salary to do business with European tourists and you’re not going to get much adoption. A non-EMV PED can be had for less than $100, which is far more palatable. I’m sure some enterprising service provider would be happy to rent them out too
  3. Why roll-out a technology that will eventually be relatively easy to break? Security is not about being totally secure, it’s about being secure enough. Build a secure device and a bad guy will work out how to break it, and this will never change. EMV capable devices are, but their very nature, incapable of adapting to a newer, more secure technology
  4. Authentication needs to be ubiquitous, people simply don’t want lots of different passwords to remember. Authentication as a Service (AaaS) will expand to include payments, and the best way of delivering this service is over a mobile device, not a credit card
  5. In order to continue their reign for a few more years, the card brands must rapidly expand their influence in regions that simply cannot support EMV

In the end you have to realise what the card brands are; they are a mechanism to get access to your money without the use of cash. This was great while they were the only game in town, but they are not anymore, and unless they can justify their interchange fees by  providing secure payments to EVERYONE’S convenience they will be the next victim of disruptive innovation.

EMV has run its course, and I would be VERY surprised if the card brands continue to support it given that fact that it actually hastens their demise, not prolongs it.