Join the Community

23,994
Expert opinions
40,646
Total members
356
New members (last 30 days)
208
New opinions (last 30 days)
29,267
Total comments

Credit card numbers are like nitroglycerine

It's terrific that merchants are increasingly pushing back on PCI-DSS.  It really is high time we shifted the emphasis from ad hoc stop gap compromise measures, onto tackling the real problem: the replayability of account data. 

Credit card numbers are a bit like nitroglycerine: handle them with great care or they'll blow up!

The slightest slip-up, the smallest weakness in database security in the face of sophisticated Advanced Persistent Threats, and tens of millions of card numbers are lost to criminals.  PCI-DSS compliance is fiercely expensive, but all it does is protect against accidents; it is powerless to stop determined attackers or corrupt insiders.

Is it fair to hold merchants responsible for the highly technical handling procedures of the PCI-DSS regime, when instead the card companies could stabilise their highly volatile card data?

The fundamental problem with payment card safety (as is the case with most digital identity security) is that numbers are replayable.  It's child's play to take account data and replay it against unsuspecting merchants, either via cloned mag stripe cards or even easier, in online CNP fraud.

Yet with chip technologies now widespread, and digital signature primitives ubiquitous in computing and Internet platforms, it's nearly trivial to eliminate replay attacks.  Not only could we dramatically reduce the cost of stolen card details, we'd pull the rug out from under organised crime, and we'd boost privacy by cutting the vicious cycle of gathering more and more ancillary personal data for proving customer identity.

Stephen Wilson, Lockstep, Sydney, Australia.

 

External

This content is provided by an external author without editing by Finextra. It expresses the views and opinions of the author.

Join the Community

23,994
Expert opinions
40,646
Total members
356
New members (last 30 days)
208
New opinions (last 30 days)
29,267
Total comments

Trending

Carlo R.W. De Meijer

Carlo R.W. De Meijer The Meyer Financial Services Advisory (MIFS) at MIFSA

Europe’s digital payments push: Consortium of EU banks launch euro-based stablecoin

Alex Malyshev

Alex Malyshev CEO, Co-founder at SDK.finance, FinTech software provider

High-Volume Transactions: Essential Benchmark or Industry Hype?

Anurag Mohapatra

Anurag Mohapatra Director of Fraud Strategy and Marketing at NICE Actimize

The High Stakes of Check Kiting: How Old School Fraud Exploits FIs

Now Hiring