site map | advertise | contact us
companies & products news research white papers classifieds videos project help
 
 
Classifieds
ATM Machine Comparison Guide
Event Calendar
Premium Reports
Slide shows

 

Recieve ATM News in your in e-mail inbox

Reach thousands of potential customers through ATM Marketplace and its sister sites.

Click to find out how.

 

Recieve ATM News in your in e-mail inbox

 

 

 

 

>Triple DES (3DES) Encryption

    

The 'gray' areas of Triple DES

Tracy Kitten, editor

• 28 Dec 2005

Triple DES. Some wonder if it's more of a conundrum than a definitive mandate.


This story and all the great free content on ATMmarketplace is supported by:

Qualtex

Manufacturer of the WeatherMaster!" line of Through-the-Wall ATMs, offers Distributor Programs for its ATMs, Accessories and Walk-Up/Drive-Up Kiosks.


Request free info
from this company!

Since 2001, when MasterCard International first introduced the idea of moving to a harder-to-crack code, the deadline for upgrades to existing ATMs (and point-of-sale terminals) has been a moving target. A quick scroll through ATMmarketplace's archives proves that.

Jerry Silva, a senior analyst with Boston-based consultancy TowerGroup, said a penalty for non-compliance is doubtful and why between 20 percent and 30 percent of U.S. financial institutions don't have Triple DES compliance even on the radar.

"I can't imagine there would be a big penalty," he said. "I think it will be like EMV in Europe, where you're liable if there is a case of fraud, but beyond that, it's not a big deal."

The truth, however, is that no one really knows what will happen if the Triple DES mandate isn't met - although most suspect MasterCard and Visa International won't enforce a penalty. And that absent fear of retribution has led to a great deal of hesitation, especially in the ISO space.

Other contributing factors, including deadline ambiguity, the lack of a big-picture understanding of the standard, and the cost associated with upgrading and replacing ATMs also have stalled the conversion process.

A look back

Most of the industry, by now, is very familiar with Triple DES. It's that complex encryption standard that's harder than single DES for hackers to break into.

start quoteThe biggest problem has been the extension after extension.end quote

-- Wayne Vandekraak,
Solvport LLC

As of Jan. 1, 2003, all newly deployed ATMs were required to support Triple DES. But deadlines for bringing existing ATMs into compliance, at least in the United States, have been confusing.

Sam Ditzion, president and chief executive officer of Boston-based Tremont Capital Group, an ATM industry advisory firm, said the Triple DES deadline has been more gray than black and white. "I suspect that we'll see a somewhat ambiguous gray period during the first part of 2006. Many ATM operators lacking formal extensions are not 100 percent Triple DES compliant yet, but I suspect that the networks and processors will either temporarily look the other way or officially warn, but not fine."

MasterCard's April 1, 2005, deadline didn't get pushed, but a number of extensions were granted. And Visa has come up with a compliance pyramid on which different deadlines have been set for different regions of the world. In the U.S., the deadline won't be enforced until Dec. 31, 2007, according to information posted on Visa's Web site, which Visa referred ATMmarketplace to in lieu of comment. No one at MasterCard could be reached.

"I think the difficult part is determining, 'What is the ultimate compliance method?'" said Kevin Gregoire, executive vice president of products and networks for Brookfield, Wis.-based Fiserv Inc. "How strong will the compliance be enforced? On one end of the spectrum the date comes, and in the event the client is not compliant, the strongest position would be that the ATM is being removed from the payment system, and that causes some disruption," which makes it unlikely.

What's Important

MasterCard's April 1, 2005, and Visa's Dec. 31, 2005, deadlines haven't moved, although a number of extensions or grace periods have been granted. Visa won't enforce its deadline until Dec. 31, 2007.

Neither MasterCard nor Visa has publicly said whether deployers that fail to comply with the Triple DES mandate will be fined, denied access the network(s) or simply held liable if a secruity breach occurs.

Deadline ambiguity, confusion about compliance and the upfront investment have led some FIs and ISOs to wait as long as possible.

Wayne Vandekraak, president and CEO of Beaverton, Ore.-based Solvport LLC, an independent ATM service company, said ISOs have been going in circles to understand the deadlines, and that's been an issue. "The biggest problem has been the extension after extension. I don't think smaller ISOs realize the risks they're running, but I think larger ones do, and that's why they're moving forward."

TowerGroup's Silva said only an estimated 35 percent of the U.S.'s 180,000 to 190,000 FI ATMs have been upgraded and/or replaced. He added that some mid-sized and small FIs will just wait it out.

Dean Stewart, director of software product marketing and management for North Canton, Ohio-based Diebold Inc., the No. 1 ATM manufacturer for U.S. FIs, said compliance for Diebold customers is closer to 75 percent in the U.S. FI space, but it's definitely not close to 100 percent.

"There were so many different dates," he said. "I would have thought that we'd be a little further along than we are now, but with the waivers, I'm not surprised."

Stewart said confusion surrounding the mandate led many deployers, especially FIs, to wait before moving forward. And Fiserv's Gregoire said not fully understanding the benefits of Triple DES led some FIs to hold off.

On the ISO side, cost has been the hold up, said Mike Cowart, director of operations for Atlanta-based RBS Lynk's ATM Services Division. "It's costly. You've got to convince a merchant that you sold an ATM to five or six years ago that he needs to upgrade, and that's a tough sell."

Triple DES upgrades and replacements haven't brought in the big bucks everyone expected. Executives at both NCR and Diebold have admitted that their companies were expecting higher ATM sales during the first two to three quarters of 2005, as FIs worked to replace older ATMs to meet the compliance deadline. (Read also, NCR, Diebold pursue other avenues in wake of dropping ATM profits.)

Sabrina Andrews-Turner, president of Grand Prairie, Texas-based Pi Systems International, which provides upgrade kits to FIs, said kit sales are just beginning to pick up.

"I'd say our customer base has doubled since this time last year," she said. "We had a lot of interest in early 2003, because they thought all of this would happen in early 2005 - the original deadline. And then when they realized the deadlines would be pushed, things slowed down in 2004. But now, with Visa and MasterCard saying this is it, 2005 has been a real bang-up year."

Processors put pressure on deployers

What has changed since last year is that processors are taking a lead role in spearheading the Triple DES switch.

Fiserv, which owns the Accel/Exchange EFT network, is pushing for a Dec. 31, 2005, deadline but will continue to process transactions on both single and Triple DES.

RBS Lynk has extended its compliance deadline to Dec. 31, 2006, and is actively working with ISOs to bring their portfolios into compliance.

Ron Herman, executive vice president of Nebraska Electronic Transfer System Inc., said all but about six of the 325 Nebraska FIs NETS works with have made the conversion. Of the 1,700 ATMs NETS processes transactions for, only 200 needed an extension until April 2006.

"We're confident that we'll have all except those 200 (ATMs) switched over by end of this year," he said, "well before what Visa is requiring."

 

 




Related articles on this topic: Triple DES (3DES) Encryption

Triple DES: Too high to comply?
Money Centers of America completes migration to Triple DES earlier than expected
Universal Money chooses Pi Systems for Triple DES upgrades
Triton selects Sagem Denmark as PIN-pad OEM
Indian banks want Triple DES ATM upgrade extension

 

© 2009 NetWorld Alliance LLC. All rights reserved.

MOST POPULAR
NCR confirms move to Georgia, in-sourcing of ATMs
Thieves use front-end loader to break into Chase bank ATM in Dallas
Bank of America says automated deposits at ATMs have some failures
ATMs reprogrammed to print out ATM, debit details on receipts
Triton, Nautilus Hyosung say it's back to ATM business as usual
Reaching the unbanked in Africa through the ATM, mobile channels
SURVEY: Russia overtakes Spain, U.K. as largest ATM market in Europe
Georgia's tax incentives paved the way for NCR move
Trojans hit more ATMs in Eastern Europe
ATM fraud and the top threats FIs are facing

NEWS HEADLINES sponsored by
Vault Cash/Cash Management: Woodforest Financial Group signs with Transoft for SaaS cash management solution
Digital Signage: John Ryan, Paco Underhill talk digital signage in banking
ATM Security: YESpay solves EMV issues for Canadian retailers with Chase Paymentech
Financial Institution ATMs: America’s Credit Union joins Credit Union 24 network
Vault Cash/Cash Management: Shell service stations in Germany sign with Wincor for upgraded cash management
ATM Security: ATM repair tech helps himself to £6,500
ATM Security: TJX reaches $9.7 million settlement in multistate suit for data breach
More News Headlines

FEATURE STORIES sponsored by
Advanced urethanes provide precision electrostatic, friction to improve cash dispensing at ATMs
A cashless society? Not yet, say experts
2008: The year of ATM skimming
Ask the Experts: ATM outsourcing in a downtrodden economy
More Feature Stories

WHITE PAPERS
Nanonation outfits Pinnacle Bank with digital signage
Branch Capture21
ATM security best practices
Diebold’s ImageWay helps credit union cut costs with streamlined check processing
EMV card fraud: Can your fraud detection system identify suspect chip card transactions?
Anti-Skimming Technology and EMV for the ATM
Check 21
More Guides & Special Reports

FEATURED PRODUCTS
A98 ATM Key Management System – A98-A -Comvelope© Solution
5% Discount on ALL Orders!
Airis ATM Continues to Support NCR 5600 Series ATMs
Seac Banche ORION
More Featured Products

VIDEO GALLERY
WRG's Apollo retail ATM saves floor space
Nautilus Hyosung touts first white-label EMV ATM in Canada
Susan Kohl of ThoughtKey talks ATMs and PCI
ArcaTech on check imaging
KIOSKCOM: ID Tech exhibits card reader solutions
More Videos

PHOTO GALLERIES
ATMIA Canada 2009
Wincor Nixdorf's International Management Seminar in Marrakech, Morocco
PULSE conference Debit ReDefined
Diebold anniversary and focus on Integrated Services
More Photo Galleries

ALSO ON NETWORLD ALLIANCE
Indiana prisoners visit family, friends via videophone kiosks   KioskMarketplace
The power of Twitter   KioskMarketplace
Hashtech Systems launches Nano kiosk line   KioskMarketplace
Indiana prisoners visit family, friends via videophone kiosks   SelfServiceWorld
The power of Twitter   SelfServiceWorld
Hashtech Systems launches Nano kiosk line   SelfServiceWorld
 
   
 
   
 
© 2009 NetWorld Alliance
 
Check out these sites for more news and information about self-service strategies and technologies:
 

Buy. Sell. Trade.
ATM Marketplace Classifieds

Get the latest ATM news delivered to
your in-box.
Click here to sign up for free.

Free Downloadable Special Publications