0 Comments
In the wake of the Heartland-hacker nab, the Payment Card Industry Security Standards Council has unveiled new best practices for retailers that aim to help merchants defend themselves against the growing number of credit- and debit-card skimming scams.
 
According to an article in DarkReading, skimming is a growing problem for grocery stores, gas stations, convenience stores and other retailers and their customers, who are increasingly falling victim to compromised POS devices and ATMs.
 
Bob Russo, the general manager of the council, says skimming is a widespread problem:
These are guidelines for what retailers should be looking at with their reader devices. We discuss different techniques for protecting those point-of-sale devices.
But Chris Paget, a security researcher who himself fell victim to an ATM-skimming attack at the recent DefCon conference in Las Vegas, tells DarkReading that skimming attacks are a symptom of an already-broken system of credit and debit cards:
The concept of a 'credit card' as it exists today is the problem. If credit cards were cryptographic devices rather than just numbers, then none of these threats would be a problem. The technology exists to implement this today and to completely eliminate credit card fraud, but it seems there's too much money being made from fraud for the card issuers to care.
Paget says the PCI guidelines neglect to address two areas of potential fraud: a malicious merchant stealing the data, and equipment that is tampered with at the factory:
If the person you give your card to at a restaurant has their own card skimmer, you're just as vulnerable. (And the guidelines) do not address the case of legitimately purchased equipment that was tampered with at the factory, nor the case of a software-only addition to an ATM or card reader.
The PCI Council's "Skimming Prevention: Best Practices for Merchants" guidelines, include a risk assessment questionnaire and self-evaluation forms to help retailers gauge their risk. The guidelines detail how to identify a rigged reader and what to do about it.

Related Content

Reader Comments

Add a Comment

We welcome your thoughtful comments. All comments will display your real name.

Want to participate in the discussion?

Or log in for complete access.

  • Clear
  • Post
Be the first to post a comment for this story.
Products & Services

ATM makeover

http://global.networldalliance.com/new/images/products/blank_logo.jpg

1209/ATM-makeover

ATM Mockup Service

http://global.networldalliance.com/new/images/products/4130.png

4130/ATM-Mockup-Service

PAI Wireless

http://global.networldalliance.com/new/images/products/4657.png

4657/PAI-Wireless

ATM Decals & Signage

http://global.networldalliance.com/new/images/products/4128.png

4128/ATM-Decals-Signage

NCR APTRA Suite

http://global.networldalliance.com/new/images/products/5001.png

5001/NCR-APTRA-Suite

ADA-Compliant Braille Decals: In Stock, Same Day Shipping

http://global.networldalliance.com/new/images/products/4726.png

4726/ADA-Compliant-Braille-Decals-In-Stock-Same-Day-Shipping

Teller Automation Services

http://global.networldalliance.com/new/images/products/Teller_Automation100.gif

1085/Teller-Automation-Services

ATM Solutions

http://global.networldalliance.com/new/images/products/5067.png

5067/ATM-Solutions

ATM Programs and Services

http://global.networldalliance.com/new/images/products/4648.png

4648/ATM-Programs-and-Services

Convenient Ordering & Industry Best Service

http://global.networldalliance.com/new/images/products/4107.png

4107/Convenient-Ordering-Industry-Best-Service

Request Information From Suppliers
Save time looking for suppliers. Complete this form to submit a Request for Information to our entire network of partners.