CONTINUE TO SITE »
or wait 15 seconds

News

Some nets extend their TDES deadlines

Members of at least two EFT networks will have some extra time to make their ATMs Triple DES compliant, thanks to an extension of key deadlines. Both Star and Pulse received variances on behalf of their members from MasterCard.

July 28, 2004

Members of at least two EFT networks will have some extra time to make their ATMs Triple DES compliant, thanks to variances from MasterCard.

Both Starand Pulse received variances on behalf of their members. For both networks, the new "drop dead" dates, when all ATMs must be Triple DES compliant, is Dec. 31, 2005 -- nine months after MasterCard's deadline of April 1, 2005.

Hugh Burke, Star's vice president of internal audit, said that many in the industry expect this deadline will be difficult to meet, due to the large number of existing ATMs that will require upgrades and lingering confusion over exactly which makes and models can be upgraded.

Star is taking a hard line on that date, Burke said. "We're working pretty hard on getting all ATMs compliant across the board by then. We don't intend to grant any extensions past that date."

Vivian Banki, Pulse's director of IT risk management, said that many Pulse members require extra time to comply because of the large expense. "These legacy ATMs are costly to upgrade," she said, "In some cases it just can't be done, so they are looking at replacements."

"They have a plan," agreed Karen Gardstein, Pulse's executive vice president of finance and administration, "They just can't do it all at once. They've got to work on it as their budgets and workforces allow."

Selling it

The new deadlines are especially appreciated by ISOs, who face the daunting task of convincing the retail merchants who actually own the ATMs to upgrade their equipment

"The extra nine months to get the deal done is huge," said Rick Westenberger, president and chief executive of Amer-e-com Digital Corporation, a Florida-based ISO with some 1,500 ATMs under contract in the United States and Canada.

Westenberger said he expects considerable pushback from Amer-e-com's merchants. "They're not getting any benefits they can see and touch for their money," he said, noting that most of Amer-e-com's customers will need to spend several hundred dollars on Triple DES upgrades.

At the least, he doesn't expect them to rush to comply. "It's just like paying taxes," he said. "When you know you owe something, do you pay in February or wait until April 14th?"

Westenberger said he has been urging ATM manufacturers to offer slightly more expensive upgrades with some "extras" -- such as a new fascia or added functionality such as phone top-ups.

"It's pretty hard to sell mud. It's a little easier if you add some chocolate to it first," he said.

Host with the most (connections)

Star and Pulse also both received extensions from MasterCard for the dates when all host connections must be Triple DES compliant.

Star received an extension until April 1, 2004, a year after MasterCard's original deadline of April 1, 2003, which has already passed. Star had sought a date of June 30, 2004, Burke said.

"We're supporting some clients at the host level today," Burke said. "But there's no way we could have gotten them all up in time to meet the original deadline (of April 1, 2003). Not all of our clients can support Triple DES on their end yet."

Pulse's extension from MasterCard is Dec. 31, 2004. However, Pulse's own deadline for its members is June 1, 2005. Noting the six-month difference, Banki said, "Pulse tried to set dates that we felt were realistic for our members. We don't want to be in the position of issuing a lot of extensions and waivers."

Meeting MasterCard's deadline will be tough because host connections are "inherently more complex," she said. "There's a lot of testing involved there."

To complicate matters even further, Banki said, Pulse is in the midst of a major internal project to bring its switch in-house.

Underscoring the difficulty of meeting Triple DES deadlines, Burke said that not all vendors provided the necessary hardware and software for certification to meet Star's deadline of June 30, 2003 for all new and replacement ATMs to be Triple DES compliant.

Using slightly different language, MasterCard's deadline was for new and replacement ATMs to be Triple DES "capable" by April 1, 2003. The difference between "compliant" and "capable" seems to boil down largely to software. MasterCard changed the wording in its original Triple DES schedule from "compliant" to "capable" after it became apparent that many vendors had the hardware required to run Triple DES -- but not necessarily the software.

Despite all of the complications, Burke said, Star already has some terminals running Triple DES. "It's real to us now that we can touch it and feel it. It's working."

Related Media




©2025 Networld Media Group, LLC. All rights reserved.
b'S1-NEW'