Join the Community

21,997
Expert opinions
44,168
Total members
415
New members (last 30 days)
152
New opinions (last 30 days)
28,672
Total comments

Credit card numbers are like nitroglycerine

It's terrific that merchants are increasingly pushing back on PCI-DSS.  It really is high time we shifted the emphasis from ad hoc stop gap compromise measures, onto tackling the real problem: the replayability of account data. 

Credit card numbers are a bit like nitroglycerine: handle them with great care or they'll blow up!

The slightest slip-up, the smallest weakness in database security in the face of sophisticated Advanced Persistent Threats, and tens of millions of card numbers are lost to criminals.  PCI-DSS compliance is fiercely expensive, but all it does is protect against accidents; it is powerless to stop determined attackers or corrupt insiders.

Is it fair to hold merchants responsible for the highly technical handling procedures of the PCI-DSS regime, when instead the card companies could stabilise their highly volatile card data?

The fundamental problem with payment card safety (as is the case with most digital identity security) is that numbers are replayable.  It's child's play to take account data and replay it against unsuspecting merchants, either via cloned mag stripe cards or even easier, in online CNP fraud.

Yet with chip technologies now widespread, and digital signature primitives ubiquitous in computing and Internet platforms, it's nearly trivial to eliminate replay attacks.  Not only could we dramatically reduce the cost of stolen card details, we'd pull the rug out from under organised crime, and we'd boost privacy by cutting the vicious cycle of gathering more and more ancillary personal data for proving customer identity.

Stephen Wilson, Lockstep, Sydney, Australia.

 

External

This content is provided by an external author without editing by Finextra. It expresses the views and opinions of the author.

Join the Community

21,997
Expert opinions
44,168
Total members
415
New members (last 30 days)
152
New opinions (last 30 days)
28,672
Total comments

Trending

Kyrylo Reitor

Kyrylo Reitor Chief Marketing Officer at International Fintech Business

Forex Market Regulation on the African Continent

Francesco Fulcoli

Francesco Fulcoli Chief Compliance and Risk Officer at Flagstone

National Payments Vision 2024: The UK's Vision for a World-Leading Ecosystem

Now Hiring