PCI-Less Card Payments: Square’s Mobile Scheme
May 25th, 2011When you push all rhetoric aside, PCI in-scope simply comes down to this: If a customer hands a payment card to any of a retailer's employees/contractors—or swipes or waves the card into a device inside or controlled by a retailer or types the information on that card into a Web site branded and controlled by a retailer—that retailer is subject to PCI. If customer doesn't, the retailer isn't. What Square's new approach, dubbed Card Case, does is fully take the retailer out of the line of fire of the card information.Read more...
Cards issued by European banks when used online cross border don't usually support AVS checks. So, when a European card is used with a billing address that's in the US, an ecom merchant wouldn't necessarily know that the shipping zip code doesn't match the billing code.
-Marc
