What Would PCI Say About Filming Payment Cards? We Shouldn’t Use That Type Of Language

Written by Walter Conway
August 3rd, 2011

A 403 Labs QSA, PCI Columnist Walt Conway has worked in payments and technology for more than 30 years, 10 of them with Visa.

Words matter. When one uses terms like “two-factor authentication,” “sensitive authentication data” or “high vulnerability” in the context of PCI DSS, the words convey a very specific meaning. Each term conveys specific information, and misuse leads to confusion and errors. A recent payment vendor move—using Webcam footage of payment cards supposedly to deliver some card-present-like advantages—misused some important payment-card terminology. The product also raises new security problems. Confusion is bad, but increased risk is far worse.

If increased risk is not enough, using video to capture payment-card information means that retailers would have to absorb all the cost of complying with every PCI requirement without the benefit of lower interchange fees. One also has to wonder if using video cameras to validate cards means retailers will need to search for rogue video devices the same way they must test for the presence of rogue wireless access points today. Speaking of videos, another bad-guy trick could be harvesting legitimate cardholders’ videos and selling them like stolen primary account numbers (PANs). This technology could result in an entirely new secondary carders market.

In the world of payment cards, the incorrect use of industry-specific terms risks misleading anyone who is not a payment-card expert, whether intentionally or accidentally.

This point is important as retailers and vendors struggle to apply all manner of 21st Century technological wizardry to circumvent the restrictions of a mid-20th Century technology: the magnetic stripe card. Each technology struggles to meet the needs of a Web-based consumer-payment market. One outcome of this struggle will be new technologies and approaches that in turn introduce their own particular layer of risk to the transaction. Another outcome is one retailers address every day: PCI DSS.

Frank Hayes’ recent column on emerging technologies to support E-Commerce (together with the thoughtful reader comments) noted that in the payment-card industry, “card present” has a specific meaning. (Related story: “Does Card Present Make Sense Any More? What Should It Look Like In A Year?”) It relates to reducing the risk (and, therefore, the cost) of a card transaction.

Anytime an issuer receives an authorization request based on reading a card’s mag stripe, that transaction has lower risk than if the card information is entered manually. This principle holds when the card is physically present at the point of sale but the mag stripe is not read or when the card is not present, for example, mail order/telephone order (MOTO) or E-Commerce transactions.

The term “card present” means a lot more than the payment card is physically present at the POS. Card present means a lower risk transaction. It means the merchant swiped the card on its POS terminal, which read the mag stripe and sent the contents to the card issuer as part of the authorization.

Reading the mag stripe matters for two reasons. At the POS, the merchant can compare the name on its card-reader screen with that embossed on the card. If they don’t match, the retailer can confiscate the card, reject the transaction or call in a Code 10 authorization. Then when the authorization request gets to the issuer, it can use additional, critical data elements contained only on the mag stripe.

For example, the mag stripe contains the card verification value or code (CVV for Visa; CVC for MasterCard). When the issuer receives a card-present authorization, the CVV/CVC can tell it if the card is the one issued. A mag stripe encoded only with information from a cardholder statement, for example, would not contain the correct CVV/CVC. Obviously, the CVV/CVC can only be analyzed when the mag stripe is read and sent to the issuer.

As an aside, many merchants and even some QSAs who may not know the card business well mistakenly confuse the CVV or CVC with the security codes written on the signature panel (the CVV2 or CVC2, respectively). The addition of the “2” is another industry-specific designation that is important. The CVV2/CVC2 is not on the mag stripe, and it has a different but related purpose in reducing fraud—specifically when the card is not present.


Comments are closed.


StorefrontBacktalk delivers the latest retail technology news & analysis. Join more than 60,000 retail IT leaders who subscribe to our free weekly email. Sign up today!

Most Recent Comments

Why Did Gonzales Hackers Like European Cards So Much Better?

I am still unclear about the core point here-- why higher value of European cards. Supply and demand, yes, makes sense. But the fact that the cards were chip and pin (EMV) should make them less valuable because that demonstrably reduces the ability to use them fraudulently. Did the author mean that the chip and pin cards could be used in a country where EMV is not implemented--the US--and this mis-match make it easier to us them since the issuing banks may not have as robust anti-fraud controls as non-EMV banks because they assumed EMV would do the fraud prevention for them Read more...
Two possible reasons that I can think of and have seen in the past - 1) Cards issued by European banks when used online cross border don't usually support AVS checks. So, when a European card is used with a billing address that's in the US, an ecom merchant wouldn't necessarily know that the shipping zip code doesn't match the billing code. 2) Also, in offline chip countries the card determines whether or not a transaction is approved, not the issuer. In my experience, European issuers haven't developed the same checks on authorization requests as US issuers. So, these cards might be more valuable because they are more likely to get approved. Read more...
A smart card slot in terminals doesn't mean there is a reader or that the reader is activated. Then, activated reader or not, the U.S. processors don't have apps certified or ready to load into those terminals to accept and process smart card transactions just yet. Don't get your card(t) before the terminal (horse). Read more...
The marketplace does speak. More fraud capacity translates to higher value for the stolen data. Because nearly 100% of all US transactions are authorized online in real time, we have less fraud regardless of whether the card is Magstripe only or chip and PIn. Hence, $10 prices for US cards vs $25 for the European counterparts. Read more...
@David True. The European cards have both an EMV chip AND a mag stripe. Europeans may generally use the chip for their transactions, but the insecure stripe remains vulnerable to skimming, whether it be from a false front on an ATM or a dishonest waiter with a handheld skimmer. If their stripe is skimmed, the track data can still be cloned and used fraudulently in the United States. If European banks only detect fraud from 9-5 GMT, that might explain why American criminals prefer them over American bank issued cards, who have fraud detection in place 24x7. Read more...

Our apologies. Due to legal and security copyright issues, we can't facilitate the printing of Premium Content. If you absolutely need a hard copy, please contact customer service.