Risk

7/1/2015
04:00 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
100%
0%

PCI Update Paves Way For Expanding Point-to-Point Encryption

Move appears designed mainly for large organizations and big-box retailers looking to lock down payment card security.

The PCI Security Standards Council, which administers the payment card industry data security standard, has made it easier for large merchants to implement point-to-point encryption (P2PE) for protecting cardholder data.

The Council this week updated its requirements to give merchants more choice and flexibility in the components they use for point-to point encryption. One of the key features in the Council’s new P2PE Version 2.0 is a provision that allows covered entities to implement and manage their own encryption tools at their point of sale systems so long as the tools are compliant with PCI requirements.

Another update gives encryption vendors and service providers more leeway in the components that they use to deploy P2PE at customer locations. Going forward, the Council will also list approved encryption components and services that organizations can use to encrypt their data.

The updates are deigned to help organizations better protect cardholder data against compromise at the point of sale, PCI Council chief technology officer Troy Leach in a statement announcing the update. “Malware that captures and steals data at the point-of-sale continues to threaten businesses and their ability to protect consumers’ payment information,” Leach said. Encrypting the data makes it valueless for attackers, he said.

The goal with P2PE is to protect cardholder data from the instant it is swiped at a POS terminal all the way through to the card processing company’s network. Unlike end-to-end encryption, P2PE works by encrypting data right at the point of acceptance. The goal is to make it harder for attackers to steal card data using POS malware tools like BlackPOS, Dexter, vSkimmer, and Backoff. Such tools typically work by capturing card data from the retail terminal, before it can be encrypted.

Version 2.0 of the PCI Council’s P2PE requirements should simply the steps that large merchants need to work through to encrypt cardholder data at the POS terminals, says Jim Huguelet, principal at The Huguelet Group LLC.

“Many merchants have come to realize that the EMV standard does not involve encrypting cardholder data, leaving that data as much at risk to theft as it is today,” Huguelet said.

EMV cards, or cards that are based on the Europay MasterCard Visa standard, store cardholder data in a tiny microchip embedded in the card and not on magnetic stripes like most cards in the U.S. currently do. The major credit card associations require all organizations that accept credit card transactions to implement point of sale terminals that are capable of accepting EMV card transaction. The deadline for that migration is this October of this year, but many believe that a vast majority of companies won’t be ready in time for the deadline.

With various reports now estimating that only 60 percent of US credit and debit cards will be reissued with EMV chips and less than 10 percent of merchants will be able to accept them by the October 2015 deadline, organizations are coming to terms with the fact that widespread EMV adoption will easily go into 2017 and perhaps longer, Huguelet says.

“With the many delays the US is encountering in deploying EMV, merchants are looking to make their payment processing environments more secure as quickly as they can and deploying encryption is the clear way to do so,” he says.

Gartner analyst Avivah Litan says the Council’s move to update its encryption requirements appears designed mostly at very large organizations.

“My initial reaction is that this is intended to benefit large merchants who want to implement their own P2PE systems,” Litan says. “I’m guessing this update is a result of some special lobbying by a handful of large big box retailers who have their own in-house capabilities."

 

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Some Guy
50%
50%
Some Guy,
User Rank: Moderator
7/2/2015 | 2:47:41 PM
It's an Arms Race .. How you can help
We can decry the inevitability of attacks, but what we can't do is accept that as the norm. It's an Arms Race; the next step is here; waiting to do nothing until a perfect solution presents itself is to commit a nirvana fallacy.

Here's where YOU can make a difference. On November 1st, if your credit card hasn't been updated to PIN & Chip (EMV) technology, vote with your pocketbook and move your credit so somewhere that does.
iNtHEmACHINE
50%
50%
iNtHEmACHINE,
User Rank: Apprentice
7/2/2015 | 12:16:09 PM
Re: Okay but...
"Low hanging fruit is the name of the game with hackers that are trying to make money from it."

Low hanging or stumbled apon is where the huge hacks have been, but money is the name of the game even if it's just a Nigerian scam or a few million numbers with expiration dates. Easy money is better, but money is money. If it's MY money I expect it to be secured.

"Good security only really attracts the security curious out there"

And making it harder does make it harder. What is security curious? <heh>

 
Whoopty
50%
50%
Whoopty,
User Rank: Ninja
7/2/2015 | 5:00:04 AM
Re: Okay but...
I know what you mean. It can make you feel a bit dispondent about security with how easy it often seems to bypass it. As long as it's difficult though, it should be relatively safe. Low hanging fruit is the name of the game with hackers that are trying to make money from it. Good security only really attracts the security curious out there. 
Blog Voyage
100%
0%
Blog Voyage,
User Rank: Strategist
7/2/2015 | 2:52:40 AM
Okay but...
"The goal is to make it harder for attackers to steal card data using POS malware tools like BlackPOS, Dexter, vSkimmer, and Backoff." Sure it will help, but hackers always have an advantage.
It Takes an Average of 3 to 6 Months to Fill a Cybersecurity Job
Kelly Jackson Higgins, Executive Editor at Dark Reading,  3/12/2019
763M Email Addresses Exposed in Latest Database Misconfiguration Episode
Curtis Franklin Jr., Senior Editor at Dark Reading,  3/11/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: LOL  Hope this one wins
Current Issue
5 Emerging Cyber Threats to Watch for in 2019
Online attackers are constantly developing new, innovative ways to break into the enterprise. This Dark Reading Tech Digest gives an in-depth look at five emerging attack trends and exploits your security team should look out for, along with helpful recommendations on how you can prevent your organization from falling victim.
Flash Poll
The State of Cyber Security Incident Response
The State of Cyber Security Incident Response
Organizations are responding to new threats with new processes for detecting and mitigating them. Here's a look at how the discipline of incident response is evolving.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-6149
PUBLISHED: 2019-03-18
An unquoted search path vulnerability was identified in Lenovo Dynamic Power Reduction Utility prior to version 2.2.2.0 that could allow a malicious user with local access to execute code with administrative privileges.
CVE-2018-15509
PUBLISHED: 2019-03-18
Five9 Agent Desktop Plus 10.0.70 has Incorrect Access Control (issue 2 of 2).
CVE-2018-20806
PUBLISHED: 2019-03-17
Phamm (aka PHP LDAP Virtual Hosting Manager) 0.6.8 allows XSS via the login page (the /public/main.php action parameter).
CVE-2019-5616
PUBLISHED: 2019-03-15
CircuitWerkes Sicon-8, a hardware device used for managing electrical devices, ships with a web-based front-end controller and implements an authentication mechanism in JavaScript that is run in the context of a user's web browser.
CVE-2018-17882
PUBLISHED: 2019-03-15
An Integer overflow vulnerability exists in the batchTransfer function of a smart contract implementation for CryptoBotsBattle (CBTB), an Ethereum token. This vulnerability could be used by an attacker to create an arbitrary amount of tokens for any user.