Mobile Payment Security The Good, the Bad and the Ugly

Slides:



Advertisements
Similar presentations
Approaches to meeting the PCI Vulnerability Management and Penetration Testing Requirements Clay Keller.
Advertisements

Surviving the PCI Self -Assessment James Placer, CISSP West Michigan Cisco Users Group Leadership Board.
October 28, Who? What? When? Why? Comply with PCI compliance policies set forth by industry Create internal policies and procedures to protect.
National Bank of Dominica Ltd Merchant Seminar Facilitator: Janiere Frank Fraud & Compliance Analyst June 16, 2011.
Evolving Challenges of PCI Compliance Charlie Wood, PCI QSA, CRISC, CISA Principal, The Bonadio Group January 10, 2014.
.. PCI Payment Card Industry Compliance October 2012 Presented By: Jason P. Rusch.
PCI DSS for Retail Industry
Troy Leach April 2012 The PCI Security Standards Council.
Michal Bodlák. Referred to as mobile money, mobile money transfer, and mobile wallet generally refer to payment services operated under financial regulation.
The GSMA July 2014 Restricted - Confidential Information
This refresher course will:
JEFF WILLIAMS INFORMATION SECURITY OFFICER CALIFORNIA STATE UNIVERSITY, SACRAMENTO Payment Card Industry Data Security Standard (PCI DSS) Compliance.
SECURITY IN E-COMMERCE VARNA FREE UNIVERSITY Prof. Teodora Bakardjieva.
Smart Payment Processing ™ Protecting Your Business from Card Data Theft Presenter: Lucas Zaichkowsky.
Credit Card Compliance Regulations Mandated by the Payment Card Industry Standards Council Accounting and Financial Services.
© 2012 Presented by: Preparation For EMV Chip Technology Keith Swiat.
© Vendor Safe Technologies 2008 B REACHES BY M ERCHANT T YPE 70% 1% 9% 20% Data provided by Visa Approved QIRA November 2008 from 475 Forensic Audits.
Credit / Debit Card Electronic Payments Industry Update on Convenience Fees, Utility Program and More! Presented by: Presented by: Michael Hodge, Regional.
Presented by : Vivian Eberhardt, Supervisor Cash and Credit Operations
Credit Card Changes that Impact You! Changes to Accounts Receivable, Cash Receipts and Student Billing 7.77 Wanda Mahon & Bucky Wall Corporate Readiness.
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Commonwealth of Massachusetts Office of the State Comptroller March 2007.
GPUG ® Summit 2011 November 8-11 Caesars Palace – Las Vegas, NV Payment Processing Online and Within Dynamics GP PCI Compliance and Secure Payment Processing.
Around the World, Around the Corner WorldPay for Small Business.
Mobile Payment Solutions and the EMV/PCI Impact
Merchant Services and Commission Payment Options Presented by: Wendy M. Yurgo President & CEO Metrics Global, Inc.
PCI and how it affects College Stores… ROBIN MAYO | PCIP ECOMMERCE MANAGER EAST CAROLINA UNIVERISTY.
Travillon Consultants
Security & PCI Compliance The Future of Electronic Payments Security & PCI Compliance Greg Grant Vice President – Managed Security Services.
PAYMU SOLUTION WALLET PROGRAM
Philip is a subject matter expert in Accenture’s Payment practice with more than 30 years experience across payments, transaction processing, networks,
Electronic Transactions for your PTA organization June 26, 2013 North Fulton Council PTA ® everychild. onevoice. ®
MasterCard Site Data Protection Program Program Alignment.
PCI DSS Managed Service Solution October 18, 2011.
The influence of PCI upon retail payment design and architectures Ian White QSA Head of UK&I and ME PCI Team September 4, 2013 Weekend Conference 7 & 8.
An Introduction to PCI Compliance. Data Breach Trends About PCI-SSC 12 Requirements of PCI-DSS Establishing Your Validation Level PCI Basics Benefits.
BZUPAGES.COM Electronic Payment Systems Most of the electronic payment systems on internet use cryptography in one way or the other to ensure confidentiality.
NUAGA May 22,  IT Specialist, Utah Department of Technology Services (DTS)  Assigned to Department of Alcoholic Beverage Control  PCI Professional.
PCI requirements in business language What can happen with the cardholder data?
PCI DSS Readiness Presented By: Paul Grégoire, CISSP, QSA, PA-QSA
Copyright © 2007 Pearson Education, Inc. Slide 6-1 E-commerce Kenneth C. Laudon Carol Guercio Traver business. technology. society. Third Edition.
Electronic Payment Systems. How do we make an electronic payment? Credit and debit cards Smart cards Electronic cash (digital cash) Electronic wallets.
Convenience Fees Solving the Puzzle Angela Gross Fifth Third Processing Solutions Executive Consultant – Government Specialist October 19, 2010.
Introduction To Plastic Card Industry (PCI) Data Security Standards (DSS) April 28,2012 Cathy Pettis, SVP ICUL Service Corporation.
Walter Conway, QSA 403 Labs, LLC Sneak Preview: What to Expect from PCI DSS v. 2.0  Changes  Clarifications  Guidance.
THE MOBILE CHANNEL IN FINANCIAL SERVICES TARIK HUSAIN BUSINESS DEVELOPMENT DIRECTOR ASIAN BANKER SUMMIT APRIL 2011.
Chapter 4 E-commerce Security and Payment.
Team 13 Prathibha and Shrimi 11/12/13 Mobile Credit Card Processing.
Learning Objectives Understand the shifts that are occurring with regard to online payments. Discuss the players and processes involved in using credit.
CIS-325: Data Communications1 CIS-325 Data Communications Dr. L. G. Williams, Instructor.
BUSINESS CLARITY ™ PCI – The Pathway to Compliance.
Fall  Comply with PCI compliance policies set forth by industry  Create internal policies and procedures to protect cardholder data  Inform and.
Standards in Use. EMV June 16Caribbean Electronic Payments LLC2.
WHAT NEW, WHAT NEXT IN PAYMENT PROCESSING. EMV WHAT IS EMV? 3  An acronym created by Europay ®, MasterCard ® and Visa ®  The global standard for the.
Payment Card Industry (PCI) Rules and Standards
The Payment Processing System
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance
Payment card industry data security standards
Internet Payment.
Breaches by Merchant Type
Chapter 4 E-commerce Security and Payment.
The Payment Processing System
Switchover from Teledeposit to VIRTUAL TERMINAL Moneris Solutions
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance
Connor Griesemer and Kevin Wu
PCI Compliance : Whys and wherefores
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance
Federal Reserve Retail Payments Risk Forum
Payment Card Industry Data Security Standards (PCI-DSS) Training
Presentation transcript:

Mobile Payment Security The Good, the Bad and the Ugly Tony Bates

This Presentation This Presentation is a discussion of the business issues Pose questions rather than provide answers This Presentation is NOT a technical presentation No techy twaddle

Payment : Security : Compliance With offices in the USA, Canada, UK and Australia, PSC is a leading global PCI and PA-DSS Assessor and Approved Scanning Vendor. One of a select few companies qualified worldwide to provide expert services and solutions to organizations that require specialist compliance or consulting support in the areas of Payments, Security or Compliance. Our focus is exclusively on Clients that accept or process payments or technology companies in the payment industry. To ensure Independence, PSC does not represent, resell or receive commissions from any third party hardware, software or solutions vendors. PSC specializes in payment transaction process, security and compliance

What is Mobile Payments ? Payment Presentment ✔ - Digital Wallets ✔ - Mobile Web payments ✔ - Online Wallets ✔ - NFC Contactless ✔ - Cash ✔ - Checks ✔ - Credit/Debit Card ✔ - FastTrack ✔ - Vehicle License Plate Payment Acceptance ✔ - Mobile Point of Sale ✔ - Smart Phone ✔ - PDA ✔ - iPad/Tablet ? - Bus or Train ? - Laptop ✗- Desktop

Mobile Payment Software - Presentment Security Card Holder’s responsibility Card company’s Cardholder Agreement No industry standards for digital wallets solutions Wallet application security? Wallet interoperability? Multiple payment instruments in a single wallet? Which one is “on top”? What about release of personal data ?

Mobile Payment Software - Interoperability Too many protocols IP over 3G/4G Bluetooth NFC Too few “true” standards Solutions tend to be monolithic Chicken and egg problems with adoption Lack of compatibility with other solutions Security models vary greatly in maturity

Mobile Payment Software - Acceptance Payment Card Industry Security Standards Council PCI Data Security Standard (PCI DSS) Applies to Services Providers and Merchants Payment Application Data Security Standard (PA-DSS) Applies to Payment applications used by Services Providers and Merchants Card Company Regulations State Regulations regarding Personal Information

OK for PADSS Category 1 Category 2 Payment application operates only on a PTS-approved mobile device. Category 2 Payment application meets ALL of the following criteria: Payment application is only provided as a complete solution “bundled” with a specific mobile device by the vendor Underlying mobile device is purpose-built (by design or by constraint) with a single function of performing payment acceptance Payment application, when installed on the “bundled” mobile device (as assessed by the Payment Application Qualified Security Assessor (PA-QSA) and explicitly documented in the payment application’s Report on Valication (ROV), provides an environment which allows the merchant to meet and maintain PCI DSS compliance.

NOT OK for PADSS Category 3 Payment application operates on any consumer electronic handheld device (e.g., smart phone, tablet, or PDA) that is not solely dedicated to payment acceptance for transaction processing

Visa Mobile Acceptance Best Practices Consumer Mobile Device: Any electronic handheld device (e.g., smart phone, tablet or PDA) that is not solely dedicated to payment acceptance and that has the ability to wirelessly communicate account data (via GSM, GPRS, CDMA, etc.) for transaction processing. Mobile Payment Acceptance Solution: Consists of mobile payment application, a consumer mobile device and, where account data is electronically read from a payment card, a hardware accessory capable of reading account data. Solutions that do not electronically read account data may not be acceptable in all territories or may face some restrictions. Clients must review local Visa Operating Regulations prior to providing mobile payment acceptance solutions to merchants.

MasterCard PADSS Mandate Effective 1 July 2012, MasterCard will revise the MasterCard SDP Program Standards to require all merchants and Service Providers that use third party-provided payment applications to only use those applications that are compliant with the Payment Card Industry Payment Application Data Security Standard (PCI PA-DSS), as applicable. The applicability of the PCI PA-DSS to third party-provided payment applications is defined in the PCI PA-DSS Program Guide. In addition, MasterCard will establish a new PA-DSS compliance validation requirement for Level 1, Level 2, and Level 3 merchants as well as Level 1 and Level 2 Service Providers.

Mobile Payment Security Testing Current solutions choose time-to market over security E.g. Square – currently no encryption in readers The usual “web” tools don’t do it Much more technical and specialized than the web A must Complexity breeds security problems Multiple protocols, devices, networks Good penetration testing by experts

Apple “iWallet” patent – Parental Controls Granted on Tuesday March 6 A method, comprising: defining one or more rules using a handheld electronic device, wherein the one or more rules establish restrictions on transactions made using a financial account associated with an account holder other than the user of the handheld electronic device; and applying the one or more rules to the financial account.

Summary Poor definition of marketplace Hard to define security solutions and standards Standards don’t fully apply – or protect Card brand mandates cover what the way they would like to see the industry Not the way the industry is Risk based assessments and penetration testing poor in this area Not enough experts

Questions Questions Tony Bates Tony@paysw.com +1 408-228-0961