PaymentsJournal
No Result
View All Result
SIGN UP
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
PaymentsJournal
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
No Result
View All Result
PaymentsJournal
No Result
View All Result

PCI Council’s EMV/Encryption Guidance Follow-up

By David Fish
November 29, 2010
in Mercator Insights
0
0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn

The new PCI guidance concerning EMV technology and thecomments of PCI council members related to EMV all point to onelarge conclusion: the introduction of EMV cards in any market isnot enough to stop payment card fraud outright. There simply is nosilver bullet. Or if there is, it isn’t EMV in and of itself. Themigration to chip cards in any market currently doing so, orcontemplating migration, should be accompanied by multiplesafeguards in payment systems that process and store sensitivedata, as well as the continual review and modification of thosesystems to comply with the PCI Data Security Standard, which itselfwas recently updated.

At a recent PCI Community Meeting, Jeremy King, PCI’sdirector in Europe stated “EMV was created to try and authenticatethe cardholder, and therefore the security is around theauthentication, rather than the actual transactiondata.”

When it comes to data security, much of the data in theEMV card transaction is transferred “in the clear,” just as themajority of magstripe card transactions are currently. If the EMVimplementation has been performed using outdated minimal standardsand the same data has been compromised in a security breach,fraudsters could use it to create cloned magstripe cards orperpetrate card-not-present fraud. This is the risk withcompromised unencrypted payment card data regardless of the formfactor (EMV Chip or Magnetic Stripe) being used at the point ofsale.

Certainly, EMV’s capabilities can stem card fraudcommitted with lost or stolen cards if the entry of a PIN isrequired with use of the chip. But the “clear” data in transit is aclear weak point. Thus the accompanying guidance on payment dataencryption!

For the first time also, the PCI council has openly statedthat what they’re calling “point-to-point encryption” (or P2PE) canassist merchants in PCI scope reduction. Which is to say that, ittoo, only tackles part of the problem. As PCI commentator WalterConway points out in his Storefrontbacktalk post on this topic,”What is important to realize…is that P2PE addresses only thetransmission of cardholder data. That is, it does not address datastorage.”

For those merchants that actually store and use cardpayment data for any number of reasons (customer service,marketing, loss prevention, etc.), PCI scoping may actually be amore complicated issue. It really depends on how the payment dataarrives in the merchants systems (whether through acquirerreporting or through in-house decryption) and whether it happens tobe tokenized or passed “in the clear.”

Of one thing we can be sure: while much effort to securethe card payment environment has resulted in some useful andbeneficial developments, none are simple, and none are total. Fornow, that silver bullet remains ever-elusive.

Read Referenced Press Release:

https://www.pcisecuritystandards.org/pdfs/pr_101005_emv_ptp.pdf

Read Referenced Articles:

http://www.bankinfosecurity.com/articles.php?art_id=3044

http://www.storefrontbacktalk.com/securityfraud/is-point-to-point-encryption-ready-for-prime-time/

0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn
Tags: Banking ChannelsCustomer RetentionDebitMerchant AcquiringMobile PaymentsPrepaidSocial Media

    Get the Latest News and Insights Delivered Daily

    Subscribe to the PaymentsJournal Newsletter for exclusive insight and data from Javelin Strategy & Research analysts and industry professionals.

    Must Reads

    Stablecoins Are Turning the Remittance Business Model on Its Head

    May 27, 2026
    legacy banking, instant payments

    The Instant Payments Shift Is Testing the Limits of Legacy Banking

    May 26, 2026
    innovation

    Companies No Longer Dabble in Innovation, They Prioritize It

    May 22, 2026
    klarna debit card

    Why Too Many Banks Are Losing Out on Merchant Services

    May 21, 2026
    embedded payments

    Embedded Payments Are Becoming Core to Vertical SaaS

    May 20, 2026
    palm scan

    Identity Fraud and the Erosion of Trust in the Age of AI

    May 19, 2026
    metamask debit card

    After Kraken’s “Skinny” Fed Account, What’s Next for Crypto?

    May 18, 2026
    agentic payment

    PhotonPay Completes its First Live Agentic Payment Together with Mastercard

    May 15, 2026

    Linkedin-in X-twitter
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter

    ©2026 PaymentsJournal.com |  Terms of Use | Privacy Policy

    • Commercial Payments
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    No Result
    View All Result