Society of Payment Security Professionals Forum  

Go Back   Society of Payment Security Professionals Forum > Discussion Groups > PCI DSS Q&A

Reply
 
Thread Tools Display Modes
  #1  
Old 01-08-2009, 04:31 AM
jbhall56's Avatar
jbhall56 jbhall56 is offline
Senior Member
 
Join Date: Feb 2007
Location: Minneapolis, MN
Posts: 1,282
Default Visa Gas Pump Deadline

We probably all saw the press pick up on the gas pump deadline Visa has put in place for 2010 yesterday, January 7, 2009.

However, what has never been clear to me was if this was a total cut over, i.e., any pumps installed after January 1, 2010 MUST be 3DES capable. OR is this like the MasterCard IP-based ATM program of a couple of years back where if you are moving an older ATM to a new location you still can reuse it, but if you were buying a new ATM, you could only buy an IP-based ATM.

In addition, just because the pumps are 3DES capable, does 3DES also have to be implemented? Based on my reading of the directive, I'm also not clear that 3DES has to necessarily be implemented.

Anyone that can provide clarifications on this topic, we would appreciate it.
__________________
Jeff Hall, Director, Risk Advisory Services
RSM McGladrey Inc
801 Nicollet Mall, 11th Floor, West Tower
Minneapolis, MN 55402-2526
612 376 9280 - office
612 395 7280 - facsimile
www.mcgladrey.com

The views presented are those of the writer and are not necessarily those of RSM McGladrey Inc
Reply With Quote
  #2  
Old 01-08-2009, 06:00 PM
andrewj's Avatar
andrewj andrewj is offline
Senior Member
 
Join Date: Mar 2007
Posts: 172
Default

You will probably be interested in this document:

http://usa.visa.com/download/merchan...dispensers.pdf

Which states on page 17:

"Effective 7/1/2010
-All transactions originating at attended and unattended POS PEDs must be encrypting PINs using TDES from the point of transaction to the issuer (end-to-end)"

This means that all _installed_ devices must be not only TDES capable, but must be _using_ TDES for PIN encryption.
Reply With Quote
  #3  
Old 01-10-2009, 08:29 AM
wconway wconway is offline
Senior Member
 
Join Date: Jun 2007
Location: San Francisco
Posts: 155
Default

My concern is who is going to install 3DES in all the zillions of pumps in a year and a half. Is this realistic? I was also a bit surprised by Visa's move as the pre-auth Special Interest Group is still working and might have something to say/recommend in this area. Oh well...
Reply With Quote
  #4  
Old 01-10-2009, 11:55 AM
andrewj's Avatar
andrewj andrewj is offline
Senior Member
 
Join Date: Mar 2007
Posts: 172
Default

As a PIN security mandate, I am not sure how this would affect any pre-auth issues. PINs must be encrypted at the time and point of entry, and the PIN and PED programs do not concern themselves with the security / storage of other cardholder data (such as track or PAN data).
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -8. The time now is 03:17 PM.


Copyright (c) The Aegenis Group, Inc.