PCI Compliance - The Good, The Bad, and The Insecure - Part 2
mavitunasecurity.com
mavitunasecurity.com
If a pentester finds that you did that, you will almost certainly get that written up sev:hi.
We work with lots of companies that handle payment card information (though we do not do PCI audits, which are a race to the bottom). The best practice solution for this problem is to isolate the cardholder information on a protected backend machine, keep it encrypted, and replace it on every other machine with an opaque token.
(You are much better off using Stripe or Braintree than doing this yourself.)
Gonna throw in a recommendation for Spreedly (http://spreedly.com) right here. It's a processor-agnostic payment vault, so that you can offload your card storage needs without having to commit to a processor for the life of your business.
Build against Spreedly and if you want to use Stripe today, and some new YC 2014 startup next year, you just change one line of code and you're done. If you store your customers' cards at your processor, you're locked in to that choice to various degrees (from having to request some kind of encrypted hand-over and re-implementing all your billing code, to having to ask every single customer to re-enter their billing info because you chose a processor that won't give you your information when you leave).
If you are collecting credit card numbers in your application, then you are still required to be PCI compliant (see TOS for the companies you've mentioned). The reasons are obvious: if your servers are hacked or you have a malicious (or just incompetent) employees then the credit card data will be at risk. Thus you will still need to do SDLC, firewalls, HTTPS, and a few other things.
If you don't want to deal with PCI at all then you might want to checkout the iFrame checkout from WePay. This way you are completely isolated from the credit card data and PCI while you still keep the user on your website.
Skimmers would become useless because the PIN number entered would only be good for a few minutes after it was captured. Stealing a credit card number and sharing online would be equally useless without the physical card.
This would, of course, cause some problems for online purchases, like Amazon's 1-click, but something like vendor-specific passcodes could solve that. You could go to your credit card website and request a passcode to provide to a specific online store. If their database gets compromised, you can revoke the password.
If it's vendor specific then it shouldn't matter if anyone else has it. Only that vendor should be able to use it. If that's not possible then if their database gets compromised, the vendor should be able to invalidate their password.
If PCI were to be revamped an actual assessment which graded real-world efficacy would be transparent to the customer prior to purchase. Real-world efficacy is the hard part, as it is not a static of any sort.
TL;DR Businesses are bound by process and governance. Attackers are not. If you use PCI as a driver for security implementation you will fail. PCI 'compliance' continues to be a fallacy of warm and fuzzy security kittens.
Most broken is the fact that US credit cards still uses magnetic stripe when everyone else have converted to using smart card chips. Why the is there visible PAN numbers on the cards and magnetic stripes this is year 2013.
Fact card companies uses broken security mechanisms on the cards. Then everybody else have to comply with PCI because their broken security.
Some banks already provide this service.[0]
The other alternative would be to buy a compatible smart-card reader.
[0]: https://www.bankofamerica.com/privacy/accounts-cards/shopsaf...
http://kencochrane.net/blog/2012/01/developers-guide-to-pci-...
If you have ever been in a meeting and been face to face with the blank stares of management while you explain why you need to spend time on hardening your servers or software, you would be thankful that PCI exists.
8.5.10 Require a minimum password length of at least seven characters.
8.5.11 Use passwords containing both numeric and alphabetic characters.
In fact, the string 'password1' exceeds the requirements.
https://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Sec...
edit: Seriously people, it's the first result for "pci" on google. Even when not spelled all caps. Come on.