Test...

The information may in fact need to be wiped once the transaction is complete but apparently the retailer captures the account number and keeps it.

That depends on what the company decides it wants to spend on PCI compliance. They can hold the info by law, but they have to go through several more compliance precautions to do so.
 
It only holds it for seconds, unless they hold CC info for returns and such which changes their PCI compliance requirements. Even without that they still have to hold it for the few seconds it takes to approve the transaction. Some companies aren't nearly as encrypted as others and hackers can snag info if they really know what they're doing. They actually tap into the swipe at the register and get it that way. It's supposed to be encrypted, but if it's not encrypted to enough levels it can be gotten and decrypted.

Yep, the article I had read on it said it was malware that hid itself at the POS system level and did just that.
 
Yep, the article I had read on it said it was malware that hid itself at the POS system level and did just that.

The only answer I see is heavier encryption at that level. There are levels of encryption and I think the current compliance level at the POS is only 1 deep. Meaning they have to decrypt 1 level down to get to the info. Holding info in your system requires something like 3 levels of encryption by law.
 
That depends on what the company decides it wants to spend on PCI compliance. They can hold the info by law, but they have to go through several more compliance precautions to do so.

I'm not sure how the encryption works. I know the PIN is a temporary transaction that is not retained but I am not sure about account numbers on debit cards since the are actually routed to bank account numbers. Credit cards have their own distinct number and are the same as the numbers on the card. It's possible that a merchants terminal is designed to capturing the bank account number as a backup for protests transactions or disputed ons. They would then have something to fall back on. With a credit card there is no liquid balance. I'm not sure about this however.
 
I'm not sure how the encryption works. I know the PIN is a temporary transaction that is not retained but I am not sure about account numbers on debit cards since the are actually routed to bank account numbers. Credit cards have their own distinct number and are the same as the numbers on the card. It's possible that a merchants terminal is designed to capturing the bank account number as a backup for protests transactions or disputed ons. They would then have something to fall back on. With a credit card there is no liquid balance. I'm not sure about this however.

Like I said, they have the option of holding personal information, but if they decide to do so they have to encrypt to the level they choose. They don't have to, though. They can rid themselves of the expense and hassle of going through that compliance by having a third party vendor doing it for them. This is the route a lot of companies are taking now as it has gotten to be too much because of compliance testing and everything that goes into making sure every single employee that comes into contact with sensitive information has to go through.
 
On a side note, I just checked my email and a buddy has sent me a "get laid now" pass!

:towel

Some days are bad and sometimes things just seem to go your way no matter what you do.

~clicking link~
 
We sing randomness in the office all the time, always seems to go back to Sitting on the Dock of the Bay.

Not trying to brag or anything but I'm probably the best whistler in these United States. If there was an Olympic event I would be there.
 
Newt the Flute, you are one bad white man.
 
It's getting to a point where you can't even spank your monkey in public anymore.

This world is just a sad fucking place.
 
Seriously though, when someone peeps their head into an office unannounced it can create an awkward situation for both the barger and the bargee.
 
Back
Top Bottom