My article discussed PCI compliance. The main topics it covered were; 1. Remote Access Security 2. Host Security 3. Network security. The old cash registers with the bells are out of date. Now almost everyone has a POS terminal hooked up to modem. POS machines are now essentially computers. However, the fact that these terminals are hooked up to the internet leaves the companies' POS systems vulnerable to attack by computer hackers. A virtual treasure trove of information is held in the POS systems, including credit card data and personal information. That is everything one would need to steal someone's identity.
Many vendors have remote access links set up for the terminals they sell for trouble shooting purposes. This is a very at-risk back door if you will. "The exploitation of improperly configured and unpatched remote management software tools is the most frequent method of attack used by hackers against POS payment systems."
The second security issue faced by new POS terminals is Host Security. The host is where everything is. Everything from authorization functionality to data back up takes place on the Host Server. “ Because so much information is stored or transmitted there, the host is considered to be the coveted “crown jewel” among hackers. A merchant must ensure that its host software does not store any prohibited data elements such as full magnetic stripe data or PIN data.”
The third security issue is network security. Many POS terminals are connect through a network via either high speed wireless, or wired. For this reason individual usernames and restricted access must be utilized, so as to know who did what where and when. One of the main problems is that many of the wireless routers that come from the store come out of the box containing default IDs and passwords that are supplied by the vendor. If a property is not careful to change the username and password that would leave the network wide open to attack. In fact, many default and IDs and passwords are available to criminals via the internet. Another vulnerability is physical attack. Devices can be placed on the terminals that catch and cop swiped credit cards.
I think this article is a good tool for any establishment. I received an email from Doubletree corporate office about the card catching devices that are being installed on the computers. People will work at a property for less than thirty days with the sole purpose of installing these gadgets and stealing credit card information. Now that we know where and what to look for management has to physically inspect all the terminals once or twice per week. I also know that not being PCI compliant can end up costing you a lot of money. A gentleman I met at a conference, works for a PCI compliance firm, and when he checked into his hotel in
4 comments:
I found this blog to be very interesting. Seeing as I have very little to no background in hotel work, I never realized how easy it was to have credit card information stolen. Not to even mention that there was an actual firm that policed this activity. I feel that Bobby found an extremely relative article and also did a good job with relating his own experiences in his blog.
I found your article and comments to be very intriguing. I was not aware at all about the physical threats regarding card catching and employees who only work at an establishment for this reason. The lengths that certain people are going at to steal certain information is incredibly alarming and a scary thought for people in the industry and travelers.
I found this article to be very interesting and informational. The extreme amounts of heightened security that companies must undertake in today's society to avoid hackers and scam artists is underestimated by many professionals. As a future member of the hospitality industry it is necessary to stay current with today's advanced technologies that comply with guest needs and wants, but additionally keep their personal information secret. PCI has undergone great feats to secure their customers identities and accounts and will be an exemplory company to base one's security systems blue print.
I again have to agree the PCI compliance is fast becoming a major trend in not only the hospitality industry but all industries who accept credit cards for payments. The security of this information is vital to the continued use of credit cards by consumers. The more people that have their credit card information violated or even just hear about the thefts the more people become reluctant to use their credit cards. This may start in the more high profile area of Internet purchasing but will also spread to large retailers and even the hotel industry. I think the hotel industry is especially vulnerable considering we require our guests to provide credit card information to secure their room and to cover any charges. Providing the hotel industry with not only the standards but systems and software which is safe and secure will become an area of great expansion in the very near future. There will be a lot of money to be made in helping the hotel industry understand all the regulations and then comply with them.
Post a Comment