Feeds

Online payment standards fall on deaf websites

Beware of Belgians bearing card codes

Intelligent flash storage arrays

We see a lot of lip service paid to the importance of complying with payment card industry standards when merchants accept credit and debit cards. But it seems plenty of websites still can't be bothered to follow the rules, which are designed to protect their customers against fraud and identity theft.

Just last week, Reg reader Martti Ylioja spotted Belgium-based Tele Ticket Service retaining most of his credit-card details, including the "CCV2" verification code that is coveted by criminal carders.

"When you log into the site the next time its still all in there - a bit dangerous practice," he wrote. He included the screenshot below to show us what he saw several days after surrendering his credit card info to the site.

Such practice is a violation of section 3.2.2 of the PCI rules, said Tom Arnold, a member of PSC, which provides consulting for companies that accept electronic payments. "To store [the CCVC2] and remember it and keep it on file is a big-time violation," he said.

The PCI standards are designed to prevent the kind of credit card heists that befell TJX after it improperly stored huge amounts of credit card data. Merchants found flouting the rules can be forced to pay penalties in some cases. We emailed representatives at Tele Ticket Service but never got a response.

Ylioja was understandably concerned about his data being stored and was unable to figure out how to remove the data from the site other then overwriting it with bogus information. And even that wasn't easy.

Screenshot of website storing credit card details

"Interestingly, I had to generate a fictitious Visa card number with a correct check sum to get it replaced," he said. ®

Intelligent flash storage arrays

More from The Register

next story
Regin: The super-spyware the security industry has been silent about
NSA fingered as likely source of complex malware family
Why did it take antivirus giants YEARS to drill into super-scary Regin? Symantec responds...
FYI this isn't just going to target Windows, Linux and OS X fans
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Home Office: Fancy flogging us some SECRET SPY GEAR?
If you do, tell NOBODY what it's for or how it works
HACKERS can DELETE SURVEILLANCE DVRS remotely – report
Hikvision devices wide open to hacking, claim securobods
'Regin': The 'New Stuxnet' spook-grade SOFTWARE WEAPON described
'A degree of technical competence rarely seen'
Syrian Electronic Army in news site 'hack' POP-UP MAYHEM
Gigya redirect exploit blamed for pop-rageous ploy
Astro-boffins start opening universe simulation data
Got a supercomputer? Want to simulate a universe? Here you go
prev story

Whitepapers

Designing and building an open ITOA architecture
Learn about a new IT data taxonomy defined by the four data sources of IT visibility: wire, machine, agent, and synthetic data sets.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
5 critical considerations for enterprise cloud backup
Key considerations when evaluating cloud backup solutions to ensure adequate protection security and availability of enterprise data.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Protecting users from Firesheep and other Sidejacking attacks with SSL
Discussing the vulnerabilities inherent in Wi-Fi networks, and how using TLS/SSL for your entire site will assure security.