On TechRepublic: 12 tech terms that make you sound old
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 22 of 22:
« Previous
Online Super Payment Gateways
I have worked in the real time payment gateway industry for twelve years I have become accustomed to the security vulnerabilities of our system. It keeps us all employed!!

Then along comes these new manual super gateways, such as http://e-path.com.au, that use 2,048bit asymmetric cryptography. There are others that have recently launched but e-Path is the only one we have tested ourselves by signing up for an account as a "customer". We of course identified ourselves to e-Path and were up front about wanting to test their system. They didn't have a problem with that.

Its not new technology but its how they use it that is really making an impact on improving security. The Zdnet article is interesting because it suggests the PCI DSS are making a compromise on the next step in their efforts to improve security because of pressure from the industry. This is actually quite true. My company was one that put great effort into lobbying the PCIDSS to allow the status-quo. If the PCIDSS forced asymmetric cryptography upon real time gateways then this would have catastrophic consequences because it would mean all real time payment gateways would be out of date and non-compliant. But my point is there are now these new manual gateways that actually do meet with this new desire for exceptional encryption security.

The question therefore is if real time gateways don't adopt this new asymmetric cryptography then we stand the chance of being left with representing security vulnerabilities from a previous era. Perhaps the industry needs to adopt it on their own, like e-Path has, in order to really address security vulnerabilities associated with accepting credit cards online.

I am very reluctant to admit it but it certainly looks like the manual system is the first major step in negating many of the vulnerabilities that currently exist within the "real time" payment gateway system.

I can't personally see how manual systems would be an economical solution for high transaction volume cc traffic but for the small online business, well, I'm busting trying to find any negatives about them.

Food for thought.
Posted by: fooj   Posted on: 03/09/07 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

Another thing...  DarbyOhara | 05/16/06
Many lawyers ARE the criminals...  kokuryu | 05/17/06
Time for an upgrade  jheine | 05/16/06
Furthermore...  techboy_z | 05/16/06
Another thing...  BlazeEagle | 05/17/06
How about making it the law  Shelendrea | 05/16/06
Hey, silly...  techboy_z | 05/16/06
=-p  Shelendrea | 05/16/06
This is ILLEGAL  kokuryu | 05/17/06
SMB encryption and access controls  schwana | 05/16/06
Active Discussion group for PCI Data Security Standard - pciFile.ORG  QDSP | 05/16/06
Solve the real problem - Merchants never needs my credit card  drorharari | 05/17/06
'The Credit'  redtalmage | 05/17/06
'The Credit'  drorharari | 05/17/06
Already available  kokuryu | 05/17/06
Citi has "Virtual Account Numbers"  JED! | 05/18/06
great news for hackers  eaze | 05/17/06
I Have Had My Account Attacked Twice  hal3650@... | 05/18/06
Credit Cards not needed for on-line purchases  jack@... | 06/21/06
Online Super-Gateways - Your Thoughts??  fooj | 09/14/06
Bank of America Boycott Credit Cards  KheshireKat | 02/28/07
Online Super Payment Gateways  fooj | 03/09/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

  • Smart Tech Expert advice on innovations in healthcare and the green technologies that make it happen. Find out more
  • Smart Business Discussion and advice on management issues that revolve around making your world smarter and more useful. More Smart Advice
  • Smart People The best and worst moves in the management and strategy trenches. Learn More