Showing posts with label regulations. Show all posts
Showing posts with label regulations. Show all posts

Wednesday, January 4, 2017

US-EMV Deadlines

And yet again, it's been a while since I posted to my blog and, in turn, it's been a while since I ruffled some feathers. So, let's start 2017 with a bang!

Over the Christmas break read an article in Digital Transactions News: How EMV-Related Chargebacks Drove Florida Merchant Duo to Sue Networks And Issuers. While reading the article, my initial thought was, "There's nothing new here. They're simply documenting how the EMV rollout went (and still is going) for many U.S. merchants." Then, in the final paragraph I read a quote from Molly Wilkinson, executive director of The Electronic Payments Coalition, a Washington, D.C.-based lobbying group that represents card networks and issuers: "Merchant groups have known about the transition to EMV cards for five years but instead of getting their act together they have tried to delay, obfuscate, and reject this solution – all while leaving customers exposed to hackers and counterfeiters." This statement has so many flaws that I'm not sure where to start, and it clearly demonstrates the ignorance of the coalition – or is altogether pushing a blatant lie.

Let's start with the merchant groups. Simply put, they are advocates for the merchants, not tools for the card brand mandates. They have no control over what the networks support, the various requirements of physically performing an EMV transaction, or the certification requirements of EMV solutions. Merchant groups have little to no role in the supposed five-year preparation window – more on this later. I would be interested in hearing exactly how these merchant groups delayed or obfuscated the U.S. EMV rollout. Now let's discuss this "rejection of the solution." They had reasons for the rejection, as I will explain.

IMHO, the largest factor of the U.S. EMV rollout failure was a lack of forethought by the card brands and EMVCo in recognizing the differences in the U.S. marketplace. EMV for the most part has been a great success in Europe and it was assumed that EMV "plans" could be lifted from Europe and plopped onto the U.S. as-is. The problem here is the plan included a thorough end-to-end testing of the "solution." In Europe, a majority of the solutions are simply stand-beside terminals with little or no integration, so certifying a couple terminal solutions with a couple of banks in each country, no big deal – project complete. Here in the U.S. , there is a much bigger diversity of banks, processors, and terminals, and a majority of the marketplace uses fully or semi-integrated solutions with the point-of-sale (POS). This translates into an exponential number of "solutions" to certify in the U.S. compared to its European counterpart. Now before people get bent that I'm bashing one or the other, my point is not that one is better than the other, my point is they are simply different and that there was a failure to plan for this difference – and the blame certainly doesn't fall on merchant groups.

Let's revisit the five-year EMV preparation window. The card brands scheduled out various deadlines for banks and processors to be EMV ready within this preparation window, and before the October 1, 2015, liability shift deadline for merchants. There were two issues here. I don't know the wording of the mandate to the processors, but from what I experienced, as long as a processor could demonstrate a working EMV solution (I'm unsure if certification was required or not), then the deadline was met. For many processors, host specifications supporting EMV were not published to integration partners (like gateways) until around May or June of 2015. And, none that I am aware of had solidified their certification process, which is a big part of an EMV solution. Most EMV solutions back then took between 4-12 months to certify. It's a little better now, but not by much. Assuming the specs were published in May, allowing for a 30-90 day development cycle plus a six-month certification, means the average "solution" would have been certified and production ready no earlier than February or March of 2016 – this is a good 4-5 months after the EMV merchant deadline.

Then we have the October deadline. Why October? Who picked this deadline? Just before the holiday shopping season when most merchants (at least larger merchants) have technology freezes in place in preparation for their busiest time of year. I'm not sure what the merchant groups were or were not conveying to the card brands or the coalition, but if I were in charge, this would have been a no-go issue.

Now, the doozy: "all while leaving customers exposed to hackers and counterfeiters." This propagates the misbelief that EMV secures the account information. EMV does not protect the card data. EMV is an authentication mechanism only. You must add point-to-point-encryption (P2PE, sometimes also referred to as end-to-end-encryption or E2EE) to secure the data. Authentication guarantees (relatively speaking) that the card is authentic and was not forged; it does not stop prying eyes from seeing the account number and expiration date in the clear. P2PE hides the data from prying eyes. The U.S. was already making a shift to P2PE, but the problem was that incorporating EMV meant a new batch of uncertified terminals entering into the solution certification chain.

Hopefully this clarifies some of the misinformation flying around about how merchants are to blame for the U.S. EMV rollout failure – or at least the missed deadline.

Monday, December 5, 2011

Debit Card Fees - Simply another front in the ongoing class war


I just read this commentary in the Washington Post: In cutting debit card fees, Fed should use Congress’s standard. I could not disagree more. I have not got a clue where the author is getting his numbers? My guess is that he is calculating the $7B vs. $14B based the campaign marketing numbers used to sell the bill to congress and the public. There are flaws in this type of thinking and I'll get into that below, however, this did get me thinking of a related but bigger problem.

I'm sure by now everyone reading this has heard about the class warfare arguments in politics. Whether you believe the "rich" should pay more or not is one issue but to me, the bigger issue is the class warfare campaign. This is a slippery slope. Take for instance the Dodd-Frank Wall Street Reform and Consumer Protection Act. This is another battle of the same war being fought under the guise of "consumer protection."

I've briefly touched on the Dodd-Frank Act before. I think that this entire bill is a big can of worms that many proponents don't understand or choose to blindly ignore. Some of the provisions of the act that has generated buzz in the payments space are the restrictions it places on debit card transaction fees. Merchants have been told they will receive huge cuts in fees due to this bill. The NRF jumped on this bandwagon early in the process. I have not fully researched their involvement, but I would not be surprised if they provided parts to create this wagon.

There is one key component that the NRF and other merchant advocates blindly missed - the title of the act. Note the last two words just before Act: "Consumer Protection!" Not "Merchant Protection." Definitely not "Bank Protection." While today having the word "bank" in your name is synonymous to "rich", who's to say that tomorrow "merchant" won't be as offensive as "bank" to politicians? Currently the Dodd-Frank Act does not specify that merchants, or consumers for that matter, will receive one dime from the restrictions as there are many hands in the fee structure pie (not to mention various carved out exceptions). I can easily see a scenario where politicians realize that consumers are not reaping the rewards they were so generously promised so out pops "[insert name(s) here] Main Street Reform and Consumer Protection Act." Since politicians are so good at adding language to fix prior failures, one can expect a generous heaping of price controls for merchants to swallow, all under the same guise of "consumer protection."

As I said, this is a slippery slope. I've warned of side effect of price controls before this Dodd-Frank Act was implemented; we are seeing them now (see my previous post). One of the latest is that Visa and MasterCard have increased credit card fees: New Visa, MasterCard rates take effect. While not publicly stated, I have to imagine that this is to compensate for the loss of debit card fees. Since credit card usage rates are still higher in the US than debit card usage, this will mean a wash or an increase in fees even if the merchant does receive the debit card "rewards."

Just to clarify, I am not anti-merchant, and I am not pro-bank fees; instead I am very pro-merchant. I am against the government controlling prices for any industry. I feel allowing the government to dictate the price of any product or service is dangerous. Yes, there is precedence for government dictated price controls and some might argue this to be a good thing, and throw out some examples. But I would argue that these price controls have caused as much or more damage and problems than they fixed -- just to someone else (the politically out of favor class at the time).

Until next time...

Monday, October 17, 2011

Is PCI Even Legal?

Back in September 2008 I put myself on PCI SSC's dung list as well as a separate entry on Bob Russo's personal ignore list with my post "PCI SSC Show Their True Colors -- Regulate for Profit". Recently I found an interesting post on Magtek's website: Fraud Mythology in the Payment World. It details a speech by Magtek CEO Mimi Hart where she rips into PCI, calling it "one of the more dangerous 'false gods' in payments." Now finally I have company on the dung lists! I have one small criticism about her speech though, every false GOD is dangerous so "dangerous" in that sentence is redundant. ;-)

Within the speech, Mimi Hart states "PCI has rapidly become a self-perpetuating, self-aggrandizing, profit-motivated authority", this got me thinking, is PCI even legal? Antitrust laws prevent the card brands from getting together in a room to set rates or make common rules for members, merchants, and customers. But before I go further, let me give a brief history lesson...

In the early days, prior to cardholder data security (pre-9/11/2001), the card brands, for the most part, relied on trust that cardholder data was being securely stored and properly used by merchants and applications. Sure, there was fine print in merchant agreements and various unpublished rules stating that merchants must do this or don't do that, but for the most part, there was no mechanism to enforce these hidden rules and fine print. After 9/11, the government decided payments needed better security and told the card brands to get it under control or they would step in.

Each of the card brands rapidly scrambled to create their own set of security mandates for merchants and vendors to follow. Visa had CISP, MasterCard had SDP, American Express had DSOP, Discover had DISC, and JCB had "security standards" (hmm, very creative!). While there were many common and compatible requirements, there were many that were unique to each, and worse, there were a few mandates that contradicted or deviated from mandates of other brands. In all this turmoil, PCI SSC was formed to unite all the security mandates and create one ring to control them all.

Ok, back to my question -- Is PCI legal?

Per the PCI SSC website: "The Council's five founding global payment brands -- American Express, Discover Financial Services, JCB International, MasterCard Worldwide, and Visa Inc. -- have agreed to incorporate the PCI DSS as the technical requirements of each of their data security compliance programs." Then a little further down on the same page, "All five payment brands share equally in the Council's governance, have equal input into the PCI Security Standards Council and share responsibility for carrying out the work of the organization."

I'm not a lawyer but to me this seems to imply that while PCI SSC is a separate organization, it is controlled by a round table of the five card brands. And because this is a "for profit" organization, this seems to have antitrust implications that may threaten PCI SSC's legal legitimacy.

PCI SSC was created as a way for the card brands to conspire to create a common set of security mandates without breaking antitrust laws. The problem is, PCI SSC is setup as a "for profit" limited liability corporation controlled by the card brands. If this was setup as a non-profit organization (as I assumed it was because of the .org domain name - silly me, another future rant) and a true standards committee like ANSI or ISO, I feel there would not be an issue. But as a "for profit" organization under the direct control of the card brands, there seems to be an issue here.

My recommendation: restructure as a non-profit organization, make the books public, and become a real open standards board eliminating the antitrust concerns.

If any antitrust attorney happens to read this, I would love to get your take on this question. Until next time...



P.S. For another take on the same speech, see the post in StorefrontBacktalk: Federal Reserve Listens to Security Vendor CEO Rip into PCI

P.S.S. Mimi, welcome to the list!



Friday, October 14, 2011

House Democrats Ask Justice Department to Probe Debit Fees

This is an interesting and quick read in Bloomberg Businessweek: House Democrats Ask Justice Department to Probe Debit Fees

If you don't have the time and need a Reader's Digest version: Lawmakers are crying because banks are making them look like incompetent boobs. That's about it.


Thursday, October 13, 2011

Swipe Fees Revisited

I hate to say I told you so but:
Oh, by the way, while I agree with most National Retail Federation stances, I believe they were dead wrong on this one. I have to imagine that someone over there is smarter than I and could have predicted side effects like these -- I guess not!  Asking the government to step in and regulate costs and fees for an industry cannot ever end well. If someone arrives on your door and says "I'm with the government and I'm here to help", RUN! But in this case, the NRF invited them in with open arms.

Thursday, June 30, 2011

My take on Swipe Fees

There is an ongoing debate in the restaurant and retail industries about swipe fees for debit cards. There are bills being written and debated in congress that address swipe fees and I see trade associations from both industries cheering on these new regulations. My advice:

Quit crying for government regulations and
start fixing the problem yourself!

There is no regulation that I'm aware of that says a business must accept plastic -- credit or debit. If merchants think the card brands are charging too much, organize something that would get your point across. Have a "no plastic day" or "no plastic week". If enough merchants participated, this would send a strong message to the card brands and with little risk of unforeseen consequences. To me, this debit swipe fee trivial, a much bigger issue are the different rates for reward cards vs. non-reward cards and not knowing the fee up front, during the authorization event. It seems strange to me that the reward card rates are rarely, if at all mentioned by these same trade groups and the reward rates are much more significant than the debit rates.

It’s a cliché of mediation, uttered by every mediator trying to push two unhappy parties to reach agreement on a resolution, that "a good settlement is one where both sides are unhappy." The problem is when politicians create regulations, having both sides unhappy does not buy votes so one side or the other is going to be ecstatic, while the other side is going to get screwed. In this environment things will change because both sides need to be profitable and this is where unforeseen consequences enter the picture. Many times (I would say most times when it comes to government regulations), these unforeseen consequences can be worse than the original problem that was being addressed. I strongly believe that it much better to keep politicians out than to suffer the unforeseen consequences that will ensue.

Friday, August 27, 2010

Gift Card Act of 2009

With much fanfare, the US House of Representatives and Senate passed the Credit Card Accountability Responsibility and Disclosure Act of 2009. For the average consumer and merchant, the full benefits and ramifications have yet to be felt. One section that was mostly overlooked, was a section that specifically addressed general-use prepaid cards, gift certificates and store gift cards. Here it is:

Credit Card Accountability Responsibility & Disclosure Act of 2009
This is a portion of H.R. 627: Credit Card Accountability Responsibility and Disclosure Act of 2009 that relates specifically to gift cards and the like:

TITLE IV--GIFT CARDS

SEC. 401. GENERAL-USE PREPAID CARDS, GIFT CERTIFICATES, AND STORE GIFT CARDS.


The Electronic Fund Transfer Act (15 U.S.C. 1693 et seq.) is amended--
  1. by redesignating sections 915 through 921 as sections 916 through 922, respectively; and
  2. by inserting after section 914 the following:

SEC. 915. GENERAL-USE PREPAID CARDS, GIFT CERTIFICATES, AND STORE GIFT CARDS.

  1. Definitions- In this section, the following definitions shall apply:
    1. DORMANCY FEE; INACTIVITY CHARGE OR FEE- The terms ‘dormancy fee’ and ‘inactivity charge or fee’ mean a fee, charge, or penalty for non-use or inactivity of a gift certificate, store gift card, or general-use prepaid card.
    2. GENERAL USE PREPAID CARD, GIFT CERTIFICATE, AND STORE GIFT CARD-
      1. GENERAL-USE PREPAID CARD- The term ‘general-use prepaid card’ means a card or other payment code or device issued by any person that is--
        1. redeemable at multiple, unaffiliated merchants or service providers, or automated teller machines;
        2. issued in a requested amount, whether or not that amount may, at the option of the issuer, be increased in value or reloaded if requested by the holder;
        3. purchased or loaded on a prepaid basis; and
        4. honored, upon presentation, by merchants for goods or services, or at automated teller machines.
      2. GIFT CERTIFICATE- The term ‘gift certificate’ means an electronic promise that is--
        1. redeemable at a single merchant or an affiliated group of merchants that share the same name, mark, or logo;
        2. issued in a specified amount that may not be increased or reloaded;
        3. purchased on a prepaid basis in exchange for payment; and
        4. honored upon presentation by such single merchant or affiliated group of merchants for goods or services.
      3. STORE GIFT CARD- The term ‘store gift card’ means an electronic promise, plastic card, or other payment code or device that is--
        1. redeemable at a single merchant or an affiliated group of merchants that share the same name, mark, or logo;
        2. issued in a specified amount, whether or not that amount may be increased in value or reloaded at the request of the holder;
        3. purchased on a prepaid basis in exchange for payment; and
        4. honored upon presentation by such single merchant or affiliated group of merchants for goods or services.
      4. EXCLUSIONS- The terms ‘general-use prepaid card’, ‘gift certificate’, and ‘store gift card’ do not include an electronic promise, plastic card, or payment code or device that is--
        1. used solely for telephone services;
        2. reloadable and not marketed or labeled as a gift card or gift certificate;
        3. a loyalty, award, or promotional gift card, as defined by the Board;
        4. not marketed to the general public;
        5. issued in paper form only (including for tickets and events); or
        6. redeemable solely for admission to events or venues at a particular location or group of affiliated locations, which may also include services or goods obtainable--
          1. at the event or venue after admission; or
          2. in conjunction with admission to such events or venues, at specific locations affiliated with and in geographic proximity to the event or venue.
    3. SERVICE FEE-
      1. IN GENERAL- The term ‘service fee’ means a periodic fee, charge, or penalty for holding or use of a gift certificate, store gift card, or general-use prepaid card.
      2. EXCLUSION- With respect to a general-use prepaid card, the term ‘service fee’ does not include a one-time initial issuance fee.
  2. Prohibition on Imposition of Fees or Charges-
    1. IN GENERAL- Except as provided under paragraphs (2) through (4), it shall be unlawful for any person to impose a dormancy fee, an inactivity charge or fee, or a service fee with respect to a gift certificate, store gift card, or general-use prepaid card.
    2. EXCEPTIONS- A dormancy fee, inactivity charge or fee, or service fee may be charged with respect to a gift certificate, store gift card, or general-use prepaid card, if--
      1. there has been no activity with respect to the certificate or card in the 12-month period ending on the date on which the charge or fee is imposed;
      2. the disclosure requirements of paragraph (3) have been met;
      3. not more than one fee may be charged in any given month; and
      4. any additional requirements that the Board may establish through rulemaking under subsection (d) have been met.
    3. DISCLOSURE REQUIREMENTS- The disclosure requirements of this paragraph are met if--
      1. the gift certificate, store gift card, or general-use prepaid card clearly and conspicuously states--
        1. that a dormancy fee, inactivity charge or fee, or service fee may be charged;
        2. the amount of such fee or charge;
        3. how often such fee or charge may be assessed; and
        4. that such fee or charge may be assessed for inactivity; and
      2. the issuer or vendor of such certificate or card informs the purchaser of such charge or fee before such certificate or card is purchased, regardless of whether the certificate or card is purchased in person, over the Internet, or by telephone.
    4. EXCLUSION- The prohibition under paragraph (1) shall not apply to any gift certificate--
      1. that is distributed pursuant to an award, loyalty, or promotional program, as defined by the Board; and
      2. with respect to which, there is no money or other value exchanged.
  3. Prohibition on Sale of Gift Cards With Expiration Dates-
    1. IN GENERAL- Except as provided under paragraph (2), it shall be unlawful for any person to sell or issue a gift certificate, store gift card, or general-use prepaid card that is subject to an expiration date.
    2. EXCEPTIONS- A gift certificate, store gift card, or general-use prepaid card may contain an expiration date if--
      1. the expiration date is not earlier than 5 years after the date on which the gift certificate was issued, or the date on which card funds were last loaded to a store gift card or general-use prepaid card; and
      2. the terms of expiration are clearly and conspicuously stated.
  4. Additional Rulemaking-
    1. IN GENERAL- The Board shall--
      1. prescribe regulations to carry out this section, in addition to any other rules or regulations required by this title, including such additional requirements as appropriate relating to the amount of dormancy fees, inactivity charges or fees, or service fees that may be assessed and the amount of remaining value of a gift certificate, store gift card, or general-use prepaid card below which such charges or fees may be assessed; and
      2. shall determine the extent to which the individual definitions and provisions of the Electronic Fund Transfer Act or Regulation E should apply to general-use prepaid cards, gift certificates, and store gift cards.
    2. CONSULTATION- In prescribing regulations under this subsection, the Board shall consult with the Federal Trade Commission.
    3. TIMING; EFFECTIVE DATE- The regulations required by this subsection shall be issued in final form not later than 9 months after the date of enactment of the Credit CARD Act of 2009.’

SEC. 402. RELATION TO STATE LAWS.

Section 920 of the Electronic Fund Transfer Act (as redesignated by this title) is amended by inserting ‘dormancy fees, inactivity charges or fees, service fees, or expiration dates of gift certificates, store gift cards, or general-use prepaid cards,’ after ‘electronic fund transfers,’.

SEC. 403. EFFECTIVE DATE.

This title and the amendments made by this title shall become effective 15 months after the date of enactment of this Act.

A complete summary and full text of the entire H.R. 627: Credit Card Accountability Responsibility and Disclosure Act of 2009 can be found at http://www.govtrack.us/congress/bill.xpd?bill=h111-627.

The Steve Sommers' Readers Digest version of the federal law is as follows:

  • If you use expiration dates with your gift cards:
    1. the expiration term cannot be less than 5 years from the time of purchase or last recharge; and
    2. you must fully disclose the expiration date policy on the card and inform the purchaser prior to the purchase of the gift card.
  • If you charge service fees to your gift cards:
    1. you cannot charge more than a single fee per month (for most merchants, no big deal),
    2. the fees can only be charged after one year of dormancy; and
    3. you must fully disclose the fees on the card and inform the purchaser prior to the purchase of the gift card.
If you are using gift certificates instead of gift cards, reread my above summary substituting “certificate” every place I mention “card.”

Now a possible gotcha here is the term dormancy -- the law states “there has been no activity with respect to the certificate or card in the 12-month period ending on the date on which the charge or fee is imposed.” Nowhere do I see a definition of “activity.” I know that California considers a balance inquiry as activity; other state only consider adding funds or purchase usage as activity. I'm sure we'll be hearing about this in court.

My recommendation: Don't use card expiration dates and instead charge a monthly service fee sometime after one year of dormancy. To be safe, I would interpret dormancy as any activity including balance inquiries.

I've always recommended not using expiration dates because many states have laws that "expired funds" are to be turned over to the state. Also, some states like California do not allow merchants to use expiration dates. If you still want to use expiration dates, I recommendation would be to not allow recharging the cards as each recharge will add a minimum of five years to the expiration date of the card.

In either case, fully document and prominently display your terms to the purchaser prior to selling the gift card. Any and all card carriers and displays should have the terms. Your web site should have a dedicated gift card page with the terms and conditions and your card stock or gift certificates should have the URL printed on it. The more places you disclose this information, the better. You don't want to be on the receiving end of a “they didn't warn me” accusation.

This Readers Digest version and recommendation, for the most part, only considers this specific federal law. You will need to incorporate any state or local laws that also apply. On the ConsumersUnion.org I did find a summary of various state laws regarding gift cards I thought useful: State Gift Card Protection Laws

Hope this info helps someone.

Side Rant - Formatting
I'm hoping that the topic numbering scheme used in this Act was simply a translation screw-up between the source where I found the document and the real document. Otherwise, someone in our government doesn't know how to follow a numbering standard. I was taught the Harvard format which I assume is the standard since most documents I read follow the same or very similar format:
  1. Topic
    1. Subtopic
      1. Major Detail
        1. Minor Detail
          1. Subdetail
Whereas this document is using the following:
  1. Topic
    1. Subtopic
      1. Major Detail
        1. Minor Detail
Maybe this is some standard attorney format to separate common language from lawyer speak? Or just is this part of the change we were promised?

Thursday, July 29, 2010

Au Contraire - Latest Gotcha from PCI SSC

Several month back many forums and blogs were discussing the (at that time) up and coming July 2010 sunset of Windows 2000. Many of these discussions included other already sunsetted operating systems. There were some heated debates over whether or not proper lock-down and compensating controls could keep a merchant compliant. Most of these discussions were settled by a posting in the PCI SCC FAQs:
PCI SSC FAQ

Would older operating systems that are no longer supported by the vendor be deemed non-compliant with the PCI DSS?

Systems that use operating systems that are no longer supported with new security patches by the vendor, OEM, or developer are not necessarily out of compliance. Compensating controls could address risks posed by using older operating systems. Exploit of legacy code is the main risk posed by an older operating system. Since well-known exploits are typically included as signatures to anti-virus, IDS/IPS and firewall filtering, a compensating control to consider is performing an exhaustive search to ensure that all known exploits for that operating system are identified, and that anti-virus, IDS/IPS and firewall rules are all updated to address those exploits. Other compensating controls could include monitoring IDS/IPS and firewall logs more frequently than required (for example, the requirement is for daily log reviews, so more frequently may be continuously and automated), or isolating and segmenting their POS systems via firewalls from the Internet and other systems in the cardholder data environment. The eventual solution is to upgrade to a new and supported operating system, and the entity should have an active plan for doing so. For more help with compensating controls, and for questions about whether a specific implementation is consistent with the standard or is 'compliant', please contact a Qualified Security Assessor.

Fast forward to today. Now, for many merchants and vendors, comes the first Windows 2000 post sunset scan from a prominent ASV - FAIL. Reason given: One or more scanned servers determined to be running Windows 2000. Upon referring this prominent ASV to the above FAQ on the PCI DSS site, they refer to the Technical and Operational Requirements for Approved Scanning Vendors (ASVs) on the same PCI DSS site:
Technical and Operational Requirements for ASVs

Obsolete environment

The ASV must report and determine as non-compliant any identified obsolete software (for example, application software or operating systems (OSs) no longer supported by the respective manufacturers. Obsolete software may expose the infrastructure to a security-related vulnerability.

The FAQ that many merchants and vendors use takes a risk assessment perspective whereas the Operating Requirements for ASVs takes a MUCH harsher authoritarian perspective -- "FAILED!" It's no wonder there is still so much confusion about PCI even after years educating the masses about PCI; people are still just as confused and pulling their hair out. I sure hope PCI SSC irons this one out quick.

An interesting side note is the wording of the Operating Requirements for ASVs: "Obsolete software may expose the infrastructure to a security-related vulnerability," yet PCI has deemed it non-compliant -- so is it vulnerable or not? If not, why is it not compliant? But this is straining at gnats -- the bigger issue is assuring people that obsolete O/Ss are not necessarily out-of-compliance while telling ASVs that obsolete O/Ss must be deemed out-of-compliance.

If you read any of my previous posts, I always harp on lowering your risk profile by eliminating card holder data from your environment. This emphasizes my belief that if you suffer a breach of card holder data, you will be found out-of-compliance no matter how compliant you thought you were. Using this as an example, if you were using Windows 2000 (post sunset) in your payment environment and your PCI assessment was based on the PCI SSC FAQ, the ASV document would deem you out-of-compliance.