AP: Weak Security Opens Door To Credit Card Hacks
Visa's head of global data security, Eduardo Perez, said the company scaled back its records review because it took too much work and because the PCI standards have improved the industry's security "considerably."
"I think we've made a lot of progress," he said. "While there have been a few large compromises, there are many more compromises we feel we've helped prevent by driving these minimum requirements." Representatives for MasterCard, American Express, Discover and JCB — which, along with Visa, steer PCI policy — either didn't return messages from the AP or directed questions to the PCI security council. PCI's general manager, Bob Russo, said inspector certification is "rigorous." Yet he also acknowledged that inconsistent audits are a problem — and that merchants and payment processors who suffered data breaches possibly shouldn't have been PCI-certified. Those companies also might have easily fallen out of compliance after their inspection, by not installing the proper security updates, and nobody noticed. The council is trying to crack down on shoddy work by requiring annual audits for the dozen companies that do the bulk of the PCI inspections. Smaller firms will be examined once every three years.- Loading Comments...
- Loading Comments...
Recent Comments
Featured Photo Galleries
| Dow Jones | S&P 500 | NASDAQ | 10-Year Note | |
|---|---|---|---|---|
| 10,441.12 | 1,109.18 | 2,206.91 | 35.96 |
Oil *
73.55
|
|
DOWN
10.88
|
UP
1.25
|
UP
5.86
|
DOWN
0.07
|
10 Yr
3.60%
SPDR Gold
111.59
|
|
-0.10%
|
+0.11%
|
+0.27%
|
-0.19%
|
Data delayed 20 minutes |














