|
|
 |
RE: FN-FORUM: PCI DSS Merchant Compliance -(All sites have to comply by June 30, 2005)
date posted 30th July 2005 21:20
It's always clients that want to "cut costs" because they have a
terminal / machine in their office and want to process cards through
that. So in effect all they're doing is having a "customer not present"
situation as if they'd taken the details over the phone.
What is daft is how cheap it is to have a proper secured system
especially considering how much they'd loose should the card found to be
fraudulent as they'd have little or no protection. I do think saving the
IP address of the submitter is a good idea though. I'll add that to the
transactino processing process.
Is there a decent resource that gives geographic locations for IP blocks
?
Cheers
Andy
-----Original Message-----
From: [EMAIL REMOVED] [EMAIL REMOVED] On Behalf Of Paul
Civati
Sent: Saturday, July 30, 2005 9:47 PM
To: Andy Macnaughton-Jones
Subject: Re: FN-FORUM: PCI DSS Merchant Compliance -(All sites have to
comply by June 30, 2005)
Andy Macnaughton-Jones [EMAIL REMOVED] wrote:
> Is there any problem with having PGP encrypted mails sent ?
That is certainly an advisable thing to do if you really *must* do it
via email.
One further thing to consider is that of order verification, for example
with live orders you may record and check the IP address of the
submitter.
One the easiest ways we spot blatantly obvious card fraud is when the
address details of the card holder are say in the US/UK and the
submitting IP is in Indonesia.
-Paul-
--
Paul Civati 0870 321 2855
Rack Sense Ltd - Managed/Business hosting - www.racksense.com =20
RackRed - Value SSL certificates and servers - www.rackred.com
--=20
Freelancers, contractors earn more with Prosperity4
Call 0870 870 4414 or visit www.prosperity4.com
and benefit from Inland Revenue approved expenses today.
To advertise here: http://www.freelancers.net/advertising.html
|
 |
|