TMCnet News

Staying on Track: What You Don't Know WILL Hurt You!
[December 08, 2006]

Staying on Track: What You Don't Know WILL Hurt You!


By TMCnet Special Guest
Joseph Sanscrainte , Attorney, Bryan Cave, LLP
 
In August of this year, Visa released a Data Security Alert to its members regarding what it considers to be the number one data security vulnerability:  storage of card “Track” data.
 
For those just tuning in, Track data refers to the information encoded on the ubiquitous magnetic stripes found on the back of credit/debit/payment cards.  There are two types of Track data that are pertinent to the payment card industry, creatively dubbed “Track 1” and “Track 2.”  The Tracks differ in terms of the organization and types of data encoded, as well as the amount of data that can be stored - however, each track contains information that is highly prized by identity thieves.
 
The information on these Tracks includes the cardholder’s name, account number and expiration date, as well as the codes necessary to authenticate “card present” transactions, such as CVV (for Visa) and CVC (for MasterCard.)  Did you ever wonder how the check-in terminal at the airport knows who you are just by having you swipe any major credit card?  That’s Track 1 in action.  (For anyone interested in learning more about these Track standards, they are defined under ISO Standard 7813.)

 
The importance of maintaining absolute security with regard to Track data can not be overstated.  As Visa warned in its August bulletin on this topic, “with little effort, a duplicate card can be created [using Track  information] that will appear indistinguishable from the original card during the authorization process.”  Concern regarding the security of this data should rise exponentially with the number of transactions a merchant processes and the number of locations from which these transactions are accepted.  (Note that in addition to the encoded magnetic stripe data, data thieves are also interested in PIN numbers and the three or four digit code that is written on back of the card used for Card Not Present transactions.)
 
When it comes to Track data, merchants may only store the specific data elements necessary to support card acceptance.  Most importantly, this means that anything outside of cardholder name, account number, expiration date and service code (all of which may be retained to process merchandise returns and transaction reversals) must be purged from all of a merchant’s systems immediately after authorization for the transaction is received.  Many merchants remain unaware of both the risks associated with storing this data, as well as the specific storage methodologies of their card point-of-sale (POS) systems.  In fact, Visa warns that “merchants that use commercially available POS systems should contact their POS vendors to validate whether the applications and versions in use are storing track data or other sensitive data, such as PINs.”
 
The risks of failure to maintain security of Track data can be significant.  As it is in the interests of the credit card Associations (Visa, MasterCard, etc.) to minimize fraud as much as possible, there are many ongoing monitoring programs in place that are designed to identify and halt fraud.  For example, Common Point of Purchase (CPP) investigations use data-mining analysis of millions of card transactions to identify locations where card data was most likely compromised.  Based upon information gleaned from a CPP investigation, an Association may alert one of its members about potential security concerns at specific merchant locations.  In turn, the member (an acquiring bank and/or processor) will then require the merchant to conduct an investigation of its systems.
 
As a result of such investigations, many merchants have discovered to their dismay that their systems are storing Track data in contravention of Association rules.  Although, this fact was unknown to the merchant, and even though the merchant may have relied on representations made by its POS system vendor, the Associations have virtually unlimited discretion to levy penalties against their members for such infractions.  The merchants, in turn, are ultimately held responsible for these penalties, which can easily amount to millions of dollars.
 
In addition to validating Track storage practices with your POS vendor, Visa also advises merchants to:  review the files written by the application and the content therein to verify that prohibited data is not stored; review the POS application itself and eliminate any functionality that enables storage of Track data; review all systems and expunge any historical prohibited data; determine whether your current practices regarding storing Track data is necessary and appropriate for your business; verify that your POS software version complies with all appropriate Association best practices (for Visa, these are the Visa Payment Application Best Practices.)
 
Perhaps the most important thing for any merchant to keep in mind is that whereas an identity thief only needs to be lucky once to collect private data, the maintainer of that information has to be vigilant at all times to prevent any such breach.  With the increasing focus at the national and international level, on data security and privacy, the responsibilities of all entities that operate in the credit/debit marketplace are only going to increase.  The Track storage issue is one that, upon discovery, is easily remedied - the trick for merchants is to ensure that they make the discovery and fix the problem before any penalties are levied against them.
 
Joseph Sanscrainte is an Attorney with Bryan Cave, LLP’s New York office.  He can be contacted at [email protected]

[ Back To TMCnet.com's Homepage ]