joanie_wexler
Writer

Cracking down on wireless credit card security

Opinion
May 14, 20072 mins

* Retailers: Pay attention to PCI security standards

Recent reports of massive credit card theft from retailers that haven’t adequately secured their Wi-Fi networks are unsettling, to say the least.

Organized gang members have been grabbing customer card data out of the air, where it has been unconscionably unencrypted, en route to a banking processing company for authorization. Other breaches are thought to have occurred when hackers tapped into Wi-Fi data streams generated by weakly encrypted wireless barcode scanners, broke the encryption code, and eavesdropped on user sessions to steal their network access credentials.

Barcode devices are perhaps most prone to the exclusive use of Wired Equivalent Privacy, or WEP, the older and easily crackable Wi-Fi encryption scheme. Many handheld barcode scanners don’t yet support stronger Wi-Fi Protected Access (WPA) and WPA2 forms of encryption, often because of the older devices’ limited memory and CPU power.

To protect against an outsider piggybacking on the barcode connection, regularly scan your airwaves for intruders. The Payment Card Industry Data Security Standard (PCI DSS) v.1.1, in effect since January 2007, requires internal and external vulnerability scans at least quarterly and every time a network topology or configuration change is made.

Quarterly scans seem pretty minimal, actually. Who’s to know if the breach is occurring (and the threat is identifiable) on the day and time the scan is done? Wireless intrusion detection and protection systems (IDS/IPS), on the other hand, scan the airwaves continually in search of unauthorized devices compromising the network.

PCI DSS v.1.1 also requires strong encryption of any wireless links (Wi-Fi or cellular) carrying credit card data. It specifies the use of WPA, WPA2, Layer 3 IPSec or Layer 7 Secure Sockets Layer/Transport Layer Security (SSL/TLS). Specifically, PCI DSS v.1.1 Requirement 4 mandates to “never rely exclusively on WEP to protect confidentiality and access to a wireless LAN.”

It remains to be seen just how the payment card industry will batten down the hatches and enforce compliance to these and other wireless DSSs other than by levying fines after a breach, when damage has already been done. For the full set of PCI DSS specs, click here.

joanie_wexler
Writer

Joanie Wexler is an independent writer and editor who has spent 20+ years writing about computer networking technologies, their business potential, and implementation considerations. She serves clients at technology companies and industry publications writing educational materials on all aspects of IT.

More from this author