Saturday 2 January 2010

Security Concerns with using your iPhone as a Credit card reader

I always thought it was strange that Apple Stores used Windows CE devices to take payments. It is testament to the power that Microsoft's Mobile OS has in the payment field, while Apple seems to have a struggled in this area.

Supposedly some folks are trying to change this and the new Card Readers for Apple portable devices are appearing.

The only reason this story is appearing here in the ZIS blog is due to the lack of basic security provision in these new addons. Slide card readers should be on their last legs and I was surprised by use of them in North America when I was last there.

Supposedly, new cards issued by North American Banks are being shipped with chips but the hardware suppliers should be on this movement as well. While chip and pin has its problems as well documented by the security group out of Cambridge and specifically Stephen J Murdoch, no one would dispute the technical advantages it has over the older magnetic strip system. The main concern that S J Murdoch has is the banks assertions that the system is completely secure and that any fraudelent activity that takes place is due to card user lack of diligence and not their systems.

I would assume that products being designed now would include at least chip and pin and adhere to the basic PCIDSS requirements.