Quantcast StorefrontBacktalk » Blog Archive » Heartland Taking Names And Kicking POS, With Visa’s Help
advertisement
advertisement

Heartland Taking Names And Kicking POS, With Visa’s Help

Written by Evan Schuman
March 24th, 2009
Like this story? Share it
To share this story with people in your social network, please click on the network icons below.

When Visa sent an E-mail to retailers telling them it was suspending Heartland, the note was explicit in saying that “Heartland will continue to serve as a processor in the Visa system.” But that didn’t stop rivals from recruiting Heartland customers by saying that they could face fines or PCI certification problems if they used them.

Visa issued a statement “clarifying” their original position, despite the fact that their original position was quite clear. Gartner issued a brief report Monday (March 23) saying that “this statement clarifies much of the confusion that arose after Heartland and RBS WorldPay were removed from Visa’s list of PCI-certified service providers. Visa had to stand by its long-standing policy, but its delisting decision had raised questions about whether the processors’ clients could continue to do business with them.”

That’s the part where I get lost. What was so confusing about Visa’s original statement that “Heartland will continue to serve as a processor in the Visa system”? Did people think that Visa would tell retailers that a vendor “will continue to serve as a processor in the Visa system” and then turn around and fine—or decertify—them for doing so?

Some of the explanation behind this comes from Heartland itself, which added some clarifications of its own on its site in an area written for merchants. “You may have been approached by Heartland’s competitors making false claims such as: ‘You could be fined because you use Heartland’ or ‘You will not be PCI compliant if you use Heartland.’ Through a series of cease and desist letters, Heartland has informed competitors that their untrue and misleading claims are baseless and unlawful. Heartland intends to initiate legal action against them if they do not immediately stop making these claims.”

What’s this? A breached processor actively defending itself? Rivals are not the only ones to feel Heartland’s ire. Last Thursday (March 19), a software security company called Cloakware issued a news release about five security holes that it wanted to flag to the world. This wasn’t exactly a lot of insightful surprising stuff (the top item on their list was “Using Vendor-Supplied Default Passwords,” followed by “unsecured access to cardholder data”). But what caught our eye was a reference near the end of the statement that said, “Heartland Payment Systems recently announced that tens of millions of credit and debit card transactions were compromised, signaling the worst breach in the Payment Card Industry history.”

Funny, I hadn’t recalled seeing any such statement from Heartland and I somehow think I would have remembered that one.


advertisement

4 Comments | Read Heartland Taking Names And Kicking POS, With Visa’s Help

  1. Tom Mahoney Says:

    Evan;

    I certainly don’t approve of advertising using Heartland’s unfortunate position but you, or rather Heartland’s competitors, raise an interesting point.

    Merchants are required to be compliant. Being compliant requires using a compliant processor. Heartland is not, at least for now, compliant. Therefore Heartland’s merchants are not compliant.

    Yes? No?

  2. Evan Schuman Says:

    Editor’s Note: The gray area here is Visa’s use of the word “probation” and Visa’s definition. It means that someone is off the PCI Compliant list, but it also means explicitly that retailers and still use them and be considered compliant. That probationed entity has to jump through a lot of testing hoops–and is put on notice that they need to fix everything quickly or they’re out–but they are still qualified to accept transactions.
    But regardless of how anyone might feel about this probation mode, Visa is within its rights to create it and to define it however it wants. Given that Visa–from the beginning–was explicit about what it meant, I have to side with Heartland on this one and say that the rivals (this time) were out-of-line. I don’t have to agree with Visa’s move (personally, I would have argued that if they wanted to have an impact, they should have cleanly removed them from the list. That would have sent a clear signal) to respect it and to argue that the industry has an obligation to abide by it.

  3. PCI Guy Says:

    Considering all of the close scrutiny Heartland has now been subject to by VISA personnel, FBI, Secret Service, and Heartland’s own staff and security consultants, their systems are now probably far more secure than most. So why on Earth did Visa decide to make a public spectacle of “suspending” Heartland? What benefit could possibly been achieved by doing that? Either VISA considers Heartland’s systems secure enough to be safe for processing transactions, or not. If they are not secure enough then they should have been REMOVED from the list, not “placed on probation”.

  4. Steve Sommers Says:

    A VISA represenative speaking at the ETA show clarified this today. The merchant is responsible from his network and down stream — meaning any POS, hardware or software that they host. Merchants must use “approved” gateways and processors but if the breach happens up stream — meaning the gateway or processor — then the merchant is not liable. Heartland is still an “approved” vendor (albeit on probation) so compliant merchants using Heartland are compliant.

Leave a Reply

Newsletter

Quickly catch-up on the latest in E-Commerce and Retail Tech with our free weekly newsletter, with urgent bulletins as news merits.
advertisement

Most Recent Comments

Kill All The Passwords

This article does mention, but does not give enough attention to, the fact that the attacks discussed are only feasible when the encrypted password file can be copied and subjected to an offline attack. The trick is to have authentication performed on a separate, much more strongly secured host - such as an Active Directory Domain Controller, or a Kerberos server, or a NIS+ server, or even using something as banal as an LDAP-over-SSL authentication dialog. In these environments, the odds of the "password file" being stolen and subjected to an offline attack go to near zero, and only online attacks may be carried out by the attacker. With sensible exponential backoff between failed password attempts, lockout after a modest number of failed attempts on a single account, and pattern detection, that minimum 7 character password is quite secure enough. Passwords aren't dead yet for security purposes, and they will be with us for a very long while to come for practical purposes. The trick is to employ them correctly. Read more...
The possibilities you describe are years away from being implemented at best, so for the moment passwords are an ugly reality. Luckily, password managers can easily manage hundreds of passwords of any length. The only thing a user needs to remember is the master password. It seems like an easier task to educate users on how to use password managers rather than implement complex security technology on a global basis. Read more...