Quantcast StorefrontBacktalk » Blog Archive » Wal-Mart’s Kiosk Trial Raises Serious PCI, Data Ownership Issues
advertisement
advertisement

This is page 3 of:

Wal-Mart’s Kiosk Trial Raises Serious PCI, Data Ownership Issues

May 27th, 2009
Like this story? Share it
To share this story with people in your social network, please click on the network icons below.

The company’s privacy statement says it might share information with law enforcement and third-party service providers that “may help us process information, extend credit, fulfill customer orders, deliver products to you, manage and enhance customer data, provide customer service, assess your interest in our products and services, or conduct customer research or satisfaction surveys.” The privacy policy notes that those companies “are also obligated to protect your personal information in accordance with e-Play’s privacy policies, except if we inform you otherwise at the time of collection,” and warns that disclosure of personal information might also be required due to litigation.

“There’ve been no discussions on selling customer information,” Rudy said. “I would be very hesitant to do that and we certainly wouldn’t do it without the permission of the consumer.” The CEO also said he’d fear angering host retailers by, for example, selling to competing retailers information cleaned from its kiosks. “I doubt our retail partners would be willing to work with us if we did that, so that’s why we won’t do it,” Rudy said.

Currently, accepting E-Play game-buying kiosks involves virtually no input from a retailer’s IT department if the units are set-up to pay money only by making deposits to credit or debit cards, as is the case in the initial Wal-Mart trial. Wal-Mart is remaining non-committal about its long-term interest in the machines and whether it would like them to offer Wal-Mart-specific forms of payment for the games that are purchased. “It’s too early to say or speculate at this time,” O’Brien said. “It’s a very small pilot. We are watching with great interest but we can’t speculate at this time how fast it will grow. For us, it’s a great service for customers and a convenience.”

Rudy said the company has game kiosks in some Wal-Mart Canada stores and in about 200 other locations, mainly Exxon and Speedway gas stations. He said E-Play has plans “with several partners” to implement a system where those who sell their games to the kiosks are issued a slip bearing a barcode they can take to the service desk. The barcode would be scanned to determine the amount of store credit available to the disk seller.

Greenleaf and O’Brien said public interest in the Wal-Mart kiosks has been high, particularly among gaming enthusiasts. O’Brien acknowledged many people are asking if there is, or ever will be, a way to get their game trade-in money in a gift card or other form that can be used immediately at the store. However, the retailer is taking a similar arms-length approach as that taken by Best Buy when it began testing kiosks last summer. “That’s a next generation we’re looking at, the in-store gift card credit,” Greenleaf said, noting “there certainly are other capabilities that e-Pay has in place with these machines” for paying game and movie sellers.

If any alternative payback method were instituted, it wouldn’t take place unless there is a future expansion of the kiosks to other Wal-Marts. “There isn’t currently an expansion plan (but) we’re optimistic about expansion and looking forward,” O’Brien said. She noted more E-Play kiosks will be installed, as part of the trial, before the end of May.


advertisement

3 Comments | Read Wal-Mart’s Kiosk Trial Raises Serious PCI, Data Ownership Issues

  1. Craig Keefner Says:

    Thanks for exploring these issues. Nice article. My guess is the credit card readers are standard HID and possibly keyboard wedge (though we hate to think that). Something to be said for the new magteks which actually do do the encoding of data at the head and eliminate encoding by software (and uses magensa service to decode). Those options might be gaining momentum just in terms of plausible denial so to speak.

  2. Atilla Ovundur Says:

    In Turkey, credit payment systems are really hard to implement in selfservice kiosk systems. Almost every bank has its own loyalty program and customers are very addictible for them. And also PCI and EMV rules are quite strong in payment systems. So Security and privacy is not first issue but integrity is main problem so as to solve.

  3. Roger van Maris Says:

    Interesting article! Dealing with big box stores can be difficult especially in balancing the visual perception of who is delivering the service in store. Point taken that WM will be on the hook for whatever the kiosk does or does not do, in the eyes of the public. It is essential to mesh the policies of the the host retailer with the policies of the provider. Trust of our clients can not be betrayed at any point or our kiosk projects will definately fail.

Leave a Reply

Newsletter

Quickly catch-up on the latest in E-Commerce and Retail Tech with our free weekly newsletter, with urgent bulletins as news merits.
advertisement

Most Recent Comments

Kill All The Passwords

This article does mention, but does not give enough attention to, the fact that the attacks discussed are only feasible when the encrypted password file can be copied and subjected to an offline attack. The trick is to have authentication performed on a separate, much more strongly secured host - such as an Active Directory Domain Controller, or a Kerberos server, or a NIS+ server, or even using something as banal as an LDAP-over-SSL authentication dialog. In these environments, the odds of the "password file" being stolen and subjected to an offline attack go to near zero, and only online attacks may be carried out by the attacker. With sensible exponential backoff between failed password attempts, lockout after a modest number of failed attempts on a single account, and pattern detection, that minimum 7 character password is quite secure enough. Passwords aren't dead yet for security purposes, and they will be with us for a very long while to come for practical purposes. The trick is to employ them correctly. Read more...
The possibilities you describe are years away from being implemented at best, so for the moment passwords are an ugly reality. Luckily, password managers can easily manage hundreds of passwords of any length. The only thing a user needs to remember is the master password. It seems like an easier task to educate users on how to use password managers rather than implement complex security technology on a global basis. Read more...