var json_comments = new Array("<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-13078165\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=146805\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=146805\">shepd</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/05/credit-card-processors-launch-a-new-strategy-to-defeat-theft.html#comment-13078165\"><abbr class=\"published\" title=\"2009-05-26T16:56:38-05:00\">May 26, 2009  4:56 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(13078165);\">Moderate</a> |</span>	<script type=\"text/javascript\" src=\"http://consumerist.com/mt-static/plugins/Moderate/moderate.js\"></script>	<script type=\"text/javascript\">		successMsg = \"\";	</script><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=13078165');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p><p>This is the internet. Connecting to 50 machines won't take someone with \"skillz\" any longer than it took them to amass that 250k computer botnet they're abusing. And how is finding the IPs of another 49 botted PCs going to help them? Consider that in all likelyhood every one of the 50 computers is going to be running exactly the same everything--break into one and you can own them all. Or are they going to have each one running its own OS and a different revision of software?</p><br /><p>And the data needs to be knitted together. Wooooo! I'm sure that will stop them! Absolutely fo' sho'!</p></p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(13078165, 'shepd')\">Reply</a></div>		<!-- if it's a top level category ' -->									<div class=\"num-replies\">3 replies</div>	    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->     <!-- Loop through the reply comments -->        <div class=\"reply-container\" >            <div class=\"comment\" id=\"comment-13107037\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=1055332\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=1055332\">karlthepagan</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/05/credit-card-processors-launch-a-new-strategy-to-defeat-theft.html#comment-13107037\"><abbr class=\"published\" title=\"2009-05-27T16:31:11-05:00\">May 27, 2009  4:31 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(13107037);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=13107037');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>@<a href=\"#c13078165\" rel=\"nofollow\">shepd</a>: Fortunately, since almost no sites have security that weak, it's not about skill or resources, but about the time the attacker spends to acquire the accounts.</p><p>Yes a 0day could own a large number of servers, but not all of them. Vendors are getting better about protecting their servers lately (see the 0day archive <a href=\"http://research.eeye.com/html/alerts/zeroday/index.html\" rel=\"nofollow\">[research.eeye.com]</a>)</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(13107037, 'karlthepagan')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	     <!-- Loop through the reply comments -->                    <div class=\"comment last\" id=\"comment-13079024\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=109411\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=109411\">sanjsrik</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/05/credit-card-processors-launch-a-new-strategy-to-defeat-theft.html#comment-13079024\"><abbr class=\"published\" title=\"2009-05-26T17:29:26-05:00\">May 26, 2009  5:29 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(13079024);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=13079024');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>@<a href=\"#c13078165\" rel=\"nofollow\">shepd</a>: <br />I posted exactly this idea.  It's dumb, if 1 computer is hackable, then 50 will be well, 50 hackable computers.</p><p>This is a dumb idea.</p><p>The apples and oranges analogy of $5 in 200,000 houses is also pretty stupid.  $5 is a physical thing in 200,000 houses which you'd have to break into to physically retrieve.  Credit card numbers are all electronic, and all available via the Internet via an IP.</p><p>Stupid idea, let me guess, consultant sold them on the idea right?</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(13079024, 'sanjsrik')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- Loop through the reply comments -->        <div class=\"reply-container\" >            <div class=\"comment last\" id=\"comment-13105395\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=439678\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-439678-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=439678\">snowburnt</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/05/credit-card-processors-launch-a-new-strategy-to-defeat-theft.html#comment-13105395\"><abbr class=\"published\" title=\"2009-05-27T15:50:02-05:00\">May 27, 2009  3:50 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(13105395);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=13105395');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>@<a href=\"#c13079024\" rel=\"nofollow\">sanjsrik</a>: A) I'm sure he's not spilling exactly how they do it.  it's quite possible that there is some sort of procedure where it encrypts each of the 50 pieces using different keys and processes and unless you know all that it won't work.</p><p>still a single point of failure, but really, if you had a new fangled method of securing something, unless it was a honey pot would you tell everyone everything about it?</p><p>He did just enough to make it sound like they were doing something to instill confidence and that's it.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(13105395, 'snowburnt')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- Loop through the reply comments -->        <div class=\"reply-container\" >            <div class=\"comment last\" id=\"comment-13114815\">    <div class=\"inner\">	 <div class=\"user-pic\">                <a href=\"http://\"><img src=\"/css/images/default.gif\"         width=\"60\" height=\"60\" alt=\"user-pic\" /></a>            </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a title=\"http://\" href=\"http://\" rel=\"nofollow\">Cheapskate Brill</a>    </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/05/credit-card-processors-launch-a-new-strategy-to-defeat-theft.html#comment-13114815\"><abbr class=\"published\" title=\"2009-05-27T19:56:02-05:00\">May 27, 2009  7:56 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(13114815);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=13114815');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p><p>Each system probably keeps the data encrypted with a different key. That would be pretty common.</p><br /><p>It's not hackers from the Internet that's the only worry. Insiders can steal the most information and breaking data across lots of servers throws up a big red flag if one user is logging into each of those servers. The PA-DSS security requirements (Visa/MC/Amex/Disc. security regs) require that all access to servers with sensitive information be logged.</p><br /><p>This whole Heartland piece is not about breaking into servers. It's about sniffing the unencrypted IP traffic between systems. The encryption system is meant to prevent someone from sneaking into the back room of your local big box retailer (or anywhere on the network) and connecting a sniffer PC to the store's card network router.</p></p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(13114815, 'Cheapskate Brill')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	</div>     <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	</div>     <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	</div>    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-13078249\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=224192\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-224192-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=224192\">johnva</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/05/credit-card-processors-launch-a-new-strategy-to-defeat-theft.html#comment-13078249\"><abbr class=\"published\" title=\"2009-05-26T16:59:40-05:00\">May 26, 2009  4:59 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(13078249);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=13078249');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>I'm surprised none of them have this sort of thing already. Well, actually I'm not that surprised, given the fact that the basic credit card system is fundamentally flawed from a security perspective. This might help to limit the processors' exposure to data breaches, but it doesn't fix the basic problem with credit cards, which is that they use a static number that can easily be stolen simply by looking at the card, using a skimmer, etc. You can use more and more sophisticated encryption and storage schemes, etc like this to limit the damage caused by breaches, and that's a good idea, but it's still way too easy for someone to steal a credit card number and use it.</p><p>If Visa/MC were really concerned about security, they should go to something like a contact smart card system with strong cryptography on the card and only one-time-use numbers for everything. But it's their decision, as it's their liability if things get stolen.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(13078249, 'johnva')\">Reply</a></div>		<!-- if it's a top level category ' -->										<div class=\"num-replies\">4 replies</div>	    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->     <!-- Loop through the reply comments -->        <div class=\"reply-container\" >            <div class=\"comment\" id=\"comment-13115021\">    <div class=\"inner\">	 <div class=\"user-pic\">                <a href=\"http://\"><img src=\"/css/images/default.gif\"         width=\"60\" height=\"60\" alt=\"user-pic\" /></a>            </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a title=\"http://\" href=\"http://\" rel=\"nofollow\">Cheapskate Brill</a>    </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/05/credit-card-processors-launch-a-new-strategy-to-defeat-theft.html#comment-13115021\"><abbr class=\"published\" title=\"2009-05-27T20:02:28-05:00\">May 27, 2009  8:02 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(13115021);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=13115021');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p><p>A debit card is \"two factor\", but a PIN is false security. Plus if it gets breached, you are SOOOO screwed. Try explaining to a bank how your super secret PIN somehow got out.</p><br /><p>And as a frequent card user, I have security concerns, but I don't want to make it inconvenient to use my card or take away the ability to use it on the internet or offline when the system is down.</p></p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(13115021, 'Cheapskate Brill')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	     <!-- Loop through the reply comments -->                    <div class=\"comment\" id=\"comment-13096276\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=68654\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-68654-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=68654\">mac-phisto</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/05/credit-card-processors-launch-a-new-strategy-to-defeat-theft.html#comment-13096276\"><abbr class=\"published\" title=\"2009-05-27T04:12:04-05:00\">May 27, 2009  4:12 AM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(13096276);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=13096276');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>@<a href=\"#c13078249\" rel=\"nofollow\">johnva</a>: </p><blockquote>But it's their decision, as it's their liability if things get stolen.</blockquote><p></p><p>see, THAT is the whole problem with the system. i'm assuming that \"their\" in your post means visa/mc. that couldn't be further from the truth. here's how a transaction pans out:</p><p>you --> retailer --> retailer's processor --> card issuer's processor --> card issuer</p><p>now, what you'll notice is that visa never really touches it, or more accurately, this is all visa. they provide the infrastructure/rules/hardware/standards for the system.</p><p>typically, when fraud occurs, the rules dictated by visa decide who pays: you, the retailer or the card issuer. visa is NEVER on the hook. breaches are a little different b/c each link is ultimately responsible for their security. in these cases, a processor could be on the hook (like w/ heartland). now, banks &amp; processors typically have insurance to mitigate these incidents, but in the face of multi-million dollar breaches, the insurers are starting to do what insurers do - tell you to piss off when you need them most.</p><p>the point is, the people most likely to lose when fraud occurs are the least likely to do anything about it. insurance companies aren't even customers of the system, so it's not like they can do a whole lot. card issuers &amp; retailers are pretty much hanging by their balls here. the processors have some interest in keeping their data safe, but the real culprit is visa &amp; they don't have any exposure here.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(13096276, 'mac-phisto')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	     <!-- Loop through the reply comments -->                    <div class=\"comment last\" id=\"comment-13081083\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=839478\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=839478\">cabalagent1</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/05/credit-card-processors-launch-a-new-strategy-to-defeat-theft.html#comment-13081083\"><abbr class=\"published\" title=\"2009-05-26T18:39:15-05:00\">May 26, 2009  6:39 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(13081083);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=13081083');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>@<a href=\"#c13078249\" rel=\"nofollow\">johnva</a>: <br />What makes me cry is that the technology to fix ALL of this exists today.</p><p>In itself, it's not rocket surgery or brain science. But getting the industry to THINK securely is a monumental undertaking. The card companies may be satisfied with PCI, but I consider it only a most basic starting point. It's a joke.</p><p>The entire credit card infrastructure needs to be overhauled, starting with the swipe terminals used at the point of sale, all the way up to the banks. I don't like giving my card to someone and having them walk out of my sight to process it. The skimmers have portable swipers, so why can't the vendors have them? While we're at it, let's make sure that the swipers are communicating securely and that the swipe and the clearinghouse have authenticated themselves.</p><p>While we're at it, let's move away from the 60 year old model of \"swipe and it's authorized\" to a 2-factor model. This will necessitate the use of portable swipes so my card never leaves my presence. Tie it to an RSA-style keytoken that changes every minute. Now, even if you have my card number, it won't do you any good unless you have my PIN and keycode. And if you do have it, it's only good for 60 seconds.</p><p>I could go on and on at each level, and wonder why nobody has done anything to fix an obviously broken system. While we're at it, let's enforce the \"Hey big retailers... you shouldn't be retaining your customer's card info\" rule. They have no real need for it, and it's only going to lead to problems.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(13081083, 'cabalagent1')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- Loop through the reply comments -->        <div class=\"reply-container\" >            <div class=\"comment last\" id=\"comment-13084945\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=224192\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-224192-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=224192\">johnva</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/05/credit-card-processors-launch-a-new-strategy-to-defeat-theft.html#comment-13084945\"><abbr class=\"published\" title=\"2009-05-26T20:30:52-05:00\">May 26, 2009  8:30 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(13084945);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=13084945');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>@<a href=\"#c13081083\" rel=\"nofollow\">cabalagent1</a>: Yeah, like I said, the entire CC infrastructure is fundamentally broken. As always, it's an issue of money that prevents it from being upgraded. It would appear that so far it's cheaper to just buy insurance or something against fraud than to actually fix the infrastructure. The sad thing is that I'd be willing to bet a large part of the infrastructure actually gets replaced periodically anyway. I'd bet that the largest part of the cost of a new credit card system would be replacing all the POS terminals out there, and the retailers already have to buy new ones of those every time they wear out. Agreed that PCI is a joke.</p><p>I think this is a case where the people involved with fixing this simply don't see it as worth it. The losses just aren't enough, yet, for them to care.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(13084945, 'johnva')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	</div>     <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	</div>    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-13078529\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=21984\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-21984-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=21984\">econobiker</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/05/credit-card-processors-launch-a-new-strategy-to-defeat-theft.html#comment-13078529\"><abbr class=\"published\" title=\"2009-05-26T17:11:20-05:00\">May 26, 2009  5:11 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(13078529);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=13078529');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p><p>I thought the scammers were beyond stealing card numbers and now running automated number generators which they then test against I-Tunes to verify as a live number?</p></p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(13078529, 'econobiker')\">Reply</a></div>		<!-- if it's a top level category ' -->							<div class=\"num-replies\">1 replies</div>	    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->     <!-- Loop through the reply comments -->        <div class=\"reply-container\" >            <div class=\"comment last\" id=\"comment-13078647\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=228308\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=228308\">Ihaveasmartpuppy</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/05/credit-card-processors-launch-a-new-strategy-to-defeat-theft.html#comment-13078647\"><abbr class=\"published\" title=\"2009-05-26T17:16:13-05:00\">May 26, 2009  5:16 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(13078647);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=13078647');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>@<a href=\"#c13078529\" rel=\"nofollow\">econobiker</a>: Yes, they are. Here's a good one:<br />Years ago one of our cc's info was stolen. The card was replaced with a new one and new number, but THAT one also had the info stolen before we even received the card in the mail. So it was either generated or stolen at the issuer. The envelope wasn't tampered with and there was no RFID chip in it so it wasn't anyone in the postal system.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(13078647, 'Ihaveasmartpuppy')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	</div>    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-13078570\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=202178\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-202178-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=202178\">wardawg</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/05/credit-card-processors-launch-a-new-strategy-to-defeat-theft.html#comment-13078570\"><abbr class=\"published\" title=\"2009-05-26T17:13:01-05:00\">May 26, 2009  5:13 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(13078570);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=13078570');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p><p>I'd be more convinced if he actually sounded like he believed in the technology himself. He readily admitted that it's not the best solution, and that there's a significant chance that it probably won't take off. And if it doesn't take off, what are the chances that the credit card companies are going to do anything about security like he suggests they should.</p><br /><p>True end-to-end enctyption is the way to go speaking from a <b>purely security minded standpoint</b>, but I'm sure I'm not the only one who gets the feeling that the credit card companies are going to have to have it shoved down their throats.</p></p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(13078570, 'wardawg')\">Reply</a></div>		<!-- if it's a top level category ' -->								<div class=\"num-replies\">2 replies</div>	    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->     <!-- Loop through the reply comments -->        <div class=\"reply-container\" >            <div class=\"comment last\" id=\"comment-13080349\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=839478\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=839478\">cabalagent1</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/05/credit-card-processors-launch-a-new-strategy-to-defeat-theft.html#comment-13080349\"><abbr class=\"published\" title=\"2009-05-26T18:14:39-05:00\">May 26, 2009  6:14 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(13080349);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=13080349');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>@<a href=\"#c13078570\" rel=\"nofollow\">wardawg</a>: <br />They should have been encrypting their data to begin with, but this only prevents the theft of the actual database itself. The database itself needs to be designed not for convienence but for security. Restrictions on views, queries and the rest. The applications they use to access the database should be rewritten from a security paradigm, not \"whatever is easiest\".</p><p>This is 99% of the problem - the original designers went with whatever was fastest, cheapest and easiest. A lot of programmers don't think in a defensive mindset, they're into whatever works and try to leave it up to the networking people to secure it. When the fault is in the application and the data, all the firewalls in the world aren't going to prevent data from being stolen.</p><p>Programming for security means returning only the minimal amount of data back to the application that is necessary to conduct the transaction. Or re-thinking the entire process. Really, places like this are just interfaces to Mastercard and Visa, I would be suprised if they really need anything more than an approval code and a transaction number. While we're at it, let's make sure all the traffic is not only encrypted, but we've authenticated each other.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(13080349, 'cabalagent1')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- Loop through the reply comments -->        <div class=\"reply-container\" >            <div class=\"comment last\" id=\"comment-13081089\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=202178\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-202178-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=202178\">wardawg</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/05/credit-card-processors-launch-a-new-strategy-to-defeat-theft.html#comment-13081089\"><abbr class=\"published\" title=\"2009-05-26T18:39:24-05:00\">May 26, 2009  6:39 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(13081089);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=13081089');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p><p>@<a href=\"http://consumerist.com/5260257/credit-card-processors-launch-a-new-strategy-to-defeat-theft#c13080349\" rel=\"nofollow\">cabalagent1</a>: You mean like having combined PKE pairs embedded in the new chip cards that match up with PKE keys in the terminal assigned to each retailer to form a full key, ensuring that the only information held at processing facilities like Moneris and Heartland is fully encrypted and can only be decrypted by MC/Visa (who would distribute the key ranges to authorized processors) but is never actually stored in the decrypted format? (/crypto nerd)</p><br /><p>There's better ways to do it I'm sure, but doing the initial encryption with a 1024 bit key between the card and the terminal using a <a href=\"http://en.wikipedia.org/wiki/Diffie-Hellman_key_exchange\" rel=\"nofollow\">diffie helman key exchange</a> would be simple to implement and make it nearly impossible to view any unencrypted data, but the chip card would have to be programmed to encrypt it's own data before going out which would increase the cost per card.</p><br /><p>Another option would be Triple-DES encryption using keys from the card, the terminal, and the issuer, but it might be harder to implement the initial key exchange.</p></p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(13081089, 'wardawg')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	</div>     <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	</div>    </div>","","","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-13079262\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=449107\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=449107\">Schlake</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/05/credit-card-processors-launch-a-new-strategy-to-defeat-theft.html#comment-13079262\"><abbr class=\"published\" title=\"2009-05-26T17:37:44-05:00\">May 26, 2009  5:37 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(13079262);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=13079262');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>When you are talking about security and encryption, the word \"proprietary\" is synonymous with \"insecure,\" not \"expensive,\" though the first does lead to the second.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(13079262, 'Schlake')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-13080842\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=125641\"><img        src=\"/mt-static/support/assets_c/userpics/userpic-125641-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=125641\">vladthepaler</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/05/credit-card-processors-launch-a-new-strategy-to-defeat-theft.html#comment-13080842\"><abbr class=\"published\" title=\"2009-05-26T18:31:09-05:00\">May 26, 2009  6:31 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(13080842);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=13080842');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>If retailers are now allowed to add a surcharge for credit card use, they could easily recover the cost of the secure transaction. It'd certainly be more fair to do it that way than to raise prices for everyone.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(13080842, 'vladthepaler')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","","","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-13083749\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=348996\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-348996-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=348996\">oldgraygeek</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/05/credit-card-processors-launch-a-new-strategy-to-defeat-theft.html#comment-13083749\"><abbr class=\"published\" title=\"2009-05-26T19:59:04-05:00\">May 26, 2009  7:59 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(13083749);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=13083749');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>I fix home PCs, and I am the smallest credit-card merchant there is. I make, on average, about one transaction per week.</p><p>If I read my merchant agreement correctly, I am responsible for financial damages caused by any data breach in my office. If I kept the card numbers, a simple break-in could ruin me: fraudulent transactions on any two or three cards I had accepted would locate me more accurately than any GPS unit.</p><p>Here's my security procedure:<br />-- Using a single-copy receipt book, I take an imprint of the card at the customer's house and get a signature.<br />-- I give the customer the signed original.<br />-- I make sure the yellow copy is legible and put it in my wallet, in case I lose the receipt book. (I did lose one book, and replaced it without worry because I knew there were no card numbers in it).<br />-- When I get home, I punch in the customer's card number, expiration date, house number and Zip code. <b>(\"Card Present?\" = Yes,</b> because I have an imprint).<br />-- My terminal dials up for approval, prints one copy of the slip with the full card number on it, and offers to print a second that would only have the last 4 numbers; I decline.<br />-- I settle the terminal, transmitting the \"batch\" of one or two transactions.<br />-- The written &amp; printed slips go into a folder.<br />-- Every Sunday, my wife shreds the contents of the folder.<br />-- She mixes the shredded slips with used cat litter and throws them away.</p><p>On any given Monday morning, I have no records of any customers' card numbers (or signatures). I'd like to retain the signatures for longer, but I can't figure out how to do that without also keeping the card numbers. I should scan them and blur the card info, but I'm too lazy to make it happen &amp; stick to it.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(13083749, 'oldgraygeek')\">Reply</a></div>		<!-- if it's a top level category ' -->								<div class=\"num-replies\">2 replies</div>	    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->     <!-- Loop through the reply comments -->        <div class=\"reply-container\" >            <div class=\"comment\" id=\"comment-13129600\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=867044\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=867044\">Révolution</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/05/credit-card-processors-launch-a-new-strategy-to-defeat-theft.html#comment-13129600\"><abbr class=\"published\" title=\"2009-05-28T07:59:17-05:00\">May 28, 2009  7:59 AM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(13129600);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=13129600');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>@<a href=\"#c13083749\" rel=\"nofollow\">oldgraygeek</a>: Highly secure digital scanning system: <br />Buy a cheap desktop<br />Bolt it to the floor<br />Install Truecrypt<br />Encrypt the files<br />Modem+Scanner<br />Fill in extra USB ports with epoxy.<br />Lock the case shut, or at least use screws.</p><p>Scanning works fine, as long as the computer isn't networked, is encrypted, and is physically secure.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(13129600, 'Révolution')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	     <!-- Loop through the reply comments -->                    <div class=\"comment last\" id=\"comment-13100917\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=68654\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-68654-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=68654\">mac-phisto</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/05/credit-card-processors-launch-a-new-strategy-to-defeat-theft.html#comment-13100917\"><abbr class=\"published\" title=\"2009-05-27T13:20:25-05:00\">May 27, 2009  1:20 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(13100917);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=13100917');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>@<a href=\"#c13083749\" rel=\"nofollow\">oldgraygeek</a>: you're leaving yourself open to some chargeback exposure if you can't produce a signed sales receipt - especially considering you're not transmitting CVC/CVV2 track data for an authorization.</p><p>i know a few merchants that do their settlement on dedicated machines disconnected from any network/internet (except when they are transmitting batches &amp; then, only via a phone line). then there's some i know that archive strictly on optical (though there's still a chance that data could be compromised in this fashion).</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(13100917, 'mac-phisto')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	</div>    </div>","","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-13090163\">    <div class=\"inner\">	 <div class=\"user-pic\">                <a href=\"http://\"><img src=\"/css/images/default.gif\"         width=\"60\" height=\"60\" alt=\"user-pic\" /></a>            </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a title=\"http://\" href=\"http://\" rel=\"nofollow\">alternatestory</a>    </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/05/credit-card-processors-launch-a-new-strategy-to-defeat-theft.html#comment-13090163\"><abbr class=\"published\" title=\"2009-05-26T23:38:05-05:00\">May 26, 2009 11:38 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(13090163);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=13090163');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>This was tremendously interesting - thanks for posting it.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(13090163, 'alternatestory')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","","","","","","","");


