Announcement

Collapse
No announcement yet.

Mastercard SecureCode Non Compliance

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    Mastercard SecureCode Non Compliance

    Hi All,

    Recently Received “Important Information” regarding “MasterCard Secure Code” and got in a panic over nothing (allegedly). This may have been covered in the forum, but the threads I read did not clear things up for me. Hopefully this ma be helpful for others who process cards offline and were confused like me.

    MasterCard SecureCode and Streamline Shop card Readers.

    Online PSP Users
    I have just been informed by Streamline that the implementation of ‘MasterCard SecureCode’ is only applicable to PSP Service Users. If card details are processed and payments taken online then, ‘MasterCard SecureCode’ must be used, fully effective from September 2008 (else Merchant account can be closed down)

    Details Captured For Offline Processing & Telephone Orders
    They tell me that telephone orders are not subject to MasterCard SecureCode validation. Comparable to this, is the capture of card details for later processing offline. Therefore, if you capture your card details to a SSL and download to process on site, you need not worry about complying with MasterCard Secure Code Validation. However, you must still self asses to prove that the card details are stored securely on you computer etc (pcidss)

    Therefore, according to Streamline Customer Services (Phillip, Streamline Cust Services, 08457616263, ext 6960), it’s business as usual for all off line card processing. As a merchant, I am assured that we should not see any difference to our card processing procedures.

    Regards,
    Nick

    #2
    Streamline told us this a while ago and i just thought it was some call centre chump talking rubbish but i feel slightly more assured now they have also informed you the same although once Actinic finally launch there payment system i think we will be taking a look at it further.

    Comment


      #3
      From Cardnet Website
      Over the last few years ‘switch’ cards have gradually been phased out and as from the 30 June 2007, the switch brand will be discontinued and you will no longer be able to display the switch logo on your web site.To display the Maestro logo on your web site and accept International and UK issued Maestro cards after this date you will need to activate MasterCard’s secure payments solution- MasterCard SecureCode.
      Brian
      www.flowergallery.co.uk
      Same day flower delivery to UK
      Same day flower delivery to Republic of Ireland
      International Flower Delivery

      Located in Argyll, Scotland, UK

      Comment


        #4
        Mastercard SecureCode is the same as Verfied by Visa which is where the credit card compaines presents an agreed challenge/password scheme to verify the identity of the cardholder when payments are are processed online.

        Clearly, if your processing a payment offline then you do not know the challenge and the cardholder should not reveal the password.

        So you're 100% correct that it has no bearing on offline processing.

        Recently there has been a lot of discussion about PCI compliance. This is a totally different issue but applies in particular to anyone who processes credit cards offline. It is far more restrictive on what processes and procedures you need to take credit card details offline and I would guess if you had problems understanding the secureCode stuff that you probably aren't up to speed on PCI compliance.

        You really need to look at the PCI compliance threads and understand how they apply to you.

        Mike

        Edit: OK. I see you do refer to PCI-DSS so you probably are aware of the issue. I would recommend anyone who isn't to read up on it.
        -----------------------------------------

        First Tackle - Fly Fishing and Game Angling

        -----------------------------------------

        Comment


          #5
          Thanks for the confirmation Mike, I was really after a second opionion in case I had been updated incorrectly by the call centre I spoke to regarding offline processing.

          I know little about PCI-DSS, but will be reading up very soon!

          Cheers,
          Nick

          Comment

          Working...
          X