PCI London: How the Payment Card Industry could kill PCI DSS
Today (23rd Jan 14) I was a panellist at PCI London 2014, quite a few people were interested in what I had to say, on removing the need for PCI DSS compliance completely by securing the payment cards further. What I said was nothing new, I have been bleating on about this since attending the first PCI SSC meeting back in 2007. Still it is a bold thing to say, especially at a conference where Visa Europe and the PCI Security Standard Council are promoting PCI DSS compliance in the UK, and with event sponsoring vendors promoting their PCI DSS compliance servicing wares. I'll summarise the views which I expressed at PCI London, which I believe could draw an end to PCI DSS compliance. Introduce Global Chip & Pin (EMV) Chip & Pin provides two-factor authentication, this means in order for the cardholder to make a payment, the cardholder requires knowledge of a 4 digit number, and possession of the payment card. This is known as a 'cardholder present' transac...