Software Development Frameworks and Contactless Payments Bypass

Software Development Frameworks and Contactless Payments Bypass

By Nancy Rand
Posted in Security
On September 11, 2020

NIST and the PCI DSS Council have both published software development frameworks. PCI DSS published a blog today highlighting an interview between Kevin Stine, Chief of the Applied Cybersecurity Division at NIST and Troy Leach, SVP, Engagement Officer at PCI SSC.  This blog discusses the importance of secure software development and contains links to additional information.

https://blog.pcisecuritystandards.org/nist-and-pci-ssc-find-common-ground-in-development-of-software-frameworks

Additionally, The Hacker News published an article about contactless payments pin bypass attack.

https://thehackernews.com/2020/09/emv-payment-card-pin-hacking.html

The PCI DSS Council published the Contactless Payments on COTS (CPoC) Security and Test requirements and vendors using the standards.

https://www.pcisecuritystandards.org/documents/Contactless_Payments_on_COTS-Security_and_Test_Requirements-v1.0.pdf?agreement=true&time=1599760885600

https://www.pcisecuritystandards.org/assessors_and_solutions/cpoc_solutions

Also available on the council website is Software-based PIN Entry on COTS (SPoC) Solutions:

https://www.pcisecuritystandards.org/assessors_and_solutions/spoc_solutions

Nancy Rand

Nancy Rand

Nancy has more than 20 years’ experience in information technology and security, solving business issues and implementing best-practice solutions that support organizational objectives. Her expertise includes leveraging, optimizing, and implementing diverse technology platforms, and management of large-scale technology projects.