<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Gilbert Verdian - I Secure Enterprises &#187; vendors</title>
	<atom:link href="http://www.gilbertverdian.com/security/category/security/vendors/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gilbertverdian.com/security</link>
	<description>talking about security, from the front line</description>
	<lastBuildDate>Sun, 08 Nov 2009 10:52:42 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Insecurity of Receipts &#8211; Part 2</title>
		<link>http://www.gilbertverdian.com/security/2007/05/insecurity-of-receipts-part-2/</link>
		<comments>http://www.gilbertverdian.com/security/2007/05/insecurity-of-receipts-part-2/#comments</comments>
		<pubDate>Tue, 08 May 2007 20:08:29 +0000</pubDate>
		<dc:creator>Gilbert Verdian</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[vendors]]></category>

		<guid isPermaLink="false">http://www.gilbertverdian.com/security/2007/05/insecurity-of-receipts-part-2/</guid>
		<description><![CDATA[Just came back from a trip to Scotland and before throwing a receipt away in the bin noticed that this one printed everything except the last 4 digits of the card whereas another receipt I had only contained the last 4 digits. Not good having these two receipts together. Coincidently on digg last week the [...]]]></description>
			<content:encoded><![CDATA[<p>Just came back from a trip to Scotland and before throwing a receipt away in the bin noticed that this one printed everything except the last 4 digits of the card whereas another receipt I had only contained the last 4 digits. Not good having these two receipts together.</p>
<p>Coincidently on <a href="http://digg.com/business_finance/Retailers_Get_Sued_For_Printing_Too_Many_Credit_Card_Digits_On_Receipts">digg</a> last week the <a href="http://online.wsj.com/public/article/SB117771144745785336-S1YwB4VdRuerW3MvcvSJBNlHLUg_20080428.html">following story on WSJ</a> explains how consumers are bringing class action lawsuits against large retailers for printing too many digits on receipts. The story states:</p>
<p>In the US,<br />
<blockquote>as of Dec. 4, retailers are prohibited from printing more than the last five digits of a credit-card or debit-card account number on receipts that are handed to customers. The receipts also can&#8217;t include the account&#8217;s expiration date. The law applies only to electronically printed receipts, rather than those that are written by hand or imprinted on old-fashioned manual machines.</p></blockquote>
<p>So you are now liable as a retailers for using a product that vendors fail to meet current laws and regulations, instead of the vendors of the point of sale systems themselves. Privacy is such a concern for consumers, as it should be, that we are doing anything in order to protect our personal data. Imagine this in another context, where a user of system is liable for a fault by the manufacturer/vendor. </p>
<p>So far &#8220;100 federal lawsuits seeking class-action status against big merchants such as Rite Aid Corp., Wendy&#8217;s International Inc., FedEx Corp., TJX Cos. and Inter Ikea Systems BV.&#8221;</p>
<p>The best case would if other countries adopted something similar as law or the requirement became part of PCI. This should be a catalyst for Point of Sale vendors to step up and address this insecurity or they themselves can also face legal liability the same way retailers are, we&#8217;ll just have to wait and see what happens in this space.</p>
<script src="http://feeds.feedburner.com/~s/450480?i=http://www.gilbertverdian.com/security/2007/05/insecurity-of-receipts-part-2/" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
			<wfw:commentRss>http://www.gilbertverdian.com/security/2007/05/insecurity-of-receipts-part-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
