Jump to content

Recommended Posts

Posted

Not sure where to put this - feel free to move...

 

Just been advised ( luckily before purchasing) that the school is looking to put in a wireless credit card machine that can be used around school to take payments for holiday clubs etc . And over the phone

 

Our current ones had to have dedicated telephone lines to work ( therefore are stationary )

 

Does anybody use machines that are mobile - thinking about proxy settings and IP addresses etc.

 

Thanks

Posted
Tell the school that anything that connects to the network has to go via you for approval and setup, then phone the supplier I guess
Posted (edited)

Hi

We have five Ingenico IWL258 machines.

 

They are on their own hidden SSID and vlan and the firewall rule allows only comms to the provider from this vlan etc

Edited by Asgard
  • Thanks 1
Posted
Tell the school that anything that connects to the network has to go via you for approval and setup, then phone the supplier I guess

 

Tried this - was on hold to supplier for over an hour then gave up...

Posted
Thanks for replies - don’t really understand how the device communicates with the bank so added challenge, also bank’s tech support not helpful - gave me a sales number to ring and was on hold for over an hour - gave up...
Posted

Just found this ... If your payment terminal is a portable machine that uses a SIM, the communication method is GPRS (Mobile / SIM)

If your payment terminal has a base unit and is connected to your internet line, the communication method is Bluetooth (IP / Broadband)

If your payment terminal has a base unit and is connected to your standard telephone line, the communication method is

Bluetooth (PSTN / Landline)

If your payment terminal is a fixed device, used in one location, and is it connected to your internet line, the communication method is

Countertop (IP / Broadband)

If your payment terminal is a fixed device, used in one location, and is it connected to your standard telephone line the communication method is Countertop (PSTN / Landline) ​

Posted

All of the above.

 

Most of the Network/LAN units Ive worked with have Proxy settings buried in the management settings but in fairness we have a dedicated gateway configured to route PCI-DSS traffic with ACLs and Firewall rules applied.

 

3G devices with M2M sims are common and widely used but it will normally be your payment gateway provider that supplies them.

 

I remember back in 2004 paying for Fuel in a rental car at the last petrol station on the road to Cape Reinga

https://en.m.wikipedia.org/wiki/Waitiki_Landing

 

The unit had a mobile cellphone attached to it!

 

Glad to say they are fully integrated now!

Posted

I would look into the GPRS units with a SIM card. I looked into connecting the card machine via broadband for my father's business, and getting the PCI-DSS compliance check is a nightmare without special equipment, security settings etc. For them, it was going to be so much hassle and expense that they went back to using it dial-up through PSTN.

 

You can't just hook a card machine into any-old Wifi or internet connection.

Posted
I would look into the GPRS units with a SIM card. I looked into connecting the card machine via broadband for my father's business, and getting the PCI-DSS compliance check is a nightmare without special equipment, security settings etc. For them, it was going to be so much hassle and expense that they went back to using it dial-up through PSTN.

 

You can't just hook a card machine into any-old Wifi or internet connection.

 

Why not though, are they saying their machines aren't secure?

Posted
Why not though, are they saying their machines aren't secure?

 

PCI compliance requires you to ensure the path the data takes (from card reader > bank/payment handler) is secure.

 

A reader on a phone line is considered secure.

A reader that uses a 3G/4G connection is secure.

A reader that connects via ethernet / wifi to the local LAN (shared with other devices) is not considered secure without extra work/expense (as @m25man mentions).

 

TLDR: The 3G/4G card reader is probably the most compliant and least expensive option.

Posted
PCI compliance requires you to ensure the path the data takes (from card reader > bank/payment handler) is secure.

 

A reader on a phone line is considered secure.

A reader that uses a 3G/4G connection is secure.

A reader that connects via ethernet / wifi to the local LAN (shared with other devices) is not considered secure without extra work/expense (as @m25man mentions).

 

TLDR: The 3G/4G card reader is probably the most compliant and least expensive option.

 

Have they not heard of TLS?

Posted
It's so secure they don't insist it's put on a private network because everyone knows it's full of bugs, unlike the rest of the ones mentioned
Posted
It's so secure they don't insist it's put on a private network

 

I mean, unless you're peforming a MITM attack......which nearly every school and large business is doing.

 

Yes, most schools and business whitelist financial transactions as "don't intercept", but what the card providers care about is:

 

Is there any evidence that someone's faffing with the transaction data?

Have you taken steps to prevent that?

What were those steps and where's the evidence?

 

Until very recently (Nov 2017) Squareup were vulnerable to HTTPS interception on a business / school network: https://www.cvedetails.com/cve/CVE-2016-2402

  • Thanks 1
Posted

Well, that was rather silly of them. Don't write your own libraries unless you know what you're doing.

 

But it's kind of the point, assuming CC reader uses TLS and you can't install your own CA on the reader, and it actually checks the security, it's secure, doesn't need its own connection/vpn/vlan

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...