<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
	>
<channel>
	<title>Comments on: Lack of credit card security when booking hotels online</title>
	<atom:link href="http://www.travel-rants.com/2009/03/30/lack-credit-card-security-booking-online/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.travel-rants.com/2009/03/30/lack-credit-card-security-booking-online/</link>
	<description></description>
	<lastBuildDate>Sun, 29 Jan 2012 01:52:48 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Itamar</title>
		<link>http://www.travel-rants.com/2009/03/30/lack-credit-card-security-booking-online/#comment-162722</link>
		<dc:creator>Itamar</dc:creator>
		<pubDate>Wed, 31 Mar 2010 10:41:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.travel-rants.com/?p=3524#comment-162722</guid>
		<description>Hi Darren,
The security flaws should definitely be taken care off, but one point to keep in mind from a consumer perspective: &quot;They are protected by the rules of card schemes&quot;

If someone writes down their Card number and CVC on a napkin and uses it online, the consumer will get his money back. Definitely for credit card transactions and even for VISA debit transactions (not sur for MC). These protection covers Fraud, Item not delivered (lost/stolen) and item not as described. But it&#039;s still  a pain as the consumer has to go through that process, so it&#039;s clearly better to cut the fraud at the source.

Regarding PCI compliance, CVC code cannot be stored (I believe there are some specific examptions) and although in the past we could make transactions without the CVC code, I believe there is now a mandate on CVC code (or it&#039;s on its way) with again some exceptions.

There are definitely ways to get around that like doing a pre-auth and charging the card a week later if the consumer didn&#039;t pay when checking-out...</description>
		<content:encoded><![CDATA[<p>Hi Darren,<br />
The security flaws should definitely be taken care off, but one point to keep in mind from a consumer perspective: &#8220;They are protected by the rules of card schemes&#8221;</p>
<p>If someone writes down their Card number and CVC on a napkin and uses it online, the consumer will get his money back. Definitely for credit card transactions and even for VISA debit transactions (not sur for MC). These protection covers Fraud, Item not delivered (lost/stolen) and item not as described. But it&#8217;s still  a pain as the consumer has to go through that process, so it&#8217;s clearly better to cut the fraud at the source.</p>
<p>Regarding PCI compliance, CVC code cannot be stored (I believe there are some specific examptions) and although in the past we could make transactions without the CVC code, I believe there is now a mandate on CVC code (or it&#8217;s on its way) with again some exceptions.</p>
<p>There are definitely ways to get around that like doing a pre-auth and charging the card a week later if the consumer didn&#8217;t pay when checking-out&#8230;
<p>
				<span id="reportcomment_results_div_162722"><a href="javascript:void(0);" onclick="reportComment_AddTextArea( 162722 );" title="Report this comment" rel="nofollow">Report this comment</a></span><br />
				<span id="reportcomment_comment_div_162722"></span>
			</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Conchetta</title>
		<link>http://www.travel-rants.com/2009/03/30/lack-credit-card-security-booking-online/#comment-160849</link>
		<dc:creator>Conchetta</dc:creator>
		<pubDate>Fri, 05 Mar 2010 17:14:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.travel-rants.com/?p=3524#comment-160849</guid>
		<description>Suggestion Re:Credit Cards. Mine are through a credit union since they are smaller &amp; humans answer the phone. I tell them where I&#039;m going &amp; any charges above a certain amount to block. They will contact me at the store I&#039;m in, ask questions only I know the answers to for verification. If they can&#039;t reach me then just block. I can live without the purchase.</description>
		<content:encoded><![CDATA[<p>Suggestion Re:Credit Cards. Mine are through a credit union since they are smaller &amp; humans answer the phone. I tell them where I&#8217;m going &amp; any charges above a certain amount to block. They will contact me at the store I&#8217;m in, ask questions only I know the answers to for verification. If they can&#8217;t reach me then just block. I can live without the purchase.
<p>
				<span id="reportcomment_results_div_160849"><a href="javascript:void(0);" onclick="reportComment_AddTextArea( 160849 );" title="Report this comment" rel="nofollow">Report this comment</a></span><br />
				<span id="reportcomment_comment_div_160849"></span>
			</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andy</title>
		<link>http://www.travel-rants.com/2009/03/30/lack-credit-card-security-booking-online/#comment-147064</link>
		<dc:creator>Andy</dc:creator>
		<pubDate>Sun, 31 May 2009 20:22:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.travel-rants.com/?p=3524#comment-147064</guid>
		<description>This is an interesting thread and one which I am pleased to say we manage effectively. At no stage, either through personal contact over the telephone or via an online booking, does any hotel or private villa owner get supplied with customers credit card details when booking through us. We don&#039;t even retain the CVC number at all. If we need to carry out a further transaction with our customers we contact them again for their number. Our gateway provider doesn&#039;t supply the CVC number to us, so if the booking is made live online even we do not have access to this number. I am happy with our security levels and know that this is crucial to us flourishing online. If we have a single slip up it could ruin our entire business and wreck hard won credibility. All our transactions are secure over the net with 128 bit SSL encrypted transactions. We provide booking solutions to private villa owners and small luxury boutique hotels and our guests know we take care of their security above all else. I would not do business with anyone that doesn&#039;t ensure customer confidence, privacy and reliability.</description>
		<content:encoded><![CDATA[<p>This is an interesting thread and one which I am pleased to say we manage effectively. At no stage, either through personal contact over the telephone or via an online booking, does any hotel or private villa owner get supplied with customers credit card details when booking through us. We don&#8217;t even retain the CVC number at all. If we need to carry out a further transaction with our customers we contact them again for their number. Our gateway provider doesn&#8217;t supply the CVC number to us, so if the booking is made live online even we do not have access to this number. I am happy with our security levels and know that this is crucial to us flourishing online. If we have a single slip up it could ruin our entire business and wreck hard won credibility. All our transactions are secure over the net with 128 bit SSL encrypted transactions. We provide booking solutions to private villa owners and small luxury boutique hotels and our guests know we take care of their security above all else. I would not do business with anyone that doesn&#8217;t ensure customer confidence, privacy and reliability.
<p>
				<span id="reportcomment_results_div_147064"><a href="javascript:void(0);" onclick="reportComment_AddTextArea( 147064 );" title="Report this comment" rel="nofollow">Report this comment</a></span><br />
				<span id="reportcomment_comment_div_147064"></span>
			</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex Bainbridge</title>
		<link>http://www.travel-rants.com/2009/03/30/lack-credit-card-security-booking-online/#comment-146773</link>
		<dc:creator>Alex Bainbridge</dc:creator>
		<pubDate>Wed, 27 May 2009 17:16:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.travel-rants.com/?p=3524#comment-146773</guid>
		<description>Hi Lina

Quoting from the standards:

&quot;11.2 Run internal and external network vulnerability scans at least quarterly and after any significant change in the network (such as new system component installations, changes in network topology, firewall rule modifications, product upgrades). Note: Quarterly external vulnerability scans must be performed by an Approved Scanning Vendor (ASV) qualified by Payment Card Industry Security Standards Council (PCI SSC). Scans conducted after network changes may be performed by the company’s internal staff.&quot;

As you say you are PCI compliant I assume you do have the scans in place (required even if self auditing) - which is good news for your customers. Would have been easier if you had just said that as I asked this question in the comment above!</description>
		<content:encoded><![CDATA[<p>Hi Lina</p>
<p>Quoting from the standards:</p>
<p>&#8220;11.2 Run internal and external network vulnerability scans at least quarterly and after any significant change in the network (such as new system component installations, changes in network topology, firewall rule modifications, product upgrades). Note: Quarterly external vulnerability scans must be performed by an Approved Scanning Vendor (ASV) qualified by Payment Card Industry Security Standards Council (PCI SSC). Scans conducted after network changes may be performed by the company’s internal staff.&#8221;</p>
<p>As you say you are PCI compliant I assume you do have the scans in place (required even if self auditing) &#8211; which is good news for your customers. Would have been easier if you had just said that as I asked this question in the comment above!
<p>
				<span id="reportcomment_results_div_146773"><a href="javascript:void(0);" onclick="reportComment_AddTextArea( 146773 );" title="Report this comment" rel="nofollow">Report this comment</a></span><br />
				<span id="reportcomment_comment_div_146773"></span>
			</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lina Zaproudi</title>
		<link>http://www.travel-rants.com/2009/03/30/lack-credit-card-security-booking-online/#comment-146770</link>
		<dc:creator>Lina Zaproudi</dc:creator>
		<pubDate>Wed, 27 May 2009 16:40:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.travel-rants.com/?p=3524#comment-146770</guid>
		<description>Hi Alex.
As discussed in more detail by email between us, we are PCI compliant.

The &quot;solution&quot; is merely a way to add a security layer on top of SSL, by using an encryption script &amp; public key on the web server and a decryption program and private password on a company PC. So the sensitive emails remain always encrypted (AES128 encryption).

For full PCI compliance, agents should consult the requirements described in the documents found here: https://www.pcisecuritystandards.org/</description>
		<content:encoded><![CDATA[<p>Hi Alex.<br />
As discussed in more detail by email between us, we are PCI compliant.</p>
<p>The &#8220;solution&#8221; is merely a way to add a security layer on top of SSL, by using an encryption script &amp; public key on the web server and a decryption program and private password on a company PC. So the sensitive emails remain always encrypted (AES128 encryption).</p>
<p>For full PCI compliance, agents should consult the requirements described in the documents found here: <a href="https://www.pcisecuritystandards.org/" rel="nofollow">https://www.pcisecuritystandards.org/</a>
<p>
				<span id="reportcomment_results_div_146770"><a href="javascript:void(0);" onclick="reportComment_AddTextArea( 146770 );" title="Report this comment" rel="nofollow">Report this comment</a></span><br />
				<span id="reportcomment_comment_div_146770"></span>
			</p>
]]></content:encoded>
	</item>
</channel>
</rss>

