3 ms·
Yes. In large scale retailers, the payment terminals would either be connected via Ethernet to the private point of sale (POS) network in the store where they
by coleca 11y ago
Yes. In large scale retailers, the payment terminals would either be connected via Ethernet to the private point of sale (POS) network in the store where they could only talk to the POS controllers, or they would be connected via USB or custom serial cables (IBM) to the POS register itself and all communications would run through the software on the POS terminal.
This password isn't the encryption key. Usually keys would be injected into the terminal either remotely through the POS terminal, POS controller or by shipping a special card w/a magstripe to the store where the manager or loss prevention person would swipe the card on each terminal that has the new key on it. PCI standards dictate that the retailer rotates the keys on a schedule with a documented procedure.
Changing the merchant ID probably would have little effect in most operations because the transactions aren't going directly to the MC/VISA/etc network, but are passing through a dedicated link to the merchant's acquiring bank. I've never tested this, but I would imagine that the acquiring bank would reject transactions that are for merchant IDs that do not belong to the customer that is leasing the connection. This situation actually happens quite often by merchants just mis-keying the merchant ID when setting up new stores.
- kw71 11y agoThanks for this insight. During a low point in my career I took on some contract work to deploy new POS at some QSR. I had to visit the secret menu on the Ingenico card terminals to verify network settings and in some cases (when whatever provisioning process did not work) manually set them. The terminals were to communicate with a local device in a 10.* IP scheme, and were supposed to get their own network settings via DHCP. I've also had Walmart refund partial purchases without my payment card being present. This shows me that it's possible that Walmart stored the payment card information.
- Nursie 11y agoSo there are a few things here I could maybe clarify, having worked in all sections of the chain from on-device security to issuing bank systems. (Remember I said maybe!) You're right, not all POS talk directly to the bank. One of the products I worked on was a store-level switch, the POS would talk to that. However the store-level switch did not have the requisite keys to decrypt all of the data the POS would put out. In particular there are some pieces of data (PIN is one) that must, by card-scheme rules, be encrypted from the point of entry all the way to the bank. The keys used to achieve this are injected into the terminal during manufacture or during an update process that can only be activated using further keys held by the banks, not at the store level. On your refund - Walmart may well be able to process a refund simply by specifying an amount and a transaction reference - they don't necessarily need to have had the card details to do that. Their bank can take that reference number and apply a refund against the transaction, looking up your account details in their database in order to inform your issuing bank about it. In some cases they may not even need to supply an account or card number to the issuing bank, just a transaction reference.