E N D
1. Secure PumpPAY Webinar September 18 & 26, 2008
Jeff Wakefield
VP Marketing
2. Agenda
Security Mandates Facing Fuel Retailers
Payment Security Mandate Roadmap
Secure PumpPAY
Overview
Models Supported
Benefits
Installation
Content Delivery
Questions
3. What do I need to do and when?
4. Visa Fuel Pump Security Mandates
5. VISA Global POS PED TDES Mandates
6. VISA PED Deployment Mandates
7. VISA PABP Mandates
8. VeriFone Solutions
9. Fuel Pump Fraud & Security
10. Fuel dispenser skimming is becoming epidemic
11. Fuel retail breaches are escalating Arizona
California
Delaware
Florida
Georgia
Indiana
Illinois
Massachusetts Michigan
Nevada
New Jersey
North Carolina
Pennsylvania
Texas
Washington
Wisconsin
12. Visa reports AFDs as primary targets Findings
Fraud activity concentrated in southern California and Florida
Specific AFD manufacturers and models targeted
Organized groups target locations: goal is track and PIN data
Targets
High volume stations
AFD located away from cashier
Access via front panel with shared ‘brass key’
Suspects impersonate pump service technicians
Reader device attached to card reader and PIN pad
13. TDES mandate does NOT mean security at the pump The TDES mandate does not increase security at the fuel dispenser
TDES makes decrypting encrypted PIN numbers harder
To our knowledge, no one has broken the DES encryption schemes and compromised PIN numbers
The current fuel pump payment security risks remain:
Limited number of brass keys to provide access to the DCR
Available ribbon cables to tap into to steal MSR data
No shroud to protect against overhead camera’s stealing PIN’s during entry
Criminals know how to tamper with existing DCR’s in the fuel dispenser
Criminals know the format of data from these pumps
Track data is not encrypted between the MSR and the EPP or current debit module (GSM, etc.)
14. Secure PumpPAY increases fuel dispenser security Extended bezel around unit eliminates or reduces ability of cameras being used for capturing PIN entries
Tactile keypad prevents keyboard overlay skimmers from being installed
OP4100 housing conceals all cables making installation of skimmers more difficult
PCI EPP 1.3 certified
15. Secure PumpPAY Product Overview August 1, 2008
16. Secure PumpPAY feature overview
17. Secure PumpPAY Security Benefits Meets the latest Payment Card Industry (PCI) requirements to provide the most secure on-line PIN entry as well as Triple DES method of encryption at the fuel dispenser
Secure PumpPAY housing conceals all cables making installation of skimmers more difficult
New keys for doors will make Secure PumpPAY units more difficult to access as keys are not widely available
18. Secure PumpPAY Enhanced Security Benefits Extended bezel around unit reduces or eliminates ability of cameras being used for capturing PIN entries
Polymer tactile keypad prevents keyboard overlay skimmers from being installed
Remote key load feature allows debit keys to be loaded in the field and helps ease the process when changing networks
19. Integrated, all-in-one design simplifies installation into existing pumps — Retrofit Kits available for all major dispenser manufacturers and models, and can be done in as little as 30 minutes.
Large color display provides bright attention-getting messages that help drive customers into the store for high margin sales.
Integrated high resolution printer included and can prominently highlight graphics such as company logos and bar-coded receipts for in-store promotions.
Additional Secure PumpPAY Benefits
20.
Built in Contactless Reader is included which future proofs your investment
Simplify management and customer interface by having the same system at all pumps.
Additional Secure PumpPAY Benefits
21. Compact design streamlines installation
PCI approved design streamlines retro-fits or new installs
Most dispensers can be completed in about an hour
Retrofit Kits include the following
OP4100 PCI compliant card reading terminal
High speed thermal printer that supports high resolution images and graphics
Dispenser door replacement panel that meets original manufacturer design and materials
Cables, connectors and power supplies
Mounting brackets and door locks
Easily integrates into Ruby and Topaz POS systems
Integrated, all-in-one design simplifies installation
22. Gilbarco Advantage Retrofit Kit
23. Tokheim Premier B Wide Retrofit Kit
24. Tokheim Premier C Wide Frame Retrofit Kit
25. Wayne Vista Retrofit Kit
26. Successful US field trials began in October 2007 16 field trail sites were installed from October 2007 to July 2008
All Released Pump Types Tested in a variety of environments
27. Installation Pre-Installation
Application installed
Content Loaded
Debit Keys downloaded from the VeriFone Portal
Installation Payment Terminal and Printer into the Door frame assembly
Day of Installation
Half of Dispensers Shut Down
Old equipment removed
Install the pre-assembled devices
Install the new Door Frame assembly
Test communication with the POS
Activate the new Payment terminals
Repeat the above process for the remaining dispensers
28. Loading Graphical Images using the SPP Installer Program
29. SPP supports Two Image Prompts Sequences
30. Save your images in an easy-to-find image library or folder
31. Loading Images is simply “drag and drop”
32. Setting the length of time each image appears
33. Preview Image Playlist to verify timing and image sequence
34. Downloading the Playlist completes the Process
35. Graphics displayed throughout SPP application
36. Graphics displayed throughout SPP application
37. Brand specific idle images - examples
38. Examples of promotional images
39. What are my options for pump security?
40. VeriFone Payment Security Solutions
41. VeriFone can help you meet your PCI goals today!