<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">
  <channel>
    
    <title>Braintree Payment Solutions</title>
    <link>http://www.braintreepaymentsolutions.com/rss/</link>
    <language>en-us</language>
    <ttl>40</ttl>
    <description>A blog about PCI DSS Compliance and payment processing including credit cards, echeck, ACH, EFT, payment gateway and credit card data storage.</description>
    
    
        
        <geo:lat>41.904667</geo:lat><geo:long>-87.625044</geo:long><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/braintree" type="application/rss+xml" /><feedburner:feedFlare href="http://add.my.yahoo.com/rss?url=http%3A%2F%2Ffeeds.feedburner.com%2Fbraintree" src="http://us.i1.yimg.com/us.yimg.com/i/us/my/addtomyyahoo4.gif">Subscribe with My Yahoo!</feedburner:feedFlare><feedburner:feedFlare href="http://www.newsgator.com/ngs/subscriber/subext.aspx?url=http%3A%2F%2Ffeeds.feedburner.com%2Fbraintree" src="http://www.newsgator.com/images/ngsub1.gif">Subscribe with NewsGator</feedburner:feedFlare><feedburner:feedFlare href="http://www.bloglines.com/sub/http://feeds.feedburner.com/braintree" src="http://www.bloglines.com/images/sub_modern11.gif">Subscribe with Bloglines</feedburner:feedFlare><feedburner:feedFlare href="http://www.netvibes.com/subscribe.php?url=http%3A%2F%2Ffeeds.feedburner.com%2Fbraintree" src="http://www.netvibes.com/img/add2netvibes.gif">Subscribe with Netvibes</feedburner:feedFlare><feedburner:feedFlare href="http://fusion.google.com/add?feedurl=http%3A%2F%2Ffeeds.feedburner.com%2Fbraintree" src="http://buttons.googlesyndication.com/fusion/add.gif">Subscribe with Google</feedburner:feedFlare><feedburner:feedFlare href="http://www.pageflakes.com/subscribe.aspx?url=http%3A%2F%2Ffeeds.feedburner.com%2Fbraintree" src="http://www.pageflakes.com/ImageFile.ashx?instanceId=Static_4&amp;fileName=ATP_blu_91x17.gif">Subscribe with Pageflakes</feedburner:feedFlare><feedburner:feedFlare href="http://www.plusmo.com/add?url=http%3A%2F%2Ffeeds.feedburner.com%2Fbraintree" src="http://plusmo.com/res/graphics/fbplusmo.gif">Subscribe with Plusmo</feedburner:feedFlare><feedburner:feedFlare href="http://my.feedlounge.com/external/subscribe?url=http%3A%2F%2Ffeeds.feedburner.com%2Fbraintree" src="http://static.feedlounge.com/buttons/subscribe_0.gif">Subscribe with FeedLounge</feedburner:feedFlare><feedburner:feedFlare href="http://www.thefreedictionary.com/_/hp/AddRSS.aspx?http%3A%2F%2Ffeeds.feedburner.com%2Fbraintree" src="http://img.tfd.com/hp/addToTheFreeDictionary.gif">Subscribe with The Free Dictionary</feedburner:feedFlare><feedburner:feedFlare href="http://www.live.com/?add=http%3A%2F%2Ffeeds.feedburner.com%2Fbraintree" src="http://tkfiles.storage.msn.com/x1piYkpqHC_35nIp1gLE68-wvzLZO8iXl_JMledmJQXP-XTBOLfmQv4zhj4MhcWEJh_GtoBIiAl1Mjh-ndp9k47If7hTaFno0mxW9_i3p_5qQw">Subscribe with Live.com</feedburner:feedFlare><feedburner:feedFlare href="http://mix.excite.eu/add?feedurl=http%3A%2F%2Ffeeds.feedburner.com%2Fbraintree" src="http://image.excite.co.uk/mix/addtomix.gif">Subscribe with Excite MIX</feedburner:feedFlare><feedburner:feedFlare href="http://www.podcastready.com/oneclick_bookmark.php?url=http%3A%2F%2Ffeeds.feedburner.com%2Fbraintree" src="http://www.podcastready.com/images/podcastready_button.gif">Subscribe with Podcast Ready</feedburner:feedFlare><feedburner:feedFlare href="http://www.addtoany.com/?linkname=Braintree%20Payment%20Solutions&amp;linkurl=http%3A%2F%2Ffeeds.feedburner.com%2Fbraintree&amp;type=feed" src="http://www.addtoany.com/addfr-b.gif">Add to Any Feed Reader</feedburner:feedFlare><feedburner:feedFlare href="http://www.fwicki.com/users/default.aspx?addfeed=http%3A%2F%2Ffeeds.feedburner.com%2Fbraintree" src="http://www.fwicki.com/images/ui/fwicki_clicklet.png">Subscribe with fwicki</feedburner:feedFlare><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><item>
          <title>Practical Ecommerce Gives Braintree 4.5/5 Star Rating</title>
          <description>&lt;p style="text-align: left;"&gt;&lt;img align="right" src="http://braintreepaymentsolutions.com/assets/315/practical-ecommerce-logo.png?1254154000" alt="" /&gt;Our credit card processing and credit card storage solutions were &lt;a href="http://www.practicalecommerce.com/articles/1286-The-PeC-Review-Braintree-Payment-Solutions-Protects-Merchants-and-Customers"&gt;recently reviewed&lt;/a&gt; by &lt;a href="http://www.practicalecommerce.com/member/873-Armando-Roggio"&gt;Armando Roggio&lt;/a&gt; at Practical Ecommerce. He gave us 4.5 out of 5 stars.&amp;nbsp; Our favorite part, &amp;quot;Braintree is a no-brainer...&amp;quot;.&amp;nbsp; Here is an excerpt:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Without a safe, reliable means of processing payments, there would be no ecommerce. So it is not a surprise that managing payments and securing credit card and customer information is a major concern for online retailers.&lt;/p&gt;
&lt;p&gt;Braintree Payment Solutions offers merchants a complete electronic payment service that quickly processes payments and keeps customer data secure, in most cases slashing a merchant&amp;rsquo;s payment card industry (PCI) compliance costs by 90 percent or more, according to the company.&lt;/p&gt;
&lt;p&gt;I was a little skeptical when I was first introduced to the Braintree solution, but after reviewing its products, asking about IP spoofing (a hacking tactic wherein the hacker pretends to be a server it is not), and consulting with an experienced developer friend, I find myself awarding Braintree Payment Solutions, four and a half out of a possible five stars in this, &amp;ldquo;The PeC Review,&amp;rdquo; my weekly attempt to introduce you to products or services that have the potential to improve your ecommerce business.&lt;/p&gt;
&lt;/blockquote&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/braintree?a=2udzA-jOlVE:SsHNuDl6ozg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=2udzA-jOlVE:SsHNuDl6ozg:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=2udzA-jOlVE:SsHNuDl6ozg:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=2udzA-jOlVE:SsHNuDl6ozg:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=2udzA-jOlVE:SsHNuDl6ozg:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=2udzA-jOlVE:SsHNuDl6ozg:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=2udzA-jOlVE:SsHNuDl6ozg:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=2udzA-jOlVE:SsHNuDl6ozg:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/braintree/~4/2udzA-jOlVE" height="1" width="1"/&gt;</description>
          <pubDate>Tue, 29 Sep 2009 17:03:00 GMT</pubDate>
          <guid isPermaLink="false">http://www.braintreepaymentsolutions.com/blog/Practical-Ecommerce-Gives-Braintree-4.5-Star-Rating/</guid>
          <link>http://feedproxy.google.com/~r/braintree/~3/2udzA-jOlVE/</link>
        <feedburner:origLink>http://www.braintreepaymentsolutions.com/blog/Practical-Ecommerce-Gives-Braintree-4.5-Star-Rating/</feedburner:origLink></item>
        
    
        
        <item>
          <title>PCI Compliance a Check-Box for 70 Percent of Retailers</title>
          <description>&lt;p&gt;According to a &lt;a href="http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=220100919"&gt;report released today&lt;/a&gt;, 70% of retailers treat PCI Compliance as a check-box. The remaining 30% are apparently taking it seriously.&lt;/p&gt;
&lt;p&gt;PCI Compliance, whether taken seriously or as a check-box, really is an economic decision: (financial cost + reputational cost + business disruptions cost) x probability of breach is &amp;le; or &amp;ge; the cost, effort and distraction of 'serious' compliance efforts. 30% apparently think the risk is too great and 70% take the business risk and do just enough to avoid being labeled as negligent.&lt;/p&gt;
&lt;p&gt;My guess is that this 70% is also observing that no matter how intense compliant efforts are, post breach forensics
&lt;meta name="Title" content=""&gt;
&lt;meta name="Keywords" content=""&gt;
&lt;meta http-equiv="Content-Type" content="text/html; charset=utf-8"&gt;
&lt;meta name="ProgId" content="Word.Document"&gt;
&lt;meta name="Generator" content="Microsoft Word 2008"&gt;
&lt;meta name="Originator" content="Microsoft Word 2008"&gt;  &lt;!--[if gte mso 9]&gt;&lt;xml&gt;
&lt;o:OfficeDocumentSettings&gt;
&lt;o:AllowPNG /&gt;
&lt;/o:OfficeDocumentSettings&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
&lt;w:WordDocument&gt;
&lt;w:Zoom&gt;0&lt;/w:Zoom&gt;
&lt;w:TrackMoves&gt;false&lt;/w:TrackMoves&gt;
&lt;w:TrackFormatting /&gt;
&lt;w:PunctuationKerning /&gt;
&lt;w:DrawingGridHorizontalSpacing&gt;18 pt&lt;/w:DrawingGridHorizontalSpacing&gt;
&lt;w:DrawingGridVerticalSpacing&gt;18 pt&lt;/w:DrawingGridVerticalSpacing&gt;
&lt;w:DisplayHorizontalDrawingGridEvery&gt;0&lt;/w:DisplayHorizontalDrawingGridEvery&gt;
&lt;w:DisplayVerticalDrawingGridEvery&gt;0&lt;/w:DisplayVerticalDrawingGridEvery&gt;
&lt;w:ValidateAgainstSchemas /&gt;
&lt;w:SaveIfXMLInvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;
&lt;w:IgnoreMixedContent&gt;false&lt;/w:IgnoreMixedContent&gt;
&lt;w:AlwaysShowPlaceholderText&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;
&lt;w:Compatibility&gt;
&lt;w:BreakWrappedTables /&gt;
&lt;w:DontGrowAutofit /&gt;
&lt;w:DontAutofitConstrainedTables /&gt;
&lt;w:DontVertAlignInTxbx /&gt;
&lt;/w:Compatibility&gt;
&lt;/w:WordDocument&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
&lt;w:LatentStyles DefLockedState="false" LatentStyleCount="276"&gt;
&lt;/w:LatentStyles&gt;
&lt;/xml&gt;&lt;![endif]--&gt; &lt;style type="text/css"&gt;
&lt;!--
 /* Font Definitions */
@font-face
	{font-family:Cambria;
	panose-1:2 4 5 3 5 4 6 3 2 4;
	mso-font-charset:0;
	mso-generic-font-family:auto;
	mso-font-pitch:variable;
	mso-font-signature:3 0 0 0 1 0;}
 /* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{mso-style-parent:"";
	margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:12.0pt;
	font-family:"Times New Roman";
	mso-ascii-font-family:Cambria;
	mso-ascii-theme-font:minor-latin;
	mso-fareast-font-family:Cambria;
	mso-fareast-theme-font:minor-latin;
	mso-hansi-font-family:Cambria;
	mso-hansi-theme-font:minor-latin;
	mso-bidi-font-family:"Times New Roman";
	mso-bidi-theme-font:minor-bidi;}
@page Section1
	{size:8.5in 11.0in;
	margin:1.0in 1.25in 1.0in 1.25in;
	mso-header-margin:.5in;
	mso-footer-margin:.5in;
	mso-paper-source:0;}
div.Section1
	{page:Section1;}
--&gt;
&lt;/style&gt; &lt;!--[if gte mso 10]&gt;
&lt;style&gt;
/* Style Definitions */
table.MsoNormalTable
{mso-style-name:"Table Normal";
mso-tstyle-rowband-size:0;
mso-tstyle-colband-size:0;
mso-style-noshow:yes;
mso-style-parent:"";
mso-padding-alt:0in 5.4pt 0in 5.4pt;
mso-para-margin:0in;
mso-para-margin-bottom:.0001pt;
mso-pagination:widow-orphan;
font-size:12.0pt;
font-family:"Times New Roman";
mso-ascii-font-family:Cambria;
mso-ascii-theme-font:minor-latin;
mso-fareast-font-family:"Times New Roman";
mso-fareast-theme-font:minor-fareast;
mso-hansi-font-family:Cambria;
mso-hansi-theme-font:minor-latin;}
&lt;/style&gt;
&lt;![endif]--&gt;  &lt;!--StartFragment--&gt;&lt;!--EndFragment--&gt;will always find non-compliance (large or small) somewhere, which will eliminate much of the benefit for trying anyways.            &lt;/meta&gt;
&lt;/meta&gt;
&lt;/meta&gt;
&lt;/meta&gt;
&lt;/meta&gt;
&lt;/meta&gt;
&lt;/p&gt;
&lt;p&gt;I think that solution providers will help bridge this gap and make compliance and security achievable and worth the cost and effort regardless of risk preference.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/braintree?a=n-FB4zbn30Y:Xnz7nvMcNhc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=n-FB4zbn30Y:Xnz7nvMcNhc:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=n-FB4zbn30Y:Xnz7nvMcNhc:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=n-FB4zbn30Y:Xnz7nvMcNhc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=n-FB4zbn30Y:Xnz7nvMcNhc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=n-FB4zbn30Y:Xnz7nvMcNhc:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=n-FB4zbn30Y:Xnz7nvMcNhc:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=n-FB4zbn30Y:Xnz7nvMcNhc:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/braintree/~4/n-FB4zbn30Y" height="1" width="1"/&gt;</description>
          <pubDate>Wed, 23 Sep 2009 19:50:00 GMT</pubDate>
          <guid isPermaLink="false">http://www.braintreepaymentsolutions.com/blog/PCI-Compliance-a-Check-Box-for-70-Percent-of-Retailers/</guid>
          <link>http://feedproxy.google.com/~r/braintree/~3/n-FB4zbn30Y/</link>
        <feedburner:origLink>http://www.braintreepaymentsolutions.com/blog/PCI-Compliance-a-Check-Box-for-70-Percent-of-Retailers/</feedburner:origLink></item>
        
    
        
        <item>
          <title>OpenTable</title>
          <description>&lt;p&gt;&lt;a href="http://braintreepaymentsolutions.com/assets/301/open-table.png?1249409949"&gt;&lt;img align="right" src="http://braintreepaymentsolutions.com/assets/301/open-table.png?1249409949" alt="" /&gt;&lt;/a&gt;We announced today that OpenTable selected us as their &lt;a href="http://www.braintreepaymentsolutions.com/why-braintree/press/Braintree-Selected-by-OpenTable-as-Global-PCI-Compliance-Solutions-Provider/"&gt;global PCI Compliance solutions&lt;/a&gt; partner.&amp;nbsp; Our solution helps OpenTable comply with PCI Compliance requirements and increases credit card data security.&amp;nbsp; The solution is currently being rolled out in the latest version of their Electronic Reservation Book that is used by 11,000 restaurants around the world.&lt;/p&gt;
&lt;p&gt;The OpenTable team has been great to work with and we couldn't be more excited about the partnership.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/braintree?a=HjMmRQXGoBM:ArkUGVQbJYA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=HjMmRQXGoBM:ArkUGVQbJYA:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=HjMmRQXGoBM:ArkUGVQbJYA:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=HjMmRQXGoBM:ArkUGVQbJYA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=HjMmRQXGoBM:ArkUGVQbJYA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=HjMmRQXGoBM:ArkUGVQbJYA:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=HjMmRQXGoBM:ArkUGVQbJYA:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=HjMmRQXGoBM:ArkUGVQbJYA:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/braintree/~4/HjMmRQXGoBM" height="1" width="1"/&gt;</description>
          <pubDate>Mon, 31 Aug 2009 12:48:00 GMT</pubDate>
          <guid isPermaLink="false">http://www.braintreepaymentsolutions.com/blog/OpenTable/</guid>
          <link>http://feedproxy.google.com/~r/braintree/~3/HjMmRQXGoBM/</link>
        <feedburner:origLink>http://www.braintreepaymentsolutions.com/blog/OpenTable/</feedburner:origLink></item>
        
    
        
        <item>
          <title>Post Heartland breach analysis and PCI Compliance limitations</title>
          <description>&lt;p&gt;Eric Ogren, writing for SearchSecurity.com and Evan Schuman and Fred Aun, from StorefrontBacktalk.com, have some insightful commentary regarding the tactics used by hackers to breach Heartland and how they relate to the limitations of the current PCI Compliance standard.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I think the key take away here is that compliance does not necessarily equal security. Here are a few highlights from their articles:&lt;/p&gt;
&lt;p&gt;&lt;a href="http://searchsecurity.techtarget.com/news/column/0,294698,sid14_gci1365304,00.html#"&gt;Eric Ogren&lt;/a&gt;&lt;br /&gt;
1. The hackers ran their malware through 20 AV products to test detection avoidance.&amp;nbsp; AV is very good at stopping known attacks of mass destruction, but is quite a bit less good about catching low profile designer attacks. Effective security should augment AV filters with technology that reflects control over the unique aspects of the organization's server and endpoint configurations. IT has choices here &amp;ndash; application whitelisting on locked-down servers will prevent execution of unauthorized software, thin clients prevent attacks from persisting at endpoints, virtual desktops and servers give IT control over endpoint configurations and automated patching systems close windows of vulnerabilities. &lt;b&gt;PCI should be more assertive in recognizing that signature-based schemes and reputation services will not catch low volume activity that is the trademark of malware designed to steal information. &lt;/b&gt;&lt;/p&gt;
&lt;p&gt;2. &lt;b&gt;It would be nice if PCI could have protected 7-Eleven and others from the same attack technique that befell TJX years earlier. &lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.storefrontbacktalk.com/securityfraud/gonzalez-the-al-capone-of-cyber-thieves/"&gt;Evan Schuman and Fred Aun&lt;/a&gt;&lt;br /&gt;
1. One retail security expert, who has firsthand knowledge of defending against these defendants and who agreed to discuss the indictment if neither her name nor employer was identified, said much in the indictment points out inherent weaknesses in PCI. The back door approach used, a time-honored hacking technique for decades, is a red flag. &amp;ldquo;Being on the inside, these probably would have passed right through firewalls as the data would be travelling in the &amp;rsquo;safe&amp;rsquo; direction. Also note that any gains a company would have from a password rotation scheme would be negated by the installation of a back door. &lt;b&gt;My main point there is that password rotation schemes are not an effective defense, and shouldn&amp;rsquo;t be elevated to such by PCI or corporate &amp;rsquo;security policies.&amp;rsquo;&lt;/b&gt; In any case, Hackers 2, PCI 0.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;2. The SQL injection tactic points out an especially significant PCI flaw, the expert said. &amp;ldquo;PCI doesn&amp;rsquo;t say boo about SQL injection attacks. It only says you must maintain secure systems and applications and review the applications annually. &lt;b&gt;But reviews are ineffective on unknown bugs &amp;ndash; they can only help recognize bugs the reviewer actually knows about&lt;/b&gt;.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;3. Another concern that she listed involved Heartland details. &amp;ldquo;The attackers installed sniffers to capture the traffic, they did not harvest data intentionally stored by Heartland on hard drives. &lt;b&gt;PCI doesn&amp;rsquo;t say anything about encrypting data on private networks, only that you must protect stored cardholder data or encrypt data traveling over open, public networks.&lt;/b&gt; And the networks obviously have the business need-to-know, that&amp;rsquo;s what they do: carry data. That&amp;rsquo;s a three-point shot for the Hackers; Hackers 6, PCI 0.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;4.&amp;nbsp; Yes, PCI compliance may have successfully defended Heartland against lesser attackers. But the bottom line is that Heartland could have been (and probably was) breached while being 100 percent PCI 1.1 compliant on all their points. &lt;b&gt;The real observation here is that PCI DSS compliance was completely ineffective against these guys, no matter how the PCI guys spin it.&lt;/b&gt;&lt;/p&gt;
&lt;div class="embed-ad"&gt;
&lt;div style="position: absolute; left: 0px; top: 0px; visibility: hidden;" id="beacon_e35e644fc6"&gt;&lt;img height="0" width="0" style="width: 0px; height: 0px;" alt="" src="http://storefrontbacktalk.com/openx/www/delivery/lg.php?bannerid=5&amp;amp;campaignid=4&amp;amp;zoneid=5&amp;amp;channel_ids=,&amp;amp;loc=http%3A%2F%2Fwww.storefrontbacktalk.com%2Fsecurityfraud%2Fgonzalez-the-al-capone-of-cyber-thieves%2F2%2F&amp;amp;cb=e35e644fc6" /&gt;&amp;ldquo;PCI says that you must regularly test security systems. These hackers dodged every bullet point of PCI. A test would (and probably did) prove nothing more than PCI-test-detectable breaches would have been detected. And finally, the hackers apparently didn&amp;rsquo;t feel compelled to comply with corporate security policies. Game, set, and match: Hackers 12, PCI 0,&amp;rdquo;&lt;/div&gt;
&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/braintree?a=i_NFY20pTO0:8r61GbXUNzQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=i_NFY20pTO0:8r61GbXUNzQ:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=i_NFY20pTO0:8r61GbXUNzQ:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=i_NFY20pTO0:8r61GbXUNzQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=i_NFY20pTO0:8r61GbXUNzQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=i_NFY20pTO0:8r61GbXUNzQ:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=i_NFY20pTO0:8r61GbXUNzQ:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=i_NFY20pTO0:8r61GbXUNzQ:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/braintree/~4/i_NFY20pTO0" height="1" width="1"/&gt;</description>
          <pubDate>Wed, 19 Aug 2009 19:19:00 GMT</pubDate>
          <guid isPermaLink="false">http://www.braintreepaymentsolutions.com/blog/Post-Heartland-breach-analysis-and-PCI-Compliance-limitations/</guid>
          <link>http://feedproxy.google.com/~r/braintree/~3/i_NFY20pTO0/</link>
        <feedburner:origLink>http://www.braintreepaymentsolutions.com/blog/Post-Heartland-breach-analysis-and-PCI-Compliance-limitations/</feedburner:origLink></item>
        
    
        
        <item>
          <title>PayPal reserves. Surprise!</title>
          <description>&lt;p&gt;I've wondered how PayPal seemingly signs up any merchant without doing any underwriting or risk assessment.  Well, now I think I have my answer. They do it &lt;a href="http://www.businessweek.com/smallbiz/running_small_business/archives/2009/08/paypals_reserve.html?chan=technology_technology+index+page_top+stories"&gt;after the fact&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;There is a lot of risk associated with providing credit card processing services to a business. If a merchant sells something that they can't deliver, don't deliver, partially deliver, deliver poorly, or that is defective in some way, and the business can't remedy the situation with their own financial resources, the credit card processor is on the hook for all the chargebacks and losses.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Merchant account providers can do a number of things to address these risks including a reserve requirement. Reserve requirements come in different shapes, sizes and flavors. Some are 6 month rolling reserves, some are fixed amounts, some require upfront money and others are collected as part of the processing volume.&lt;/p&gt;
&lt;p&gt;When cash flow management is one of the most important components of running a business, a reserve requirement is probably something better identified before, rather than after, the fact.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/braintree?a=bwLQ7eiqIDw:CvjlzRpefRk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=bwLQ7eiqIDw:CvjlzRpefRk:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=bwLQ7eiqIDw:CvjlzRpefRk:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=bwLQ7eiqIDw:CvjlzRpefRk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=bwLQ7eiqIDw:CvjlzRpefRk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=bwLQ7eiqIDw:CvjlzRpefRk:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=bwLQ7eiqIDw:CvjlzRpefRk:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=bwLQ7eiqIDw:CvjlzRpefRk:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/braintree/~4/bwLQ7eiqIDw" height="1" width="1"/&gt;</description>
          <pubDate>Thu, 13 Aug 2009 15:07:00 GMT</pubDate>
          <guid isPermaLink="false">http://www.braintreepaymentsolutions.com/blog/paypal-reserves-surprise/</guid>
          <link>http://feedproxy.google.com/~r/braintree/~3/bwLQ7eiqIDw/</link>
        <feedburner:origLink>http://www.braintreepaymentsolutions.com/blog/paypal-reserves-surprise/</feedburner:origLink></item>
        
    
        
        <item>
          <title>PayPal Adaptive Payments</title>
          <description>&lt;div class="comment_content"&gt;
&lt;p&gt;Following in the footsteps of Amazon's efforts in the payments space, PayPal announced a new service they're calling Adaptive Payments (TechCrunch has the &lt;a href="http://www.techcrunch.com/2009/07/06/paypal-looks-to-crush-amazons-fledgling-payment-service-with-a-new-secret-api/"&gt;new API posted&lt;/a&gt;).&amp;nbsp; It allows merchants/developers to become payment aggregators whereby they can accept and dynamically distribute payments among multiple parties. It's a great move by Paypal that leverages the network of users they've built over the past decade as well as their global payments capabilities, but there are some limitations. I think there are a few things to note.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Context&lt;/b&gt;&lt;br /&gt;
Paypal has overcome several limitations and or unappealing features of traditional payment methods (check and credit card - I'm excluding cash in this discussion) and payment channels (banks and wire transfer services). For example, for an individual to pay someone, instead of writing a check or sending a wire transfer, a Paypal user can easily send money to another Paypal user.&lt;/p&gt;
&lt;p&gt;Credit cards, which are used for a substantial percentage of all commerce in the U.S. and around the world, were built around a 1:1 relationship between cardholder and merchant. However, not user to user (though MasterCard just recently announced a transfer service using Obopay's platform). This is one structural limitation that has provided Paypal the opportunity to grow like it has.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Target Opportunity&lt;/b&gt;&lt;br /&gt;
Adaptive Payments solves a few key problem for merchants and developers: 1) global B2B, B2C and C2C money transfers. A U.S. business can accomplish the same payment flexibility as Paypal's new service by using electronic funds transfers (EFT) domestically, and not require that the recipient have a Paypal account. However, things get complex and there are several limitations when expanding outside of the U.S. 2) Paypal service eliminates the need for recipients to have a bank account and 3) dynamic, global and multi-party payment distribution.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Limitations&lt;/b&gt; &lt;b&gt;of Adaptive Payments&lt;/b&gt;&lt;br /&gt;
According to Paypal's API's, all payment participants are required to have a Paypal account: &amp;ldquo;The payment sender, receiver(s), and application owner must each have a PayPal account. Senders and receivers may have personal accounts; however, application owners must have business accounts.&amp;rdquo; The solution works for prearranged payment distribution relationships as the barrier to participate is setting up a new Paypal account beforehand.&lt;/p&gt;
&lt;p&gt;For realtime, non-prearranged payment situations, this solution has a serious drawback which could hinder it's adoption. Paypal has no choice but to maintain this requirement because payments have to stay on it's network. In other words, in some situations, its greatest strategic asset may also turn out to be its Achilles heel.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Network Effect&lt;/b&gt;&lt;br /&gt;
I think the big story in all of this is the following: the major card brands such as Visa, MasterCard, American Express and Discover have done an exceptional job over the years building a global network of cardholders and accepting merchants to facilitate commerce. It's now a global standard.&amp;nbsp; They have built substantial barriers to entry for others (look at Revolution Money who has raised around a $100 million to try and penetrate the U.S. market).&lt;br /&gt;
&lt;br /&gt;
Collectively, the internet, globalization, social networks, and mobile phones have been shifting the payments landscape and reducing these barriers.&amp;nbsp; It's the wave that Paypal and other innovators have been riding and has turned what was a potential threat and minor scratch for the card brands into an open wound.&lt;/p&gt;
&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/braintree?a=bc-SHO67sAU:iCJ5K_kPMmE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=bc-SHO67sAU:iCJ5K_kPMmE:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=bc-SHO67sAU:iCJ5K_kPMmE:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=bc-SHO67sAU:iCJ5K_kPMmE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=bc-SHO67sAU:iCJ5K_kPMmE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=bc-SHO67sAU:iCJ5K_kPMmE:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=bc-SHO67sAU:iCJ5K_kPMmE:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=bc-SHO67sAU:iCJ5K_kPMmE:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/braintree/~4/bc-SHO67sAU" height="1" width="1"/&gt;</description>
          <pubDate>Thu, 09 Jul 2009 02:02:00 GMT</pubDate>
          <guid isPermaLink="false">http://www.braintreepaymentsolutions.com/blog/PayPal-Adaptive-Payments/</guid>
          <link>http://feedproxy.google.com/~r/braintree/~3/bc-SHO67sAU/</link>
        <feedburner:origLink>http://www.braintreepaymentsolutions.com/blog/PayPal-Adaptive-Payments/</feedburner:origLink></item>
        
    
        
        <item>
          <title>PCI DSS Compliance basics for credit card data security</title>
          <description>&lt;p&gt;&lt;a href="http://www.braintreepaymentsolutions.com/pci-dss-compliance/"&gt;PCI DSS Compliance&lt;/a&gt; is an industry-mandated security standard that applies to all businesses that handle, process or store credit cards. &lt;br /&gt;
&lt;br /&gt;
There are 12 core requirements and roughly 250 controls, but as an oversimplification it boils down to three things: 1) all merchants, regardless if credit card data is stored, must achieve and maintain compliance at all times (all deadlines have passed); 2) merchants cannot store certain credit card information including &lt;a href="http://www.braintreepaymentsolutions.com/blog/merchants-are-prohibited-from-storing-cvv2-csc-per-pci-standards/"&gt;CVV2, CVC2 and CID codes&lt;/a&gt; (three or four-digit numbers), &lt;a href="http://www.braintreepaymentsolutions.com/blog/track-data-cannot-be-stored-according-to-pci-regulations/"&gt;track data&lt;/a&gt; from the magnetic strip or PIN data; 3) if permitted credit card information such as name, credit card number and expiration date is stored, certain security standards are required. A number of recent &lt;a href="http://www.braintreepaymentsolutions.com/blog/featured/pci-compliance-and-the-cost-of-a-credit-card-breach/"&gt;high profile breaches&lt;/a&gt; have been raising awareness and risks associated with PCI Compliance.  &lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;The motivation to become compliant &lt;/strong&gt; The major credit card companies have provided both carrots and sticks in order to compel merchants to become and maintain compliance. The incentives include &lt;a href="http://usa.visa.com/merchants/risk_management/cisp_overview.html"&gt;'safe harbor'&lt;/a&gt; from certain penalties and fines if a merchant is compliant &lt;em&gt;at&lt;/em&gt; the time of breach. &lt;br /&gt;
&lt;br /&gt;
Without compliance, if a merchant is breached and has credit card information stolen, depending on the size of the breach, PCI related fines can be as high as $500,000 per incident. In severe cases, merchants can even be given the 'Death Penalty,' preventing them from accepting credit cards. In all, depending on the number of cards stolen, merchants are estimated to spend between $90 and $302 &lt;em&gt;per record&lt;/em&gt; (see graph below).  &lt;strong&gt;&lt;br /&gt;
&lt;br /&gt;
The Payment Card Industry Data Security Standard (PCI DSS)&lt;/strong&gt; &lt;br /&gt;
&lt;strong&gt;&lt;br /&gt;
What is PCI DSS?&lt;/strong&gt; &lt;br /&gt;
It's a comprehensive security standard that establishes common processes and precautions for handling, processing, storing and transmitting credit card data.  &lt;strong&gt;&lt;br /&gt;
&lt;br /&gt;
Who created it?&lt;/strong&gt; While Visa and MasterCard originally developed it, as of September of 2006 American Express, Discover, JCB, MasterCard and Visa jointly formed the PCI Security Standards Council.  &lt;strong&gt;&lt;br /&gt;
&lt;br /&gt;
Why was it created?&lt;/strong&gt; It was created in response to a spike in data security breaches over the last few years. A large number of both small and large businesses have been breached including &lt;a href="http://www.braintreepaymentsolutions.com/blog/pci-compliance-and-the-cost-of-a-credit-card-breach/"&gt;TJX&lt;/a&gt;, Bank of America, Citigroup, BJ's Wholesale Club, Hotels.com, LexisNexis, Polo Ralph Lauren and Wachovia.  &lt;strong&gt;&lt;br /&gt;
&lt;br /&gt;
Who's at risk?&lt;/strong&gt; Any business that processes, transmits, or stores credit card information. While the publicity of security breaches has recently been focused on larger companies, Visa reports that the majority of breaches are &lt;a href="http://www.braintreepaymentsolutions.com/blog/pci-related-fines-for-breaches-at-small-businesses/"&gt;occurring at small businesses&lt;/a&gt;.&lt;/p&gt;
&lt;!--more--&gt;
&lt;p&gt;&lt;strong&gt;What are the 12 mandated security requirements?&lt;/strong&gt;  &lt;br /&gt;
1. Install and maintain a firewall configuration to protect data &lt;br /&gt;
2. Do not use vendor-supplied defaults for system passwords and other security parameters &lt;br /&gt;
3. Protect stored data &lt;br /&gt;
4. Encrypt transmission of cardholder data and sensitive information across public networks &lt;br /&gt;
5. Use and regularly update anti-virus software &lt;br /&gt;
6. Develop and maintain secure systems and applications &lt;br /&gt;
7. Restrict access to data by business need-to-know &lt;br /&gt;
8. Assign a unique ID to each person with computer access &lt;br /&gt;
9. Restrict physical access to cardholder data &lt;br /&gt;
10. Track and monitor all access to network resources and cardholder data &lt;br /&gt;
11. Regularly test security systems and processes &lt;br /&gt;
12. Maintain a policy that addresses information security&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;What credit card information can and cannot be stored? &lt;/strong&gt;&lt;/p&gt;
&lt;p style="text-align: center;"&gt;&lt;a title="storage-chart.jpg" href="http://www.braintreepaymentsolutions.com/blog/wp-content/uploads/2007/10/storage-chart.jpg"&gt;&lt;img src="http://www.braintreepaymentsolutions.com/blog/wp-content/uploads/2007/10/storage-chart.jpg" alt="storage-chart.jpg" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;How much does it cost to become compliant? &lt;/strong&gt;&lt;br /&gt;
It depends on business type, credit card processing and storage practices and existing IT environment. Read &lt;a href="http://www.braintreepaymentsolutions.com/blog/what-does-it-cost-to-become-pci-compliant/"&gt;here for a more complete overview.&lt;/a&gt;  &lt;strong&gt;&lt;br /&gt;
&lt;br /&gt;
What do merchants have at risk if credit card information is breached? &lt;/strong&gt;   Fines up to $500,000 per incident   Remediation costs estimated at $90 to $302 per record   Potential customer lawsuits   Company reputation and brand damage&lt;/p&gt;
&lt;p style="text-align: center;"&gt;&lt;a title="Cost of a credit card breach" href="http://www.braintreepaymentsolutions.com/blog/wp-content/uploads/2007/10/cost-of-a-credit-card-breach.png"&gt;&lt;img src="http://www.braintreepaymentsolutions.com/blog/wp-content/uploads/2007/10/cost-of-a-credit-card-breach.png" alt="Cost of a credit card breach" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Are their different requirements for large and small businesses? &lt;/strong&gt;  Yes. Merchants belong to one of four levels that is determined by annual transaction volumes. These transactions volumes apply to the highest number of a single card type per year, e.g. a merchant doing 5,000,000 Visa and 2,000,000 MasterCard transactions annually, even though cumulatively equal 7,000,000, would qualify as Level 2.&lt;/p&gt;
&lt;p style="text-align: center;"&gt;&lt;a title="PCI Levels" href="http://www.braintreepaymentsolutions.com/blog/wp-content/uploads/2007/10/pci-levels.jpg"&gt;&lt;img src="http://www.braintreepaymentsolutions.com/blog/wp-content/uploads/2007/10/pci-levels.jpg" alt="PCI Levels" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Definitions from above: &lt;/strong&gt;&lt;/p&gt;
&lt;blockquote&gt;&lt;strong&gt;On-Site Security Audit&lt;/strong&gt; The audit must be completed by Level 1 merchants. Merchants can choose to complete the audit internally or hire an outside Qualified Security Assessor to complete the Report on Compliance (ROC). &lt;a title="http://usa.visa.com/business/accepting_visa/ops_risk_management/cisp_tools_faq.html" href="http://usa.visa.com/business/accepting_visa/ops_risk_management/cisp_tools_faq.html" target="_blank"&gt;PCI Security Audit Procedures &amp;amp; Reporting&lt;/a&gt;&lt;/blockquote&gt; &lt;blockquote&gt;&lt;a href="http://www.braintreepaymentsolutions.com/blog/updated-pci-dss-self-assessment-questionnaire-saq-version-11/"&gt;&lt;strong&gt;Self-Assessment Questionnaire&lt;/strong&gt;&lt;/a&gt; (SAQ) Initially the Council had a one size fits all SAQ but it proved too challenging and complicated for the different types and sizes of merchants. In February 2008, the merchant released four versions of the SAQ in an attempt to better accommodate merchant profiles. Here is a summary:
&lt;ul type="disc"&gt;
    &lt;li&gt;&lt;a href="https://www.pcisecuritystandards.org/saq/instructions_v11.shtml"&gt;SAQ A&lt;/a&gt;: Addresses requirements applicable to merchants who have outsourced all processing, transmission and storage of cardholder data.&lt;/li&gt;
    &lt;li&gt;&lt;a href="https://www.pcisecuritystandards.org/saq/instructions_v11.shtml"&gt;SAQ B&lt;/a&gt;: Created to address requirements pertinent to merchants who process cardholder data via imprint machines or stand-alone dial-up terminals only.&lt;/li&gt;
    &lt;li&gt;&lt;a href="https://www.pcisecuritystandards.org/saq/instructions_v11.shtml"&gt;SAQ C&lt;/a&gt;: Constructed to focus on requirements applicable to merchants whose payment applications systems are connected to the Internet.&lt;/li&gt;
    &lt;li&gt;&lt;a href="https://www.pcisecuritystandards.org/saq/instructions_v11.shtml"&gt;SAQ D&lt;/a&gt;: Designed to address requirements relevant to all service providers defined by a payment brand as eligible to complete an SAQ and those merchants who do not fall under the types addressed by SAQ A, B or C.&lt;/li&gt;
&lt;/ul&gt;
&lt;a href="http://www.braintreepaymentsolutions.com/blog/vulnerability-and-security-assessment-scans-for-pci-dss-compliance/"&gt; &lt;strong&gt;Network Vulnerability Scans&lt;/strong&gt;&lt;/a&gt; The PCI Standard requires merchants to scan all outward facing IP addresses. These IP addresses are not protected by a firewall and can be hacked through an open port. The SAQ identifies and mitigates risk from the inside (behind the firewall) while the IP scans identify and mitigate risk from the outside.  &lt;strong&gt;Validation&lt;/strong&gt; &lt;strong&gt;Dates&lt;/strong&gt; The Card Associations have set specific dates for validation. Level 1 merchants were required to validate compliance by 9/30/2007, Level 2 by 12/31/07, and the Level 3 and 4 deadlines are processor/acquirer specific.&lt;/blockquote&gt;
&lt;p&gt;&lt;strong&gt;How to Get Started &lt;/strong&gt;&lt;br /&gt;
1. Identify the individuals that will be responsible for PCI compliance in your organization and assemble a team that includes members from each area. &lt;br /&gt;
2. Determine your merchant level (1-4). &lt;br /&gt;
3. Determine which &lt;a href="http://www.braintreepaymentsolutions.com/blog/updated-pci-dss-self-assessment-questionnaire-saq-version-11/"&gt;SAQ&lt;/a&gt; your organization will need to complete. &lt;br /&gt;
4. Evaluate whether your organization will try to achieve compliance internally or engage with a &lt;a href="http://www.braintreepaymentsolutions.com/blog/qualified-security-assessors-qsas-for-pci-dss-compliance/"&gt;Qualified Security Assessor (QSA)&lt;/a&gt;. &lt;br /&gt;
5. Engage with an &lt;a href="http://www.braintreepaymentsolutions.com/blog/vulnerability-and-security-assessment-scans-for-pci-dss-compliance/"&gt;Approved Scanning Vendor (ASV)&lt;/a&gt; to start the required external IP vulnerability scans. &lt;br /&gt;
6. Make sure that your organization has an Information Security Policy and that it is being enforced. &lt;br /&gt;
7. Immediately address any significant deficiencies discovered during the assessment or scan. &lt;br /&gt;
8. Retain record of self-assessments, scans, and follow-up activities. Be prepared to provide these documents upon request.  &lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;What should you do if breached?&lt;/strong&gt;  In the event of a security incident, merchants must take immediate action to: &lt;br /&gt;
1. Contain and limit the exposure. Conduct a thorough investigation of the suspected or confirmed loss or theft of account information within 24 hours of the compromise &lt;br /&gt;
2. Alert all necessary parties. Be sure to notify:  * Merchant Account Provider * Visa Fraud Control Group at (650) 432-2978 * Local FBI Office * U.S. Secret Service (if Visa payment data is compromised)  &lt;br /&gt;
3. Provide the compromised Visa accounts to Visa Fraud Control Group within 24 hours. &lt;br /&gt;
4. Within four business days of the reported compromise, provide Visa with an incident report.  &lt;br /&gt;
&lt;br /&gt;
Here is a step-by-step guide from Visa - &lt;em&gt;&lt;a title="http://www.usa.visa.com/business/accepting_visa/ops_risk_management/cisp_if_compromised.html?it=c|/business/accepting_visa/ops_risk_management/cisp%2Ehtml|If%20Compromised" href="http://www.usa.visa.com/business/accepting_visa/ops_risk_management/cisp_if_compromised.html?it=c%7C/business/accepting_visa/ops_risk_management/cisp%2Ehtml%7CIf%20Compromised" target="_blank"&gt;What To Do If Compromised&lt;/a&gt;&lt;/em&gt;.  &lt;br /&gt;
&lt;br /&gt;
Additional resources: A non-profit organization, RSPA produced a 12-minute video aimed at educating smaller restaurant and retail merchants about the &lt;a href="http://www.braintreepaymentsolutions.com/blog/what-small-businesses-need-to-know-about-pci-compliance/"&gt;risks associated with PCI Compliance&lt;/a&gt;.  &lt;br /&gt;
&lt;br /&gt;
Other related posts:   &lt;a href="http://www.braintreepaymentsolutions.com/blog/pci-compliance-and-the-cost-of-a-credit-card-breach/"&gt;&lt;br /&gt;
PCI DSS Compliance&lt;/a&gt; and the cost of a credit card breach   &lt;br /&gt;
PCI DSS Payment Card Industry &lt;a href="http://www.braintreepaymentsolutions.com/blog/pci-dss-payment-card-industry-self-assessment-questionnaire-saq/"&gt;Self-Assessment Questionnaire&lt;/a&gt; (SAQ)   &lt;a href="http://www.braintreepaymentsolutions.com/blog/vulnerability-and-security-assessment-scans-for-pci-dss-compliance/"&gt;&lt;br /&gt;
Vulnerability and security assessment scans&lt;/a&gt; for PCI DSS Compliance    &lt;br /&gt;
&lt;br /&gt;
Braintree solutions: The Smart Approach to &lt;a href="http://www.braintreepaymentsolutions.com/pci-compliance.php"&gt;PCI DSS Compliance&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/braintree?a=7Qm-VtZ2nRY:xpUqkn9GHmw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=7Qm-VtZ2nRY:xpUqkn9GHmw:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=7Qm-VtZ2nRY:xpUqkn9GHmw:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=7Qm-VtZ2nRY:xpUqkn9GHmw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=7Qm-VtZ2nRY:xpUqkn9GHmw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=7Qm-VtZ2nRY:xpUqkn9GHmw:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=7Qm-VtZ2nRY:xpUqkn9GHmw:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=7Qm-VtZ2nRY:xpUqkn9GHmw:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/braintree/~4/7Qm-VtZ2nRY" height="1" width="1"/&gt;</description>
          <pubDate>Tue, 07 Jul 2009 14:52:00 GMT</pubDate>
          <guid isPermaLink="false">http://www.braintreepaymentsolutions.com/blog/pci-compliance-basics-for-credit-card-secuirty/</guid>
          <link>http://feedproxy.google.com/~r/braintree/~3/7Qm-VtZ2nRY/</link>
        <feedburner:origLink>http://www.braintreepaymentsolutions.com/blog/pci-compliance-basics-for-credit-card-secuirty/</feedburner:origLink></item>
        
    
        
        <item>
          <title>Where do credit card fees come from?</title>
          <description>&lt;p&gt;&lt;a title="Visa &amp;amp; MasterCard" href="http://www.braintreepaymentsolutions.com/blog/wp-content/uploads/2007/12/visa-mastercard.jpg"&gt;&lt;img class="alignRight" src="http://www.braintreepaymentsolutions.com/blog/wp-content/uploads/2007/12/visa-mastercard.jpg" alt="" /&gt;&lt;/a&gt;It is known by some, but not all, that businesses pay fees in order to accept credit cards as a form of payment. In fact, over 7 million merchants in the U.S. accept credit cards. During 2007 they collectively paid over 30 billion in credit card acceptance fees.&lt;/p&gt;


	&lt;p&gt;Despite the size of the industry, its a mystery to most who is pocketing all this money and how prices are determined and reported.  I had a &lt;span class="caps"&gt;CPA&lt;/span&gt; tell me the other day, &amp;#8220;I&amp;#8217;m a smart guy. I understand numbers, pricing and reconciliation, but for whatever reason I just cannot get my head around credit card processing fees and the unbelievably complicated way companies report them.&amp;#8221; He&amp;#8217;s not alone.  Hopefully this article will clear up some of that confusion as I provide some context about where credit card fees come from, who&amp;#8217;s making the money, and how fees and rates are determined.&lt;/p&gt;


	&lt;p&gt;&lt;strong&gt;Issuing Financial Institutions make roughly 85% of all credit and debit card processing fees&lt;/strong&gt;
The financial institutions that issue credit and debit cards are the biggest benefactors.  Some financial institutions such as banks co-issue debit and credit cards with Visa and or MasterCard while others such as American Express and Discover issue them directly (though now after years of litigation,  some banks are now issuing American Express to cardholders).   Before Visa and MasterCard went public, they were associations primarily owned by the issuing financial institutions. Collectively Visa and MasterCard own roughly 75% of the credit cards in the market.&lt;/p&gt;


	&lt;p&gt;These issuing financial institutions make money every time a card they issued is used to purchase something. For example, let&amp;#8217;s assume that a business is paying an effective rate of 3.5% to accept credit cards (that 3.5% is usually comprised of a discount rate and a per transaction fee but I just used a flat rate for simplification purposes). Roughly 85% of that 3.5% is going to the issuing bank. The remaining 15% is divided among Visa or MasterCard, the credit card processor, and if there is one, the Independent Sales Organization (ISO).&lt;/p&gt;


	&lt;p&gt;&lt;strong&gt;How do financial institutions justify their fees?&lt;/strong&gt;
Credit card usage has seen explosive growth in the past 20 years for a number of reasons.  Benefits of using plastic include 15 to 45 days to pay original purchases, rewards, a line of credit for extra spending power, fraud protection, a monthly accounting of all purchases and general convenience.  The use of Purchase Cards by Corporations or the government (GSA) has also been growing rapidly to lower the cost and to streamline Accounts Receivable and Payables.&lt;/p&gt;


	&lt;p&gt;An example of some of the costs these financial institutions incur providing and maintaining card holders include fraud, bad debt, customer support, rewards and other perks, and float (they pay for your purchases before you pay them). Usage rewards alone account for roughly 40% of the fees they generate and end up back in the pockets of cardholders. They fiercely compete for new cardholders primarily on their rewards programs.&lt;/p&gt;


	&lt;p&gt;Continuing our example from above, if you buy movie tickets for $20 and the movie theater is paying 3.5%, the financial institution that issued that credit card would make $0.60 ($20&amp;#215;3.5% = $0.70, x 85% equals $0.60). Visa and MasterCard add their respective fees of .0925% and .0950% on top of what the banks charge (Note: that&amp;#8217;s 9.25 and 9.50 basis points. 100 basis points equals 1%).  Adding the fees from the bank and Visa or MasterCard together form what is called &amp;#8216;interchange&amp;#8217;.&lt;/p&gt;


	&lt;p&gt;You now understand why you find a credit card offer in your mailbox everyday. Outside of the 18% interest rates, annual fees, and late fees, being a card issuer is a lucrative business! The issuing institutions are making money on both the front and back end.&lt;/p&gt;


	&lt;p&gt;&lt;strong&gt;That seems simple enough, why does everyone say it&amp;#8217;s so complex?&lt;/strong&gt;
From a high level, the rate structure seems pretty simple, but it gets messy fast once we get into the details. There are over 100 different interchange &amp;#8216;rates&amp;#8217; or &amp;#8216;categories&amp;#8217;. The particular rate that is charged on any given transaction depends on a number of variables, including:&lt;/p&gt;


	&lt;p&gt;1) The type of card that is used in the transaction i.e. debit, credit, rewards, or business card, international, etc.
2) Where the card is used i.e. restaurant, retail, gas, business to business, ecommerce, etc.
3) The method of usage i.e. swiped, over the phone, or via ecommerce.
4) What information the business captures during the transaction i.e. name, address, tax ID, tax amount, unit description, etc. (the information required is a whole other layer of complexity).
5) When the transaction is submitted to the processor for settlement and funds transfer after the initial authorization.&lt;/p&gt;


	&lt;p&gt;As you can see, it&amp;#8217;s a very complicated matrix. Very few people, including those who&amp;#8217;ve been in the industry for years, really understand interchange.&lt;/p&gt;


	&lt;p&gt;&lt;strong&gt;Qualifying for different rate categories and getting hit with downgrades &lt;/strong&gt;
Merchants can often do more than they think to better manage the credit card fees they pay.   For example, transactions can be &amp;#8216;downgraded&amp;#8217; (penalized) when they don&amp;#8217;t meet interchange requirements.  Example reasons for downgrades include not capturing the correct information when processing (such as billing zip), settling the transaction after a certain period of time, not swiping the transaction and many more. Learning how to recognize these penalties and then making the appropriate adjustments can help you lower the fees that are paid.&lt;/p&gt;


	&lt;p&gt;One downgrade example is if an a restaurant employee hand keys a credit card number into the point of sale system because the magnetic strip can&amp;#8217;t be read, the transaction falls into a different and higher rate category . The transaction is penalized because &amp;#8216;non swiped&amp;#8217; transactions carry more risk and therefore higher interchange fees. The increase in rate can be significant ranging from 30 basis points to 2%, or more depending on how the service provider has the account priced.&lt;/p&gt;


	&lt;p&gt;Different rate categories and downgrades are the dirty little secret for merchant service providers. It&amp;#8217;s where they make most of their margin because they offer artificially low rates and don&amp;#8217;t disclose higher market ups on transactions that don&amp;#8217;t fall into a specific rate category. Too many merchants fall for this and think they&amp;#8217;re paying the single, highly competitive rate that was advertised.&lt;/p&gt;


	&lt;p&gt;A quick search of merchant service providers will demonstrate that non disclosure of fees is a standard practice.  &lt;a href="http://www.braintreepaymentsolutions.com/blog/rule-breakers-in-the-credit-card-processing-industry/"&gt;See two examples here.&lt;/a&gt;&lt;/p&gt;


	&lt;p&gt;&lt;strong&gt;The undecipherable monthly credit card statement&lt;/strong&gt;
As icing on the cake, the unreadable format most merchant service providers use to present this information to you on a monthly basis doesn&amp;#8217;t help. Of course, the format used is not because they have no other option, it&amp;#8217;s because that&amp;#8217;s what makes them the most amount of money.&lt;/p&gt;


	&lt;p&gt;&lt;strong&gt;The frustration with credit card fees&lt;/strong&gt;
Some merchants accept credit cards because they find them to be a easier and more efficient method of accepting money from customers.  Most merchants however accept them because they have no other choice. Many merchants and advocacy groups have cried foul lately with Visa and MasterCard increasing &amp;#8216;interchange&amp;#8217; fees over 117% in the past five years while maintaining over 75% market share. The Card Associations have been accused of being monopolistic.&lt;/p&gt;


	&lt;p&gt;&lt;strong&gt;Interchange has come under increased pressure lately&lt;/strong&gt;
A few years ago, Wal-Mart won a class action lawsuit against Visa and MasterCard. They claimed that debit card interchange was being improperly priced because it had the same interchange rate as credit cards. Among other things, they argued that debit cards should be have a lower interchange rate because money comes directly out of the cardholders account versus a credit card where there is 15 to 45 days between purchase and payment. The courts agreed and awarded Wal-Mart and other retailers billions of dollars in compensatory damages.   There are currently a number of other legal battles against the Card Associations surrounding interchange.&lt;/p&gt;


	&lt;p&gt;&lt;strong&gt;
&lt;/strong&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/braintree?a=3xYw4DUlFWg:Ihr_HkOtSPk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=3xYw4DUlFWg:Ihr_HkOtSPk:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=3xYw4DUlFWg:Ihr_HkOtSPk:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=3xYw4DUlFWg:Ihr_HkOtSPk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=3xYw4DUlFWg:Ihr_HkOtSPk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=3xYw4DUlFWg:Ihr_HkOtSPk:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=3xYw4DUlFWg:Ihr_HkOtSPk:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=3xYw4DUlFWg:Ihr_HkOtSPk:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/braintree/~4/3xYw4DUlFWg" height="1" width="1"/&gt;</description>
          <pubDate>Fri, 12 Jun 2009 07:00:00 GMT</pubDate>
          <guid isPermaLink="false">http://www.braintreepaymentsolutions.com/blog/where-do-credit-card-fees-come-from-cc/</guid>
          <link>http://feedproxy.google.com/~r/braintree/~3/3xYw4DUlFWg/</link>
        <feedburner:origLink>http://www.braintreepaymentsolutions.com/blog/where-do-credit-card-fees-come-from-cc/</feedburner:origLink></item>
        
    
        
        <item>
          <title>Account Verification with a Zero Dollar Value authorization request</title>
          <description>&lt;p&gt;&lt;a href="braintreepaymentsolutions.com/assets/167/Visa_logo.gif"&gt;&lt;img align="right" src="http://www.braintreepaymentsolutions.com/assets/167/Visa_logo.gif" alt="" /&gt;&lt;/a&gt;We've been getting a lot of questions about Visa's new Account Verification service. Hopefully this will help clear things up a little.&lt;/p&gt;
&lt;p&gt;For years, card not present merchants (ecommerce, phone, fax, mail) have needed to verify a cardholder's information upon acceptance when there was a delay between collecting the credit card data and actually charging the card.&amp;nbsp; For example, a merchant may collect the credit card information during the initial sign up process but offer a 30 day trial period before charging the card. In this situation, it's in the best interest of the merchant to verify the cardholder's information including the credit card number, expiration date, address and CVV value for accuracy and legitimacy. The only way of doing this today is by doing a $1.00 authorization (Visa refers to these as Ghost Authorizations). &amp;nbsp; While the authorization does eventually expire, some banks will show the pending $1.00 authorization which leads to merchants inevitably getting support questions regarding an improper charge.&lt;/p&gt;
&lt;p&gt;Visa's new Account Verification program is an alternative to the $1.00 authorization. With this program, a merchant will be able to do a Zero Dollar Value authorization request which can include Address Verification (AVS) and CVV verification. MasterCard has as similar verification process for card not present recurring billing merchants with a $1.00 'test transaction'. Visa is charging for this service but MasterCard is not.&lt;/p&gt;
&lt;p&gt;Interestingly, according to Visa, the problem that merchants have was not the primary driver behind creating the Account Verification program. Visa is trying to eliminate $1.00 authorization request because it has a negative impact on cardholder spending.&amp;nbsp; For those us who live in the space and deal with the shortcomings and problems caused by the $1.00 auth, we're pleased with the creation of the Account Verification product whether we (merchants and service providers) were considered or not.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Related posts:&lt;br /&gt;
&lt;a href="http://www.braintreepaymentsolutions.com/blog/Visa-misuse-of-authorization/"&gt;Visa Misuse of Authorization&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/braintree?a=dNX-v9uzOAc:69fC47D-xug:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=dNX-v9uzOAc:69fC47D-xug:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=dNX-v9uzOAc:69fC47D-xug:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=dNX-v9uzOAc:69fC47D-xug:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=dNX-v9uzOAc:69fC47D-xug:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=dNX-v9uzOAc:69fC47D-xug:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=dNX-v9uzOAc:69fC47D-xug:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=dNX-v9uzOAc:69fC47D-xug:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/braintree/~4/dNX-v9uzOAc" height="1" width="1"/&gt;</description>
          <pubDate>Tue, 09 Jun 2009 14:55:00 GMT</pubDate>
          <guid isPermaLink="false">http://www.braintreepaymentsolutions.com/blog/Account-Verification-with-a-Zero-Dollar-Value-authorization-request/</guid>
          <link>http://feedproxy.google.com/~r/braintree/~3/dNX-v9uzOAc/</link>
        <feedburner:origLink>http://www.braintreepaymentsolutions.com/blog/Account-Verification-with-a-Zero-Dollar-Value-authorization-request/</feedburner:origLink></item>
        
    
        
        <item>
          <title>Visa Acquirer Processing Fee (APF) and MasterCard Network Access Brand Usage Fee (NABU)</title>
          <description>&lt;p&gt;Increasing fees for existing users of a product or service is never an easy thing. While there is rarely a perfect time to raise prices, there certainly are some times that are better than others.&amp;nbsp; In the midst of some of the most intense dialogs that have taken place over credit card interchange, the fees that merchants pay the issuing banks to accept credit cards, Visa and MasterCard have announced one of the largest fee increases in years.&amp;nbsp; The timing of their fee increase could possibly be written up in a case study as an example of what not to do.&lt;br /&gt;
&lt;br /&gt;
Starting on July 1, 2009, Visa is introducing a U.S. Acquirer Processing Fee (APF). The fee will be $0.0195 on all Visa branded authorizations acquired in the U.S. regardless of where the issuer/cardholder is located. On April 18, 2009, MasterCard implemented a new Network Access and Brand Usage (NABU). Fee of $0.0185 for all U.S. based sales and credit/refund transactions.&lt;br /&gt;
&lt;br /&gt;
For merchants that have a larger average ticket of $150, the Visa fee increase is pretty insignificant and amounts to 1 basis point (100 basis points = 1%). For a lower average ticket of $15, it amounts to a more significant 13 basis point increase. &lt;br /&gt;
&lt;br /&gt;
The timing of the fee increase, while bad, may have been strategic in the wake of all the congressional activity surrounding the credit card reform that passed last month. I'm speculating, but I wonder if both Visa and MasterCard, facing some legislative risk, were trying to re-anchor the pricing discussion at a higher starting point in case congressional mood were to turn in favor of the groups lobbying for action. Alternatively, the fee increase could have had nothing to do with this 'chatter' and was fueled by that fact that both are now a public companies and need to take care of their shareholders and stock prices.&lt;/p&gt;
&lt;p&gt;I spoke to a Visa representative recently at an industry conference and asked about the fee. I was told that they were increasing the price to more fairly align value created and price. Even if that is the case, and it's quantitatively supported, they need to do a better job selling these measurements with everyone actively engaged in the interchange pricing debate.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/braintree?a=WPfg9DwZ8_Y:NpXQpEYv8c0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=WPfg9DwZ8_Y:NpXQpEYv8c0:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=WPfg9DwZ8_Y:NpXQpEYv8c0:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=WPfg9DwZ8_Y:NpXQpEYv8c0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=WPfg9DwZ8_Y:NpXQpEYv8c0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=WPfg9DwZ8_Y:NpXQpEYv8c0:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=WPfg9DwZ8_Y:NpXQpEYv8c0:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=WPfg9DwZ8_Y:NpXQpEYv8c0:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/braintree/~4/WPfg9DwZ8_Y" height="1" width="1"/&gt;</description>
          <pubDate>Mon, 08 Jun 2009 20:32:00 GMT</pubDate>
          <guid isPermaLink="false">http://www.braintreepaymentsolutions.com/blog/Visa-Acquirer-Processing-Fee-APF-and-MasterCard-Network-Access-Brand-Usage-Fee-NABU/</guid>
          <link>http://feedproxy.google.com/~r/braintree/~3/WPfg9DwZ8_Y/</link>
        <feedburner:origLink>http://www.braintreepaymentsolutions.com/blog/Visa-Acquirer-Processing-Fee-APF-and-MasterCard-Network-Access-Brand-Usage-Fee-NABU/</feedburner:origLink></item>
        
    
        
        <item>
          <title>Visa Misuse of Authorization</title>
          <description>&lt;p&gt;&lt;a href="http://braintreepaymentsolutions.com/assets/167/Visa_logo.gif"&gt;&lt;img align="right" src="http://braintreepaymentsolutions.com/assets/167/Visa_logo.gif?1231134548" alt="" /&gt;&lt;/a&gt;Starting October 1, 2009, Visa will start assessing a 'misuse' fee for authorizations that are not either settled or reversed within certain timeframes. Visa refers to these as 'ghost authorizations'.&lt;/p&gt;
&lt;p&gt;In the past, merchants frequently performed a $1.00 authorization only (without settlement) for verification and to retreive address verification (AVS) and CVV match or mismatch information. Visa explains that they're trying to reduce ghost authorizations because they restrict a cardholders ability to buy and increases declines.&lt;/p&gt;
&lt;p&gt;Here is what merchants will need to do in order to comply with the new processing guideline and avoid the misuse fee. Card present authorizations must be reversed within 24 hours that have been submitted in error and/or cardholder cancelled.&amp;nbsp; For card not present transactions, full or partial authorization reversals must be processed within 72 hours.&amp;nbsp; Settlement must occur within 10 days of authorization for all merchants except Travel and Entertainment segments, which must clear within 20 days of authorization regardless of transaction date.&lt;/p&gt;
&lt;p&gt;Visa has stated that they will be monitoring ghost authorizations and reversal levels to prevent abuse of the system and even levying fines in excessive cases. They've not revealed any thresholds or fine potential details.&lt;/p&gt;
&lt;p&gt;As an alternative method to verify cardholder data, Visa has introduced Account Verification which will allow for a Zero Dollar Value authorization request and can include AVS and CVV data. MasterCard has as similar verification process for card not present recurring billing merchants with a $1.00 'test transaction'. Visa is charging for this service but MasterCard is not.&lt;/p&gt;
&lt;p&gt;Yet obstacles remain with the implementation of these new changes. Many of the larger processors do not support authorization reversals and some don't have an ETA yet on supporting Visa or MasterCard's Account Verification services.&amp;nbsp; Many of the the Visa and MasterCard issuers (financial institutions that issue the debit/credit cards) are not able to support these services today. Visa has mandated compliance from all their issuers and MasterCard is expected to follow.&lt;/p&gt;
&lt;p&gt;Related blog posts:&lt;br /&gt;
&lt;a href="http://www.braintreepaymentsolutions.com/blog/Account-Verification-with-a-Zero-Dollar-Value-authorization-request/"&gt;Account Verification with a Zero Dollar authorization request&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/braintree?a=gRDe0xA8dd4:tUxgNWWh3EU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=gRDe0xA8dd4:tUxgNWWh3EU:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=gRDe0xA8dd4:tUxgNWWh3EU:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=gRDe0xA8dd4:tUxgNWWh3EU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=gRDe0xA8dd4:tUxgNWWh3EU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=gRDe0xA8dd4:tUxgNWWh3EU:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=gRDe0xA8dd4:tUxgNWWh3EU:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=gRDe0xA8dd4:tUxgNWWh3EU:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/braintree/~4/gRDe0xA8dd4" height="1" width="1"/&gt;</description>
          <pubDate>Mon, 18 May 2009 14:47:00 GMT</pubDate>
          <guid isPermaLink="false">http://www.braintreepaymentsolutions.com/blog/Visa-misuse-of-authorization/</guid>
          <link>http://feedproxy.google.com/~r/braintree/~3/gRDe0xA8dd4/</link>
        <feedburner:origLink>http://www.braintreepaymentsolutions.com/blog/Visa-misuse-of-authorization/</feedburner:origLink></item>
        
    
        
        <item>
          <title>Why do merchant account providers ask for a personal guaranty? </title>
          <description>&lt;p&gt;Nearly all &lt;a href="http://www.braintreepaymentsolutions.com/payment-processing/merchant-account/"&gt;merchant account providers&lt;/a&gt; will require that a personal &lt;span id=":8wu" dir="ltr"&gt;guaranty&lt;/span&gt; be signed by the owner(s) before approving an account for &lt;a href="http://www.braintreepaymentsolutions.com/payment-processing/merchant-account/"&gt;credit card acceptance&lt;/a&gt;. Some owners are justifiably reluctant to sign a personal &lt;span id=":8wu" dir="ltr"&gt;guaranty&lt;/span&gt;. After all, that's one of the main reasons a legal entity was set up in the first place: to protect individuals in the organization from being subject to the company's liabilities. Most providers will waive the requirement if a) the company is public, or b) the organization is a registered 501c3 or 501c4, or c) the company's financials are adequate to satisfy the underwriters' concern about the underlying risk.&lt;br /&gt;
&lt;br /&gt;
So where is the risk? Basically, a &lt;a href="http://www.braintreepaymentsolutions.com/payment-processing/merchant-account/"&gt;merchant account provider&lt;/a&gt; is at risk for every dollar that passes through the &lt;a href="http://www.braintreepaymentsolutions.com/payment-processing/merchant-account/"&gt;merchant account&lt;/a&gt; during a 6 month period. Here is a risk scenario:&lt;br /&gt;
&lt;br /&gt;
Widget Company comes out with a new electronic gadget for $30.00.&amp;nbsp; During their first month, sales are over $100,000 and everyone in the company is ecstatic.&amp;nbsp; To try and build upon the momentum, Widget Company decides to spend all their cash on an AdWords campaign.&amp;nbsp; Ten days later, Widget finds out that all the gadgets they sold have a bug and need to be replaced. Widget doesn't have the cash to replace them so they tell customers that they are sorry, they won't be able to honor the 90 warranty that was included.&amp;nbsp; The cardholders who bought those gadgets are going to be unhappy with the response and will call their bank to initiate a chargeback (a formal dispute process). The &lt;a href="http://www.braintreepaymentsolutions.com/payment-processing/merchant-account/"&gt;merchant account provider&lt;/a&gt; will in turn attempt to debit Widget's bank account for the amount being disputed to cover their loss but their are insufficient funds at that point. At that point, the &lt;a href="http://www.braintreepaymentsolutions.com/payment-processing/merchant-account/"&gt;merchant account provider&lt;/a&gt; is financially responsible to refund all those customers who bought the gadget and filed a dispute with their bank.&lt;br /&gt;
&lt;br /&gt;
Merchant account face this risk with every product or service sold including services, software, memberships, consulting and anything else that is purchsed with a credit card.&amp;nbsp; Therefore, when a merchant account underwriter reviews an account, they try to calculate the risk associated with the account. Their risk analysis will include the merchants projected sales, the product or service being sold, company history, company financials and owner(s) credit. The exposure window for credit card transacions is six months (or up to 18 months in special circumstances), which is how long a cardholder technically has to dispute a charge (chargeback). This is also why &lt;a href="http://www.braintreepaymentsolutions.com/blog/annual-credit-card-billing-subscriptions/"&gt;annual billing&lt;/a&gt; and lifetime memberships present underwriting and risk challenges. &lt;br /&gt;
&lt;br /&gt;
The example above is an honest mistake.&amp;nbsp; But &lt;a href="http://www.braintreepaymentsolutions.com/payment-processing/merchant-account/"&gt;merchant account providers&lt;/a&gt; are also cognizant of classic merchant account fraud: set up a &lt;a href="http://www.braintreepaymentsolutions.com/payment-processing/merchant-account/"&gt;merchant account&lt;/a&gt;, sell a bunch of goods or services, receive the money within 48 hours and then pack it up and skip town without delivering the items or services that were sold. Without a personal &lt;span id=":8wu" dir="ltr"&gt;guaranty&lt;/span&gt;, the business can declare bankruptcy and the owners would be shielded from any consequence. In this scenario, the personal &lt;span id=":8wu" dir="ltr"&gt;guaranty&lt;/span&gt; is primarily used as a deterrent to prevent bad behavior.&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
Merchants can always ask for exceptions and underwriters may or may not provide them. There are alternative arrangments that underwriters will ocassionally propose in place of a personal guaranty such as a rolling reserve or a fixed amount up front.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/braintree?a=NAgbBD9hkIE:69Q4GpGbQoA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=NAgbBD9hkIE:69Q4GpGbQoA:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=NAgbBD9hkIE:69Q4GpGbQoA:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=NAgbBD9hkIE:69Q4GpGbQoA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=NAgbBD9hkIE:69Q4GpGbQoA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=NAgbBD9hkIE:69Q4GpGbQoA:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=NAgbBD9hkIE:69Q4GpGbQoA:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=NAgbBD9hkIE:69Q4GpGbQoA:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/braintree/~4/NAgbBD9hkIE" height="1" width="1"/&gt;</description>
          <pubDate>Tue, 03 Feb 2009 21:32:00 GMT</pubDate>
          <guid isPermaLink="false">http://www.braintreepaymentsolutions.com/blog/Why-do-merchant-account-providers-ask-for-a-personal-guaranty/</guid>
          <link>http://feedproxy.google.com/~r/braintree/~3/NAgbBD9hkIE/</link>
        <feedburner:origLink>http://www.braintreepaymentsolutions.com/blog/Why-do-merchant-account-providers-ask-for-a-personal-guaranty/</feedburner:origLink></item>
        
    
        
        <item>
          <title>Cost of Data Breach up 2.7% </title>
          <description>&lt;p&gt;The &lt;a target="_blank" href="http://online.wsj.com/article/SB123354707064638461.html?mod=todays_us_marketplace"&gt;WSJ reports&lt;/a&gt; that a new Ponemon Institute found that the cost of a breach was up 2.7% during 2008 to $202 per compromised record. The average expense to an organization was $6.6 million in direct and indirect costs, which includes the cost of notifying victims and maintaining information hot lines as well as legal, investigative and administrative expenses.&lt;/p&gt;
&lt;p&gt;Report Highlights:&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;Industries with the highest number of breaches: Health care and financial services&lt;/li&gt;
    &lt;li&gt;Most common causes of breaches: negligence, third-party providers, and portable devices including laptops&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The survey examined costs incurred by 43 organizations in 17 industries after a data breach and included breaches of between 4,200 records and more than 113,000.&amp;nbsp;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/braintree?a=dcQsPEM6x1o:OPtYK9K8wJI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=dcQsPEM6x1o:OPtYK9K8wJI:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=dcQsPEM6x1o:OPtYK9K8wJI:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=dcQsPEM6x1o:OPtYK9K8wJI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=dcQsPEM6x1o:OPtYK9K8wJI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=dcQsPEM6x1o:OPtYK9K8wJI:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=dcQsPEM6x1o:OPtYK9K8wJI:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=dcQsPEM6x1o:OPtYK9K8wJI:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/braintree/~4/dcQsPEM6x1o" height="1" width="1"/&gt;</description>
          <pubDate>Mon, 02 Feb 2009 15:37:00 GMT</pubDate>
          <guid isPermaLink="false">http://www.braintreepaymentsolutions.com/blog/Cost-of-Data-Breach-up-2.7/</guid>
          <link>http://feedproxy.google.com/~r/braintree/~3/dcQsPEM6x1o/</link>
        <feedburner:origLink>http://www.braintreepaymentsolutions.com/blog/Cost-of-Data-Breach-up-2.7/</feedburner:origLink></item>
        
    
        
        <item>
          <title>Data Breaches up in 2008</title>
          <description>&lt;p&gt;A report out this week by the &lt;a href="http://www.idtheftcenter.org/artman2/publish/lib_survey/ITRC_2008_Breach_List.shtml"&gt;Identity Theft Resource Center&lt;/a&gt; claimed the &lt;i&gt;reported&lt;/i&gt; data breaches were up by 47% duing 2008, reaching 656. Some interesting highlights (NOTE: this is not only credit card data): &lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;Only 2.4% of breaches had encryption or other strong protection in use&lt;/li&gt;
    &lt;li&gt;Only 8.5% had password protection&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;About their method:&lt;/p&gt;
&lt;p&gt;The ITRC tracks five categories of data loss methods: data on the move, accidental exposure, insider theft, subcontractors, and hacking. Subcontractor breaches, whild counted as one breach each, in some cases affected dozens of companies. The number of breaches does not affect the number of companies affected. ITRC uses media, notification lists and government agencies to confirm breaches.&amp;nbsp; To be considered a breach, it must include the loss of personal identiying information like a SSN.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/braintree?a=QkSgRWdxdu0:mr8zDuhvYk4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=QkSgRWdxdu0:mr8zDuhvYk4:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=QkSgRWdxdu0:mr8zDuhvYk4:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=QkSgRWdxdu0:mr8zDuhvYk4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=QkSgRWdxdu0:mr8zDuhvYk4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=QkSgRWdxdu0:mr8zDuhvYk4:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=QkSgRWdxdu0:mr8zDuhvYk4:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=QkSgRWdxdu0:mr8zDuhvYk4:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/braintree/~4/QkSgRWdxdu0" height="1" width="1"/&gt;</description>
          <pubDate>Fri, 09 Jan 2009 18:44:00 GMT</pubDate>
          <guid isPermaLink="false">http://www.braintreepaymentsolutions.com/blog/Data-Breaches-up-in-2008/</guid>
          <link>http://feedproxy.google.com/~r/braintree/~3/QkSgRWdxdu0/</link>
        <feedburner:origLink>http://www.braintreepaymentsolutions.com/blog/Data-Breaches-up-in-2008/</feedburner:origLink></item>
        
    
        
        <item>
          <title>Costco, your marketing department has gone rogue</title>
          <description>&lt;p&gt;Costco advertises unbeatable credit card processing rates of 1.64% and 1.99% in their November magazine. The problem? It's like a national long distance provider advertising a flat $.05 per minute that actually only includes your zip code.&lt;/p&gt;
&lt;p&gt;And the first benefit Costco touts regarding their services? &amp;quot;No Hidden Fees&amp;quot;&lt;/p&gt;
&lt;p&gt;Any business that accepts credit cards will tell you that this advertisement is misleading. If a merchant were to actually sign up, expecting to pay these rates, they would be unpleasantly surprised to find out that the &lt;i&gt;actual&lt;/i&gt; rates are:&lt;/p&gt;
&lt;p&gt;* 1.64% and $.20 for swiped transactions &lt;br /&gt;
* 1.99% and $.27 for non swiped transactions &lt;br /&gt;
&lt;b&gt; * 2.96% $.32 for rewards, business, corporate, non-AVS, authorizations not settled within 24 hours, and a host of other conditions.&lt;br /&gt;
* 3.80% $.32 for government or international cards&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;I don't know about you, but that's a minor * that I would want to know about before buying.&lt;/p&gt;
&lt;p&gt;Come on Costco, you're a brand we trust. We realize others in the industry do the exact same thing, but your customers deserve better.&lt;/p&gt;
&lt;p&gt;&lt;img src="http://www.braintreepaymentsolutions.com/assets/253/Costco-no-hidden-fees-08.png" alt="" /&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/braintree?a=wgjAkGnTtis:Tz0QbEx2wNU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=wgjAkGnTtis:Tz0QbEx2wNU:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=wgjAkGnTtis:Tz0QbEx2wNU:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=wgjAkGnTtis:Tz0QbEx2wNU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=wgjAkGnTtis:Tz0QbEx2wNU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=wgjAkGnTtis:Tz0QbEx2wNU:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=wgjAkGnTtis:Tz0QbEx2wNU:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=wgjAkGnTtis:Tz0QbEx2wNU:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/braintree/~4/wgjAkGnTtis" height="1" width="1"/&gt;</description>
          <pubDate>Fri, 05 Dec 2008 16:47:00 GMT</pubDate>
          <guid isPermaLink="false">http://www.braintreepaymentsolutions.com/blog/Costco-your-marketing-department-has-gone-rogue/</guid>
          <link>http://feedproxy.google.com/~r/braintree/~3/wgjAkGnTtis/</link>
        <feedburner:origLink>http://www.braintreepaymentsolutions.com/blog/Costco-your-marketing-department-has-gone-rogue/</feedburner:origLink></item>
        
    
        
        <item>
          <title>2008 Credit Card Data Breach Trends</title>
          <description>&lt;p style="text-align: left;"&gt;&lt;img align="right" alt="" src="http://www.braintreepaymentsolutions.com/assets/247/Credit_card_lock.jpg?1228422968" /&gt;I recently listened to a presentation by a security group that performs forensics work when a merchant experiences a credit card data breach.  Here are the breach trends they've seen during 2008:&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Methods of entry - &lt;/b&gt;largely unchanged&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;Insecure remote access software&lt;/li&gt;
    &lt;li&gt;SQL injection&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;b&gt;Breaching credit card data&lt;/b&gt; - evolved strategies&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;Capturing credit card data in transit over the network between devices&amp;nbsp;&lt;/li&gt;
    &lt;li&gt;Via program modification after a vulnerable application was breached&lt;/li&gt;
    &lt;li&gt;Via collection of Random Access Memory (RAM) contents&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;b&gt;Techniques used&lt;/b&gt; - most apply to software POS&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;Key-logging&amp;nbsp;&lt;/li&gt;
    &lt;li&gt;Network sniffers&lt;/li&gt;
    &lt;li&gt;Serial port sniffers&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;b&gt;Case Study&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;In one case study they shared the criminal was able to penetrate the network via remote access software. They then installed a debugging tool to collect RAM contents and malware to parse track data. The malware then uploaded the data to a Russian website.&amp;nbsp; The merchant was using a PABP POS that was not collecting prohibited cardholder data.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/braintree?a=np953g9xP10:RLmko9RcDdg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=np953g9xP10:RLmko9RcDdg:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=np953g9xP10:RLmko9RcDdg:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=np953g9xP10:RLmko9RcDdg:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=np953g9xP10:RLmko9RcDdg:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=np953g9xP10:RLmko9RcDdg:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=np953g9xP10:RLmko9RcDdg:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=np953g9xP10:RLmko9RcDdg:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/braintree/~4/np953g9xP10" height="1" width="1"/&gt;</description>
          <pubDate>Tue, 25 Nov 2008 14:13:00 GMT</pubDate>
          <guid isPermaLink="false">http://www.braintreepaymentsolutions.com/blog/2008-Credit-Card-Data-Breach-Trends/</guid>
          <link>http://feedproxy.google.com/~r/braintree/~3/np953g9xP10/</link>
        <feedburner:origLink>http://www.braintreepaymentsolutions.com/blog/2008-Credit-Card-Data-Breach-Trends/</feedburner:origLink></item>
        
    
        
    
        
    
        
        <item>
          <title>MasterCard interchange changes for Utility, Real Estate and Insurance merchants</title>
          <description>&lt;p style="margin: 0px 0px 12px; font-family: Arial; font-style: normal; font-variant: normal; font-weight: normal; font-size: 12px; line-height: normal; font-size-adjust: none; font-stretch: normal; text-align: left;"&gt;&lt;span style="letter-spacing: 0px;"&gt;&lt;img hspace="6" align="left" src="http://braintreepaymentsolutions.com/assets/165/masterCard.jpg" alt="master card" /&gt;MasterCard announced some changes to their interchange pricing today that will be effective October 3, 2008.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0px 0px 12px; font-family: Arial; font-style: normal; font-variant: normal; font-weight: normal; font-size: 12px; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;&lt;span style="letter-spacing: 0px;"&gt;As some quick context if you are new to this. Here is an oversimplification: merchants pay fees to &lt;a href="http://www.braintreepaymentsolutions.com/payment-processing/merchant-account/"&gt;accept credit cards&lt;/a&gt;. Financial institutions that issue credit and debit cards make roughly 75% of the fees that merchants pay (merchant account providers charge the other 25% of the fees). When MasterCard makes changes to 'Interchange', they are adjusting the wholesale pricing of the fees that make up MasterCard and their financial issuing institution's 75% of fees. To the casual observer in this industry - these updates below won't make a lot of sense without some additional context.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Utilities&lt;/b&gt;&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;Merchants no longer need to register for their Utility Program&lt;/li&gt;
    &lt;li&gt;MC is discontinuing their Service Industries Incentive Program (SIIP). The SIIP program offered a lower discount rate and transaction fee. Utilities will now be charged a fixed fee per transaction which is lower on average than rates paid on SIIP and closer to pin debit rates.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;b&gt;Real Estate&lt;/b&gt;&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;Discontinuing two Debit interchange categories (Merit III and UCAF), otherwise pricing stays the same.&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;b&gt;Insurance &lt;/b&gt;&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;Similar to utilities, discontinuing the discounted SIIP rates. Merit III, Merit I Merchant/Full UCAF Debit are no longer eligible.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;b&gt;Telecommunications  &lt;/b&gt;&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;Similiar to utilities and insurance, discontinuing the discounted SIIP rates &lt;i&gt;but &lt;/i&gt;Merit III, Merit I Merchant/Full UCAF Debit &lt;i&gt;are still eligible&lt;/i&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;b&gt;Related Posts&lt;/b&gt;&lt;br /&gt;
&lt;a href="http://www.braintreepaymentsolutions.com/blog/where-do-credit-card-fees-come-from-cc/"&gt;Where do credit card fees come from?&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/braintree?a=1jMicoE4ktU:RbIGckTM4kU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=1jMicoE4ktU:RbIGckTM4kU:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=1jMicoE4ktU:RbIGckTM4kU:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=1jMicoE4ktU:RbIGckTM4kU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=1jMicoE4ktU:RbIGckTM4kU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=1jMicoE4ktU:RbIGckTM4kU:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=1jMicoE4ktU:RbIGckTM4kU:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=1jMicoE4ktU:RbIGckTM4kU:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/braintree/~4/1jMicoE4ktU" height="1" width="1"/&gt;</description>
          <pubDate>Wed, 15 Oct 2008 19:23:00 GMT</pubDate>
          <guid isPermaLink="false">http://www.braintreepaymentsolutions.com/blog/mastercard-interchange-changes-for-utility-real-estate-and-insurance-merchants/</guid>
          <link>http://feedproxy.google.com/~r/braintree/~3/1jMicoE4ktU/</link>
        <feedburner:origLink>http://www.braintreepaymentsolutions.com/blog/mastercard-interchange-changes-for-utility-real-estate-and-insurance-merchants/</feedburner:origLink></item>
        
    
        
        <item>
          <title>California Data Breach Law Vetoed - Again</title>
          <description>&lt;p&gt;&lt;span style="font-size: 10pt;"&gt;&lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9116078"&gt;Computer World&lt;/a&gt; reports the following today:&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin-left: 24pt;"&gt;&lt;span style="font-size: 10pt;"&gt;For the second time in 12 months, California Gov. Arnold Schwarzenegger has vetoed &lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;taxonomyName=Security&amp;amp;articleId=9114062&amp;amp;taxonomyId=17&amp;amp;pageNumber=1"&gt;proposed legislation&lt;/a&gt; that would have required retailers and other businesses operating in the state to take specific steps to &lt;a href="http://www.braintreepaymentsolutions.com/pci-dss-compliance/"&gt;prevent credit and debit card data from being compromised&lt;/a&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin-left: 24pt;"&gt;&lt;span style="font-size: 10pt;"&gt;The latest version of the bill &amp;mdash; known as the Consumer Data Protection Act, or AB 1656 &lt;a target="new" href="http://www.leginfo.ca.gov/pub/07-08/bill/asm/ab_1651-1700/ab_1656_bill_20080806_amended_sen_v92.pdf"&gt;(download PDF)&lt;/a&gt; &amp;mdash; would also have required retailers that accept payment card transactions to disclose more details about any data breaches to the individuals affected by them. The bill was approved by the California State Assembly on a 74-1 vote last month, a week after the state Senate passed it by a 34-3 margin.&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin-left: 24pt;"&gt;&lt;span style="font-size: 10pt;"&gt;But in a veto message that he sent to state legislators on Tuesday &lt;a target="new" href="http://gov.ca.gov/pdf/press/AB1656_Jones_Veto_Message.pdf"&gt;(download PDF)&lt;/a&gt;, Schwarzenegger said he was refusing to sign the bill for the same reasons he &lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9042630"&gt;turned down&lt;/a&gt; the original version of the measure last October. &amp;quot;As I stated in last year's veto of a similar bill, this bill attempts to legislate in an area where the marketplace has already assigned responsibilities and liabilities that provide for the protection of consumers,&amp;quot; Schwarzenegger wrote.&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin-left: 24pt;"&gt;&lt;span style="font-size: 10pt;"&gt;The governor said that requiring companies to notify consumers about breaches, even when there is no evidence of any personal data actually being stolen, would result in &amp;quot;significant costs&amp;quot; for businesses and the state government. In addition, he said, the controls mandated in AB 1656 would lock companies into current &lt;a href="http://www.braintreepaymentsolutions.com/pci-dss-compliance/"&gt;credit card data security&lt;/a&gt; best practices, creating a disincentive for them to adopt new and more comprehensive industry standards and ensuring that the law would remain &amp;quot;static in the face of future, unseen concerns.&amp;quot;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: 10pt;"&gt;Seems like practical, good decision making to me. Nice work Schwarzenegger.&lt;/span&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/braintree?a=uqUsKZ7SlyM:OUmG755eE-c:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=uqUsKZ7SlyM:OUmG755eE-c:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=uqUsKZ7SlyM:OUmG755eE-c:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=uqUsKZ7SlyM:OUmG755eE-c:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=uqUsKZ7SlyM:OUmG755eE-c:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=uqUsKZ7SlyM:OUmG755eE-c:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=uqUsKZ7SlyM:OUmG755eE-c:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=uqUsKZ7SlyM:OUmG755eE-c:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/braintree/~4/uqUsKZ7SlyM" height="1" width="1"/&gt;</description>
          <pubDate>Fri, 03 Oct 2008 22:12:00 GMT</pubDate>
          <guid isPermaLink="false">http://www.braintreepaymentsolutions.com/blog/california-data-breach-law-vetoed---again/</guid>
          <link>http://feedproxy.google.com/~r/braintree/~3/uqUsKZ7SlyM/</link>
        <feedburner:origLink>http://www.braintreepaymentsolutions.com/blog/california-data-breach-law-vetoed---again/</feedburner:origLink></item>
        
    
        
        <item>
          <title>Annual Credit Card Billing Subscriptions </title>
          <description>&lt;p style="margin: 0px 0px 12px; font-family: Arial; font-style: normal; font-variant: normal; font-weight: normal; font-size: 12px; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;&lt;span style="letter-spacing: 0px;"&gt;Coming up with the optimal pricing structure for a product or service is tough. Beyond factors such as competitor pricing and target market price point analysis, merchants need to consider the limitations that accompany collecting money via a credit card.&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0px 0px 12px; font-family: Arial; font-style: normal; font-variant: normal; font-weight: normal; font-size: 12px; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;&lt;span style="letter-spacing: 0px;"&gt;The reason behind the limitation: financial risk. &amp;nbsp;&lt;a href="http://www.braintreepaymentsolutions.com/payment-processing/merchant-account/"&gt;Merchant account&lt;/a&gt; providers are on the hook for the money their customers process. For example, if a company accepts 1,000 annual subscriptions at $129 and then declares bankruptcy two months later, the merchant account provider is responsible for paying back the full $129,000 to cardholders when they file chargebacks.&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0px 0px 12px; font-family: Arial; font-style: normal; font-variant: normal; font-weight: normal; font-size: 12px; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;&lt;span style="letter-spacing: 0px;"&gt;Some merchant account providers will maintain a hardline for anything greater than 30 day &lt;a href="http://www.braintreepaymentsolutions.com/recurring-billing/"&gt;recurring billing&lt;/a&gt; cycles while others with a bigger appetite for risk may allow quarterly, semi-annual or annual billing from the start. This becomes less of an issue if a company has a demonstrated track record and financial strength. &amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0px 0px 12px; font-family: Arial; font-style: normal; font-variant: normal; font-weight: normal; font-size: 12px; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;&lt;span style="letter-spacing: 0px;"&gt;Whatever billing strategy a company pursues, it's a good idea to make sure that all billing intentions and practices are fully disclosed upfront to avoid future problems. &amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;Related: &lt;br /&gt;
Jason Fried of 37signals has a&lt;/span&gt;&lt;span style=""&gt; &lt;a href="http://www.37signals.com/svn/posts/753-ask-37signals-how-do-you-process-credit-cards"&gt;&lt;span style="text-decoration: underline; letter-spacing: 0px;"&gt;good post about their experience with this&lt;/span&gt;&lt;/a&gt;.&lt;/span&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/braintree?a=7Orm50T5ays:1goP2A6p_3A:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=7Orm50T5ays:1goP2A6p_3A:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=7Orm50T5ays:1goP2A6p_3A:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=7Orm50T5ays:1goP2A6p_3A:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=7Orm50T5ays:1goP2A6p_3A:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=7Orm50T5ays:1goP2A6p_3A:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=7Orm50T5ays:1goP2A6p_3A:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=7Orm50T5ays:1goP2A6p_3A:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/braintree/~4/7Orm50T5ays" height="1" width="1"/&gt;</description>
          <pubDate>Thu, 02 Oct 2008 20:25:00 GMT</pubDate>
          <guid isPermaLink="false">http://www.braintreepaymentsolutions.com/blog/annual-credit-card-billing-subscriptions/</guid>
          <link>http://feedproxy.google.com/~r/braintree/~3/7Orm50T5ays/</link>
        <feedburner:origLink>http://www.braintreepaymentsolutions.com/blog/annual-credit-card-billing-subscriptions/</feedburner:origLink></item>
        
    
        
        <item>
          <title>Visa working on payment applications for Android </title>
          <description>&lt;p&gt;&lt;span style="font-size: 10pt; font-family: Arial;"&gt;&lt;!--[if !supportEmptyParas]--&gt;&lt;img height="179" width="100" align="right" alt="" src="http://www.braintreepaymentsolutions.com/assets/166/android_phone.png?1225208457" /&gt;Last month Visa announced that they are moving to alert customers of suspected &lt;a href="http://www.braintreepaymentsolutions.com/payment-processing/risk-and-fraud-management/"&gt;credit card fraud&lt;/a&gt; via mobile phone. This week they announced more ambitious plans to build &lt;a href="http://www.braintreepaymentsolutions.com/"&gt;online payment&lt;/a&gt; applications with Nokia for Google&amp;rsquo;s Android. &lt;!--[endif]--&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: 10pt; font-family: Arial;"&gt;The goal is to allow users to make remote and contactless payments as well as transfer money. Remote payments should be marked user convenience and transferring money is a big move for Visa into a space they've not been before. The biggest barrier to contactless payments will be the required point of sale upgrades to allow for Near-Field Communications (NFC) where users just wave their phone a few inches from the device.&lt;span style=""&gt; &lt;br /&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/braintree?a=w6KDsXcjBWw:QayHS-ijuBo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=w6KDsXcjBWw:QayHS-ijuBo:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=w6KDsXcjBWw:QayHS-ijuBo:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=w6KDsXcjBWw:QayHS-ijuBo:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=w6KDsXcjBWw:QayHS-ijuBo:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=w6KDsXcjBWw:QayHS-ijuBo:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=w6KDsXcjBWw:QayHS-ijuBo:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=w6KDsXcjBWw:QayHS-ijuBo:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/braintree/~4/w6KDsXcjBWw" height="1" width="1"/&gt;</description>
          <pubDate>Tue, 30 Sep 2008 19:48:00 GMT</pubDate>
          <guid isPermaLink="false">http://www.braintreepaymentsolutions.com/blog/visa-working-on-payment-applications-for-android/</guid>
          <link>http://feedproxy.google.com/~r/braintree/~3/w6KDsXcjBWw/</link>
        <feedburner:origLink>http://www.braintreepaymentsolutions.com/blog/visa-working-on-payment-applications-for-android/</feedburner:origLink></item>
        
    
        
        <item>
          <title>Visa Transaction Alerts via email and mobile phone</title>
          <description>&lt;p&gt;&lt;img align="right" src="http://www.braintreepaymentsolutions.com/assets/167/Visa_logo.gif?1225209172" alt="" /&gt;Digital Transactions reports today that in 2009, in an effort to reduce &lt;a href="http://www.braintreepaymentsolutions.com/payment-processing/risk-and-fraud-management/"&gt;credit card fraud&lt;/a&gt;, Visa will provide cardholders the ability to be instantly notified via email or text message of any usage of their debit, credit or ATM card.  The service is in beta with a number of U.S. and Canadian banks.&lt;/p&gt;
&lt;p&gt;The system will allow users to set transaction amount notification thresholds. If a transaction is suspicious users can immediately call a 800 number to report it.  Today it takes 98 days on average to detect identify theft and 72 days for bank card fraud (&lt;a href="http://www.javelinstrategy.com/"&gt;Javelin Research&lt;/a&gt;).&lt;/p&gt;
&lt;p&gt;This type of notification service has the potential to dramatically reduce that.  So in short, Visa is shifting fraud screening and prevention costs to cardholders. Nice work Visa.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/braintree?a=nitaN2vrdWo:wAcGJBIm4SA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=nitaN2vrdWo:wAcGJBIm4SA:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=nitaN2vrdWo:wAcGJBIm4SA:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=nitaN2vrdWo:wAcGJBIm4SA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=nitaN2vrdWo:wAcGJBIm4SA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=nitaN2vrdWo:wAcGJBIm4SA:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=nitaN2vrdWo:wAcGJBIm4SA:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=nitaN2vrdWo:wAcGJBIm4SA:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/braintree/~4/nitaN2vrdWo" height="1" width="1"/&gt;</description>
          <pubDate>Fri, 22 Aug 2008 14:12:00 GMT</pubDate>
          <guid isPermaLink="false">http://www.braintreepaymentsolutions.com/blog/visa-transaction-alerts-via-email-and-mobile-phone/</guid>
          <link>http://feedproxy.google.com/~r/braintree/~3/nitaN2vrdWo/</link>
        <feedburner:origLink>http://www.braintreepaymentsolutions.com/blog/visa-transaction-alerts-via-email-and-mobile-phone/</feedburner:origLink></item>
        
    
        
        <item>
          <title>Gen Y Preferred Online Payment Method</title>
          <description>&lt;p&gt;&lt;img align="right" src="http://www.braintreepaymentsolutions.com/assets/169/paypal_logo.jpg?1225209533" alt="" /&gt;Interesting because I thought PayPal would have much higher preferred status among this demographic.&lt;/p&gt;
&lt;blockquote&gt;Credit Card:      65%&lt;br /&gt;
Debit Card:       22%&lt;br /&gt;
Checking:          8%&lt;br /&gt;
&lt;strong&gt;PayPal:               3%&lt;br /&gt;
&lt;/strong&gt;  Other:                2%&lt;/blockquote&gt;
&lt;p&gt;Generation Y includes those born in 80's to 90's (18 - 28 year olds). Thank you &lt;a href="http://www.firstannapolis.com"&gt;First Annapolis&lt;/a&gt; for the data and &lt;a href="http://www.electran.org" target="_blank"&gt;Transaction Trends&lt;/a&gt; for publishing.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/braintree?a=GUbWYNn01oc:-XNIdh6JhKw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=GUbWYNn01oc:-XNIdh6JhKw:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=GUbWYNn01oc:-XNIdh6JhKw:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=GUbWYNn01oc:-XNIdh6JhKw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=GUbWYNn01oc:-XNIdh6JhKw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=GUbWYNn01oc:-XNIdh6JhKw:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=GUbWYNn01oc:-XNIdh6JhKw:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=GUbWYNn01oc:-XNIdh6JhKw:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/braintree/~4/GUbWYNn01oc" height="1" width="1"/&gt;</description>
          <pubDate>Wed, 13 Aug 2008 13:23:00 GMT</pubDate>
          <guid isPermaLink="false">http://www.braintreepaymentsolutions.com/blog/gen-y-preferred-online-payment-method/</guid>
          <link>http://feedproxy.google.com/~r/braintree/~3/GUbWYNn01oc/</link>
        <feedburner:origLink>http://www.braintreepaymentsolutions.com/blog/gen-y-preferred-online-payment-method/</feedburner:origLink></item>
        
    
        
        <item>
          <title>Largest indictment of credit card hackers to date</title>
          <description>&lt;p&gt;&lt;img height="223" align="right" width="150" src="http://www.braintreepaymentsolutions.com/assets/168/Credit_card_security.jpg?1225209445" alt="" /&gt;The Justice Department unveiled possibly their largest indictment of credit card data hackers yesterday. Nine people from the U.S. Estonia, Ukraine, China and Belarus are being charged for allegedly stealing over 40 million credit card records from nine retailers.&lt;/p&gt;
&lt;p&gt;They successfully stole credit card data by using &lt;a target="_blank" href="http://en.wikipedia.org/wiki/Packet_sniffer"&gt;'sniffing' &lt;/a&gt;programs on both wireless networks and on cash registers.  Once captured, the criminals would load the data onto the magnetic strip of blank credit cards and then withdraw cash from ATM's.&lt;/p&gt;
&lt;p&gt;The issuing financial institutions of the stolen cards take large financial losses because cardholders are not responsible for fraud - they are.   For example, Justice Department reports that at one Dave &amp;amp; Busters restaurant location the sniffing program captured roughly 5,000 cards that resulted in over $600,000 of losses to the finanical institutions that issued those cards.&lt;/p&gt;
&lt;p&gt;The affected retailers include Sports Authority, Office Max, BJ's Wholesale Club, Marshall's, T.J. Maxx and a few others.&lt;/p&gt;
&lt;p&gt;Other related posts: &lt;br /&gt;
&lt;a href="http://www.braintreepaymentsolutions.com/blog/pci-compliance-and-the-cost-of-a-credit-card-breach/"&gt;The cost of a credit card breach&lt;/a&gt;  &lt;br /&gt;
&lt;a href="http://www.braintreepaymentsolutions.com/blog/pci-compliance-basics-for-credit-card-secuirty/"&gt;PCI Compliance basics&lt;/a&gt;  &lt;br /&gt;
&lt;a href="http://www.braintreepaymentsolutions.com/blog/what-does-it-cost-to-become-pci-compliant/"&gt;The cost to become PCI Compliant&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/braintree?a=EGMWnPIdUsg:1Q5mSWWoV9Y:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=EGMWnPIdUsg:1Q5mSWWoV9Y:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=EGMWnPIdUsg:1Q5mSWWoV9Y:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=EGMWnPIdUsg:1Q5mSWWoV9Y:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=EGMWnPIdUsg:1Q5mSWWoV9Y:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=EGMWnPIdUsg:1Q5mSWWoV9Y:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=EGMWnPIdUsg:1Q5mSWWoV9Y:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=EGMWnPIdUsg:1Q5mSWWoV9Y:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/braintree/~4/EGMWnPIdUsg" height="1" width="1"/&gt;</description>
          <pubDate>Wed, 06 Aug 2008 09:39:00 GMT</pubDate>
          <guid isPermaLink="false">http://www.braintreepaymentsolutions.com/blog/largest-indictment-of-credit-card-hackers-to-date/</guid>
          <link>http://feedproxy.google.com/~r/braintree/~3/EGMWnPIdUsg/</link>
        <feedburner:origLink>http://www.braintreepaymentsolutions.com/blog/largest-indictment-of-credit-card-hackers-to-date/</feedburner:origLink></item>
        
    
        
        <item>
          <title>Tax, Fuel, Debt, Recurring and GSA V/MC Interchange Updates </title>
          <description>&lt;p&gt;&lt;img height="119" width="93" class="alignright size-medium wp-image-218" title="visa-mastercard" src="http://www.braintreepaymentsolutions.com/blog/wp-content/uploads/2008/07/visa-mastercard.jpg" alt="" /&gt;Visa &amp;amp; MasterCard have announced some pretty significant changes.   Visa is out with two new categories: Debt Repayment and Government to Government. Tax Payment is officially coming out of pilot and interchange reductions at the pump. MasterCard introduces a recurring billing 'preauthorized request' - a great idea.    All these will be effective  October 3rd, 2008:&lt;/p&gt;
&lt;p&gt;&lt;span style="text-decoration: underline;"&gt;&lt;strong&gt;Visa Updates  &lt;br /&gt;
&lt;/strong&gt;&lt;/span&gt;Debt Repayment Programs for U.S. consumer auto loan, credit card, residential mortgage and student loan for &lt;span style="text-decoration: underline;"&gt;debit card only&lt;/span&gt;&lt;strong&gt;. &lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;Availability for Financial Institutions Merchandise &amp;amp; Services, Non Financial Foreign Currency Money Orders (no wire transfers) and Travelers Cheques).&lt;/li&gt;
    &lt;li&gt;Cannot be used for bad debt, uncollectible debt charge-off debt and debt sold to collection agencies.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Fuel &lt;/strong&gt;- Trying to reduce the pain at the pump (and appease angry gas station owners):&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;Consumer Debit Cards: a maximum interchange amount is now in place, replacing what was formerly a discount rate and transaction fee that varied with amount.&lt;/li&gt;
    &lt;li&gt;Consumer Credit Cards: lowered by as much as .50 bps on certain cards and consolidated into a single rate for 6 different card types- Automated Fuel Dispenser (AFD) Partial Authorization&lt;/li&gt;
    &lt;li&gt;Partial Authorization: POS Vendors will be required to support this functionality by 10/3/08.  As some context, when a consumer swipes a card today today at an AFD an authorization is done for $50 to check validity and availability of funds before approving to pump.  That's referred to as a 'Partial Authorization' so if the consumer only pumps $40 of fuel the initial $50 authorization, the merchant can capture for the $40.  A problem with that method is that if a check (Signature Debit) or pre-paid card is used and the card does not have the available funds it will be denied.  With the Partial Authorization implemented, the issuer would respond with the available amount instead of denying the transaction.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Tax Payments&lt;/strong&gt; - Visa has had this program in pilot mode for several years now:&amp;nbsp;&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;Merchants are required to register for this - no sign up fees before April 1, 2009.&lt;/li&gt;
    &lt;li&gt;Existing interchange rates will apply * Interchange rate of $2.50 will apply to consumer debit transactions that are qualified&lt;/li&gt;
    &lt;li&gt;Service or convenience fee may be assessed. Fee can be variable for consumer credit and commercial cards but a flat fee must be charged for consumer debit transactions and may not exceed $3.95 (could they make it any more difficult?)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Commercial Card GSA - &lt;/strong&gt;Introduction of Government-to-Government interchange program (G2G). Level II &amp;amp; III data is not required.&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;$5,000 minimum has been removed * Special interchange rate for transactions over $8,750 is removed with interchange rate increasing .25 bps and $4.&lt;/li&gt;
    &lt;li&gt;GSA Purchase cards will not be available for Commercial Card Level III rates.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="text-decoration: underline;"&gt;MasterCard&lt;/span&gt;  &lt;br /&gt;
Test transaction for &lt;a href="http://www.braintreepaymentsolutions.com/recurring-billing/"&gt;Recurring Billing&lt;/a&gt; &lt;/strong&gt;&lt;strong&gt;&lt;br /&gt;
&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;$1 authorization for account status before requesting full amount authorization.  (nice work whomever came up with this idea!)&lt;/li&gt;
    &lt;li&gt;What's going on MasterCard?&amp;nbsp; Only 1 Update?&lt;/li&gt;
&lt;/ul&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/braintree?a=JhTjj-2LVdA:QhNe1oQXjsU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=JhTjj-2LVdA:QhNe1oQXjsU:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=JhTjj-2LVdA:QhNe1oQXjsU:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=JhTjj-2LVdA:QhNe1oQXjsU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=JhTjj-2LVdA:QhNe1oQXjsU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=JhTjj-2LVdA:QhNe1oQXjsU:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=JhTjj-2LVdA:QhNe1oQXjsU:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=JhTjj-2LVdA:QhNe1oQXjsU:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/braintree/~4/JhTjj-2LVdA" height="1" width="1"/&gt;</description>
          <pubDate>Wed, 23 Jul 2008 13:37:00 GMT</pubDate>
          <guid isPermaLink="false">http://www.braintreepaymentsolutions.com/blog/tax-fuel-debt-recurring-and-gsa-vmc-interchange-updates/</guid>
          <link>http://feedproxy.google.com/~r/braintree/~3/JhTjj-2LVdA/</link>
        <feedburner:origLink>http://www.braintreepaymentsolutions.com/blog/tax-fuel-debt-recurring-and-gsa-vmc-interchange-updates/</feedburner:origLink></item>
        
    
        
        <item>
          <title>Merchant Account Basics</title>
          <description>&lt;p&gt;There is a lot of confusion surrounding &lt;a href="http://www.braintreepaymentsolutions.com/"&gt;credit card processing&lt;/a&gt; and &lt;a href="http://www.braintreepaymentsolutions.com/payment-processing/merchant-account/"&gt;merchant accounts&lt;/a&gt;.  Some of the most common areas of confusion are the different types of organizations that sell the services, what entities actually process the transactions and the &lt;a href="http://www.braintreepaymentsolutions.com/blog/where-do-credit-card-fees-come-from-cc/"&gt;fees and pricing&lt;/a&gt; structures that continue to form an unsolvable mystery for most merchants. I'm going to provide a broad overview that will hopefully help make sense of this complicated industry.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The necessity of merchant accounts &lt;br /&gt;
&lt;/strong&gt; Some merchants prefer accepting credit cards because they are a much more convenient and cost effective way of collecting payments from customers. Other merchants, while it still may be convenient, struggle to pay the relatively high fees on their already thin margins. Either way, merchants can make a number of improvements in their credit card processing by becoming more informed.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Providers of merchant accounts&lt;/strong&gt; &lt;br /&gt;
If you want to get a new merchant account or switch from your existing provider, one thing is for sure: there is no shortage of companies that are anxious to earn your business. You can find merchant service providers by looking in the yellow pages, searching online, talking to your bank, or just waiting for the next sales person to either call you or walk into your business (which shouldn't be long). The key is choosing the RIGHT provider for your business.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Not all service providers are made equal&lt;/strong&gt; &lt;br /&gt;
There are really two types of merchant service providers: processors and resellers (resellers are known in the industry as Independent Sales Organizations (ISO's) and/or Merchant Service Providers (MSP's)). Your first thought is probably that you would rather go with a processor to cut out the middle man, but I'll show you why it's not that clean cut. Before I started Braintree, I worked for a processor and saw first hand some of the limitations they had in providing solutions to merchants. I'll provide more detailed descriptions of both options and then offer an assessment of their differences.  &lt;br /&gt;
&lt;br /&gt;
1) &lt;strong&gt;Processors&lt;/strong&gt; - Also known as Acquirers, processors are distinguished by their ability to actually process a transaction. To be a processor, a company must have the technical capability to receive transaction data from a merchant via a telephone line or the internet and then communicate with the appropriate financial institutions to approve or decline transactions. Processors must also be able to settle completed transactions through financial institutions in order to deposit funds into the merchant's bank account.  &lt;br /&gt;
&lt;br /&gt;
The processing industry is highly concentrated with the top five processors maintaining over 70% of all transaction volume. Processors can be banks or non-banks.  While processors do maintain a direct sales force of their own, they primarily work through ISOs to acquire and maintain their merchant base. A processor's business model is really one of economies of scale. They're volume shops. They essentially outsource the sales function to ISOs.  I don't have data on this but I would guess that over 80% of the 7 million U.S. merchants work with an ISO.  &lt;br /&gt;
&lt;br /&gt;
Below is simple diagram of the transaction flow. I took the liberty of putting my company in the value chain, but because Braintree is an ISO, there is a processor behind the scenes doing the actual transaction processing. Because most everything is private labeled, it's difficult for most merchants to discern whether  their service provider is a processor or an ISO. Be careful not to be improperly influenced by this.  Most sales people try to use the 'we are the processor' line to gain additional credibility when in reality it doesn't  really matter.&amp;nbsp;&lt;/p&gt;
&lt;!-- &lt;p style="text-align: center;"&gt;&lt;img alt="" src="http://www.braintreepaymentsolutions.com/assets/152/Transaction-Process.png" /&gt;&lt;/p&gt; possibly redundant--&gt;
&lt;p style="text-align: center;"&gt;&lt;img width="470" height="166" align="middle" src="http://braintreepaymentsolutions.com/assets/152/Transaction-Process.png" alt="" /&gt;&lt;/p&gt;
&lt;p style="text-align: left;"&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;2) ISOs -&lt;/strong&gt; ISOs resell the products or services of one or multiple processors. They can also develop their own or aggregate other value added products and services. ISO's range from a little sketchy to best in class providers.  &lt;strong&gt;&lt;br /&gt;
&lt;br /&gt;
There are two types of ISOs:  &lt;/strong&gt;&lt;br /&gt;
a. &lt;strong&gt;Banks&lt;/strong&gt; - Banks of all shapes and sizes are ISOs. Wells Fargo, for example, is an ISO of First Data. Your local community and large regional banks are most likely ISOs. Banks entered into the merchant services business because it was a natural fit with their product and service offerings. It's a way to increase revenue per customer. Most, but not all banks, will private label the services so that it's difficult to distinguish whether they are a processor or ISO. The benefit of working with a bank is that you can consolidate your financial services.  The drawback is the you usually get out of the box solutions and service. &lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-size: 12pt;"&gt; &lt;span&gt; &lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;/span&gt;  b. &lt;strong&gt;Non-banks&lt;/strong&gt; - These types of ISOs range from some of the most dynamic and capable providers to firms who don't represent the industry very well.  &lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Industry Dynamics &lt;/strong&gt;There are a few dynamics that make the industry landscape quite interesting.&lt;span style="font-size: 12pt;"&gt; &lt;/span&gt;First, there are few barriers to entry due to the lack of certifications, licenses, and capital requirements. Secondly, there really is no active regulatory body that oversees and enforces acceptable practices. So naturally, with these two market conditions, merchants need to be mindful and thorough in selecting a provider.  &lt;strong&gt;&lt;br /&gt;
&lt;br /&gt;
Processors versus ISOs&lt;/strong&gt;&lt;strong&gt;&lt;span style="font-size: 12pt;"&gt; &lt;/span&gt;&lt;/strong&gt; In comparing the two, ISOs offer all of the products and services that processors do (because they are reselling) but processors can't always offer the same products and services as ISOs.  This is because ISOs can resell for multiple processors and can either develop their own technologies or aggregate solutions from other providers.  ISOs have largely been the most successful creators of value-added services while attempts by processors have usually been pretty clunky.  ISO's also tend to be smaller, which usually (but not always) leads to better customer service.  &lt;br /&gt;
&lt;br /&gt;
Processors are usually a safer bet for newer merchants that are still learning about the industry. Most still maintain what I consider less-than-upfront pricing practices, but with their services it is less common to hear about some of the more serious problems that merchants encounter when they deal with the wrong ISO.  As for price, in most cases, there really is very little to no difference.  I argue, and fully disclose my vested interest, that in nearly any situation a best in class, non-bank ISO can provide more value than a processor.  For some other considerations about what to bear in mind when evaluating different providers, you can read &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://braintreepaymentsolutions.com/blog/merchant-services/how-to-choose-a-merchant-service-provider/"&gt;How to choose a merchant service provider&lt;/a&gt;&lt;/span&gt;.  &lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Business specific merchant accounts &lt;/strong&gt; The rates, terms, and conditions of your merchant account will largely depend on your type of business and the provider you choose. Business types are first divided into two buckets: card present (swiped) and card-not-present (non-swiped). Card present merchants, such as restaurants and brick and mortar retailers are low risk and have fairly simple needs. Card-not-present merchants are much more difficult because the risk level is substantially higher when people are transacting business via the internet, telephone, etc.  Other risk factors that will affect your merchant account are the types of goods that you're selling, delivery times, whether or not a deposit is required, and about 20 other variables. Most underwriting groups use some sort of &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.investopedia.com/terms/a/actuarialrisk.asp"&gt;actuarial model&lt;/a&gt;&lt;/span&gt; to determine their guidelines.  &lt;br /&gt;
&lt;br /&gt;
To give you an idea of one risk merchant service provider face, here is an example. Let's say that you sell $100,000 in books online. Within 48 hours of selling those items, the customer's money is deposited into your bank account. If you take that $100k and skip town without shipping the books to the people who bought them, the merchant service provider is stuck with the $100k bill because customers are going to contest and win the charge with their banks. So for a few hundred dollars a month in revenue, the risk better be pretty manageable for the provider.  &lt;strong&gt;&lt;br /&gt;
&lt;br /&gt;
Paperwork and underwriting &lt;/strong&gt; Most companies have a two page application that will require you to fill out both personal and business information. Many people are justifiably concerned about giving out personal information including their social security number. However, unless you are a publicly traded or non-profit, I don't know of a merchant provider that will underwrite a business without it.  When asked why all of the personal information is needed, most companies will point to the Patriot Act that was passed in Congress shortly after 9/11. It basically requires all financial institutions, which include credit card processors, to collect specific identifying information about their customers. &lt;a href="http://www.gcglaw.com/resources/financial/identification.html"&gt;Click here&lt;/a&gt; for more information on this.  You will also be required to sign a personal guarantee before the application is approved. &lt;br /&gt;
&lt;br /&gt;
Most business owners will respond that they incorporated so that they wouldn't be required to sign a personally guarantee. The underwriter will respond by asking why they should have more faith in your business than you do. Both sides have valid points. I think that the issue boils down to whether or not the business will deliver the goods or services that were purchased under the accepted terms and conditions. The personal guarantee is not so much useful in collecting money, but instead used as a deterrent against fraudulent and irresponsible behavior.  &lt;strong&gt;&lt;br /&gt;
&lt;br /&gt;
Be Careful&lt;/strong&gt; As you can see in this very high level introduction to the industry, there are a lot of complexities and much to learn. You can also read my post on &lt;a href="http://braintreepaymentsolutions.com/blog/featured/some-advice-to-help-you-avoid-common-mistakes/" target="_blank"&gt;Some advice to help you avoid common mistakes. &lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/braintree?a=wXNa-6JXkBE:1iC2SBFDFNg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=wXNa-6JXkBE:1iC2SBFDFNg:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=wXNa-6JXkBE:1iC2SBFDFNg:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=wXNa-6JXkBE:1iC2SBFDFNg:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=wXNa-6JXkBE:1iC2SBFDFNg:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=wXNa-6JXkBE:1iC2SBFDFNg:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=wXNa-6JXkBE:1iC2SBFDFNg:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=wXNa-6JXkBE:1iC2SBFDFNg:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/braintree/~4/wXNa-6JXkBE" height="1" width="1"/&gt;</description>
          <pubDate>Fri, 11 Jul 2008 07:00:00 GMT</pubDate>
          <guid isPermaLink="false">http://www.braintreepaymentsolutions.com/blog/merchant-account-basics/</guid>
          <link>http://feedproxy.google.com/~r/braintree/~3/wXNa-6JXkBE/</link>
        <feedburner:origLink>http://www.braintreepaymentsolutions.com/blog/merchant-account-basics/</feedburner:origLink></item>
        
    
        
        <item>
          <title>PCI DSS Requirement 6.6 - Code Review or Web Application Firewall (WAP)</title>
          <description>&lt;p&gt;The deadline to comply with &lt;a href="http://www.braintreepaymentsolutions.com/pci-dss-compliance/"&gt;PCI DSS&lt;/a&gt; Requirement 6.6 was June 30th, 2008.   Merchants have been given two options:&lt;/p&gt;
&lt;blockquote&gt;1. Have all custom application code reviewed for common vulnerabilities by an organization that specializes in application security.&lt;br /&gt;
2. Install an application-layer firewall in front of web-facing applications.&lt;/blockquote&gt;
&lt;p&gt;The driver behind this new requirement is that a large percentage of &lt;a title="credit card breaches" href="http://www.braintreepaymentsolutions.com/blog/pci-compliance-and-the-cost-of-a-credit-card-breach/" target="_blank"&gt;credit card breaches&lt;/a&gt; are due to SQL Injection, Cross Site Scripting (XSS) and Buffer Overflow attacks.  The intent of this requirement is to eliminate  those vulnerabilities which would contribute to a significant reduction in breaches.  Here is the Information Supplement supplied by the PCI Security Standards Council.&lt;/p&gt;
&lt;div&gt;&lt;object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="200" height="200" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"&gt;&lt;param name="allowScriptAccess" value="always" /&gt;&lt;param name="src" value="http://static.issuu.com/webembed/viewers/style1/v1/IssuuViewer.swf?mode=preview&amp;amp;previewLayout=white&amp;amp;username=braintree&amp;amp;docName=pa-dss_press_release&amp;amp;documentId=080416160711-defc456175344ef490d68b97880184be&amp;amp;autoFlip=true&amp;amp;backgroundColor=ffffff&amp;amp;layout=white" /&gt;&lt;embed type="application/x-shockwave-flash" width="200" height="200" src="http://static.issuu.com/webembed/viewers/style1/v1/IssuuViewer.swf?mode=preview&amp;amp;previewLayout=white&amp;amp;username=braintree&amp;amp;docName=pa-dss_press_release&amp;amp;documentId=080416160711-defc456175344ef490d68b97880184be&amp;amp;autoFlip=true&amp;amp;backgroundColor=ffffff&amp;amp;layout=white" allowscriptaccess="always"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;
&lt;div&gt;Other related posts:&lt;/div&gt;
&lt;div&gt;&lt;a href="http://www.braintreepaymentsolutions.com/blog/pci-compliance-and-the-cost-of-a-credit-card-breach/"&gt;The cost of a credit card breach&lt;/a&gt;&lt;/div&gt;
&lt;div&gt;&lt;a href="http://www.braintreepaymentsolutions.com/blog/pci-compliance-basics-for-credit-card-secuirty/"&gt;PCI Compliance basics&lt;/a&gt;&lt;/div&gt;
&lt;div&gt;&lt;a href="http://www.braintreepaymentsolutions.com/blog/what-does-it-cost-to-become-pci-compliant/"&gt;The cost to become PCI Compliant&lt;/a&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/braintree?a=bZ32qVXBLa4:5ZEcOlKrCC0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=bZ32qVXBLa4:5ZEcOlKrCC0:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=bZ32qVXBLa4:5ZEcOlKrCC0:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=bZ32qVXBLa4:5ZEcOlKrCC0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=bZ32qVXBLa4:5ZEcOlKrCC0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=bZ32qVXBLa4:5ZEcOlKrCC0:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=bZ32qVXBLa4:5ZEcOlKrCC0:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=bZ32qVXBLa4:5ZEcOlKrCC0:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/braintree/~4/bZ32qVXBLa4" height="1" width="1"/&gt;</description>
          <pubDate>Thu, 10 Jul 2008 14:09:00 GMT</pubDate>
          <guid isPermaLink="false">http://www.braintreepaymentsolutions.com/blog/pci-dss-requirement-66-code-review-or-web-application-firewall-wap/</guid>
          <link>http://feedproxy.google.com/~r/braintree/~3/bZ32qVXBLa4/</link>
        <feedburner:origLink>http://www.braintreepaymentsolutions.com/blog/pci-dss-requirement-66-code-review-or-web-application-firewall-wap/</feedburner:origLink></item>
        
    
        
        <item>
          <title>What does it cost to become PCI Compliant?</title>
          <description>&lt;p&gt;The cost of becoming &lt;a href="http://www.braintreepaymentsolutions.com/pci-dss-compliance/"&gt;PCI DSS Compliant&lt;/a&gt; depends on a number of factors including your business type, number of transactions processed annually, existing IT infrastructure, and current credit/debit card processing and storage practices.&amp;nbsp;Gartner estimates that during 2007, the nation's largest merchants, classified as Level 1  (processing in excess of 6 million transactions of a single card type per year), will spend $125,000 assessing the scope of required PCI-related work and another  $568,000 to meet the requirements. &lt;br /&gt;
&lt;br /&gt;
As an example, Robin Sidel and Pui-Wing Tam of the WSJ &lt;a href="http://online.wsj.com/article/SB119128527341745878.html"&gt;recently reported&lt;/a&gt; that &lt;a href="http://www.guitarcenter.com/"&gt;Guitar Center&lt;/a&gt;, a national retailer of 210 stores, recently spent nearly $500,000 to become compliant.  Gartner also concluded that Level 2 merchants, those processing  between 1 and 6 million annual transactions, will spend $105,000 to determine scope and another $267,000 for compliance. Level 3 merchants, processing between 20,000 and 1,000,000 e-commerce transactions, are expected to spend $44,000 assessing and $81,000 for compliance.  The costs associated with Level 4 merchants, those doing less than 20,000 ecommerce transactions or up to 1,000,000  non-ecommerce transactions, varies widely.  &lt;br /&gt;
&lt;br /&gt;
Only Level 1 merchants are required to have an on-site audit. Levels 2, 3 and 4 need to fill out the &lt;a href="http://www.braintreepaymentsolutions.com/blog/updated-pci-dss-self-assessment-questionnaire-saq-version-11/"&gt;Self Assessment Questionnaire&lt;/a&gt; and sign up for a &lt;a href="http://www.braintreepaymentsolutions.com/blog/vulnerability-and-security-assessment-scans-for-pci-dss-compliance/"&gt;quarterly scan&lt;/a&gt; to check vulnerabilities on all outward-facing IP addresses.   A rough estimate for the scans is $150 to $2,500 per IP address per year.  &lt;br /&gt;
&lt;br /&gt;
Other costs may include software and hardware upgrades if information is stored in house.  Gartner estimates that a company with 100,000 credit cards on file will pay $6 dollars in encryption costs per card.  Alternatively, merchants can use technologies such as tokenization where the data storage is remote, which typically have per transaction fees instead of upfront costs.  All of these estimates exclude the cost of labor and the opportunity cost of pursuing other profit-making endeavors.  &lt;br /&gt;
&lt;br /&gt;
Smaller restaurants and retailers that only have a single terminal or POS system are still required to become compliant. Both need to fill out the Self Assessment Questionnaire, but the compliance process is usually much less involved. Merchants that are using POS systems to process credit cards need to make sure they are not improperly storing prohibited card data and need to verify that their vendor is PABP compliant (soon to become PA-DSS).   To verify that your POS system is not storing prohibited information and is compliant, see this updated list was published in &lt;a href="http://www.braintreepaymentsolutions.com/blog/visa-mandates-that-merchants-eliminate-the-use-of-vulnerable-payment-applications/"&gt;November 2007&lt;/a&gt;.  Some merchants such as &lt;a href="http://online.wsj.com/article/SB119042666704635941.html?mod=sphere_ts"&gt;Brad Friedlander&lt;/a&gt;, a restaurant owner in Cleveland with two stores, paid $50,000 on technology upgrades to become compliant. Any merchant that accepts, stores, or processes credit card information is required to already be compliant. &lt;br /&gt;
&lt;br /&gt;
The Card Associations have determined specific dates about when merchants need to validate compliance. Level 1 merchants were required to validate compliance by &lt;a href="http://www.braintreepaymentsolutions.com/blog/sept-30-deadline-passes-for-pci-compliance/"&gt;9/30/07&lt;/a&gt;. Level 2 are expected to validate compliance by &lt;a href="http://www.braintreepaymentsolutions.com/blog/dec-31-2007-is-the-next-big-pci-compliance-deadline/"&gt;12/31/07&lt;/a&gt;.  Level 3 and 4 validation deadlines will come, but at this point they have been left up to the merchant's specific acquirer to be determined.  Not only is becoming compliant not optional, but Card Associations have threatened larger merchants with the imposition of monthly fines until compliance is obtained.   They've also threatened to increase the cost of interchange, which would increase these merchants' processing costs.  But perhaps most importantly, the Card Associations will levy fines and penalties if a merchant is not PCI Compliant at the time of breach. The fines can be devastating to merchants. I've written about two breaches, both of which had significant consequences. One merchant is &lt;a href="http://www.braintreepaymentsolutions.com/blog/pci-compliance-and-the-cost-of-a-credit-card-breach/"&gt;large&lt;/a&gt;, the other is &lt;a href="http://www.braintreepaymentsolutions.com/blog/pci-related-fines-for-breaches-at-small-businesses/"&gt;small&lt;/a&gt;.  &lt;br /&gt;
&lt;br /&gt;
In addition, merchants face remediation and discovery costs can be just as costly, if not more so, than the fines. For a cumulative number, Gartner estimates that the cost of a data security breach can range from &lt;a href="http://www.braintreepaymentsolutions.com/blog/pci-compliance-basics-for-credit-card-secuirty/"&gt;$90 to $305 per customer record&lt;/a&gt;.  Some merchants are frustrated about the PCI requirements, while others see them as basic security requirements that should already be in place. A common misconception is that compliance equals security, but a number of recent breaches have proven that not to be the case.&lt;/p&gt;
&lt;p&gt;Other related posts: &lt;a href="http://www.braintreepaymentsolutions.com/blog/pci-compliance-basics-for-credit-card-secuirty/"&gt;PCI DSS Compliance&lt;/a&gt; basics for credit card security &lt;br /&gt;
&lt;a href="http://www.braintreepaymentsolutions.com/blog/pci-compliance-and-the-cost-of-a-credit-card-breach/"&gt;PCI DSS Compliance&lt;/a&gt; and the cost of a credit card breach  &lt;br /&gt;
Braintree solutions: The Smart Approach to &lt;a href="http://www.braintreepaymentsolutions.com/pci-compliance.php"&gt;PCI DSS Compliance&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/braintree?a=6WxhFxKDjWE:Y9PI1R4qLNc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=6WxhFxKDjWE:Y9PI1R4qLNc:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=6WxhFxKDjWE:Y9PI1R4qLNc:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=6WxhFxKDjWE:Y9PI1R4qLNc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=6WxhFxKDjWE:Y9PI1R4qLNc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=6WxhFxKDjWE:Y9PI1R4qLNc:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=6WxhFxKDjWE:Y9PI1R4qLNc:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=6WxhFxKDjWE:Y9PI1R4qLNc:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/braintree/~4/6WxhFxKDjWE" height="1" width="1"/&gt;</description>
          <pubDate>Wed, 25 Jun 2008 16:18:00 GMT</pubDate>
          <guid isPermaLink="false">http://www.braintreepaymentsolutions.com/blog/what-does-it-cost-to-become-pci-compliant/</guid>
          <link>http://feedproxy.google.com/~r/braintree/~3/6WxhFxKDjWE/</link>
        <feedburner:origLink>http://www.braintreepaymentsolutions.com/blog/what-does-it-cost-to-become-pci-compliant/</feedburner:origLink></item>
        
    
        
        <item>
          <title>ACH and e-check validation and processing </title>
          <description>&lt;p&gt;&lt;a href="http://www.braintreepaymentsolutions.com/blog/wp-content/uploads/2008/05/e-check-processing-and-validation.jpg"&gt;&lt;img width="300" height="202" alt="" src="http://www.braintreepaymentsolutions.com/blog/wp-content/uploads/2008/05/e-check-processing-and-validation-300x202.jpg" title="e-check-processing-and-validation" class="alignright size-medium wp-image-215" /&gt;&lt;/a&gt;  &lt;a href="http://www.braintreepaymentsolutions.com/payment-processing/echeck-and-ach/"&gt;E-checks and ACH debits&lt;/a&gt; are not direct alternative payment types to credit cards. This is primarily due to their respective validation and authorization capabilities.  &lt;br /&gt;
&lt;br /&gt;
With a credit card, a merchant can submit a request to the issuing financial institution and the approval or decline is returned in under 3 seconds. That 'authorization amount' is then guaranteed to the merchant for up to 30 days (depending on the institution and card type).  With an e-check or ach debit, there is 'no real time validation' capability. &lt;br /&gt;
&lt;br /&gt;
The closest thing to it is  'networks' owned by bank and company conglomerates that serve up a 'scoring' system based on shared data.  They use this information to make their best prediction regarding whether an account is open or closed. If there is insufficient information to provide a score, that response is provided as well. &lt;br /&gt;
&lt;br /&gt;
These networks typically cover a high percentage of financial institutions (~95%).  The most important thing to note however is that no &lt;a href="http://www.braintreepaymentsolutions.com/payment-processing/echeck-and-ach/"&gt;e-check or ACH&lt;/a&gt; validation service verifies sufficient or insufficient funds. Even if it could, an authorization request can't 'hold' or 'guarantee' the funds like a credit card transaction.  These limitations are why &lt;a href="http://www.braintreepaymentsolutions.com/payment-processing/echeck-and-ach/"&gt;e-check and ACH payment methods&lt;/a&gt; have not been as widely adopted as credit cards. &lt;br /&gt;
&lt;br /&gt;
They are great payment types for 'trusted' payments such as &lt;a href="http://www.braintreepaymentsolutions.com/recurring-billing/"&gt;recurring billing&lt;/a&gt; for gym membership and utilities, etc. but inadequate for ecommerce or other 'arms length' transactions.  Realizing these short comings, the industry has been trying to get their foot in the door by coming up with a better solution. One such approach allows consumers to choose to pay via their online banking. When that option is selected, the merchant redirects the consumer to their own financial institution's website where they log in and complete the payment. &lt;br /&gt;
&lt;br /&gt;
Thumbs up for the innovation, but as a consumer, I love my credit card and the convenience and protection it provides.  It's certainly a hot topic right now and will be interesting to watch how this plays out.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/braintree?a=pKEWCejP9wk:r9oiVR13V4Y:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=pKEWCejP9wk:r9oiVR13V4Y:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=pKEWCejP9wk:r9oiVR13V4Y:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=pKEWCejP9wk:r9oiVR13V4Y:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=pKEWCejP9wk:r9oiVR13V4Y:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=pKEWCejP9wk:r9oiVR13V4Y:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/braintree?a=pKEWCejP9wk:r9oiVR13V4Y:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/braintree?i=pKEWCejP9wk:r9oiVR13V4Y:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/braintree/~4/pKEWCejP9wk" height="1" width="1"/&gt;</description>
          <pubDate>Fri, 30 May 2008 09:00:00 GMT</pubDate>
          <guid isPermaLink="false">http://www.braintreepaymentsolutions.com/blog/ach-and-e-check-validation-and-processing/</guid>
          <link>http://feedproxy.google.com/~r/braintree/~3/pKEWCejP9wk/</link>
        <feedburner:origLink>http://www.braintreepaymentsolutions.com/blog/ach-and-e-check-validation-and-processing/</feedburner:origLink></item>
        
    
    
  </channel>
</rss>
