<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Card Swipe Devices, Hosted Payment Forms, &amp;amp; PCI Compliance in Integration and Testing</title>
    <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Card-Swipe-Devices-Hosted-Payment-Forms-amp-PCI-Compliance/m-p/30210#M15814</link>
    <description>&lt;P&gt;I'm the developer for a desktop software application uses the SIM method/Hosted Payment Form to process payments through Authorize.net. In the past, many of our customers have used a standard (non-encrypted) magnetic card swipe reader in conjunction with the SIM Hosted Payment Form to input the cardholder data.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Recently, however, there's been some concern over whether this is PCI Compliant, and if they should be using a reader that supports point-to-point encryption. I know that MagTek has a reader on the market that works with Authorize.net, and I understand that using the encrypted reader is probably a better, more secure&amp;nbsp;solution,&amp;nbsp;but my question is this--is using a standard, un-encrypted reader with a Hosted Payment Form still permissable under the PCI DSS? Since using a standard card reader (which basically emulates keyboard input) is really no different than keying in the card number with the keyboard (and that's still permissable--right?), I don't see why it wouldn't be.&lt;/P&gt;</description>
    <pubDate>Fri, 28 Sep 2012 13:56:55 GMT</pubDate>
    <dc:creator>silentsky</dc:creator>
    <dc:date>2012-09-28T13:56:55Z</dc:date>
    <item>
      <title>Card Swipe Devices, Hosted Payment Forms, &amp; PCI Compliance</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Card-Swipe-Devices-Hosted-Payment-Forms-amp-PCI-Compliance/m-p/30210#M15814</link>
      <description>&lt;P&gt;I'm the developer for a desktop software application uses the SIM method/Hosted Payment Form to process payments through Authorize.net. In the past, many of our customers have used a standard (non-encrypted) magnetic card swipe reader in conjunction with the SIM Hosted Payment Form to input the cardholder data.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Recently, however, there's been some concern over whether this is PCI Compliant, and if they should be using a reader that supports point-to-point encryption. I know that MagTek has a reader on the market that works with Authorize.net, and I understand that using the encrypted reader is probably a better, more secure&amp;nbsp;solution,&amp;nbsp;but my question is this--is using a standard, un-encrypted reader with a Hosted Payment Form still permissable under the PCI DSS? Since using a standard card reader (which basically emulates keyboard input) is really no different than keying in the card number with the keyboard (and that's still permissable--right?), I don't see why it wouldn't be.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Sep 2012 13:56:55 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Card-Swipe-Devices-Hosted-Payment-Forms-amp-PCI-Compliance/m-p/30210#M15814</guid>
      <dc:creator>silentsky</dc:creator>
      <dc:date>2012-09-28T13:56:55Z</dc:date>
    </item>
    <item>
      <title>Re: Card Swipe Devices, Hosted Payment Forms, &amp; PCI Compliance</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Card-Swipe-Devices-Hosted-Payment-Forms-amp-PCI-Compliance/m-p/30332#M15872</link>
      <description>&lt;P&gt;The Server Integration Method (SIM) is used to present a payment form to the customer so that they can key in their card information for a Card Not Present (CNP) transaction. This method is not to be used with any kind of card reader, as that would, by definition, be a Card Present (CP) transaction.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;CNP and CP transactions are handled completely differently by card processors and require differently configured Authorize.Net accounts. Authorize.Net provides a separately documented CP API which allows you to read and submit track data that you have gathered with a card reader. At this time, we do not yet support encrypted card readers through any of our APIs.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Oct 2012 19:26:44 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Card-Swipe-Devices-Hosted-Payment-Forms-amp-PCI-Compliance/m-p/30332#M15872</guid>
      <dc:creator>Trevor</dc:creator>
      <dc:date>2012-10-01T19:26:44Z</dc:date>
    </item>
  </channel>
</rss>

