Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Siddique Hameed - Security for WooCommerce Payments

WooConf
April 07, 2016

Siddique Hameed - Security for WooCommerce Payments

Security for WooCommerce Payments

There is a huge gap among small businesses and their customers across the U.S. Over 90% of consumers are shopping online, yet only 28% of businesses have an online store. Businesses cite security and risk as some of the largest obstacles to selling online. Security for payments is continuously improving and evolving. In this presentation you will learn about the latest initiatives on how to provide a secure payments experience for your customers and your business. You will also hear best practices for managing risk from an expert in the payments industry.

WooConf

April 07, 2016
Tweet

More Decks by WooConf

Other Decks in Technology

Transcript

  1. ©2016 MasterCard 83 Card Not Present(CNP) fraud is a major

    concern for U.S. merchants and is expected to grow. Source: 1. TBD, Seven times harder to detect and prevent card not present fraud vs card present transactions. The U.S. is responsible for 47 percent of the world’s card fraud despite only accounting for 24 percent of total worldwide card volume. Online CNP fraud has increased by 120% in past decade.
  2. ©2016 MasterCard 84 How your business is at risk Making

    sales is a must, but you can’t get afford to fall victim to fraud. of US merchants who sell online are reporting increased CNP fraud3 42% Increase in fraudulent transactions from H2 2013 to H1 20141 1 in 86 transactions were fraudulent 32% Increase in fraud
 attempts on digital goods in Q3 of 20152 254% Source: 1.. ACI Worldwide, 2. Forter Global Fraud Index, 3. The Strawhecker Group
  3. 1. Cardholder submits MasterCard account to merchant Merchant’s bank asks

    MasterCard to determine cardholder’s bank MasterCard validates and approves sending to issuer’s bank for purchase approval Issuer’s bank approves the purchase MasterCard sends approval to merchant’s bank Merchant’s bank sends approval to Merchant Transaction Security Tokenization AVS/CVC Checks Velocity Checks Avoid Data Breach Avoid Fraudulent Card Use Location Checks
  4. GET /security/getme.php? name=Rahul&submit=submit HTTP/1.1 Host: www.rahuldeshpande.net Connection: keep-alive Accept: text/html,application/xhtml

    +xml,application/xml;q=0.9,*/*;q=0.8 User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_8_4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/29.0.1547.65 Safari/537.36 Accept-Encoding: gzip,deflate,sdch Accept-Language: en-US,en;q=0.8 https://www.rahuldeshpande.net/security/getme.php?name=Rahul http://www.rahuldeshpande.net/security/getme.php?name=Rahul SSL at Transport Layer
  5. Your website (server) Customer (browser) Payment Gateway Credit Card Information

    PCI Exposure - sensitive data Credit Card Information
  6. AVS/CVC Address Verification Service/ Card Verification Codes • Lower fraud

    • Chargebacks • Higher approval rate • Flag potential issues with orders
  7. Location Checks for Fraud • Billing vs. Shipping address •

    IP address vs. billing • Person using a proxy • Known networks • IP location – country • Which country the card is registered
  8. Velocity Checks for Fraud • Number of payments by the

    same card • IP address • Device • Email • Number of payments
  9. Start accepting payments now. It’s that simple. • Merchant account

    • Instant acceptance • Built by MasterCard Simplify Commerce