Home / Companies / Evervault / Blog / April 2025

April 2025 Summaries

4 posts from Evervault

Filter
Month: Year:
Post Summaries Back to Blog
Japan is experiencing a rise in online fraud, prompting updates to the Credit Card Security Guidelines, including a mandate for the implementation of the 3D Secure protocol by March 2025. 3D Secure adds an extra layer of authentication to online credit card transactions, aiming to prevent fraudulent activities and shift liability away from merchants. As e-commerce grows, especially in sectors like recurring payments and cross-border transactions, businesses need to adopt these security measures to comply with the revised guidelines. The guidelines, updated by the Japan Consumer Credit Association and the Ministry of Economy, Trade and Industry, require stronger data protection and widespread adoption of 3D Secure, with specific deadlines for businesses, acquirers, and credit card issuers. Early adopters of 3D Secure not only meet regulatory requirements but also gain a competitive advantage by reducing fraud risk and enhancing customer trust. Evervault offers a flexible, developer-friendly solution to implement 3D Secure, allowing seamless integration with existing payment infrastructures without vendor lock-in. As the deadline approaches, businesses are encouraged to act promptly to ensure compliance and safeguard their operations against fraud.
Apr 10, 2025 1,868 words in the original blog post.
3D Secure (3DS) is a security protocol aimed at reducing fraud in online card-not-present transactions by adding an authentication step during checkout, and while it hasn't been widely adopted in the US compared to the European Union, the trend is shifting as US businesses recognize its benefits in reducing fraud without significantly impacting conversion rates. The second version, 3DS2, addresses earlier issues such as clunky user interfaces and transaction abandonment by offering a risk-based authentication model that supports frictionless flows for low-risk transactions and seamless biometric verification for higher-risk cases. Despite initial hesitations due to concerns over conversion rates and implementation difficulties, modern 3DS provides enhanced customer experiences and significant fraud prevention advantages, including liability shifts for chargebacks, which can be critical for businesses vulnerable to fraud. Providers like Evervault offer solutions that integrate 3DS without locking businesses into specific processors, allowing for customizable and scalable implementations that preserve brand experience. As digital commerce and mobile payments increase, along with rising fraud threats, US adoption of 3DS is gaining momentum, driven by advancements in the protocol and global consumer expectations for robust online authentication measures.
Apr 10, 2025 2,374 words in the original blog post.
Tokenization has been a fundamental method for securing card data, traditionally achieved through static tokens tied to a specific merchant, but has evolved with the introduction of network tokens, which offer dynamic and flexible security managed by entities like Visa and Mastercard. While traditional card tokenization is simple and cost-effective, it faces limitations such as the need for manual updates and its inability to operate across multiple merchants, often leading to transaction declines. In contrast, network tokens support automatic updates, work across various merchants and channels, utilize transaction-specific cryptograms for enhanced fraud prevention, and offer a seamless customer experience even when card details change. Despite the advantages of network tokens, their implementation can be complex, requiring significant updates to payment systems and potentially leading to vendor lock-in for smaller merchants. As card networks advocate for the adoption of network tokens due to their superior authorization rates and fraud reduction capabilities, these modern tokens are poised to become the standard in secure payment solutions, although traditional methods still hold value for businesses with less complex needs.
Apr 07, 2025 957 words in the original blog post.
During a webinar titled "A Practical Guide to PCI Script Security and 6.4.3 and 11.6.1 Compliance," several key questions and their answers were shared regarding PCI compliance. Non-compliance with PCI can lead to fines, determined by card brands and potentially passed to merchants via acquirers. The difference between third-party and Level 1 iFrames was clarified, emphasizing that only Level 1 PCI DSS compliant service providers should serve iFrames for cardholder data. Acquirers may conduct spot audits using Qualified Security Assessors (QSAs) to verify Merchant SAQs, with the findings reported to card brands, who then decide on compliance actions. PCI DSS compliance enforcement varies; merchants are typically held accountable by their acquiring banks, whereas service providers may face enforcement from card brands or customer demands. While a Content Security Policy (CSP) is useful, it may not suffice alone for 3D-Secure workflows, and alternative monitoring methods for script changes are recommended. Key security-related HTTP headers to monitor include CSP, HSTS, and others, with some deprecated in favor of CSP directives. The webinar offers insights into managing browser scripts in line with PCI DSS 4.0 requirements.
Apr 01, 2025 677 words in the original blog post.