Folks there is a lot of truth and more rumor in this post about security... This is EXACTLY what I do every day... I am a certified CPISM (Certified Payment-Card Industry Security Manager) I deal with Visa, Mastercard, Discover, JCB and American Express every day.... I provide security and risk management for roughly 10,000 level 4 merchants, 100 level 3 merchants, and our own companies level 1.
The number one compromise is not from using websites (It is definatley on the high list) but from Integrated Point of sale machines. These are your mom and pop shops that usually purchase a computer that processes credit cards and keeps customer information on hand. The communications are typically broadband and they have no IT group in place to manage a firewall, virus protection or good business policies. Your card data is stored on those computers for many many years, until the past couple of years there wasnt any regulation on these systems but now there are PCI (Payment Card Industry) requirements as well as a newly formed group called the PCI SSC or Payment Card Industry Security Standards Council. This group now requires that the software companies sell meet a very difficult set of guidlines including encryption, storage, communications and the management of all of these things...
Next time you go inside any store look and see if they use a little device with a keypad to swipe the card and then push a fwe buttons on it or if they swipe a card into a system and it prints out on a nice piece of paper on a printer or if it just prints on a small receipt printer with no card swipe or keys. I challenge you to this because every time that you allow someone to swipe you card into a computer you are probably having your data saved on a hard drive there in that shop.
A perfect example is recently when I went to get my hair cut I walked up to the counter and noticed they had an Integrated POS system, I obviously distracted the receptionist and she said yes we swipe the card here and it comes up on the screen. I asked her if she new anything about PADSS (Payment Application Data Security Standards) from Visa and she said no. We started discussing it and she invited me around the corner to take a look. (This was scary that she just let me behind the counter to play with her computer) but I noticed that she was browsing the Internet on the very computer that she wanted to swipe my card on...
You need to protect yourselves and make sure that your letting the right places touch your cards.... How do you think that TJ Maxx was hacked? Insecure wireless communications...
The list goes on and on of how hackers get the data, its not your local script kiddies either its organized crime stealing this data....
If any of you have any questions about security please let me know so I can help...
cap