Alex Bainbridge's Musings on travel ecommerce blog
Musings on travel ecommerce blog
Blog home  Blog home

Are retail hotel OTA’s trading in compliance with the PCI credit card standards?

Monday, March 31st, 2008

Last week Tim Hughes from “The BOOT” (a blog about the business of online travel) highlighted, in this post, that 2 well known hotel online travel agents (OTAs) allegedly maintain lax security on their customer credit card data.

In particular Tim mentions

  • Booking.com (part of Priceline - Nasdaq:PCLN) - Europe’s leading online hotel reservations agency by room nights sold (Based in Holland)
  • CentralR.com - An online hotel reservation company based in Ireland

The prolem that Tim outlines is a process problem not unique to how the two named agents operate. In essence the business process is as follows:

  1. Customer makes online booking on an online hotel reservation website (or partner site)
  2. The end customer gives their credit card information to the central website
  3. The credit card details are transmitted (sometimes by fax) to the end hotel. The hotel can then use these credit card details in order to charge a customer in the event that they cancel or “no show” their reservation. The detail that is transmitted to the hotel contains all information required to charge a card, including the ID number found on the back of cards.

So what is wrong with this?
All companies that handle credit card information have to comply with the PCI (Payment Card Industry) credit card standards.

Adherence to these standards isn’t voluntary - but mandatory. They are agreed by both Visa and Mastercard and are the industry standard.

Some sample standards that can be found in the document….

  1. The CVC2/CVV2/CID numbers are not permitted to be stored
  2. Sensitive information must be encrypted during transmission over networks that are easy and common for a hacker to intercept, modify, and divert data while in transit (Alex’s note - this I assume includes fax machines)
  3. Identify all users with a unique user name before allowing them to access system components or cardholder data (Alex’s note - NOT generic usernames or one username per hotel)
  4. Change passwords at least every 90 days
  5. Physically secure all paper and electronic media (including computers, electronic media, networking and communications hardware, telecommunication lines, paper receipts, paper reports, and faxes) that contain cardholder data
  6. Maintain strict control over the internal or external distribution of any kind of media that contains cardholder data including the following:
    1. Classify the media so it can be identified as confidential
    2. Send the media by secured courier or other delivery method that can be accurately tracked (Alex’s note - this onus is on the sender, not the recipient - so the hotel booking agency can’t say that it is down to the hotel how they secure their incoming faxes)
  7. Screen potential employees to minimize the risk of attacks from internal sources (Alex’s note - unless the employee is a store cashier who only have access to one card number at a time)
  8. If cardholder data is shared with service providers, then contractually the following is required:
    1. Service providers must adhere to the PCI requirements (Alex’s note - i.e. hotels must adhere)
    2. Agreement that includes an acknowledgement that the service provider is responsible for the security of cardholder data the provider processes

and I could go on…..

The last standard is an interesting one…. it seems to put the onus on the hotelier to adhere to PCI standards…. so perhaps this is what the hotel OTAs are relying on.

Conclusion
It seems that as a result of working with many small and independent hotels that somehow letting the hotel receive the card details is the only way that these large OTA hotel booking agencies are able to operate their business.

Is their whole business model at risk?

After all, hotels are known for employing temporary staff…. and as comments in Tim’s original post point out many hotels store credit card numbers in excel files on desktop computers…. The credit card providers are becoming tougher and tougher with ensuring PCI compliance so watch out hotels……


If you want to be notified next time something is published sign up for email alerts or subscribe to the RSS feed. Thank you for reading!





More posts (maybe related, maybe not)


2 Responses to “Are retail hotel OTA’s trading in compliance with the PCI credit card standards?”


  1. April 11th, 2008 at 12:56 pm
    Diane Shaib

    Orbiscom Ltd, a Dublin Ireland based company, originated a product in 1999 that can handle this issue…and the product is offered for free on credit and debit cards by many of the world’s leading credit and debit card issuers in the US and Europe (Citibank, Bank of America, PayPal, etc). A disposable card number, linked to a consumer’s real card number, is generated along with a one-time-use CVV and expiration date. These details can be given to the hotel when making a reservation and if the data is compromised there is no risk to the consumer since the disposable numbers were generated with specific controls set for the hotel, an amount, and an expiration date. The disposable numbers can then be used to settle the bill when the consumer checks out, or the consumer can put the bill on the “real” card account. The card companies have not done a lot of marketing for these products so many consumers do not even know they have access to them. I suggest people call their card company and ask how to sign up (it’s free) or ask why their company does not offer them if they don’t. Millions of cardholders have used them so far…on billions of dollars of e-commerce.

  2. April 16th, 2008 at 9:35 am
    Alex Bainbridge

    Diane,
    Thank you for your feedback.

    The PCI standards don’t distinguish between storage of “throwaway” credit card numbers vs “real” numbers. (Probably because they can’t be distinguished without specific knowledge?).

    So I can see how your system could help consumers - but not help the hotels - or am I missing something?




This blog is about travel ecommerce with a focus on topics of interest to tour operators & travel companies

Alex has previously started up a small tour operator (5 staff) and also worked for leading "dot coms", airlines, hotel chains and tour operators advising and project managing web, ecommerce and reservation system projects.

Alex is available for travel ecommerce consulting via Travel UCD. Travel UCD also operates TourCMS - a web based reservation system for small tour operators


RSS Feed

Subscribe via daily email



AddThis Feed Button

Homepage
About this blog
Best of the blog (top 10 posts!)

Recent comments
Tamara: It’s a lot of money! But I guess it’s probably good value for the column inches it generates - of course as long as you get to the top five! To guarantee that it looks like you have to have...

Alex Bainbridge: Hi Tamara …. as for PhoCusWright….. I am sure that at the point the judges judged they were impartial - however it was a fairly self selecting group who put themselves forward to be judged...

Darren Cronian: Alex, I am worried that we are becoming on the same wave length. http://www.traveldotnet.co.uk/ articles/lets-not-forget-offli ne-travel-innovation/ No, I have just read this post now, I didn’t...

Pete Meyers: Alex - I’m really looking forward to hearing the pirate story, well done!

Ben Colclough: I must say I had more fun acting out a chicken in a restaurant in Yunnan, China than I would have had with the flip book. Seriously though - it is a good idea & innovative. Not sure I would want to...

Alex Bainbridge: Hi Pete The times I would have found this useful (PocketComms) I really wouldn’t have wanted to put an iphone into someone elses hands! For example negotiating with a people smuggling ship in...

Pete Meyers: I think the best innovation is a combination of great ideas and succinct execution. To your example about the PocketComms, it was a good idea that fermented for a number of years, yet who’s to say...

Tamara: This is an interesting debate. I wonder what the PhocusWright judges views are. They seemed to be very clear however that they wanted to reward companies who had actually created something - rather than simply...

Ben Colclough: P&G, generally regarded as a very innovative large consumer branded company has an approach to innovation that throws some light on this. They embrace failure as a necessary part of innovation. This...

Categories
Top commentators
Kevin May
Darren Cronian
Jeremy Head
John
Ben Colclough
Alex Bainbridge
graham steele
Ian McKee
Big Travel Web
Tamara
Guillaume
Ignacio
Neil MacLean
Dominic
John Pyle

Other travel & tourism blogs
Travolution
The Boot
Hotel Blogs
Travel Rants
TraveBlather
Travel PR Blog
Dot Tourism
Albert Barra [Spanish]

Wiwih blogs - a directory of travel industry blogs

Small Fish Big Ocean

Come and join my travel business social network! for small tour operators and niche agents


TourCMS