But what about security within the application How do you know that the app itself isn t just storing up all the card numbers it reads and that nice little old lady selling tomatoes from her van isn t going to go home and clean out everyone The fact is that you don t. And that s where PCI comes in. The Payment Card Industry Security Standards Council is a group of credit card providers (American Express, Discover, JCB, MasterCard, and Visa) that have formed a regulatory board that enforces security standards on, among other things, vendors of transaction processors such as credit card apps for the iPhone. When the Government decided that individuals would only be responsible for a maximum $50 of fraudulent charges on stolen credit cards, that burden shifted to the credit card providers. The companies banded together to try and minimize their losses (estimated at over $4 billion annually). NOTE: PCI security standards encompass a lot more than just credit card processing applications. For more information, go to For developers of applications that process credit cards, whether it be iPhone apps such as the one shown in Figure 8 3 or simple web apps that use the https:// post mechanism, come July 1, 2010 all applications must be certified by the PCI Security Council. What this means is that any applications that are not certified as being in compliance will not be usable.
