User's Manual

DRAFT
MX 900 Series Installation Guide 7
March 1, 2012
PIN Protection Measures
The following techniques can be employed to provide for effective screening of
the PIN-entry keypad during the PIN-entry process. These methods would
typically be used in combination, though in some cases a method might be used
singly.
Positioning of terminal on the check-stand in such a way as to make visual
observation of the PIN-entry process infeasible. Examples include:
Visual shields designed into the check-stand. The shields may be
solely for shielding purposes, or may be part of the general check-
stand design.
Position the PIN Entry Device (PED) so that it is angled in such a way
that PIN spying is difficult.
Installing PED on an adjustable stand that allows consumers to swivel the
terminal sideways and/or tilt it forwards/backwards to a position that
makes visual observation of the PIN-entry process difficult.
Positioning of in-store security cameras so that the PIN-entry keypad is
not visible.
The following table describes the two preferred mounting methods and the
recommended measure to protect from PIN capture in four observation
corridors:
VeriFone also recommends instruction of the cardholder regarding safe
PIN-entry. This can be done with a combination of:
Signage on the PED
Prompts on the display, possibly with a “click-through” screen
Literature at the point of sale
A logo for safe PIN-entry process
Note: For a detailed discussion of PINpad Security Best Practices, see the
MX 900 Reference Manual.
Mounting Methods and Protection Measures
Method Cashier Customer Queue
Countertop without
stand
Use signage
behind the PED
Install so that customer is
between PED and next in queue
Countertop with
Stand
No Action
Needed
Install so that customer is
between PED and next in queue