dbltoe:
I offer two comments.
Some merchant accounts will require SSL for your site even if you process the transaction off-site.
Certainly, if you gather any customer data, PCI compliance is mandatory whether the transaction is made on the site, off-site, by phone, etc.
This is ridicularly incorrect. What if a merchant doesn't even have a website (or one used as a showcase only, with orders to be made by phone only)?. In the first instance it isn't possible to have SSL on a site that doesn't exist. In the second instance, the customers CC details are never transmittted across the 'net anyway, so SSL is a non player.
dbltoe:
Certainly, if you gather any customer data, PCI compliance is mandatory whether the transaction is made on the site, off-site, by phone, etc.
Yes, it is true that merchant taking orders by phone (and even in a physical store) must be PCI compliant, but this compliance has more to do with how/where the customers data is stored than it does in regards to how the data is obtained.
SSL only comes into play if the CC data is transfered across the internet, and if a store doesn't do thier own CC processing, for example, using PayPal IPN or PayPal Express then the SSL encryption is performed between the customer and the payment processor (not the merchants store), therefore such sites are PCI compliant in this regard. The merchants own site isn't required to have SSL.
If this were NOT the case then surely PayPal itself would be in breach of the PCI requirements?
PayPal Payments Pro is a different ballgame, because the CC details are sent from the customer to the merchant (and then processed via PayPal), therefore SSL is mandatory. Other payment processors work the same way, with the same requirements.
dbltoe:
Certainly, if you gather any customer data, PCI compliance is mandatory whether the transaction is made on the site, off-site, by phone, etc.
I need to be a bit pendatic here. There is no PCI requirement for storing (or transmitting) of customer data. Any such requirements would be store policy, or some other policy (ISO accreditation for example, and even then it becomes more of a side effect of the manadory customer privacy policy, with nothing to do with PCI).
PCI compliance covers the transmission & storage of data that will identify any given customer with his/her CC details. If the CC details aren't stored (on the merchants site) then this is no connection between the CC information and whatever other information a merchant may or may not choose to store on their site.
dbltoe:
Now a question. If one of the main requirements of PCI compliance is to Encrypt transmission of cardholder data across open, public networks how can one accomplish this without an SSL?
Isn't this obvious? By using a Payment processor, such as PayPal where the transmission of the cardholder data is transmitted from the card holder directly to the payment processor and never touches the merchants store in any way, shape or form. The data is enctryped by PayPal's SSL. The stores SSL (if they had one) doesn't come into play.
Incidently, SSL is nowhere near one of the 'main' requirements of PCI,which "provides an actionable framework for developing a robust account data security process - including preventing, detecting and reacting to security incidents". SSL is just an essental but minor component of this framework.
Since most merchants don't do their own CC processing these days then PCI compliance it a complete non issue (but it does highlight good security practices).
Those merchants that DO process CC payments ON THEIR OWN WEBSITE OR BY PHONE, etc, MUST be fully compliant with the PCI requirements, but sadly, many aren't. Sure, they'll comply with the "Encrypt transmission of cardholder data across open, public networks" by purhasing a $12.00 SSL (even though a self signed certificate is also fully compliant), and sure, many of them will do a "PCI compliance scan" of their website to meet the 'prevention' requirements, but that is generally where their compliance ends. Very few merchants (ISO accredited companys excluded) have any policy or plans to cover the detection of 'security incidents' and even less have a policy as to how to react to any such incidents. With no written policy in place these merchants are only partially PCI compliant. Fortunately<?> (for them, but not thier customers) audits are rare, so most get away with this partial compliance - Well, that is until their database gets compromised and all of their stored CC data is released to the public, and THEN they have some serious question to answer, and will be subject to prosecution... In the meantime they are quite happy to live in ignorance because they appear to be compliant because they have SSL and are using a server that has at some time or other been scanned for vulnerabilities.
I didn't spend ~5 years of training just to learn how to set up a firewall, or how encyrption works, it also covered topic as PCI compliance, ISO900x compliance, Government Security policy, and a shop load of other 'boring paperwork' that is essential for someone trained to act in a IT security advisory capacity.
I don't expect to be able to teach all I have learned in these forums, but I can at least put my training into practice by dispelling some of the myths and replacing them with facts. Not to show how 'clever' I am, but for the benefit of those few people that are willing to read and learn.
Nothing I have stated is a 'secret', and every word of it can be verified from many different sources. The hard part is wading through all the information availalbe, most of which is provided by companies that sell SSL certificates, so naturally they only write about what is in thier best interests and make little or no attempt to go any deeper than that, because to do so is going to cost them sales.
By all means, feel free to discuss PCI compliance further (if you must), but please don't make the mistake of thinking that SSL is a 'main part' of compliance because nothing could be further from the truth.
Cheers
Rod (adv dip network security)