We now live in a world where a software application can enable a smartphone to accept payments from contactless cards, mobile phones, and smartwatches. The shift from traditional hardware-based payment solutions to software-based solutions presents a big opportunity for micro-merchants but it also brings new challenges. The largest of those challenges is security.
Here's an in-depth overview of the security aspects of a SoftPOS solution:
1. Device Diversity and the "Untrusted Device" Paradigm:
SoftPOS solutions are designed to run on various models of smartphones, known as Commercial Off-the-Shelf (COTS) devices. These devices come with diverse underlying hardware and software configurations, making it challenging to rely solely on the security of the device or its mobile operating system. Consequently, the security approach for SoftPOS revolves around treating the mobile device as "Untrusted," where the software must provide robust protection against a wide range of potential threats.
2. Security Testing and Evaluation:
Before SoftPOS solutions can start accepting payments, they undergo rigorous testing and security evaluations. These assessments are crucial to ensure that the software can withstand various forms of attacks, from malware and remote intrusions to physical access by malicious actors.
3. Industry Standards and Certification Bodies:
Two prominent industry bodies play a pivotal role in certifying and ensuring the security of SoftPOS solutions:
4. EMVCo SoftPOS Certifications:
The security evaluation assesses whether the two components work seamlessly to perform regular checks on the security status and integrity of the solution and if necessary, mitigate any detected threats. These checks include but are not limited to device tampering, rooting, debug mode, emulation, malware protection, side-loading and device binding amongst other checks.
5. PCI SSC SoftPOS Certifications:
6. Monitoring and Attestation
SoftPOS solutions require a monitoring and attestation system for terminals to swiftly identify any potential intrusion or tampering, thus ensuring the security of all transactions. Solutions must implement comprehensive mechanisms to assess the softPOS terminals' well-being, temperature, security, and root status, among other factors. The provision of real-time reporting, remote management, and device access empowers efficient device management and enhances overall security.
SoftPOS solutions have evolved to offer a flexible and versatile way of accepting payments using mobile devices. Security remains paramount in this space. With certifications from EMVCo and the PCI SSC solutions are robust, capable of withstanding threats, and compliant with industry standards. This commitment to security is essential to maintain customer trust and confidence in the ever-evolving world of digital payments. At Lipa Payments, we handle all necessary certifications, ensuring that when you white-label our solution or utilise our SDK, you can do so with confidence, free from security concerns.
Try our
Lipa SoftPOS payment system today to see how easy it is to use, or
contact us for a personalised consultation and we will help you get started with digital payments.