Security

Does the Heartland breach prove PCI useless?

by Steve Ragan - Jan 26 2009, 17:50

Share


Share

Interested in a more interactive TTH? Join our Facebook Group
Want regular updates from The Tech Herald? Follow us on Twitter

Comment on this Story

Note our older Talkback system is still running below. We hope to import existing comments into the new system shortly. Guest posting is still allowed, however, you can now login with any number of social network accounts.

Talkback

Add your comment (no registration required)

page: 1 

godencrantzJan 27th, 2009 - 02:57:33

PCI ultimately will fail. There is technology available that enables the card number on the magnetic swipe to be changed with each use. I believe this is the only method to insure security. Look up www.privasys.com or www.qsecure.com. Both offer technology that make a credit card number history and not personal information.

Report this comment

AdmynJan 28th, 2009 - 15:07:08

PCI is not useless, it is a security measure, not a security solution, being compliant does NOT mean you are secure.

Report this comment

PCI MattersSep 17th, 2009 - 22:15:15

PCI is very relevant and is providing significant preventative controls today that without the work that has been invested in, we would easily see multiple times the compromises we are seeing today. However I think that it could be said that multiple times the amount of the actual breach losses is spent in PCI compliance. One of the major problems is getting this industry to take controls seriously as an ongoing security process.

The industry started 6 years ago as a total joke in terms of data security (not just with regards to card data)with almost no controls and really negligent approaches to information security. PCI was a response to this and in many cases where merchants, service providers, application vendors and processors took security and controls to heart and not just compliance they have made huge strides in information protection. Many of these merchants and service providers have gained huge benefits in process improvements and innovation in IT technology as part of their remediation.

I would say that one area that has failed in PCI compliance alongside merchants not taking it seriously as a process is QSA's that provide negligent assessment work and just execute check list audits. If you look at the recent major breaches you will see Trustwave attached to most of them. They are known to provide cookie cutter, fast-food versions of assessments by junior QSA’s with little experience and customers are left with a false sense of security by achieving their “SEAL” of compliance. Worse yet they try to sell a bunch of managed security services to 'make' them compliant that should be a conflict of interest to start with.

The jist is that if merchants and SP don't take the intent of PCI to heart and address security alongside compliance and don't select a competent QSA that will help them implement a real program then you will see everyone say PCI is failing. The question should be who is failing PCI.

Report this comment

page: 1 

Add your comment (no registration required)

AddThis Social Bookmark Button

Advertising

Advertising

Advertising

Latest

Review: Motorola Droid
Facebook settlement means little in the long run
Naked Windows 7 vulnerable to Malware if left in default state
Adobe patches Shockwave Player
SSL flaw allows man-in-the-middle attacks

Latest Articles on Monsters&Critics

'Ghost Lab' uncovers the spectre of John Wilkes Booth, Nov. 10
Taiwan man has been catching rats for mom for 24 years
Camoranesi's brace triggers Juve's hammering of Atalanta (Roundup)
Pedro the hero as Barcelona thrash Mallorca (1st Lead)
Peres: "Peace process is not a lost case"
Djokovic, Federer to face off for fifth time this season (2nd Roundup)
Imperious Arsenal go second; Spurs into top four (Roundup)
Nine-man Deportivo move up to fourth by winning in Getafe
Storm Chasers 'Inside the Tornado' Sunday, Nov. 8
Napoli lose momentum against lowly Catania

Notice: Undefined index: continent in /home/thetechh/public_html/class/class.slot.php on line 173

Notice: Undefined index: continent in /home/thetechh/public_html/class/class.slot.php on line 173

Notice: Undefined index: continent in /home/thetechh/public_html/class/class.slot.php on line 173

Notice: Undefined index: continent in /home/thetechh/public_html/class/class.slot.php on line 173