<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>Retail Information Security</title>
	
	<link>http://www.retailinfosec.com</link>
	<description>Retail &amp; Hospitality Information Security (including PCI)</description>
	<pubDate>Fri, 03 Sep 2010 15:46:02 +0000</pubDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
			<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/retailinfosec/aloi" /><feedburner:info uri="retailinfosec/aloi" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><item>
		<title>Interesting Posts Summary</title>
		<link>http://feedproxy.google.com/~r/retailinfosec/aloi/~3/UdrpvJ4HdE4/</link>
		<comments>http://www.retailinfosec.com/2010/09/03/interesting-posts-summary/#comments</comments>
		<pubDate>Fri, 03 Sep 2010 15:46:02 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Interesting]]></category>

		<category><![CDATA[Retailers]]></category>

		<category><![CDATA[application security]]></category>

		<category><![CDATA[article]]></category>

		<category><![CDATA[Articles]]></category>

		<category><![CDATA[business]]></category>

		<category><![CDATA[cloud security]]></category>

		<category><![CDATA[EMV]]></category>

		<category><![CDATA[Magnetic stripe card]]></category>

		<category><![CDATA[Payment Card Industry Data Security Standard]]></category>

		<category><![CDATA[payment security]]></category>

		<category><![CDATA[security]]></category>

		<category><![CDATA[skimming]]></category>

		<category><![CDATA[VISA]]></category>

		<guid isPermaLink="false">http://www.retailinfosec.com/?p=462</guid>
		<description><![CDATA[I&#8217;ve been traveling a lot lately and, although I&#8217;ve read and had lots of commentary about a number of blog posts and news article recently relating to retail security, I haven&#8217;t had the time to write them down and post them&#8230;
So I&#8217;ve decided that I&#8217;m going to post a summary of the posts and articles that I&#8217;ve read over the last week or so that I&#8217;ve thought were interesting and relevant.  This isn&#8217;t what I&#8217;d really prefer to do - I&#8217;d much rather take the opportunity to rant about something ...]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve been traveling a lot lately and, although I&#8217;ve read and had lots of commentary about a number of blog posts and news article recently relating to retail security, I haven&#8217;t had the time to write them down and post them&#8230;</p>
<p>So I&#8217;ve decided that I&#8217;m going to post a summary of the posts and articles that I&#8217;ve read over the last week or so that I&#8217;ve thought were interesting and relevant.  This isn&#8217;t what I&#8217;d really prefer to do - I&#8217;d much rather take the opportunity to rant about something or to try to explain something that we&#8217;ve seen out in the &#8216;real world&#8217;, but sometimes you just don&#8217;t have the time, so forgive me my laziness this time around.</p>
<p><a href="http://http://pymnts.com/heartland-payment-systems-and-discover-agree-to-5-million-intrusion-settlement-20100901006944/" onclick="javascript:pageTracker._trackPageview('/outbound/article/pymnts.com');">Heartland and Discover Agree to Settlement</a></p>
<p><a href="http://www.ehospitalitytimes.com/?p=2722" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.ehospitalitytimes.com');">PCI Compliance - Why Spas, Hotels, and Resorts Can No Longer Ignore IT</a></p>
<p><a href="http://www.netspi.com/blog/2010/09/02/security-in-the-cloud/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.netspi.com');">NetSPI Blog - Security in the Cloud</a></p>
<p><a href="http://www.storefrontbacktalk.com/securityfraud/visa-raises-the-bar-for-pa-dss-applications-and-vendors/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.storefrontbacktalk.com');">Some Additional Commentary on VISA Payment Security Best Practices Guidelines&#8230;</a></p>
<p><a href="http://www.americanbanker.com/btn_issues/23_9/the-fed-gets-involved-with-emv-1024784-1.html" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.americanbanker.com');">The Fed Gets Involved with EMV</a> (I find EMV an interesting topic although I might be alone in this&#8230;)</p>
<p><a href="http://www.bankinfosecurity.com/articles.php?art_id=2877" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.bankinfosecurity.com');">Skimming: Old Crime, New Tools</a> (this one is also interesting to me)</p>
<p>I hope that you find these article interesting and I&#8217;ll get back to more comment-rich posting shortly.  Thanks!</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://pindebit.blogspot.com/2010/07/european-payments-council-newsletter.html" onclick="javascript:pageTracker._trackPageview('/outbound/article/pindebit.blogspot.com');">European Payments Council Newsletter: New Business Opportunities with Chip and PIN</a> (pindebit.blogspot.com)</li>
<li class="zemanta-article-ul-li"><a href="http://pindebit.blogspot.com/2010/07/is-us-wising-up-to-smart-card-use-in.html" onclick="javascript:pageTracker._trackPageview('/outbound/article/pindebit.blogspot.com');">Is U.S. &#8220;Wising Up&#8221; to Smart Card Use in America?</a> (pindebit.blogspot.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.zemanta.com');"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/zemified_e.png?x-id=6b82c886-8c68-4800-ab92-1dab440067e1" alt="Enhanced by Zemanta" /></a><span class="zem-script more-related more-info pretty-attribution paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>

<!-- Chitika|Premium - WordPress Plugin --><div class="chitika-adspace below"><script type="text/javascript"><!--
ch_client = "acrittenden";
ch_type = "mpu";
ch_width = 468;
ch_height = 120;
ch_color_bg = "";
ch_color_title = "";
ch_color_site_link = "";
ch_color_text = "";
ch_non_contextual = 4;
ch_vertical = "premium";
ch_font_title = "";
ch_font_text = "";
ch_sid = "wordpress-plugin";
var ch_queries = new Array( );
var ch_selected=Math.floor((Math.random()*ch_queries.length));
if ( ch_selected < ch_queries.length ) {
ch_query = ch_queries[ch_selected];
}
//--></script>
<script  src="http://scripts.chitika.net/eminimalls/amm.js" type="text/javascript"></script></div><img src="http://feeds.feedburner.com/~r/retailinfosec/aloi/~4/UdrpvJ4HdE4" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.retailinfosec.com/2010/09/03/interesting-posts-summary/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.retailinfosec.com/2010/09/03/interesting-posts-summary/</feedburner:origLink></item>
		<item>
		<title>Some Security Metrics Education</title>
		<link>http://feedproxy.google.com/~r/retailinfosec/aloi/~3/GRMhcwoBRCM/</link>
		<comments>http://www.retailinfosec.com/2010/08/25/some-security-metrics-education/#comments</comments>
		<pubDate>Wed, 25 Aug 2010 19:12:43 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Interesting]]></category>

		<category><![CDATA[application security]]></category>

		<category><![CDATA[featured]]></category>

		<category><![CDATA[budgeting]]></category>

		<category><![CDATA[Metrics]]></category>

		<category><![CDATA[security]]></category>

		<category><![CDATA[security metrics]]></category>

		<category><![CDATA[tracking]]></category>

		<guid isPermaLink="false">http://www.retailinfosec.com/?p=458</guid>
		<description><![CDATA[
Short post here, but things always seem to happen in groups, so I thought I&#8217;d make everyone aware of a couple of current and upcoming opportunities to dig into a very important topic (particularly during budget season) - Security Metrics.
NetSPI is putting on a webinar tomorrow (Thursday, Aug 26th) with Symantec - here&#8217;s the info/sign-up page on their website (full disclosure, if you don&#8217;t know by now I work for NetSPI):
Application Security - without metrics it doesn&#8217;t exist
And I got the August issue of The ISSA Journal yesterday and the ...]]></description>
			<content:encoded><![CDATA[<div class="mceTemp"></div>
<div id="attachment_459" class="wp-caption alignleft" style="width: 160px"><a href="http://www.retailinfosec.com/wp-content/uploads/2010/08/actual-is-not-normal-a-tribute-to-edward-tufte.jpg" ><img class="size-thumbnail wp-image-459 " title="actual-is-not-normal-a-tribute-to-edward-tufte" src="http://www.retailinfosec.com/wp-content/uploads/2010/08/actual-is-not-normal-a-tribute-to-edward-tufte-150x150.jpg" alt="Actual is not normal (a tribute to Edward Tufte) - kevindooley via flickr" width="150" height="150" /></a><p class="wp-caption-text">Actual is not normal (a tribute to Edward Tufte) - kevindooley via flickr</p></div>
<p>Short post here, but things always seem to happen in groups, so I thought I&#8217;d make everyone aware of a couple of current and upcoming opportunities to dig into a very important topic (particularly during budget season) - Security Metrics.</p>
<p>NetSPI is putting on a webinar tomorrow (Thursday, Aug 26th) with Symantec - here&#8217;s the info/sign-up page on their website (full disclosure, if you don&#8217;t know by now I work for NetSPI):</p>
<p><a href="http://www.netspi.com/registration/register.php?event=f623329af4ac4a4b27a106e6fbda3ed0" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.netspi.com');">Application Security - without metrics it doesn&#8217;t exist</a></p>
<p>And I got the August issue of The ISSA Journal yesterday and the cover story is &#8216;Security Metrics, An Overview&#8217; by Clare Nelson.  It&#8217;s a good starting point for Security Metrics and it provides a good list of sources for additional information.  You&#8217;re going to have to be an ISSA member to access the article, but if you are reading this blog you should probably join the ISSA regardless (it&#8217;s like $95 a year or something).</p>
<p>The Journal is available to ISSA members for download from the ISSA site - <a href="http://www.issa.org" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.issa.org');">ISSA </a></p>
<p>I will highlight one of the sources that Clare uses for her article (seriously - join the ISSA and read her article) - the Center for Internet Security - not all of their information is free, but the information that you would need to get started implementing a security metrics program is free - it&#8217;ll at least get your conversations started&#8230;   <a href="http://cisecurity.org" onclick="javascript:pageTracker._trackPageview('/outbound/article/cisecurity.org');">CIS</a></p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://blog.tenablesecurity.com/2010/08/security-metrics---is-this-network-getting-better.html" onclick="javascript:pageTracker._trackPageview('/outbound/article/blog.tenablesecurity.com');">Security Metrics - Is This Network Getting Better?</a> (tenablesecurity.com)</li>
</ul>
<p><a id="aptureLink_ou9lZBzzYA" style="margin: 0pt auto; text-align: center; display: block; padding: 0px 6px;" href="http://www.amazon.com/gp/product/0321349989?tag=apture-20" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.amazon.com');"><img style="border: 0px none;" title="Amazon.com: Security Metrics: Replacing Fear, Uncertainty, and Doubt…" src="http://placeholder.apture.com/ph/360x320_AmazonProduct/" alt="" width="360px" height="320px" /></a></p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.zemanta.com');"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/zemified_e.png?x-id=d07ffe87-5551-4e3d-900c-943b6252586d" alt="Enhanced by Zemanta" /></a><span class="zem-script more-related more-info pretty-attribution paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>

<!-- Chitika|Premium - WordPress Plugin --><div class="chitika-adspace below"><script type="text/javascript"><!--
ch_client = "acrittenden";
ch_type = "mpu";
ch_width = 468;
ch_height = 120;
ch_color_bg = "";
ch_color_title = "";
ch_color_site_link = "";
ch_color_text = "";
ch_non_contextual = 4;
ch_vertical = "premium";
ch_font_title = "";
ch_font_text = "";
ch_sid = "wordpress-plugin";
var ch_queries = new Array( );
var ch_selected=Math.floor((Math.random()*ch_queries.length));
if ( ch_selected < ch_queries.length ) {
ch_query = ch_queries[ch_selected];
}
//--></script>
<script  src="http://scripts.chitika.net/eminimalls/amm.js" type="text/javascript"></script></div><img src="http://feeds.feedburner.com/~r/retailinfosec/aloi/~4/GRMhcwoBRCM" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.retailinfosec.com/2010/08/25/some-security-metrics-education/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.retailinfosec.com/2010/08/25/some-security-metrics-education/</feedburner:origLink></item>
		<item>
		<title>VISA Provides Guidance on Secure Implementation and Management of Payment Applications</title>
		<link>http://feedproxy.google.com/~r/retailinfosec/aloi/~3/KTfAMrZzZEA/</link>
		<comments>http://www.retailinfosec.com/2010/08/25/visa-provides-guidance-on-secure-implementation-and-management-of-payment-applications/#comments</comments>
		<pubDate>Wed, 25 Aug 2010 14:42:32 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[PCI News]]></category>

		<category><![CDATA[Vendors]]></category>

		<category><![CDATA[application security]]></category>

		<category><![CDATA[headline]]></category>

		<category><![CDATA[Data security]]></category>

		<category><![CDATA[PA-DSS]]></category>

		<category><![CDATA[PADSS]]></category>

		<category><![CDATA[Payment card industry]]></category>

		<category><![CDATA[Payment Card Industry Data Security Standard]]></category>

		<category><![CDATA[reseller]]></category>

		<category><![CDATA[security]]></category>

		<category><![CDATA[Tokenization (data security)]]></category>

		<category><![CDATA[Visa Inc]]></category>

		<guid isPermaLink="false">http://www.retailinfosec.com/?p=446</guid>
		<description><![CDATA[I walked into the office this morning and got this in my RSS feed aggregator:
VISA Provides Guidance on Secure Implementation and Management of Payment Applications [link]
After  taking a look at the press release and looking through the actual  document that VISA (and SANS apparently) produced [link] I think it’s a  pretty interesting move on the part of VISA.  If you haven’t yet taken a  look and you work for a retailer or a software vendor that sells to the  retail space, I’d advise downloading the ...]]></description>
			<content:encoded><![CDATA[<h4><span style="font-size: 11pt; background-color: transparent; font-weight: normal; font-style: normal; text-decoration: none; vertical-align: baseline; font-family: Arial; color: #000000;">I walked into the office this morning and got this in my RSS feed aggregator:</span></h4>
<p><a href="http://www.prnewswire.com/news-releases/visa-provides-guidance-on-secure-implementation-and-management-of-payment-applications-101369319.html" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.prnewswire.com');"><em><strong>VISA Provides Guidance on Secure Implementation and Management of Payment Applications</strong></em></a> [link]</p>
<p><span style="font-size: 11pt; background-color: transparent; font-weight: normal; font-style: normal; text-decoration: none; vertical-align: baseline; font-family: Arial; color: #000000;">After  taking a look at the press release and looking through the actual  document that <a href="http://usa.visa.com/download/merchants/bulletin_payment_app_companies_best_practices.pdf" onclick="javascript:pageTracker._trackPageview('/outbound/article/usa.visa.com');">VISA (and SANS apparently) produced [link]</a> I think it’s a  pretty interesting move on the part of <a class="zem_slink freebase/en/visa" title="Visa Inc." rel="homepage" href="http://www.corporate.visa.com" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.corporate.visa.com');">VISA</a>.  If you haven’t yet taken a  look and you work for a retailer or a software vendor that sells to the  retail space, I’d advise downloading the document and reviewing. </span><br />
<span style="font-size: 11pt; background-color: transparent; font-weight: normal; font-style: normal; text-decoration: none; vertical-align: baseline; font-family: Arial; color: #000000;"><br class="kix-line-break" />Basically,  this guidance provides VISA’s best-practices regarding the  implementation and support of payment applications that are already  PA-DSS validated.  It appears that some of the recent breaches that have  occurred (<a href="http://www.retailinfosec.com/2010/06/02/additional-information-about-that-potential-lawsuit/" >as per the post here</a>) where the break-down in security may  have happened during the implementation of the software or through  after-deployment support processes has created some action </span></p>
<div id="attachment_447" class="wp-caption alignright" style="width: 160px"><a href="http://www.retailinfosec.com/wp-content/uploads/2010/08/untitled_by_paalia_via_flickr.jpg" ><img class="size-thumbnail wp-image-447 " title="untitled_by_paalia_via_flickr" src="http://www.retailinfosec.com/wp-content/uploads/2010/08/untitled_by_paalia_via_flickr-150x150.jpg" alt="untitled_by_paalia_via_flickr" width="150" height="150" /></a><p class="wp-caption-text">untitled_by_paalia_via_flickr</p></div>
<p><span style="font-size: 11pt; background-color: transparent; font-weight: normal; font-style: normal; text-decoration: none; vertical-align: baseline; font-family: Arial; color: #000000;">from VISA.</span></p>
<p><span style="font-size: 11pt; background-color: transparent; font-weight: normal; font-style: normal; text-decoration: none; vertical-align: baseline; font-family: Arial; color: #000000;">Now - what does this mean for you?</span></p>
<p><span style="font-size: 11pt; background-color: transparent; font-weight: normal; font-style: normal; text-decoration: none; vertical-align: baseline; font-family: Arial; color: #000000;">If  you are a retailer - I’d say that it provides you a list of items that  you are going to want to discuss with your software vendors and their  resellers.  Most of the items in the document are something that your  vendors should already be doing already, but some will, most likely, not  be in place today (the reseller training program is something that I  wouldn’t expect everyone to have in place today for example).  Number 6  in the press release is interesting as well - most of the software  vendors that I’ve been working with are trying not to force an upgrade  on all their retail clients (you’d expect otherwise, but, really, most  of the vendors aren’t being pushy about it with their clients as far as I  can tell), but in #6 VISA is basically telling the vendors to tell you  that you have to upgrade if you have an older, pre-validation, version  of their solution.</span></p>
<p><span style="font-size: 11pt; background-color: transparent; font-weight: normal; font-style: normal; text-decoration: none; vertical-align: baseline; font-family: Arial; color: #000000;">If  you are a software vendor - get ready to spend more money and good luck  not being held responsible for the actions of your resellers&#8230;  In all  honesty - most of the items shouldn’t be a huge stretch (a lot of this  is just good application security stuff), but the specific notes  regarding the reseller training program makes this interesting.  I’m  sure that you already have some sort of program in place for your  resellers, but this might be a bit different from your general training -  what happens when a reseller installs your solution incorrectly AFTER  going through your newly implemented security training program and there  is a breach?  Who’s going to take the blame (legally or otherwise) for  the incorrect installation?</span></p>
<p><span style="font-size: 11pt; background-color: transparent; font-weight: normal; font-style: normal; text-decoration: none; vertical-align: baseline; font-family: Arial; color: #000000;">If you have any comments or insight that you’d like to add - please feel free to comment or send me a note via the contact page.</span></p>
<p><span style="font-size: 11pt; background-color: transparent; font-weight: normal; font-style: normal; text-decoration: none; vertical-align: baseline; font-family: Arial; color: #000000;">Also  - I’ll be heading down to the PCI SSC meeting in September - look for a  post after that trip highlighting some of the changes coming from the  council on the <a class="zem_slink freebase/en/pci_dss" title="Payment Card Industry Data Security Standard" rel="wikipedia" href="http://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Security_Standard" onclick="javascript:pageTracker._trackPageview('/outbound/article/en.wikipedia.org');">PCI DSS</a>.<br />
</span></p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://r.zemanta.com/?u=http%3A//www.newswire.ca/en/releases/archive/July2010/15/c4310.html&amp;a=20952785&amp;rid=b6744971-b0bf-4ea4-9b2b-9cb795b70028&amp;e=a6aa6255027138aa5a51d3484891842a" onclick="javascript:pageTracker._trackPageview('/outbound/article/r.zemanta.com');">Visa Releases Global Best Practices for Card Data Tokenization</a> (newswire.ca)</li>
<li class="zemanta-article-ul-li"><a href="http://blog.deurainfosec.com/pci-ssc-releases-highlights-for-2-0-changes" onclick="javascript:pageTracker._trackPageview('/outbound/article/blog.deurainfosec.com');">PCI SSC releases highlights for 2.0 changes</a> (deurainfosec.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.channelweb.co.uk/crn/news/2266290/plug-pci-compliance-gap" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.channelweb.co.uk');">Time to plug the PCI compliance gap</a> (channelweb.co.uk)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.zemanta.com');"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/zemified_e.png?x-id=b6744971-b0bf-4ea4-9b2b-9cb795b70028" alt="Enhanced by Zemanta" /></a><span class="zem-script more-related more-info pretty-attribution paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>

<!-- Chitika|Premium - WordPress Plugin --><div class="chitika-adspace below"><script type="text/javascript"><!--
ch_client = "acrittenden";
ch_type = "mpu";
ch_width = 468;
ch_height = 120;
ch_color_bg = "";
ch_color_title = "";
ch_color_site_link = "";
ch_color_text = "";
ch_non_contextual = 4;
ch_vertical = "premium";
ch_font_title = "";
ch_font_text = "";
ch_sid = "wordpress-plugin";
var ch_queries = new Array( );
var ch_selected=Math.floor((Math.random()*ch_queries.length));
if ( ch_selected < ch_queries.length ) {
ch_query = ch_queries[ch_selected];
}
//--></script>
<script  src="http://scripts.chitika.net/eminimalls/amm.js" type="text/javascript"></script></div><img src="http://feeds.feedburner.com/~r/retailinfosec/aloi/~4/KTfAMrZzZEA" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.retailinfosec.com/2010/08/25/visa-provides-guidance-on-secure-implementation-and-management-of-payment-applications/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.retailinfosec.com/2010/08/25/visa-provides-guidance-on-secure-implementation-and-management-of-payment-applications/</feedburner:origLink></item>
		<item>
		<title>Why Your Phone Can’t Really Replace Your Credit Card | Epicenter | Wired.com</title>
		<link>http://feedproxy.google.com/~r/retailinfosec/aloi/~3/M78mxLaxmVU/</link>
		<comments>http://www.retailinfosec.com/2010/08/05/why-your-phone-can%e2%80%99t-really-replace-your-credit-card-epicenter%c2%a0-wiredcom/#comments</comments>
		<pubDate>Fri, 06 Aug 2010 02:19:33 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Interesting]]></category>

		<category><![CDATA[featured]]></category>

		<category><![CDATA[article]]></category>

		<category><![CDATA[credit cards]]></category>

		<category><![CDATA[payments]]></category>

		<category><![CDATA[Wired]]></category>

		<guid isPermaLink="false">http://www.retailinfosec.com/?p=443</guid>
		<description><![CDATA[This is a good, quick article from Wired in response to some recent news stories that the wireless carriers were trying to do an end-around on the credit card companies.  Some one finally got around to doing some actual investigation on what the carriers were doing and it&#8217;s not an end-around, Discover&#8217;s highly involved.
The article also talks about why the major card brands work and attempts at breaking the system and introducing a new model for credit cards (none of which have yet worked)&#8230;  Not really a security article, but ...]]></description>
			<content:encoded><![CDATA[<p>This is a good, quick article from Wired in response to some recent news stories that the wireless carriers were trying to do an end-around on the credit card companies.  Some one finally got around to doing some actual investigation on what the carriers were doing and it&#8217;s not an end-around, Discover&#8217;s highly involved.</p>
<p>The article also talks about why the major card brands work and attempts at breaking the system and introducing a new model for credit cards (none of which have yet worked)&#8230;  Not really a security article, but one that is highly relevant given the focus on payment security.</p>
<p><a href="http://www.wired.com/epicenter/2010/08/phone-credit-card/2/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.wired.com');">Why Your Phone Can’t Really Replace Your Credit Card | Epicenter | Wired.com</a>.</p>

<!-- Chitika|Premium - WordPress Plugin --><div class="chitika-adspace below"><script type="text/javascript"><!--
ch_client = "acrittenden";
ch_type = "mpu";
ch_width = 468;
ch_height = 120;
ch_color_bg = "";
ch_color_title = "";
ch_color_site_link = "";
ch_color_text = "";
ch_non_contextual = 4;
ch_vertical = "premium";
ch_font_title = "";
ch_font_text = "";
ch_sid = "wordpress-plugin";
var ch_queries = new Array( );
var ch_selected=Math.floor((Math.random()*ch_queries.length));
if ( ch_selected < ch_queries.length ) {
ch_query = ch_queries[ch_selected];
}
//--></script>
<script  src="http://scripts.chitika.net/eminimalls/amm.js" type="text/javascript"></script></div><img src="http://feeds.feedburner.com/~r/retailinfosec/aloi/~4/M78mxLaxmVU" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.retailinfosec.com/2010/08/05/why-your-phone-can%e2%80%99t-really-replace-your-credit-card-epicenter%c2%a0-wiredcom/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.retailinfosec.com/2010/08/05/why-your-phone-can%e2%80%99t-really-replace-your-credit-card-epicenter%c2%a0-wiredcom/</feedburner:origLink></item>
		<item>
		<title>Visa Releases New Guidelines For Protecting Card Data</title>
		<link>http://feedproxy.google.com/~r/retailinfosec/aloi/~3/MG1xszZ_pQ4/</link>
		<comments>http://www.retailinfosec.com/2010/07/27/visa-releases-new-guidelines-for-protecting-card-data/#comments</comments>
		<pubDate>Tue, 27 Jul 2010 17:00:58 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Alerts]]></category>

		<category><![CDATA[announcements]]></category>

		<category><![CDATA[guidelines]]></category>

		<category><![CDATA[standards]]></category>

		<category><![CDATA[tokenization]]></category>

		<category><![CDATA[VISA]]></category>

		<guid isPermaLink="false">http://www.retailinfosec.com/2010/07/27/visa-releases-new-guidelines-for-protecting-card-data/</guid>
		<description><![CDATA[For those of you paying attention - I&#8217;m sure that you&#8217;ve already seen this announcement and probably taken a cursory look through the documentation.
I&#8217;ve been a bit out-of-pocket recently (a combination of famility vacation &#38; working on projects with some of our large retail and retail technology clients), but wanted to make sure that I made note of this information from VISA in case you hadn&#8217;t seen it.
Sorry - that&#8217;s it, but as we get through the next crazy week (it&#8217;s Black Hat after all&#8230;) I&#8217;ll try to be more ...]]></description>
			<content:encoded><![CDATA[<p>For those of you paying attention - I&#8217;m sure that you&#8217;ve already seen this announcement and probably taken a cursory look through the documentation.</p>
<p>I&#8217;ve been a bit out-of-pocket recently (a combination of famility vacation &amp; working on projects with some of our large retail and retail technology clients), but wanted to make sure that I made note of this information from VISA in case you hadn&#8217;t seen it.</p>
<p>Sorry - that&#8217;s it, but as we get through the next crazy week (it&#8217;s Black Hat after all&#8230;) I&#8217;ll try to be more active on the blog - I&#8217;ve got a few thoughts on the recent payment terminal announcements from VISA as you might imagine.  Thanks!</p>
<p><a href="http://www.networkcomputing.com/wan-security/visa-releases-new-guidelines-for-protecting-card-data.php" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.networkcomputing.com');">Visa Releases New Guidelines For Protecting Card Data - Network Computing</a>.</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://pindebit.blogspot.com/2010/07/visa-inc-completes-acquisition-of.html" onclick="javascript:pageTracker._trackPageview('/outbound/article/pindebit.blogspot.com');">Visa Inc. Completes Acquisition of CyberSource</a> (pindebit.blogspot.com)</li>
<li class="zemanta-article-ul-li"><a href="https://www.brandenwilliams.com/blog/2010/07/15/tokenization-and-chargebacks/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.brandenwilliams.com');">Tokenization and Chargebacks</a> (brandenwilliams.com)</li>
<li class="zemanta-article-ul-li"><a href="http://go.theregister.com/feed/www.theregister.co.uk/2010/07/08/visa_pci_approval_pin_pads/" onclick="javascript:pageTracker._trackPageview('/outbound/article/go.theregister.com');">Visa yanks PCI approval from PIN entry kit</a> (go.theregister.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.zemanta.com');"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/zemified_e.png?x-id=c8277b4e-f5d6-47aa-a303-21ebce9d1378" alt="Enhanced by Zemanta" /></a><span class="zem-script more-related more-info pretty-attribution paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>

<!-- Chitika|Premium - WordPress Plugin --><div class="chitika-adspace below"><script type="text/javascript"><!--
ch_client = "acrittenden";
ch_type = "mpu";
ch_width = 468;
ch_height = 120;
ch_color_bg = "";
ch_color_title = "";
ch_color_site_link = "";
ch_color_text = "";
ch_non_contextual = 4;
ch_vertical = "premium";
ch_font_title = "";
ch_font_text = "";
ch_sid = "wordpress-plugin";
var ch_queries = new Array( );
var ch_selected=Math.floor((Math.random()*ch_queries.length));
if ( ch_selected < ch_queries.length ) {
ch_query = ch_queries[ch_selected];
}
//--></script>
<script  src="http://scripts.chitika.net/eminimalls/amm.js" type="text/javascript"></script></div><img src="http://feeds.feedburner.com/~r/retailinfosec/aloi/~4/MG1xszZ_pQ4" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.retailinfosec.com/2010/07/27/visa-releases-new-guidelines-for-protecting-card-data/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.retailinfosec.com/2010/07/27/visa-releases-new-guidelines-for-protecting-card-data/</feedburner:origLink></item>
		<item>
		<title>Firewall Security - a short article and comment</title>
		<link>http://feedproxy.google.com/~r/retailinfosec/aloi/~3/N8g8628k7Tc/</link>
		<comments>http://www.retailinfosec.com/2010/06/15/firewall-security-a-short-article-and-comment/#comments</comments>
		<pubDate>Tue, 15 Jun 2010 19:08:32 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Interesting]]></category>

		<category><![CDATA[featured]]></category>

		<category><![CDATA[firewall]]></category>

		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.retailinfosec.com/?p=422</guid>
		<description><![CDATA[This morning I read the short article that I link to below.  It&#8217;s focused on firewall management and review which is a topic that I think many retail and hospitality organizations should be paying more attention to.
The study in the article was sponsored by a vendor that provides firewall management solutions (go figure), but it doesn&#8217;t mean that the message isn&#8217;t an important one - firewalls are easy to forget about once you
have them in place and (particularly in retail and hospitality) there are so many things that your network ...]]></description>
			<content:encoded><![CDATA[<p>This morning I read the short article that I link to below.  It&#8217;s focused on firewall management and review which is a topic that I think many retail and hospitality organizations should be paying more attention to.</p>
<p>The study in the article was sponsored by a vendor that provides firewall management solutions (go figure), but it doesn&#8217;t mean that the message isn&#8217;t an important one - firewalls are easy to forget about once you</p>
<div id="attachment_426" class="wp-caption alignright" style="width: 310px"><a href="http://www.retailinfosec.com/wp-content/uploads/2010/06/private-property-mollybob.jpg" ><img class="size-medium wp-image-426 " title="private-property-mollybob" src="http://www.retailinfosec.com/wp-content/uploads/2010/06/private-property-mollybob-300x225.jpg" alt="Private Property - via Flickr - mollybob" width="300" height="225" /></a><p class="wp-caption-text">Private Property - via Flickr - mollybob</p></div>
<p>have them in place and (particularly in retail and hospitality) there are so many things that your network and security people have on their to-do list that seem more pressing today then reviewing your firewall rules&#8230;</p>
<p>Now, I&#8217;m not supporting the vendor that sponsored this study and wouldn&#8217;t have the slightest feedback on its products effectiveness, but I am supporting the concept of reviewing and maintaining your firewall configuration.  The company that I work for does a lot of firewall rule assessment and while we are often engaged in this capacity as part of a client&#8217;s normal security operations, that isn&#8217;t always the case.  Sometimes it&#8217;s because management hasn&#8217;t appreciated the need to properly maintain firewall rules and now legitimate network traffic is being affected.</p>
<p>OK - back to the article - what&#8217;s also interesting is the implication that a company that is not taking the proper steps to review their firewall rules periodically will run into legal liability issues if they are breached.  They hit this point fairly hard, but don&#8217;t really provide much in the way of support for their argument.  However, it&#8217;s probably fairly valid - if an organization doesn&#8217;t manage their firewalls effectively (and isn&#8217;t able to demonstrate that they are doing so) it certainly could be something that a lawyer might latch onto &#8230;</p>
<p><a href="http://www.ctoedge.com/content/perils-firewall-security" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.ctoedge.com');">The Perils of Firewall Security | CTO Edge</a>.</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.computing.co.uk/computing/news/2264409/professionals-cheat-audits" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.computing.co.uk');">One in 10 IT professionals cheat in audits</a> (computing.co.uk)</li>
<li class="zemanta-article-ul-li"><a href="http://news.cnet.com/8301-1001_3-20003521-92.html?part=rss&amp;subj=news&amp;tag=2547-1_3-0-20" onclick="javascript:pageTracker._trackPageview('/outbound/article/news.cnet.com');">McAfee updates firewall hardware for enterprises</a> (news.cnet.com)</li>
</ul>
<p><a id="aptureLink_58WqfLql2z" style="margin: 0pt auto; text-align: center; display: block; padding: 0px 6px;" href="http://en.wikipedia.org/wiki/Firewall%20%28computing%29" onclick="javascript:pageTracker._trackPageview('/outbound/article/en.wikipedia.org');"><img style="border: 0px none;" title="Firewall (computing)" src="http://placeholder.apture.com/ph/360x320_WikipediaArticle/" alt="" width="360px" height="320px" /></a></p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.zemanta.com');"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/zemified_e.png?x-id=609e036d-22d5-4291-ae64-1bbdcac3d312" alt="Enhanced by Zemanta" /></a><span class="zem-script more-related more-info pretty-attribution paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>

<!-- Chitika|Premium - WordPress Plugin --><div class="chitika-adspace below"><script type="text/javascript"><!--
ch_client = "acrittenden";
ch_type = "mpu";
ch_width = 468;
ch_height = 120;
ch_color_bg = "";
ch_color_title = "";
ch_color_site_link = "";
ch_color_text = "";
ch_non_contextual = 4;
ch_vertical = "premium";
ch_font_title = "";
ch_font_text = "";
ch_sid = "wordpress-plugin";
var ch_queries = new Array( );
var ch_selected=Math.floor((Math.random()*ch_queries.length));
if ( ch_selected < ch_queries.length ) {
ch_query = ch_queries[ch_selected];
}
//--></script>
<script  src="http://scripts.chitika.net/eminimalls/amm.js" type="text/javascript"></script></div><img src="http://feeds.feedburner.com/~r/retailinfosec/aloi/~4/N8g8628k7Tc" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.retailinfosec.com/2010/06/15/firewall-security-a-short-article-and-comment/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.retailinfosec.com/2010/06/15/firewall-security-a-short-article-and-comment/</feedburner:origLink></item>
		<item>
		<title>Short Post On A Lesson Learned - Hackers Break Into Reddit’s Gmail and Twitter Accounts</title>
		<link>http://feedproxy.google.com/~r/retailinfosec/aloi/~3/mIxdi2KOe_g/</link>
		<comments>http://www.retailinfosec.com/2010/06/11/short-post-on-a-lesson-learned-hackers-break-into-reddit%e2%80%99s-gmail-and-twitter-accounts/#comments</comments>
		<pubDate>Fri, 11 Jun 2010 14:56:41 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Alerts]]></category>

		<category><![CDATA[Interesting]]></category>

		<category><![CDATA[gmail]]></category>

		<category><![CDATA[reddit]]></category>

		<category><![CDATA[social media]]></category>

		<guid isPermaLink="false">http://www.retailinfosec.com/?p=418</guid>
		<description><![CDATA[Why am I posting this on a retail infosec blog?  Because of the last two paragraphs:
&#8230; Why does Reddit use a Gmail account for this purpose, anyway? One of  the site’s moderators answers: “When we were much, much smaller (no mail  server, etc) it was the easiest way for several people to get to the  feedback account at the same time, and it stuck.”
So there you  have it: as the company grows, it should continually update its security  practices, otherwise it might find that certain ...]]></description>
			<content:encoded><![CDATA[<p>Why am I posting this on a retail infosec blog?  Because of the last two paragraphs:</p>
<blockquote><p>&#8230; Why does Reddit use a Gmail account for this purpose, anyway? One of  the site’s moderators answers: “When we were much, much smaller (no mail  server, etc) it was the easiest way for several people to get to the  feedback account at the same time, and it stuck.”</p>
<p>So there you  have it: as the company grows, it should continually update its security  practices, otherwise it might find that certain solutions, that were  good enough a couple of years ago, simply don’t cut it anymore.</p></blockquote>
<p>This is a common situation with many organizations (including many retailers) - not keeping security up-to-snuff as the organization and it&#8217;s systems, personnel, and needs grow and change.</p>
<p>While a social media site like Reddit may not be subject to security and compliance oversight like a retailer would be it reinforces something that I&#8217;m constantly discussing with clients - security (and compliance) is a process and, while point-in-time validations are necessary, they are just that - a point in time.</p>
<p>Make sure that you&#8217;re keeping security needs in mind as your organization and it&#8217;s environment changes&#8230;.</p>
<p><a href="http://mashable.com/2010/06/11/hackers-reddit-gmail/" onclick="javascript:pageTracker._trackPageview('/outbound/article/mashable.com');">Hackers Break Into Reddit’s Gmail and Twitter Accounts</a>.</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://mashable.com/2010/06/11/hackers-reddit-gmail/" onclick="javascript:pageTracker._trackPageview('/outbound/article/mashable.com');">Hackers Break Into Reddit&#8217;s Gmail and Twitter Accounts</a> (mashable.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.zemanta.com');"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/zemified_e.png?x-id=c09e3331-7654-406a-8f6b-b26af0d0bf5d" alt="Enhanced by Zemanta" /></a><span class="zem-script more-related more-info pretty-attribution paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>

<!-- Chitika|Premium - WordPress Plugin --><div class="chitika-adspace below"><script type="text/javascript"><!--
ch_client = "acrittenden";
ch_type = "mpu";
ch_width = 468;
ch_height = 120;
ch_color_bg = "";
ch_color_title = "";
ch_color_site_link = "";
ch_color_text = "";
ch_non_contextual = 4;
ch_vertical = "premium";
ch_font_title = "";
ch_font_text = "";
ch_sid = "wordpress-plugin";
var ch_queries = new Array( );
var ch_selected=Math.floor((Math.random()*ch_queries.length));
if ( ch_selected < ch_queries.length ) {
ch_query = ch_queries[ch_selected];
}
//--></script>
<script  src="http://scripts.chitika.net/eminimalls/amm.js" type="text/javascript"></script></div><img src="http://feeds.feedburner.com/~r/retailinfosec/aloi/~4/mIxdi2KOe_g" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.retailinfosec.com/2010/06/11/short-post-on-a-lesson-learned-hackers-break-into-reddit%e2%80%99s-gmail-and-twitter-accounts/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.retailinfosec.com/2010/06/11/short-post-on-a-lesson-learned-hackers-break-into-reddit%e2%80%99s-gmail-and-twitter-accounts/</feedburner:origLink></item>
		<item>
		<title>FTC Settlement Order with Dave &amp; Busters</title>
		<link>http://feedproxy.google.com/~r/retailinfosec/aloi/~3/xdBGdK8W4nM/</link>
		<comments>http://www.retailinfosec.com/2010/06/09/ftc-settlement-order-with-dave-busters/#comments</comments>
		<pubDate>Wed, 09 Jun 2010 18:33:22 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Alerts]]></category>

		<category><![CDATA[Retailers]]></category>

		<category><![CDATA[featured]]></category>

		<guid isPermaLink="false">http://www.retailinfosec.com/?p=412</guid>
		<description><![CDATA[Again via Office of Inadequate Security&#8230; their link is below.
So Dave &#38; Busters&#8217; FTC settlement is finalized and it illustrates another concern for merchants that aren&#8217;t taking a comprehensive approach to security - the burden of being monitored by the FTC.  Here&#8217;s the quote from the press release:
The settlement requires Dave &#38; Buster’s to establish and maintain a  program designed to protect the security, confidentiality, and integrity  of personal information collected from customers.  It also requires the  company to obtain independent, professional audits, every other year ...]]></description>
			<content:encoded><![CDATA[<p>Again via Office of Inadequate Security&#8230; their link is below.</p>
<p>So Dave &amp; Busters&#8217; <a class="zem_slink freebase/en/federal_trade_commission" title="Federal Trade Commission" rel="homepage" href="http://www.ftc.gov" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.ftc.gov');">FTC</a> <a class="zem_slink freebase/en/settlement_hierarchy" title="Human settlement" rel="wikipedia" href="http://en.wikipedia.org/wiki/Human_settlement" onclick="javascript:pageTracker._trackPageview('/outbound/article/en.wikipedia.org');">settlement</a> is finalized and it illustrates another concern for merchants that aren&#8217;t taking a comprehensive approach to security - the burden of being monitored by the FTC.  Here&#8217;s the quote from the press release:</p>
<blockquote><p>The settlement requires <a class="zem_slink freebase/en/dave_busters" title="Dave &amp; Buster's" rel="homepage" href="http://www.daveandbusters.com" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.daveandbusters.com');">Dave &amp; Buster’s</a> to establish and maintain a  program designed to protect the security, confidentiality, and integrity  of personal information collected from customers.  It also requires the  company to obtain independent, professional audits, every other year  for 10 years, to ensure that the security program meets the standards of  the settlement.  In addition, the proposed settlement contains standard  record-keeping provisions to allow the FTC to monitor compliance.</p></blockquote>
<p>This is a huge deal - having an &#8216;independent, professional audit&#8217; of your security program every other year is not covered by your PCI Report on Compliance.  It is an additional audit requirement that goes well beyond PCI&#8217;s card-specific requirements and requires a far more in-depth review of your full security program.  It also requires putting in place the &#8217;standard record-keeping provisions to allow the FTC to monitor compliance.&#8217;  In other words - it&#8217;s not getting ready every year for your QSA, it&#8217;s maintaining the appropriate information and providing access to that information 365 days a year.  Dave &amp; Buster&#8217;s is going</p>
<p>to be requ</p>
<p>ired to document every aspect of their entire security program and be able to demonstrate it&#8217;s effectiveness to auditors and the FTC.</p>
<p>Add this to your list of stuff to worry about and make sure that, if your executive man</p>
<p>agement team isn&#8217;t putting the proper focus on security and compliance, that they understand that this additional concern is real - it&#8217;s not just about PCI.  And if they think maintaining PCI compliance is expensive&#8230;..</p>
<p><a href="http://www.databreaches.net/?p=12090" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.databreaches.net');">FTC Approves Final Settlement Order with Dave &amp; Busters | Office of Inadequate Security</a>.</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.ftc.gov/opa/2010/03/davebusters.shtm" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.ftc.gov');">Dave &amp; Buster&#8217;s Settles FTC Charges it Failed to Protect Consumers&#8217; Information</a> (ftc.gov)</li>
<li class="zemanta-article-ul-li"><a href="http://blog.deurainfosec.com/man-sentenced-for-hacking-restaurant-card-data" onclick="javascript:pageTracker._trackPageview('/outbound/article/blog.deurainfosec.com');">Man sentenced for hacking restaurant card data</a> (deurainfosec.com)</li>
<li class="zemanta-article-ul-li"><a href="http://go.theregister.com/feed/www.theregister.co.uk/2010/03/25/gonzalez_sentenced/" onclick="javascript:pageTracker._trackPageview('/outbound/article/go.theregister.com');">Hacker&#8217;s record credit card theft fetches 20-year sentence</a> (go.theregister.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/eb41ea85-6a34-45c0-b24e-768d4570a02c/" onclick="javascript:pageTracker._trackPageview('/outbound/article/reblog.zemanta.com');"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=eb41ea85-6a34-45c0-b24e-768d4570a02c" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related more-info pretty-attribution paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>

<!-- Chitika|Premium - WordPress Plugin --><div class="chitika-adspace below"><script type="text/javascript"><!--
ch_client = "acrittenden";
ch_type = "mpu";
ch_width = 468;
ch_height = 120;
ch_color_bg = "";
ch_color_title = "";
ch_color_site_link = "";
ch_color_text = "";
ch_non_contextual = 4;
ch_vertical = "premium";
ch_font_title = "";
ch_font_text = "";
ch_sid = "wordpress-plugin";
var ch_queries = new Array( );
var ch_selected=Math.floor((Math.random()*ch_queries.length));
if ( ch_selected < ch_queries.length ) {
ch_query = ch_queries[ch_selected];
}
//--></script>
<script  src="http://scripts.chitika.net/eminimalls/amm.js" type="text/javascript"></script></div><img src="http://feeds.feedburner.com/~r/retailinfosec/aloi/~4/xdBGdK8W4nM" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.retailinfosec.com/2010/06/09/ftc-settlement-order-with-dave-busters/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.retailinfosec.com/2010/06/09/ftc-settlement-order-with-dave-busters/</feedburner:origLink></item>
		<item>
		<title>Additional Information About That Potential Lawsuit</title>
		<link>http://feedproxy.google.com/~r/retailinfosec/aloi/~3/12rUPlK8KzU/</link>
		<comments>http://www.retailinfosec.com/2010/06/02/additional-information-about-that-potential-lawsuit/#comments</comments>
		<pubDate>Wed, 02 Jun 2010 17:28:55 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Alerts]]></category>

		<category><![CDATA[Interesting]]></category>

		<category><![CDATA[PCI News]]></category>

		<category><![CDATA[Retailers]]></category>

		<category><![CDATA[Vendors]]></category>

		<category><![CDATA[featured]]></category>

		<category><![CDATA[Brew HaHa!]]></category>

		<category><![CDATA[CC Productions]]></category>

		<category><![CDATA[lawsuit]]></category>

		<category><![CDATA[Mercury]]></category>

		<category><![CDATA[Mercury Payments]]></category>

		<category><![CDATA[PA-DSS]]></category>

		<category><![CDATA[PCI]]></category>

		<category><![CDATA[PCI-DSS]]></category>

		<category><![CDATA[Point of sale]]></category>

		<category><![CDATA[POSitouch]]></category>

		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.retailinfosec.com/?p=403</guid>
		<description><![CDATA[After posting about the press release regarding the potential lawsuit (here) I got an email from the PR firm that had sent the release out.  He, in turn, connected me to Charles Hoff - the attorney for the retailer that is considering the suit, Brew HaHa!.  We had a very interesting conversation and, not being a lawyer, I&#8217;m not going to make any comments about the merits of any lawsuit that may or may not come from this episode, but, as I said, the conversation was interesting and this is ...]]></description>
			<content:encoded><![CDATA[<p>After posting about the press release regarding the potential lawsuit (<a href="http://www.retailinfosec.com/2010/05/27/lawsuit-brewing-against-popular-pos-software-provider-and-reseller/"  target="_blank">here</a>) I got an email from the PR firm that had sent the release out.  He, in turn, connected me to Charles Hoff - the attorney for the retailer that is considering the suit, Brew HaHa!.  We had a very interesting conversation and, not being a lawyer, I&#8217;m not going to make any comments about the merits of any lawsuit that may or may not come from this episode, but, as I said, the conversation was interesting and this is what I can share from that discussion:</p>
<p>I&#8217;m not a lawyer, so let&#8217;s put this caveat onto everything below -  This is all from one-side of the discussion and it&#8217;s all alleged and I don&#8217;t support one side or the other in this situation.</p>
<ul>
<li>Brew HaHa! purchased a &#8216;turn-key&#8217; solution from what they understood to be a &#8216;exclusive&#8217; reseller of the POSitouch POS solution - <a href="http://www.c-c-p.com/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.c-c-p.com');">CC Productions</a></li>
<li>It was explained to them that they could utilize a payments solution from <a href="http://www.mercurypay.com/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.mercurypay.com');" target="_blank">Mercury Payments </a>- any alternative to Mercury would cost Brew HaHa! additional money</li>
<li>Charles claims that Brew HaHa! was not informed that the Mercury solution that was being implemented was not PCI / <a class="zem_slink freebase/guid/9202a8c04000641f800000000bebb66e" title="PA-DSS" rel="wikipedia" href="http://en.wikipedia.org/wiki/PA-DSS" onclick="javascript:pageTracker._trackPageview('/outbound/article/en.wikipedia.org');">PA-DSS</a> compliant and that, after the system was implemented, Brew HaHa! noticed that they were being charged a fee to allow Mercury to make the changes needed for their solution to be PCI compliant.  According to Charles, that&#8217;s the first time they realized that the solution wasn&#8217;t compliant.</li>
<li>They have had a forensics team in and they determined that malware was present on the environment and that the malware was aggregating cardholder data (among other things)</li>
<li>There is another, larger merchant that has yet to come forward that may have a similar situation and complaint&#8230;</li>
</ul>
<p>Not a lot really (I&#8217;m not a great interviewer - not enough practice), but it did answer some of my questions and raise some more.</p>
<p>Also, Restaurant Data Concepts sent a press release as well - <a href="http://www.databreaches.net/?p=11943" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.databreaches.net');" target="_blank">link</a> (the link heads over to the Office Of Inadequate Security site - which is an excellent site btw).  Take a look at the release as it also makes some very interesting points.  Although, I will say that the statement, &#8216;It is not overly difficult or expensive for a merchant to protect themselves against theft of cardholder information&#8217; is a little unfair - it can get very expensive and quite technically involved for many merchants.  The other line I thought was interesting - &#8216;A small expenditure to upgrade and secure their system can stave off significant costs and penalties&#8230;&#8217;</p>
<p>Ultimately it breaks down like this for me:</p>
<ol>
<li>There&#8217;s an involved chain of companies/products/services involved here: Restaurant Data Concepts (software) &#8212;&gt; CC Productions (hardware/installation/implementation/Mercury resellers maybe as well?) &#8212;&gt; Mercury Payments (software?/processing) &#8212;&gt;Brew HaHa!(which is responsible for their broader PCI requirements).    Lot&#8217;s of places for someone to not do their job with PCI/security.  Lots of places to miss something or to not even realize that something wasn&#8217;t getting done by someone else in the chain.</li>
<li>There is a responsibility that lies with a software vendor (as documented in PA-DSS), but does that responsibility extend to resellers?  &#8216;Exclusive&#8217; resellers?</li>
<li>When a small merchant without a big IT staff purchases a &#8216;turn-key&#8217; solution, what does that mean for PCI?</li>
<li>If a reseller or a technology vendor doesn&#8217;t volunteer the fact that they aren&#8217;t PCI compliant (or PA-DSS validated) does that mean anything?  Yes, the retailer should have asked (and really contractually obligated) the vendor regarding compliance, but is the provider responsible for disclosing?  (Either way, it&#8217;s a pretty crappy move if it really went down that way).</li>
</ol>
<p>Regardless - it should continue to be interesting.</p>
<p>Some Additional Info:</p>
<p><a href="http://www.retailinfosec.com/2010/05/27/lawsuit-brewing-against-popular-pos-software-provider-and-reseller/"  target="_blank">Lawsuit Brewing&#8230;</a></p>
<p><a href="http://www.databreaches.net/?p=11932" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.databreaches.net');" target="_blank">Brew HaHa breach no laughing matter</a></p>
<p><a id="aptureLink_w4xxeAWaZ3" style="margin: 0pt auto; text-align: center; display: block; padding: 0px 6px;" href="http://en.wikipedia.org/wiki/Payment%20Card%20Industry%20Data%20Security%20Standard" onclick="javascript:pageTracker._trackPageview('/outbound/article/en.wikipedia.org');"><img style="border: 0px none;" title="Payment Card Industry Data Security Standard" src="http://placeholder.apture.com/ph/360x320_WikipediaArticle/" alt="" width="360px" height="320px" /></a></p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/2c2aa33c-8ca7-44e4-9cf1-e2aa997b8104/" onclick="javascript:pageTracker._trackPageview('/outbound/article/reblog.zemanta.com');"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=2c2aa33c-8ca7-44e4-9cf1-e2aa997b8104" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related more-info pretty-attribution paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>

<!-- Chitika|Premium - WordPress Plugin --><div class="chitika-adspace below"><script type="text/javascript"><!--
ch_client = "acrittenden";
ch_type = "mpu";
ch_width = 468;
ch_height = 120;
ch_color_bg = "";
ch_color_title = "";
ch_color_site_link = "";
ch_color_text = "";
ch_non_contextual = 4;
ch_vertical = "premium";
ch_font_title = "";
ch_font_text = "";
ch_sid = "wordpress-plugin";
var ch_queries = new Array( );
var ch_selected=Math.floor((Math.random()*ch_queries.length));
if ( ch_selected < ch_queries.length ) {
ch_query = ch_queries[ch_selected];
}
//--></script>
<script  src="http://scripts.chitika.net/eminimalls/amm.js" type="text/javascript"></script></div><img src="http://feeds.feedburner.com/~r/retailinfosec/aloi/~4/12rUPlK8KzU" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.retailinfosec.com/2010/06/02/additional-information-about-that-potential-lawsuit/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.retailinfosec.com/2010/06/02/additional-information-about-that-potential-lawsuit/</feedburner:origLink></item>
		<item>
		<title>Lawsuit Brewing Against Popular POS Software Provider and Reseller</title>
		<link>http://feedproxy.google.com/~r/retailinfosec/aloi/~3/C4eFzxoDP5g/</link>
		<comments>http://www.retailinfosec.com/2010/05/27/lawsuit-brewing-against-popular-pos-software-provider-and-reseller/#comments</comments>
		<pubDate>Thu, 27 May 2010 17:16:14 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Alerts]]></category>

		<category><![CDATA[PCI News]]></category>

		<category><![CDATA[application security]]></category>

		<category><![CDATA[featured]]></category>

		<category><![CDATA[lawsuit]]></category>

		<category><![CDATA[PA-DSS]]></category>

		<category><![CDATA[PABP]]></category>

		<category><![CDATA[PADSS]]></category>

		<category><![CDATA[Payment Card Industry Data Security Standard]]></category>

		<category><![CDATA[Point of sale]]></category>

		<category><![CDATA[Point of Sale Systems]]></category>

		<category><![CDATA[POSitouch]]></category>

		<guid isPermaLink="false">http://www.retailinfosec.com/?p=399</guid>
		<description><![CDATA[Hey look - another lawsuit&#8230;.
Well - right now it&#8217;s just the threat of a suit&#8230;  The information is a bit thin and I&#8217;m not sure (based on the press release) whether or not this is a complaint about the software, the implementation of the software, the hardware system, or all of the above.
What it does look like is a bit of a fishing exercise by the law firms - let&#8217;s send out the press release, make it general enough that we include just about anyone that even thought about touching the ...]]></description>
			<content:encoded><![CDATA[<p>Hey look - another <a class="zem_slink freebase/en/lawsuit" title="Lawsuit" rel="wikipedia" href="http://en.wikipedia.org/wiki/Lawsuit" onclick="javascript:pageTracker._trackPageview('/outbound/article/en.wikipedia.org');">lawsuit</a>&#8230;.</p>
<p>Well - right now it&#8217;s just the threat of a suit&#8230;  The information is a bit thin and I&#8217;m not sure (based on the <a class="zem_slink freebase/en/news_release" title="Press release" rel="wikipedia" href="http://en.wikipedia.org/wiki/Press_release" onclick="javascript:pageTracker._trackPageview('/outbound/article/en.wikipedia.org');">press release</a>) whether or not this is a complaint about the software, the implementation of the software, the hardware system, or all of the above.</p>
<p>What it does look like is a bit of a fishing exercise by the law firms - let&#8217;s send out the press release, make it general enough that we include just about anyone that even thought about touching the system and see if the vendors jump for that settlement opening (&#8217;there is hope that RDC and CC Productions will decide to resolve the  situation before it goes to court.&#8217;).</p>
<p>This could be very interesting if it is more than just a &#8217;shake-down&#8217; - we don&#8217;t know the software releases/revs, we don&#8217;t know when systems were installed, we don&#8217;t know how the alleged breaches actually occurred, we don&#8217;t know much of anything except that the lawyers are crying &#8216;PCI&#8217; and waiting to see what happens&#8230;</p>
<p>It might be a completely legitimate complaint by merchants that implemented a solution that was over-sold to them as a fix to their &#8216;PCI problem&#8217;.  It might be that the merchants installed a solution that was secure in itself, but didn&#8217;t take any steps to secure their own environment beyond the <a class="zem_slink freebase/en/point_of_sale" title="Point of sale" rel="wikipedia" href="http://en.wikipedia.org/wiki/Point_of_sale" onclick="javascript:pageTracker._trackPageview('/outbound/article/en.wikipedia.org');">POS</a>.  It might be that the implementer took a secure solution and made it insecure through improper implementation (following that <a class="zem_slink freebase/guid/9202a8c04000641f800000000bebb66e" title="PA-DSS" rel="wikipedia" href="http://en.wikipedia.org/wiki/PA-DSS" onclick="javascript:pageTracker._trackPageview('/outbound/article/en.wikipedia.org');">PA-DSS</a> Program Guide?  huh?).  It might be software issues.  It might be who knows what&#8230;..</p>
<p>I want more information and I want to know if they are going through with this or if they are just using this as leverage.</p>
<p>Looking at the PA-DSS validated list, two of the POSitouch solutions are listed - both under <a class="zem_slink freebase/en/pci_dss" title="Payment Card Industry Data Security Standard" rel="wikipedia" href="http://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Security_Standard" onclick="javascript:pageTracker._trackPageview('/outbound/article/en.wikipedia.org');">PABP</a> 1.4 - don&#8217;t know if these were the solutions/revs that the merchants had installed, but, if they were it would be an interesting exercise to see how much protection the <a id="aptureLink_hZhKtAzh2t" href="https://www.pcisecuritystandards.org/security_standards/vpa/" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.pcisecuritystandards.org');">PA-DSS validated list</a> would provide a POS vendor&#8230;</p>
<p><a href="http://www.prlog.org/10700613-lawsuit-brewing-against-popular-pos-software-provider-and-reseller.html" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.prlog.org');">Lawsuit Brewing Against Popular POS Software Provider and Reseller</a>.</p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/9577292b-5635-41cf-8b13-155409cffb66/" onclick="javascript:pageTracker._trackPageview('/outbound/article/reblog.zemanta.com');"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=9577292b-5635-41cf-8b13-155409cffb66" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related more-info pretty-attribution paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>

<!-- Chitika|Premium - WordPress Plugin --><div class="chitika-adspace below"><script type="text/javascript"><!--
ch_client = "acrittenden";
ch_type = "mpu";
ch_width = 468;
ch_height = 120;
ch_color_bg = "";
ch_color_title = "";
ch_color_site_link = "";
ch_color_text = "";
ch_non_contextual = 4;
ch_vertical = "premium";
ch_font_title = "";
ch_font_text = "";
ch_sid = "wordpress-plugin";
var ch_queries = new Array( );
var ch_selected=Math.floor((Math.random()*ch_queries.length));
if ( ch_selected < ch_queries.length ) {
ch_query = ch_queries[ch_selected];
}
//--></script>
<script  src="http://scripts.chitika.net/eminimalls/amm.js" type="text/javascript"></script></div><img src="http://feeds.feedburner.com/~r/retailinfosec/aloi/~4/C4eFzxoDP5g" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.retailinfosec.com/2010/05/27/lawsuit-brewing-against-popular-pos-software-provider-and-reseller/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.retailinfosec.com/2010/05/27/lawsuit-brewing-against-popular-pos-software-provider-and-reseller/</feedburner:origLink></item>
	</channel>
</rss>
