Showing posts with label PCI. Show all posts
Showing posts with label PCI. Show all posts

19 May 2010

#PCI Compliance Does Not Equal #Security

By Danny Lieberman, Security Expert and Founder of Software Associates 



I recently saw a post from a blog on a corporate web site from a company called Cloud compliance, entitled Is Compliance is the New Security Standard.
Cloud Compliance provides a SaaS-based identity and Access Assessment (IdAA) solution that helps identify and remediate access control and entitlement policy violations. We combine the economies of cloud computing with fundamental performance management principles to provide easy, low cost analysis of access rights toprevent audit findings (sic) and ensure compliance with regulations such as SOX, GLBA, PCI DSS, HIPAA and NERC.
The basic thesis of the blog post was that since companies have to spend money on compliance anyhow, they might as well spend the money once and rename the effort “security”.
This is an interesting notion – although perhaps “placebo security” might be a cheaper approach.
Compliance is not equivalent to security  for several fundamental reasons.
Let’s examine this curious notion, using  PCI DSS 1.2 as a generic example of a regulatory compliance standard that is used to protect payment card numbers:
  • Filling out a form or having an auditor check off a list is not logically equivalent to installing and validating security countermeasures. A threat modeling exercise is stronger than filling out a form or auditing controls – it’s significant that threat modeling is not even mentioned by PCI DSS, despite the ROI in think time.
  • Although PCI DSS 1.2 is better than previous versions – it still lags the curve of typical data security threats – which means that even if a business implements all the controls – they are probably still vulnerable.
  • PCI DSS was designed by the card associations – there is no way that any blanket standard will fit the needs of a particular business – anymore than a size 38 regular suit will fit a 5′ 7″ man who weighs 120 kg and wrestles professionally.
  • PCI DSS talks about controls with absolutely no  context of value at risk. A retailer selling diamond rings on-line, may self-comply as a Level 4 merchant but in fact have more value at risk than then the payment processor service provider he uses. (See my previous post on Small merchants at risk from fraudulent transactions )
  • PCI DSS strives to ensure continued compliance to their (albeit flawed) standard with quarterly (for Level 1) and yearly (for everyone else) audits.   The only problem with this is that a lot of things can happen in 3 months (and certainly in a year).   The automated scanning that many Level 2-4 merchants do is essentially worthless but more importantly – the threat scenarios shift quickly these days – especially when you take into account employees and contractors who as people are by definition, unpredictable.
  • PCI DSS 1.2 mandates security controls for untrusted networks and external attacks.   The phrases “trusted insider” or “business partner” are not mentioned once in the standard. This is absurd, since a significant percentage of the customer data breaches in the past few years involved trusted insiders and business partners. A card processor can be 100 percent compliant but because they have a Mafia sleeper working in IT – they could be regularly leaking credit card numbers. This is not a theoretical threat.
  • Finally – PCI DSS is a standard for whom? It’s a standard to help the card associations protect their supply chain.   It is not a policy used by the management of a company in order to improve customer service and grow sales volume.
To summarize:
  • PCI DSS is a standard for the card associations not for your business, nor for your customers.
  • As a security standard it is better than none at all, but leaves much to be desired because it is not oriented towards the business and consumer protection

Source: http://alturl.com/crs7

Taking CreditCard #Security Seriously

by David F. Carr05.17.10, 06:00 PM EDT

Small businesses should not expect to fly under the radar forever.




The easiest way for small businesses to address the information security requirements imposed by credit card companies is the wrong way. I'm talking about lying and praying.
In 2004 the major credit card companies got together to define a common Payment Card Industry Data Security Standard (PCI DSS, often referred to as just PCI). They are gradually ratcheting up the pressure on merchants of all sizes to comply. Large companies, and some smaller ones that process a large volume of transactions (particularly if they're doing it on the Web), are required to have an independent review of their processes and systems by a security professional credentialed as a qualified security assessor (QSA). Most small businesses can instead complete a self-assessment questionnaire, where they essentially grade themselves. That's where the lying comes in. It's not so hard to check off all the right answers ("Sure, I review my e-commerce server logs on a daily basis.") without actually making them true.
If you're lying, you had better also be praying. If caught, you could be fined for non-compliance, to the tune of tens or hundreds of thousands of dollars--enough to put many a small organization out of business. Expect even harsher treatment if someone hacks your systems and downloads card data you claimed you weren't even storing.
Most of the requirements are basic security, like making sure there is a firewall between your Internet connection and any system that stores credit card numbers. Factory default passwords on your network equipment must be changed, so that no one can log on as user "admin," password "admin." And so on. More specifically, you're responsible for protecting card holder data, and there's some data you're never supposed to store--like the full contents of a card's magnetic strip.
Many small businesses are still under the impression that the rules don't apply to them because they're too small, or because they don't conduct e-commerce. Actually, the rules apply to any business--and even any nonprofit--that takes credit card payments. You can look for ways to lighten the compliance burden, but you can't get yourself off the hook entirely. Even if no one has yet compelled you to complete a questionnaire or conduct an automated scan of your networks, you're still supposed to be locking down your systems.
Some businesses complain this all sounds too complicated and expensive. But they are missing the point, says Anton Chuvakin, author of PCI Compliance: Understand and Implement Effective PCI Data Security Standard Compliance. The PCI rules really represent theminimum security standards businesses must meet to be fair to their customers, who, after all, are trusting the merchant every time they hand over a credit card number. In the wake of a card security breach, a larger business might suffer from the fines, damages and adverse publicity resulting from a card security breach. By contrast, "a small business is more likely to be GONE," Chuvakin said. "Businesses that endanger their customers really do deserve to die."
If your organization is not equipped to handle credit card data securely, maybe you should not be handling it at all. Look for ways to shift as much of the burden as possible onto a service provider that specializes in secure payment processing. Services such as PayPal and Authorize.net let you forward customers to their websites for payment processing; credit card numbers never pass through your hands at all.
Small businesses such as restaurants that use an older generation of countertop credit card terminals may be breaking the rules inadvertently because the device stores magnetic stripe data or otherwise violates the PCI requirements. So consider upgrading to a payment device that is certified PCI compliant. Basic terminals capable of encrypting Personal Identification Number (PIN) codes and protecting other sensitive information are available for as little as $100 and might even be offered free by merchant account services trying to win your business. The PCI Security Standards Council publishes a list of approved devices. Just remember that using a compliant device is only one element of making your business compliant.
Even if you're not storing anything explicitly prohibited, you may be storing more credit card data than you need to. Small merchants typically store a day's worth of credit card numbers on a card swipe terminal, then process all the transactions in a batch at the end of the day. Bigger retailers may record the card numbers in a centralized database so they can track all a customer's purchases, and so they can retrieve the number if they need to issue a refund. But do you need to retain those numbers at all?
Perhaps not. Martin McKeay, a QSA and author of the Network Security Blog, recommends looking at new strategies for using end-to-end encryption and "tokenization."
For example, payment processor First Data ( FDC - news -people ) and security software firm RSA Security have developed a product called TransArmor that allows merchants to get authorization for a credit card number and then immediately dispose of the card number, replacing it with a token. The token is another number that acts as a stand-in for the credit card number itself. First Data keeps track of which tokens correspond with which credit card numbers. So if you're executing previously authorized transactions at the end of the day, you send First Data a batch of tokens, and it relays the card numbers on to the bank. But if the tokens are stolen, by themselves they are worthless to anyone else.
"With this, the only time you need the true credit card number is when you do the authorization," says Craig Tieken, First Data vice president of merchant product management. "The merchant, in our opinion, no longer needs the card number." TransArmor is still in beta testing, scheduled for release in the summer of 2010.
David F. Carr is Forbes' columnist on technology for small to midsize businesses. Contact him at david@carrcommunications.com.
Source: http://alturl.com/wipe




23 April 2010

Are Physical #Attacks On POS PIN Pads Rising?



Written by Evan Schuman
April 21st, 2010


One of the oldest tenets in security is that professional thieves will always attack the perceived weak point of security. A burglar will hit the back door until it’s reinforced with multiple deadbolts and then he’ll turn to the window. If that’s replaced with bullet-proof glass with bars in front, he’ll ring the doorbell. If every door and window is perfectly protected, he’ll sledgehammer through the wall.


This reality is why we’re seeing a sharp increase in reported thefts of PIN pad units. Substantial efforts in recent years to protect the data within a split second of a card being swiped have done little beyond making PIN pads the victim of physical attacks. Units are replaced either with a skimmer attached or by a clone of the full device.
The attacks require more courage and brawn than a typical cyberthief displays. (Although with cyberthief extraordinaire Albert Gonzalez’s claims that he regularly performed 5,000 sit-ups per session, maybe he’d have been an exception.)
As BankInfoSecurity reported on Monday (April 19), an attack on Hancock Fabrics is an ideal example of this PIN pad trend. The chain confirmed that, last summer, “PIN pad units at a limited number of Hancock Fabrics stores were stolen and replaced with visually identical, but fraudulent, PIN pad units.”
The problem with Hancock’s statement is the four steps CEO Jane Aggers said the chain is taking to correct the issue. First, “upgrading the PIN pad units at the point of sale in all of our stores with new PIN pad units that were designed to meet the toughest security requirements.” Second, “working with forensic investigators to analyze the extent of any unauthorized access to customer information and to identify and address any issues that have been identified.” Third, “installing automated systems to monitor each of the PIN pad units daily to look for suspicious activity.” And fourth, “implementing new store-wide policies with respect to daily inspection of the PIN pad units.”
Upgrading the PIN pad units is a fine way to go. But anything short of soldering them to the wall and encasing the units with bullet-proof glass won’t address physical attacks. Although working with forensic investigators is a great thing, it won’t prevent similar attacks from happening again.
The “automated systems” that will “look for suspicious activity” sound an awful lot like video cameras, which are fine but also easily disabled. “Daily inspection” points sound like a good idea, but it’s something that will likely be relaxed within two weeks of being launched.
How about automating some of these tasks?
Or what about discreetly placing RFID tags in multiple locations around the POS area. They would constantly ping each other and loudly alert the store whenever the distance between any two tagged devices changes. The new lookalike devices would be easily detected, unless the thieves are able to remove the RFID tag and place it in the same place on the new unit.
That’s very difficult to do in a quick swap. Also, that tag can be affixed in such a way as to break the main device if it’s forcibly removed. If the units are working properly, a change in location would be detected the instant any tampering begins.
As for a skimmer being attached, perhaps a very sensitive weight verification mechanism could flag any devices that seem to gain a little mass overnight. (Good idea for PIN pads. Bad idea for columnists.)