SEARCH RESULTS
 
Showing 1-10 of 13 records
 
Expand article

New attack trend pushes POS encryption to the fore

2008-05-20 07:23:13 by Editor in Computerworld Security News
 
The recent rash of data thefts from retail point-of-sale systems is prompting security vendors and payment processing firms to offer tools for encrypting POS information
 
 
 
 
 
Expand article

New attack trend pushes POS encryption to the fore

2008-05-22 00:00:00 by HASH0x84731a4 in Network World on Security
 
The relatively scant attention that retailers have paid to securing their point-of-sale systems over the past few years is making the POS setups increasingly attractive targets for cybercrooks who are looking to steal payment card data
 
 
 
 
 
Expand article

Technology Tales from Thailand: KBank Fraud Management

2008-08-20 07:16:51 by Tim Bass in The Complex Event Processing Blog
 
...possibility of on-line credit card fraud; and in Keyloggers: Why Banks Need Two-Factor Authentication I described how KBank uses SMS-based one-time-passwords (OTP) to authenticate transactions In addition to the above services, KBankoffers a service that permits users to receive an SMS message that details any change in account balance and/or...
 
 
 
 
 
Expand article

Data security and the "chasm of protection"

2008-06-17 13:25:00 by Manu Namboodiri in Data Protection, Management and Leakage
 
...POS devices, encrypted with the POS application as cards are read in. As this data is required by another application, it has to be first decrypted so this in-store application can read it. It may then encrypt it again as it stores on in-store servers. Now assume you have another application in the data centers that is used for card...
 
 
 
 
 
Expand article

Is PCI compliance creating a false sense of security?

2008-03-28 09:44:50 by Burton Group in Security and Risk Management Strategies Blog
 
...posed up to 4.2 million credit and debit cardholders to potential fraud The result of this breach so far has been about 1,800 instances of fraud as reported by company officials, all company information has been removed from their website (Im assuming while they reevaluate their transaction strategy and architecture) except for a news brief...
 
 
 
 
 
Expand article

Security of "Rogue" or "Shadow" IT?

2008-04-03 12:27:00 by Dr Anton Chuvakin in Anton Chuvakin Blog -
 
...pos t raises some of the alarms with "shadow IT Both tools [ iPhone and Google Apps ] were marketed directly to the appeal of the end-user and made every effort to create a tool (or set of tools) which could be brought into the business environment by an end-user with as little effort as possible Corporate IT is left fighting the new battle...
 
 
 
 
 
Expand article

Hannaford Supermarkets

The Article has images
2008-03-22 12:27:00 by Random InfoSec Guy in Security Coin
...posts below - about the ATM authorizations ? If you look at the message formats, they have card numbers and expiration dates. What was compromised ? Card numbers and expiration dates. (ISO 8583 seems to have track data in its message transmissions - but not until a long way into the stream, and for some reason, I didn't notice it in my raw...
 
 
 
 
 
Expand article

Is PCI compliance creating a false sense of security?

2008-03-28 09:44:50 by Burton Group in Security and Risk Management Strategies Blog
 
...posed up to 4.2 million credit and debit cardholders to potential fraud The result of this breach so far has been about 1,800 instances of fraud as reported by company officials, all company information has been removed from their website (I???m assuming while they reevaluate their transaction strategy and architecture) except for a news...
 
 
 
 
 
Expand article

The Other Certificate Lifecycle Management Companies

2008-05-31 16:53:11 by Editor in Cheap Hack
 
In my recent column on certificate lifecycle management I named three companies in the business ( RSA , Microsoft and Venafi ) and prodded other vendors to come forward and identify themselves. Only one has done so, confirming my suspicion that this is a small market. That vendor is Trustwave with their Certificate Lifecycle Manager . a fairly...