SecurityRatty :: tag: pos
Featured Articles :: New attack trend pushes POS encryption to the fore :: New attack trend pushes POS encryption to the fore :: Technology Tales from Thailand: KBank Fraud Management :: Data security and the "chasm of protection" :: Is PCI compliance creating a false sense of security? :: Security of "Rogue" or "Shadow" IT? :: Hannaford Supermarkets :: Is PCI compliance creating a false sense of security? :: The Other Certificate Lifecycle Management Companies :: PC Universe is shrinking thanks to McAfee Secure's cluelessness
The recent rash of data thefts from retail point-of-sale systems is prompting security vendors and payment processing firms to offer tools for encrypting POS information
The relatively scant attention that retailers have paid to securing their point-of-sale systems over the past few years is making the POS setups increasingly attractive targets for cybercrooks who are looking to steal payment card data
...possibility of on-line credit card fraud; and in Keyloggers: Why Banks Need Two-Factor Authentication I described how KBank uses SMS-based one-time-passwords (OTP) to authenticate transactions
In addition to the above services, KBankoffers a service that permits users to receive an SMS message that details any change in account balance and/or...
...POS devices, encrypted with the POS application as cards are read in. As this data is required by another application, it has to be first decrypted so this in-store application can read it. It may then encrypt it again as it stores on in-store servers. Now assume you have another application in the data centers that is used for card...
...posed up to 4.2 million credit and debit cardholders to potential fraud
The result of this breach so far has been about 1,800 instances of fraud as reported by company officials, all company information has been removed from their website (Im assuming while they reevaluate their transaction strategy and architecture) except for a news brief...
...pos t raises some of the alarms with "shadow IT
Both tools [ iPhone and Google Apps ] were marketed directly to the appeal of the end-user and made every effort to create a tool (or set of tools) which could be brought into the business environment by an end-user with as little effort as possible
Corporate IT is left fighting the new battle...
...posts below - about the ATM authorizations ? If you look at the message formats, they have card numbers and expiration dates. What was compromised ? Card numbers and expiration dates. (ISO 8583 seems to have track data in its message transmissions - but not until a long way into the stream, and for some reason, I didn't notice it in my raw...
...posed up to 4.2 million credit and debit cardholders to potential fraud
The result of this breach so far has been about 1,800 instances of fraud as reported by company officials, all company information has been removed from their website (I???m assuming while they reevaluate their transaction strategy and architecture) except for a news...
In my recent column on certificate lifecycle management I named three companies in the business ( RSA , Microsoft and Venafi ) and prodded other vendors to come forward and identify themselves. Only one has done so, confirming my suspicion that this is a small market. That vendor is Trustwave with their Certificate Lifecycle Manager . a fairly...