Thursday, April 25, 2013

Would you like SLIME coated SPAM with that?

Does anyone else get annoyed with installers, or worse, auto-updaters that constantly sneak in the pre-checked browser toolbar du jour? This is a pet peeve of mine. Two of the biggest offenders on my list are Oracle with their Java and Adobe with their Flash, Shockwave and PDF viewers. These two companies I'll barely tolerate but with most other companies, I'll abort from the installation process as soon as I see the pre-checked toolbar option.

To me, this is a slimy tactic to create a revenue stream for the vendor -- they get paid for tricking people into installing these toolbars. Akin to stuff used cars salesmen would do in years past that gave their profession the stigma they still have today.

If you get annoyed as me, I urge you to complain to these companies. Demand that they quit trying to trick users into installing toolbar or any additional SPAM. Simply un-checking the option by default would eliminate the slime factor, greatly enhancing the vendor's reputation.

Back to work now. Thanks for reading.

Friday, February 8, 2013

Complete List of PCI-Validated P2PE Applications and Providers

Validated P2PE Solutions

(this page intentionally left blank - really! - click here to view)

Validated P2PE Applications

(this page intentionally left blank - really! - click here to view)

On the 4titude blog (Shift4's Voice with Attitude), there is a recent post: Why Shift4 is Not (Yet) a PCI-Validated P2PE Application Provider. I created this post to debate anyone who might disagree -- just keep it civil.

Thursday, August 23, 2012

Cybertheft Crackdown My Butt

I've read several stories of late flaunting some high profile cases where it seemed law enforcement and judges were finally cracking down on cybercrimes and cybertheft. I thought we finally made the turn and were prosecuting the perpetrators (hackers) of these crimes the way they should have been prosecuted all along. Then I read this today: http://www.bankinfosecurity.com/rbs-worldpay-sentence-too-light-a-5058/op-1

In a nutshell, the mastermind of the RBS WorldPay hack, where $9 million was pilfered from U.S. bank accounts, was sentenced to 30 months in prison and ordered to pay $89,000 in restitutions. Let's see, $89,000+30 months for $9 million, that comes out to a $297,000 per month. That's a pretty good payoff. I understand that he had accomplices' so he did not pocket the entire $9 million; but many wannabe hackers reading this will see it as $9 million for 30 months. This sends a strong message: Cybercrime pays!

Until sentences are large enough to discourage the crime, nothing will change: More money will need to be spent for cyber security -- more hacking -- more money -- more hacking -- and so on…

Thursday, May 24, 2012

My Take on PCI DSS Compliance

As promised, I finished my PCI usefulness post. It can be found on the Shift4 4titude site:


As the title suggests, it is not a glowing review of PCI, or more specifically PCS DSS compliance. Anyway, I don't want to give away too much here. Enjoy.

Thursday, May 17, 2012

Global Payments Breach Growing

The latest reports I read are that the Global Payments breach started in January 2011 -- more than a year earlier than initially thought. To me the story here is that during this timeframe Global Payments went through at least two onsite PCI audits and neither caught the breach in progress. Since Visa and MasterCard were so quick on pulling Global Payment's PCI certification, should they not also pull the QSA's certification(s) as well? I'm not sure if there were more than one QSA involved nor am I certain who it was -- but that does not really matter as my next post will describe. I am currently writing a post on the usefulness of PCI, or lack thereof. Stay tuned...

Monday, December 5, 2011

Debit Card Fees - Simply another front in the ongoing class war


I just read this commentary in the Washington Post: In cutting debit card fees, Fed should use Congress’s standard. I could not disagree more. I have not got a clue where the author is getting his numbers? My guess is that he is calculating the $7B vs. $14B based the campaign marketing numbers used to sell the bill to congress and the public. There are flaws in this type of thinking and I'll get into that below, however, this did get me thinking of a related but bigger problem.

I'm sure by now everyone reading this has heard about the class warfare arguments in politics. Whether you believe the "rich" should pay more or not is one issue but to me, the bigger issue is the class warfare campaign. This is a slippery slope. Take for instance the Dodd-Frank Wall Street Reform and Consumer Protection Act. This is another battle of the same war being fought under the guise of "consumer protection."

I've briefly touched on the Dodd-Frank Act before. I think that this entire bill is a big can of worms that many proponents don't understand or choose to blindly ignore. Some of the provisions of the act that has generated buzz in the payments space are the restrictions it places on debit card transaction fees. Merchants have been told they will receive huge cuts in fees due to this bill. The NRF jumped on this bandwagon early in the process. I have not fully researched their involvement, but I would not be surprised if they provided parts to create this wagon.

There is one key component that the NRF and other merchant advocates blindly missed - the title of the act. Note the last two words just before Act: "Consumer Protection!" Not "Merchant Protection." Definitely not "Bank Protection." While today having the word "bank" in your name is synonymous to "rich", who's to say that tomorrow "merchant" won't be as offensive as "bank" to politicians? Currently the Dodd-Frank Act does not specify that merchants, or consumers for that matter, will receive one dime from the restrictions as there are many hands in the fee structure pie (not to mention various carved out exceptions). I can easily see a scenario where politicians realize that consumers are not reaping the rewards they were so generously promised so out pops "[insert name(s) here] Main Street Reform and Consumer Protection Act." Since politicians are so good at adding language to fix prior failures, one can expect a generous heaping of price controls for merchants to swallow, all under the same guise of "consumer protection."

As I said, this is a slippery slope. I've warned of side effect of price controls before this Dodd-Frank Act was implemented; we are seeing them now (see my previous post). One of the latest is that Visa and MasterCard have increased credit card fees: New Visa, MasterCard rates take effect. While not publicly stated, I have to imagine that this is to compensate for the loss of debit card fees. Since credit card usage rates are still higher in the US than debit card usage, this will mean a wash or an increase in fees even if the merchant does receive the debit card "rewards."

Just to clarify, I am not anti-merchant, and I am not pro-bank fees; instead I am very pro-merchant. I am against the government controlling prices for any industry. I feel allowing the government to dictate the price of any product or service is dangerous. Yes, there is precedence for government dictated price controls and some might argue this to be a good thing, and throw out some examples. But I would argue that these price controls have caused as much or more damage and problems than they fixed -- just to someone else (the politically out of favor class at the time).

Until next time...