Friday, September 27, 2013

Tokenization IS Encryption - NOT! - Part 4

Oh no -- I've stepped in it again! I did not plan of four parts, but the saga continues:
Some day the saga will end. While comments can be posted here or there as I read them both, posting comments directly on the 4titude blog will probably confuse people less as they have something to reference.

Saturday, May 25, 2013

Dog Pile!!!

I've done it again. You can see my latest rant Dog Pile!!! that conveys some of my, let’s say “passionate” thoughts on placing more burden on merchants for breaches. Enjoy.

Thursday, April 25, 2013

Would you like SLIME coated SPAM with that?

Does anyone else get annoyed with installers, or worse, auto-updaters that constantly sneak in the pre-checked browser toolbar du jour? This is a pet peeve of mine. Two of the biggest offenders on my list are Oracle with their Java and Adobe with their Flash, Shockwave and PDF viewers. These two companies I'll barely tolerate but with most other companies, I'll abort from the installation process as soon as I see the pre-checked toolbar option.

To me, this is a slimy tactic to create a revenue stream for the vendor -- they get paid for tricking people into installing these toolbars. Akin to stuff used cars salesmen would do in years past that gave their profession the stigma they still have today.

If you get annoyed as me, I urge you to complain to these companies. Demand that they quit trying to trick users into installing toolbar or any additional SPAM. Simply un-checking the option by default would eliminate the slime factor, greatly enhancing the vendor's reputation.

Back to work now. Thanks for reading.

Friday, February 8, 2013

Complete List of PCI-Validated P2PE Applications and Providers

Validated P2PE Solutions

(this page intentionally left blank - really! - click here to view)

Validated P2PE Applications

(this page intentionally left blank - really! - click here to view)

On the 4titude blog (Shift4's Voice with Attitude), there is a recent post: Why Shift4 is Not (Yet) a PCI-Validated P2PE Application Provider. I created this post to debate anyone who might disagree -- just keep it civil.

Thursday, August 23, 2012

Cybertheft Crackdown My Butt

I've read several stories of late flaunting some high profile cases where it seemed law enforcement and judges were finally cracking down on cybercrimes and cybertheft. I thought we finally made the turn and were prosecuting the perpetrators (hackers) of these crimes the way they should have been prosecuted all along. Then I read this today: http://www.bankinfosecurity.com/rbs-worldpay-sentence-too-light-a-5058/op-1

In a nutshell, the mastermind of the RBS WorldPay hack, where $9 million was pilfered from U.S. bank accounts, was sentenced to 30 months in prison and ordered to pay $89,000 in restitutions. Let's see, $89,000+30 months for $9 million, that comes out to a $297,000 per month. That's a pretty good payoff. I understand that he had accomplices' so he did not pocket the entire $9 million; but many wannabe hackers reading this will see it as $9 million for 30 months. This sends a strong message: Cybercrime pays!

Until sentences are large enough to discourage the crime, nothing will change: More money will need to be spent for cyber security -- more hacking -- more money -- more hacking -- and so on…

Thursday, May 24, 2012

My Take on PCI DSS Compliance

As promised, I finished my PCI usefulness post. It can be found on the Shift4 4titude site:


As the title suggests, it is not a glowing review of PCI, or more specifically PCS DSS compliance. Anyway, I don't want to give away too much here. Enjoy.