Remember the days when a flaw was a flaw and an exploit of one of these flaws was an exploit? Now-a-days people and vendors throw around Zero-Day Flaw like it's a marketing term. There is no such thing as a flaw, only updates that add features and "enhance security" and emergency hot fixes that plug zero-day flaws that hackers somehow create. I predict that the next generation of marketization will be the dropping of "flaw" and reframe the term as Zero-Day Hack. This way there is no implication of a flaw.
To me, this is akin to people using the word "opportunities" for the word "issues", "issue" for "problem", "not being truthful" for "liar".
A free form area where I can post random thoughts and ideas or simply vent on various current events affecting the payment industry or topics I have addressed on other forums.
Thursday, October 10, 2013
Friday, September 27, 2013
Tokenization IS Encryption - NOT! - Part 4
Oh no -- I've stepped in it again! I did not plan of four parts, but the saga continues:
Some day the saga will end. While comments can be posted here or there as I read them both, posting comments directly on the 4titude blog will probably confuse people less as they have something to reference.
Some day the saga will end. While comments can be posted here or there as I read them both, posting comments directly on the 4titude blog will probably confuse people less as they have something to reference.
Monday, September 23, 2013
Saturday, May 25, 2013
Dog Pile!!!
I've done it again. You can see my latest rant Dog Pile!!! that conveys some of my, let’s say “passionate” thoughts on placing more burden on merchants
for breaches. Enjoy.
Thursday, April 25, 2013
Would you like SLIME coated SPAM with that?
Does anyone else get annoyed with installers, or worse, auto-updaters that constantly sneak in the pre-checked browser toolbar du jour? This is a pet peeve of mine. Two of the biggest offenders on my list are Oracle with their Java and Adobe with their Flash, Shockwave and PDF viewers. These two companies I'll barely tolerate but with most other companies, I'll abort from the installation process as soon as I see the pre-checked toolbar option.
To me, this is a slimy tactic to create a revenue stream for the vendor -- they get paid for tricking people into installing these toolbars. Akin to stuff used cars salesmen would do in years past that gave their profession the stigma they still have today.
If you get annoyed as me, I urge you to complain to these companies. Demand that they quit trying to trick users into installing toolbar or any additional SPAM. Simply un-checking the option by default would eliminate the slime factor, greatly enhancing the vendor's reputation.
Back to work now. Thanks for reading.
To me, this is a slimy tactic to create a revenue stream for the vendor -- they get paid for tricking people into installing these toolbars. Akin to stuff used cars salesmen would do in years past that gave their profession the stigma they still have today.
If you get annoyed as me, I urge you to complain to these companies. Demand that they quit trying to trick users into installing toolbar or any additional SPAM. Simply un-checking the option by default would eliminate the slime factor, greatly enhancing the vendor's reputation.
Back to work now. Thanks for reading.
Friday, February 8, 2013
Complete List of PCI-Validated P2PE Applications and Providers
Validated P2PE Solutions
(this page intentionally left blank - really! - click here to view)
Validated P2PE Applications
(this page intentionally left blank - really! - click here to view)
On the 4titude blog (Shift4's Voice with Attitude), there is a recent post: Why Shift4 is Not (Yet) a PCI-Validated P2PE Application Provider. I created this post to debate anyone who might disagree -- just keep it civil.
Thursday, August 23, 2012
Cybertheft Crackdown My Butt
I've read several stories of late flaunting some high
profile cases where it seemed law enforcement and judges were finally cracking
down on cybercrimes and cybertheft. I thought we finally made the turn and were
prosecuting the perpetrators (hackers) of these crimes the way they should have
been prosecuted all along. Then I read this today: http://www.bankinfosecurity.com/rbs-worldpay-sentence-too-light-a-5058/op-1
In a nutshell, the mastermind of the RBS WorldPay hack,
where $9 million was pilfered from U.S. bank accounts, was sentenced to 30
months in prison and ordered to pay $89,000 in restitutions. Let's see, $89,000+30
months for $9 million, that comes out to a $297,000 per month. That's a pretty
good payoff. I understand that he had accomplices' so he did not pocket the
entire $9 million; but many wannabe hackers reading this will see it as $9
million for 30 months. This sends a strong message: Cybercrime pays!
Until sentences are large enough to discourage the crime, nothing
will change: More money will need to be spent for cyber security -- more
hacking -- more money -- more hacking -- and so on…
Subscribe to:
Posts (Atom)
