October Herding Cats and Off to Brussels! standard

Greetings folks! Couple of updates in this post. October’s Herding Cats is up and ready for you to read! Pretty soon here I will be setting up a URL where you can download all the published versions of this column regardless of your membership status with the ISSA. Need a little time though baby birds. Until then, members of the ISSA can download the most recent version here. As you can tell, I have been reading a lot of James Patterson recently. Sorry about that. Also, if you are going to be at the PCI Europe Community Meeting this week, look me up! I’ll be wheels down in Brussels on Tuesday in time for the networking session. I am looking ...

Continue Reading

PDF Wars: The Rise of the Evil Document standard

VeriSign’s Managed Security Services group provides all kinds of services to assist organizations in the heavy lifting associated with some security tasks. Those tasks that are easy if you have one, but not easy if you have a thousand. In a recent internal email string, one of our engineers told us they are seeing a dramatic increase in the amount of PDFs that have malicious JavaScript embedded in them. These exploits use the OpenAction function (like the HTML document.onload() function) as a vehicle to obtain full machine compromise with a root kit. I’m not sure why we feel the need to embed scripting into a PDF (isn’t that what the web and offline browsing is for?), but it appears that ...

Continue Reading

So you think your memory is safe? standard

One of the topics that I often get into discussions with customers is pulling data out of volatile memory (RAM). The argument that is usually made related to insecure RAM storage is, “Well, someone would have to get on the machine and know exactly where to look in memory and it would just not be feasible for someone to do.” My response to this argument is typically something along the lines of “Obscurity is NOT Security.” Obscurity is a poor defense against security problems. It now appears there is evidence of malware that can grab data in memory to the hacker’s delight. It’s not really rocket science folks; it is actually pretty simple. This technique has legitimate uses in programming, ...

Continue Reading

PCI Version 1.2 Changes standard

Are you interested in how 1.2 affects you? The Council provided a detailed list of changes between the two standards, but sometimes it can be a little overwhelming. The guys over at Aegenis have posted a good summary for those of you who want to cut to the chase. If you have specific questions to your business, why not reach out to a VeriSign consultant? We can provide you the expertise you need! Possibly Related Posts: PCI DSS 4.0 Released plus BOOK DETAILS! PCI Council Loses $600K in Revenue, PO Population on the Decline Why PCI DSS 4.0 Needs to be a Complete Rewrite Orfei Steps Down Should you be a PCI Participating Organization?

Continue Reading

PCI-DSS V1.2 is RELEASED! standard

Just like the rest of you, I couldn’t sleep all night. I tossed and turned in anticipation for this glorious day. It was much like being a kid again and waiting for Christmas morning to hurry up and get here so I could open presents! I jumped out of bed promptly when my alarm went off, got ready for my day and bounded up my stairs to my new office (I’ve moved my office so that the new kiddo can get the bigger room), plopped myself into my chair and furiously tried to wake up my PC. I unlocked it and browsed over and … *sigh* should have slept in. I’ve been hitting reload every ten seconds since (Grey’s Anatomy ...

Continue Reading

PCI-SSC, you are such a tease. standard

I wandered over to the PCI-SSC site today and noticed that they have reposted the press release from August 18 reminding everyone that the new version of the standard will be announced TOMORROW. Thanks for the reminder; I’m pretty sure we all have that date etched into our brains via green laser. Tease…. Possibly Related Posts: PCI DSS 4.0 Released plus BOOK DETAILS! PCI Council Loses $600K in Revenue, PO Population on the Decline Why PCI DSS 4.0 Needs to be a Complete Rewrite Orfei Steps Down Should you be a PCI Participating Organization?

Continue Reading

Thank you PCI-SSC and Orlando! standard

The US PCI Conference is now over, and what a quick two days. There are many changes coming for the new standard, and I’m very excited about talking to you all. We are putting together a webinar to discuss, in detail, the changes that you will be facing. Look for an announcement on that soon. It was great talking with many of you about the issues that we all face every day. I look forward to talking again soon and helping you build creative solutions to these challenges. Oh, and a quick tidbit for you all. If you get a business card from a processor, sometimes even when you put it in a blazing fire pit, it will not burn! ...

Continue Reading

LiveBlog: PCI 1.2 Review, On to the break! standard

OK, the questions have not been really earth shattering. I’m heading to a customer call in a few, so will not be live blogging the latter half. We do have coverage and I will post anything crazy here shortly. Possibly Related Posts: PCI DSS 4.0 Released plus BOOK DETAILS! PCI Council Loses $600K in Revenue, PO Population on the Decline Why PCI DSS 4.0 Needs to be a Complete Rewrite Orfei Steps Down Should you be a PCI Participating Organization?

Continue Reading

LiveBlog: PCI 1.2 Review, Anti-Virus standard

We’re just reviewing these changes and before hundreds of people queued up at the microphone, the intent of the change is to prevent an “automatic exclusion” of Unix or Mainframe technologies. Looks like Anti-Virus is now a case-by-case basis for review. My opinion is that ANY desktop computer with access to the internet should have A/V on it as it is at a higher risk for compromise. In some cases there can be exceptions, and technologies like Solidcore and/or Bit9 can be excellent compensating controls. Possibly Related Posts: PCI DSS 4.0 Released plus BOOK DETAILS! PCI Council Loses $600K in Revenue, PO Population on the Decline Why PCI DSS 4.0 Needs to be a Complete Rewrite Orfei Steps Down Should ...

Continue Reading

LiveBlog: PCI 1.2 Review, Wireless Technologies standard

Clarification that wireless technologies are defined as any point where you make a jump over air. That could include things like Satellite, Microwave, RFID, WiFi, GSM/GPRS, etc. This may become problematic for some users as I believe some QSAs have only been focusing on WiFi and Cellular technologies. The only piece that is somewhat left open here is “carrier-based” technologies. Some network links provided by the Telco include jumps across microwave. Possibly Related Posts: PCI DSS 4.0 Released plus BOOK DETAILS! PCI Council Loses $600K in Revenue, PO Population on the Decline Why PCI DSS 4.0 Needs to be a Complete Rewrite Orfei Steps Down Should you be a PCI Participating Organization?

Continue Reading