SEARCH RESULTS
 
Showing 1-10 of 37 records
 
Expand article

Do you trust the merchants to protect your credit cards?

2007-12-11 09:01:26 by Khalid Kark in Security & Risk Management
 
...merchants to store complete card numbers. Currently, some merchants are required to keep credit card numbers for up to 18 months to satisfy card retrieval and dispute requests. The letter said, "Instead of making the industry jump through hoops to create an impenetrable fortress, retailers want to eliminate the incentive for hackers to break...
 
 
 
 
 
Expand article

McIrony: An unexpected response from McAfee

2008-08-30 13:04:00 by Russ McRee in HolisticInfoSec.org
 
...merchants to a higher standard, without alienating them and losing business Can they not embrace the security research community in a fashion that McAfee, the security community, the merchants, and consumers can all benefit from Can they not be more transparent in their approach, providing more details and feedback about their methods, their...
 
 
 
 
 
Expand article

PCI certification on Websites

2007-10-05 00:00:00 by Manju Mude in Speaking of Security, the RSA Blog and Podcast
 
...merchants have expressed interest in this. Currently, there is no official seal or website logo for merchants that are PCI DSS compliant. However, there are a number of popular seals that web merchants may use to represent good security practices. These include
 
 
 
 
 
Expand article

99% PCI Compliance?

2008-01-25 11:58:00 by Dr Anton Chuvakin in Anton Chuvakin Blog -
 
...Merchants and 92% of Level 2 Merchants have met compliance or have submitted an approved remediation program Is this cool or what I bet it is an "or what Others say " more than a year after the TJX breach first came to light, only 30 percent of retailers are PCI compliant, according to Sophos 2008 Internet Security Report What's the story...
 
 
 
 
 
Expand article

PCI Compliance not going away - 42% not compliant

2008-02-20 14:57:00 by Ryan Shopp in practical risk management
 
...merchants did not reach their respective PCI compliance deadlines. The penalty of non-compliance is merchants incur monthly fines (up to $25,000) until they meet and sustain data security compliance requirements Now that is some attention grabbing marketing and I plan to be on that virtual seminar Almost half (and that's not a stacked...
 
 
 
 
 
Expand article

PCI Data Collection: Your CVV isn't special

2007-08-22 00:00:00 by Manju Mude in Speaking of Security, the RSA Blog and Podcast
 
...merchants have no choice but to collect and store card data for extended periods of time, for bookkeeping, transmission or customer service needs. Additionally, an extremely limited number of them may even have to collect CVV2 information, to ease the customer experience. PCI is very clear about forbidding the storage of PIN and CVV2...
 
 
 
 
 
Expand article

Is PCI compliance creating a false sense of security?

2008-03-28 09:44:50 by Burton Group in Security and Risk Management Strategies Blog
 
...merchants were PCI compliant (compared with 12% in March 2006) and that 62% of midsize merchants were compliant (compared with 15% at the end of 2006). These two merchant categories represent approximately two-thirds of Visa's transaction volume. With other credit card issuers lagging, it seems that theres still a lot of risk in using your...
 
 
 
 
 
Expand article

Is PCI compliance creating a false sense of security?

2008-03-28 09:44:50 by Burton Group in Security and Risk Management Strategies Blog
 
...merchants were PCI compliant (compared with 12% in March 2006) and that 62% of midsize merchants were compliant (compared with 15% at the end of 2006). These two merchant categories represent approximately two-thirds of Visa's transaction volume. With other credit card issuers lagging, it seems that there???s still a lot of risk in using your...
 
 
 
 
 
Expand article

Confidential information sent to PinPay.net and SoftCard.biz is exposed

The Article has images
2008-05-08 13:26:03 by Evan Francen in The Breach Blog
...Merchants, Agents and customers Number Affected Unknown Types of Data Name, mailing address, phone number, email address, date of birth, city of birth, sex, and one or more of the following (chosen from drop-down Passport Voting ID card PAN card Driving License card Government issued ID card Social Security Card Military ID card Consular...
 
 
 
 
 
Expand article

Fun Reading on Security - 2

2008-05-09 12:20:00 by Dr Anton Chuvakin in Anton Chuvakin Blog -