Archive | Uncategorized

Hilter, Cloud Computing, and PCI DSS

Good lord I laughed hard when I watched this.

Hitler, Cloud Computing and PCI DSS

Pretty geeky, but it sums it up well. My favourite: “You gave it a .4! What does that even mean?!?”

Posted in Uncategorized0 Comments

Franchise models, responsibilities, and the Impact on PCI Compliance

An interesting post from blog.elementps.com on the difficulties of franschise models and their impact on the paths of responsibility for PCI DSS compliance.

From a branding standpoint, franchisors have a lot to lose if one of their franchisees falls victim to a breach.  Depending on the level of media attention the breach garners, one for a store in downtown Philadelphia has the potential to negatively affect the brand – and, arguably, sales— across the state, regionally or even nationally.

The interesting thing with franchising and PCI DSS is that while franchisees may have individual merchant accounts with the bank (and therefore be responsible for their own reporting) the impact of a breach on the franchisers compliance may come up for question if a breach was to occur, as well as the inevitable brand reputation loss…

I’d be interested to here any feedback from the field on the topic.

Reblog this post [with Zemanta]

Posted in Uncategorized0 Comments

WPA Cracked

I know that this is fairly old news, but the rate of take up of wireless in the enterprise space makes it worthy of attention, and indeed the first real post on this blog.

I guess it was always going to happen. The fruit is hanging far to low with wireless networking for it not to attract a hell of a lot of the wrong type of attention. The saving grace is the fact that TKIP Personal seems to be the only flavor of WPA threatened.

The paper, Practical Attacks against WEP and WPA, is available for download. Giddy up!

Reblog this post [with Zemanta]

Posted in Uncategorized, Wireless Security0 Comments