jump to navigation

Guest Post: “Of Payments, Privacy, and Social Networks” April 15, 2012

Posted by Chris Mark in Industry News, InfoSec & Privacy.
Tags: , , , , ,
add a comment

As I have been out of town at a charity event and had little time to blog, I am publishing a blog from the incomperable Dr. Heather Mark 😉  Please enjoy…

“By now, many of you have probably heard about the smartphone app creatively and aptly named “Girls Around Me.” For those that have not heard, it is essentially an application that aggregates the “check in” location data of women using Facebook, foursquare, and other social, location based services.  It then displays for the user the locations and names of “girls around” him (or her, I don’t think the app discriminates).  The app promises to “turn your town into a dating paradise.”  For privacy professionals, the app sparks an interesting debate.  Is privacy infringed if the person in question volunteers the information.  On one side of the argument are those that would say “no – if the user has volunteered information then privacy is not compromised by the application.”  The converse of that argument, however, is one that centers on a definition of privacy that hinges on the appropriate use of information.  If the user did not volunteer the information in an effort to join this “dating paradise” then privacy is certainly infringed.  Certainly, one can see that the application in the wrong hands has the potential for misuse.  But, what if we use the information for good, rather than evil?”  read more here! 

Another Total Security Failure!?- 750K Socials Stolen in Utah April 10, 2012

Posted by Chris Mark in Industry News, InfoSec & Privacy.
Tags: , , , , , , ,
add a comment

(RANT ALERT) While everyone is fighting over who gets to eviscerate Global Payments in the press today, a major breach of sensitive data goes unnoticed.  For the record…Credit Card theft is NOT identity theft.  Steal my credit card every day of the week…I have zero liability. Do NOT steal my social or passport or drivers license. We seem to be focused on the wrong data at times. I live in Utah and am pretty sure my wife, and my own 2 year old son’s Social was included in this breach.

Today on Foxnews.com a story was posted about how hackers stole “hundreds of thousands of social security numbers” from the Utah Health Department.  Well…this is not entirely accurate.  The data thieves did steal the Socials but they also stole medical information and other personal information such as names, addresses etc.  The total number of records is nearing 900,000.  Here is my beef…according to  the story: (more…)

Ethical Relativism- Sky News Morphs into Anonymous? April 5, 2012

Posted by Chris Mark in Industry News, InfoSec & Privacy, Laws and Leglslation.
Tags: , , , , , , ,
2 comments

By now most are probably aware of the email hacking scandal that severely damaged Rupert Murdoch’s NewsCorp empire.  NewsCorp reporters were caught illegally accessing phone calls of the UK Royal family and hacking into email accounts of individuals.  Murdochs’ son had to resign from his position as Chairman of BSkyB which own UK’s Sky News.

According to a report on CNN this morning UK news channel Sky News said Thursday it had authorized its journalists to hack into the e-mail of individual members of the public on two occasions.  The very same people (journalists) that will scream for “freedom of speech” and “freedom of the press” and claim journalistic integrity are now violating the public’s privacy in a scramble to maintain market share and increase revenue?  (more…)

“Blaming the Victim and the PCI DSS is…Passe”- PCI DSS; GlobalPayments & Data Theft April 1, 2012

Posted by Chris Mark in Data Breach, Industry News, InfoSec & Privacy, PCI DSS, Risk & Risk Management.
Tags: , , , , , , , ,
add a comment

In an effort beat the “PCI Evangelists”; “wagon jumpers”, “naysayers”, and “PCI Haters” to the punch, I am publishing my post on a Sunday evening.  By tomorrow morning the speculation on how the GlobalPayments compromise occurred will be in full swing and no doubt, many will have already condemned the company for “PCI DSS non compliance” or being “sick, lame, or lazy” when it comes to their PCI DSS compliance or information security.  Others will have published articles condemning the PCI DSS as ‘ineffective’, ‘irrelevant’, or simply ‘stupid’.

Before they are condemned I want to go on record and say it NOT a PCI DSS compliance issue that caused the compromise. Like Heartland Payment Systems, Royal Bank of Scotland Worldpay and many more before them, GlobalPayments has been held out as the paragon of PCI DSS compliance for years.  Now that they have been breached they will be expected to wear a scarlet letter for the foreseeable future. I have no doubt that by the end of next week their status as a “Level 1 PCI DSS Compliant Service Provider”  will have either been revoked by the card brands or be under “review”.In the same vein, there will be many who shout from the rooftops that the PCI DSS is “irrelevant”, “outdated” and so on.  Neither of these positions are accurate.

Here it goes…(drum roll please)…

The PCI DSS is a solid set of information security controls and represents minimum necessary controls to minimize the likelihood of data compromise through common, identified vulnerabilities. (more…)

What to do if your card was compromised and used… April 1, 2012

Posted by Chris Mark in Data Breach, Industry News, InfoSec & Privacy.
Tags: , , , , , ,
add a comment

I have already read 5 different articles where experienced and well known security evangelists are discussing how their credit card data was exposed and how it exposed them to danger.  Here are some things to understand about credit card theft and liability.  First, credit card theft is NOT identity theft.  Certainly, criminals can make fraudulent transactions but they cannot assume your identity to buy a boat, house, or get further credit.

Second, Under Federal law, consumers are limited to $50 for fraudulent credit card transactions.  The major card brands (Visa, MC, Amex, JCB, Discover) all have “Zero” liability clauses.  This means that if your card was used fraudulently…you have no liability for transaction that run over their networks. If it is a PIN based transaction (debit, for example) there are other considerations.  You can read more on this post. “Signature or PIN? Credit or Debit?…the answers”  If the Global Payments breach was limited to track 1 or track 2 data as reports indicate, then the PIN issue is not relevant.

Here is what you should do…

1) check your credit and debit card accounts. Debit cards can be processed as an ‘offline’ transaction which means they run over credit networks.  The criminals can use them just like stolen credit cards.  If you see unauthorized transactions take the next step.

2) call your issuing bank (bank listed on your card) and inform them of the fraudulent transactions.  They will require you to complete an affidavit stating it was not your charge, etc. etc.  If you have unauthorized charges on your bank account from the debit card being compromised, read the post here as it is a bit more complex from time to time. Understand that your bank will CANCEL the card and reissue a new card.  Make sure you have taken steps to update your bills etc.

3) continue to monitor your accounts for fraudulent activity…that simple.

Hopefully this helps assuage some concerns