There’s a cheesy quote by Norman Vincent Peale which goes; “Shoot for the moon. Even if you miss, you’ll land among the stars.”

This does not apply if PCI compliance is your end goal.

Set PCI compliance as your goal and miss, and you haven’t even made it out of the barrel. However, if you shoot for REAL security, there is a very good chance you’ll achieve compliance with almost any standard or regulation along the way.

PCI has always been, and will always be a minimum set of security controls and nothing more. The SSC has said as much themselves, as have the card brands, as has anyone else who actually knows what they are doing. This is not meant as a criticism of the standard, they don’t have a lot of choice, and any organisation treating PCI as an annual project, and/or is bitching about how difficult it is, deserves what they get.

As I’ve said more times than I care to admit; “Take the phrase ‘cardholder data’ out of the DSS and replace it with the phrase ‘personal information about your family’. Now name ONE requirement you don’t want in place? Seriously, name one. So if you agree that these are nothing more than the most basic security controls, why have you not put them in place already?

In every section of the DSS there is a LOT of room for better practices, for example:

DSS Section 1 – Do you to have device-to-device-only rules configured, or just a business justification for the ones you have?

DSS Section 2 – Do the testing procedures for a system require a configuration standard for every device type, or every individual device?

DSS Section 3 – Can you really perform manual key management well?

DSS Section 6 – Should you include ONLY the OWASP Top 10 in your app security testing?

DS Section 10 – Do you have to log centrally, and can you really perform manual reviews of your log files on a daily basis?

…and so on and so on. And let’s not forget this is still just about credit card data, validated just once a year, and [potentially] only on a small sub-set of your environment.

If you were to perform a business wide risk assessment, then a security controls gap analysis, you would come up with many deficiencies in your security programme. Then, IF you were to actually take this seriously and not just seeing security as an expense, you would come up with a remediation plan that I can [almost] guarantee would achieve PCI compliance on the way to your goals.

Chances are better than even that you have not even performed the risk assessment, so you have no idea what you goals ARE, and look at PCI compliance as something to get out of the way as soon as possible. You will achieve PCI compliance as a tick-in-the-box exercise, throw good money after bad, and start all over again next year.

This is unfortunate, as your appropriate security goals would most likely have kept you compliant throughout the year, saving you a significant amount of time, effort and cost on re-certification. Oh, you would also be a lot more secure.

I bet Target, Neiman Marcus and Michaels wish they had done security properly.

Every time you go above an beyond what PCI requires, you are building a database of compensating controls. The more compensating controls you have, they less constrictive PCI becomes, and the closer you get to applying the expense of PCI to your actual business goals. Eventually there will be no waste.

This marks the beginning of a 12 part series where I will explain the intent of the 12 main sections of the PCI DSS, as well as provide guidance and options on how to go above and beyond PCI so that you can you can focus on the meaning of PCI and not just the words. More importantly, you can focus on your business.

[If you liked this article, please share! Want more like it, subscribe!]

In the near future, most of us will want to:

  1. be able to walk into the supermarket, collect our stuff, and walk straight out with the payment already processed in the background
  2. receive instant coupons, or 2-for-1 offers, or other value add services WHILE shopping
  3. receive a warning if an item contains something to which we are allergic
  4. receive a reminder from your fridge / freezer / cabinets that you are low on certain products while you are walking down the relevant aisle
  5. …and so on.

However, you cannot have any of these things unless you made the necessary information available to the supermarket chain you are in. And they will not make these things available TO you unless they have good assurance that you, are in fact, you.

To enable just those 4 things listed above, you had to release a significant amount of personal data, all of which can have privacy implications:

  1. requires a number of things – from biometrics (facial recognition for example) to financial account access
  2. requires a comprehensive and always growing record of your choices, preferences, and habits
  3. requires details of certain bits of medical data
  4. requires your entire kitchen / bathroom / bedroom to be enabled for the Internet of Things, as well as a highly detailed geolocation on your whereabouts
  5. …and so on.

Are you OK with that?

I am, but I know many who are not, and I also know that as the generations progress, there will be less and less concern over these ‘conveniences’, as they will have become common place. I will go as far as to say that within the next 10 years, any supermarket NOT providing some of all of these services will not be able to compete, and possibly become Internet-Free corner stores where you’ll find the world’s ‘privacy paranoid’ shopping for their tin-foil helmets and electronic cloaking devices.

The bottom line is that the concept of privacy itself is changing. The generation of kids in secondary schools today has never known life without the Internet, and in most industrialised nations, every kid has a mobile phone. They are always plugged in, always connected, and, as never before, a vast majority of their lives is recorded somewhere online. They are active on social media, SMS, chat, email, and every other technology designed to stay in touch 24/7.

Our idea of privacy is not theirs, and everything from racial prejudice to the stigma attached to nudity will standardise and globalise, and I cannot help but think for the better. Your children’s education will no longer be tied entirely to the doctrines of the previous generations, and self perpetuating ignorance has no place in a time when every piece of knowledge is at your fingertips. Not that this will stop those determined to be an arse.

I’m certainly not talking about some utopia here, ignorance in all its forms will never go away, but if the vast majority of your life is an open and available book, your complete identity becomes an ultimate form of authentication, and the security OF your identity only gets better as your life progresses.

The current ability to authenticate only against static data will no longer suffice (passwords, secret questions etc.), and the coming methods of identity management and authentication will completely change the face of privacy.

I see this as a good thing, but I’ll leave it to the folks hiding away in Faraday cages to make sure that Big Brother doesn’t get everything his way.

 

In continuation of my crusade against EMV in general, the card schemes have announced an end to issuer-only fraud liability for non-chip transaction starting in October 2015. The so called ‘liability shift’.

For those who don’t know, it’s the issuers of the credit card that accept the liability for fraud during a branded credit card transaction, which is why they receive the lion’s share of the fees associated with the transaction (interchange fees). But now, if the merchant does not upgrade their point-of-sale terminals to those capable of accepting chip cards, it’s the merchant who suffers the fraud loss. Same thing goes for a consumer who wants to continue using swipe  & signature cards.

While I assume that those with disabilities, and / or the elderly will be given the option to not change to chip & PIN, the fact remains that the enormous cost of the transition to this ‘new’ technology will not be born by those who have basically created the problem over the course of over 60 years; the card brands. It will be the consumer …eventually, because the merchants / retailers will have to re-coup their up front costs.

And all this just to keep taking credit cards!

Why do retailers and banks STILL see credit cards as the only form of non-cash payment? Why DO the card brands have so much power over end-user payments technology when there are ‘only’ ~6 billion credit cards in the world and >7 billion mobile phones? On top of that, mobile phones have a far wider distribution than an EMV infrastructure can EVER hope to duplicate, and you have what I would see as a very simple choice in how to transition away from plastic.

I’ve said it repeatedly; payments is NOT about the FORM of payment, it’s about authentication of the individual to the organisation holding the funds (usually a bank), and NO form of account-detail-up-front (read credit card number, even a token of one) can ever be as secure as one protected by proper identity management. Yes, even on a mobile device.

What the US retailers are going to do is spend an absolute fortune on a payment acceptance technology that will be impossible to upgrade to anything else, nor will it be anywhere near as flexible for those retailers wishing to innovate in new forms of value-add services and marketing drives.

I have no problem with the card brands making a ton of money, that’s business and they do have a lot to add in the payment arena, but to continue the push for EMV is as horrendously self-serving as it is pointless. If it’s not them pushing for it, and it’s actually the Fed, then THEY should do their homework and talk to the retailers.

However, if the retailers aren’t going to do anything about this, then it pretty much serves them right.

For example; What card brand or issuer is going to tell Walmart that they can’t use an EMV alternative that has been shown to have a similar security profile AND infinitely greater business benefits? Can you really see them giving up a multi-million dollar revenue stream just to enforce a patch on a 60+ year old technology?

No, neither can I.

In the most ridiculous decision possible, Target have agree to ACCELERATE their ‘smart card rollout’ to the tune of about $100M;

Target to accelerate $100 million chip-enabled smart card program: CFO, Reuters, Feb 03, 2014

Let me say that again; ONE HUNDRED MILLION DOLLARS!

How exactly are these new smart cards (which is EMV / Chip & PIN obviously)  going to reduce “cyber theft” when they do absolutely nothing except prevent card present fraud? It’s not as though this amazing chip-enabled technology actually encrypts the cardholder data point-to-point (that’s a terminal function, if available), so it doesn’t stop Target saving the data post-auth. And because not ALL US retailers and merchants are going to accelerate THEIR programs, Target have done nothing to prevent the real menace; card NOT present fraud.

What are they going to do when their customers start demanding other forms of payment, like mobile? Or when they start losing market share because value-add services won’t integrate with their shiny new static-function payment terminals? Spend ANOTHER $100M?

I’ve said it a hundred times, payments is NOT about the payment functionality itself, it’s about the AUTHENTICATION of the individual trying to MAKE the payment. In that, Target are completely missing the point.

If this is pressure from the card brands shame on them, if it’s pressure from ‘Government regulators’, shame on THEM, but if this is just Target being short-sighted and throwing good money after bad, then I hope their share-holders wake up before it’s too late.

I for one would be really pissed if had a vested interest in this.

Why, in the face of threats, do we humans either spend an inordinate amount of time blaming others, or insist on patching the symptoms instead of solving the root cause?

  • Target: I had my credit card data stolen, so let me buy millions of dollars of new PEDs
  • ICO: The NHS lost some data, so let’s fine them.
  • Rest of the World: The NSA is reading our emails, so let’s encrypt them.

Every one of these reactions has completely missed the point, and are the definitive closing the barn door after the horse has bolted.

Question: Do you tell your deepest secrets to your loved ones in a very loud voice in the middle of a room crowded with strangers? Or do you wait until you’re alone, and even then talk quietly just in case?

And yet you think you should have privacy on the Internet?  You could not yell any louder than that. Forget your RIGHT to privacy, focus on YOUR ability to KEEP things private.

Even with encryption, who has the best equipment and expertise; you, or the NSA? Or worse; you, or organised crime? They are extremes, so let’s bring it closer to home; you, or your IT admin? How about; you, or your children?

So now, instead of solving the problem, security vendors are going to inundate you with offers to encrypt your data, encrypt your communications, encrypt your very identity, and they will all fail. 2014 should be the Year of Identity Management & Authentication, or to put it more facetiously; The Year of Only You Being You.

Here’s a ridiculously long and complicated analogy of your identity;

Imagine that you are a 1,000 piece puzzle, and when all of the pieces are together, only then can you see the full picture. As the puzzle is broken up and distributed across many hundreds of separate locations, the picture fades from each piece until it’s just plain white. Anyone stealing even a couple of hundred pieces will never be able to re-create you, never know what the picture is, or even where to find the rest of it.

Now, image that access to your most private information was tied to the complete picture, would that not be infinitely better than a username and password, or a 4 digit PIN?

Your true identity, the everything that is you, is made of things that cannot be put into a mechanism for authentication. Yet all we have right now is 3 factors: something you know (password), something you have (physical token), and something you are (biometrics). What about your likes and dislikes? Your future plans? Your everyday interactions?

All of theses things and infinitely more make up your true identity, and until we can come up with a way to get a whole bunch of them into a practical and seamless method of authentication, your data will be at risk, regardless of encryption. Yes, encryption may add a layer of security, somewhat akin to building your fence higher than your neighbours, but any commercial encryption product that will be pushed for home PC or mobile users will be practically useless.

Instead, privacy will come from the exact same source as identity managements’ will; very wide distribution of data with extremely limited ability to piece it all together. Some may disagree with my previous blog on the benefits of ‘profiling’, but you cannot have a robust identity without it. Bitcoin has proved that you do not need single databases/sources of storage for this stuff, the interconnectivity of the Internet’s individual systems can provide that with the right front end.

So, bottom line; don’t waste your money on expensive encryption solutions unless those solutions are performing the above distribution (bitcloud for example), but then it’s not encryption as we know it, it’s the next generation of privacy.