My rather unusual theory; that too much privacy might actually reduce your security, stems from a few things:

1) Security is all about baselines, and anything that falls outside of those baselines should be prevented, or at least investigated;

2) Everything you do in life is based around one thing; your identity. Relationships, work, and everything you do over the Internet is a direct reflection of all the things that make you, you. It’s the AUTHENTICATION of your identity that enables your everyday actions online. It also exposes your data, and;

3) The one thing that has no place in pro-active security; Big Data, actually has an enormous role to play in your privacy and the security of your identity. Somewhat counterintuitively, it’s the big data that provides the baseline from which your identity can be protected.

Most of us know that your spending patterns are what the banks / card brands use to detect potential fraud, but this data is only a small part of your identity, the sum of which includes (but is not limited to); your location, work history, financial history, family and friends, likes and dislikes, and pretty much everything you’ve ever posted online.

What if your identity could be profiled? Not in the negative way used to profile ‘possible terrorists’, but in a way that prevents someone else from being you. For example:

1) Why would you buy an international airline ticket if you don’t have a passport, or if you have never previously left your own country?;

2) Would someone start posting hate filled messages on FB /Twitter etc. if all they’ve posted previously are funny cat stories?;

3) Would someone change address and order new credit cards if nothing in their ‘profile’ suggested they were moving?;

4) Would someone go on a spending spree, when their ‘profile’ suggests a lifetime of frugality?;

…and so on.

The answer to all of these questions, is maybe, and except for 2., they most certainly should not be stopped from performing these legitimate actions, but there COULD be a greater degree of due diligence on the part of the organisations fulfilling these requests to confirm identity first. This is only possible if they have access to a profile from which to make these necessary decisions.

The profile does not have to contain all of your deepest darkest secrets, but enough of your identity has to be available for organisations to make judgment calls. Yes, this could be used for targeted marketing (not everyone is covered by the GDPR), and yes, bad people will always find ways of using a ‘profile’ for more nefarious reasons, but we already HAVE many forms of profiling that we take for granted; credit scores, CV/resumes, social media content, circle of friends, clubs / associations and so on.

The use of these existing profiles for good and bad is not so much in the individual components, it’s in the whole, and it’s one of the rare instances where the whole is in fact greater than the sum of its parts. However, the more information that’s out there should lead to a safer profile due to numerous overlapping and cross-referenced checks and balances, all of which report back to you.

Of course, there will always be those who instantly assume this will become an Orwellian dystopia and move to a cabin in the woods, and there will be those who see it as a utopia and jump in head first. The answers for the rest of us lie somewhere in-between, and will evolve over time.

This generation is already making it happen in my opinion, with the prevalence of social media entire lives are being documented online, and the apparent lack of common sense when it comes to posting compromising selfies suggests that our idea of what’s ‘private’, is not theirs. What my generation cares about, cannot be forced upon the next, and our values cannot dictate how the next generation leads their lives, but what we CAN do is design an identity framework that turns privacy into what it’s always been; a form of ‘currency’ for which YOU need to take full responsibility.

Spend too much and you’ll have no identity to call your own, spend too little and you’ll be left behind.

What you want, and what we don’t currently have, is a choice.

[If you liked this article, please share! Want more like it, subscribe!]

Just about everyone who writes on information security has had ample blodder from the Target / Neiman Marcus et al breaches, myself included. Some blame the PCI standards or the card brands themselves, some blame the retailers for not doing enough, and those that are a little more charitable, just blame the thieves.

In the end, it’s not about blame, it’s about learning the lesson, making the necessary adjustments, and moving on responsibly. Unfortunately, this will NOT include being able to move on from credit cards or from the PCI DSS v3.0 any time soon, so organisations wanting to avoid becoming the next Target (excuse the pun), had better pay more attention to their enterprise-wide security program, not just their annual compliance ‘projects’.

Just as importantly, they need to pay VERY close attention to innovation in the payment / authentication space, and advances in more real-time security measures / technologies.

Nothing in the PCI DSS is anything other than a bare minimum, and represents enough security for the card brands to say they are doing what they can. But any organisation who thinks this is enough will eventually lose data, and I for one have no sympathy.

You can look at every single requirement and come up with two choices: 1) Good enough for PCI, and 2) Appropriate for the business. 9 times out of 10, the second option is more difficult to implement, but in almost every instance, it is both easier to maintain, and more secure.

For example;

PCI DSS Requirements 1.X are all about networking, firewalls, segmentation and the like, and while it does stress that every service/protocol/port must have a business justification, it does not state specifically that every individual in-scope device must have least-privilege inbound and outbound rules applied.

  1. 1.1.6.a – Verify that firewall and router configuration standards include a documented list of all services, protocols and ports, including business justification for each
  2. 1.2.1.a – Examine firewall and router configuration standards to verify that they identify inbound and outbound traffic necessary for the cardholder data environment.
  3. 1.2.1.b – Examine firewall and router configurations to verify that inbound and outbound traffic is limited to that which is necessary for the cardholder data environment.

Yes, we can imply it means each device (especially 1.2.1.b), and yes, it’s the right thing to do, but no QSA can enforce anything that is not specifically written within the standard. If they had just replaced “the cardholder data environment” with “each in-scope system” DSS Section 1 would be VERY different, and instil a significantly better security posture.

However, if they DID change it to least privilege for every device, is it actually possible to implement and maintain it? Same goes for more robust configuration standards (DSS Section 2), or real-time logging (DSS Section 10), what should be done is very different from what the DSS requires.

In answer to the question, yes, it is possible, and it all boils down to one thing; baselines

Security is not about crunching big data to determine patterns, that’s only truly relevant in forensics when it’s already too late. Real security is knowing exactly what something SHOULD look like performing normally, and reporting everything outside of that. Keep it simple, or it cannot be monitored, maintained, or measured, but the PCI DSS can never go this far.

Hypothetical: If you knew every running service, listening port, and permitted connections each in-scope device should maintain to perform its function, then anything NOT those things should be investigated. That’s a baseline. Security would dictate that you have alerts based on these anomalies for all systems, not a sample of them and certainly not once a year (point-in-time).

How difficult would it be to automate this process so that EVERY system (not just PCI ones) reports back on a daily/weekly/monthly – or ANY period of time less tun a year! – basis to a centralised management console to perform the baseline comparisons? Then what’s to stop you comparing the device’s listening ports to firewall rule sets to make sure they are properly defined? Or comparing them against enterprise policies and standards, or known business data flows?

Not one organisation or security vendor is doing this properly, at least not that I have seen, or not yet. Some vendors do bits of this, but the last thing you want to do is patch together a bunch of separate, non-integrated systems, as the effort to do so will usually outweigh the risk mitigation, or the cost-to-benefit ratio.

However, none of this can happen until you have centralised and accurate asset management, and seeing as the PCI DSS just added that as a requirement in v3.0, most organisations have a long way to go before they can ever achieve this ultimate in security; continuous compliance validation.

First, any discussion on ‘mobile payments’ needs to start with a explanation of what I mean by it. There are many definitions and types of mobile payment; anything from SMS, to direct mobile, to mobile web, and from NFC to QR can all be labeled a ‘mobile payment’.

However, from my perspective, there are really only two main categories of mobile payment:

1. A mobile device is used in authenticating the individual making the payment, the transaction happens in the background (e.g. e-wallets), and;

2. An application on the mobile device passes the sensitive payment details (e.g. paying with credit card through a web browser)

Clearly 1. is better than 2., as mobile phones will probably never be as secure as we’d like them to be.

Second, I think it must be understood that ‘payments’ in general is NOT about the payment itself, that’s just detail, it’s about the authentication of the individual making the payment. Whether you have a checking account, a line of credit, an e-wallet, etc. as your source of funds, you don’t care how you get to it as long as doing so is safe, convenient, widely available, and value for money.

However, safety and convenience have always been, and will always be, a balance of mutual exclusivity. In other words, the more you have of one, the less you have of the other.

The reasons mobile payments are nowhere near as ubiquitous as credit cards […yet], are myriad and include;

1. Credit cards are familiar to, and used by, a large chunk of the planet. There are approximately 7bn of them out there and they have been around for over 60 years

2. They are very widespread, and the use of them is a well establish process

3. Smartphone use is not as great in some regions as it is in the US / Europe, significantly limiting the available payments functionally

4. Large retail have not adopted them significantly, and the card brands are making things difficult

5. People just don’t trust them yet, and they are more complicated for the ageing portions of our population

However, this will not stop the trend, and these two ‘statistics’ pretty much say it all;

1. The average time it takes to realise you’ve lost a credit card is 11 days, the average time it takes to realise you’ve lost you mobile phone is 4.5 MINUTES.

2. By the end of 2014, there will be more mobile phones in use than there are people on the planet (>7bn).

Unfortunately  the transition of the non-cash payments ecosystem to mobile will be from credit cards, which requires the support of the card brands, who, for obvious reasons, are loathe to provide it. Both the PCI DSS and the PA DSS standards stifle innovation by making any form of compliance for mobile payments on Cat 3 mobile devices (phones, tablets etc.) exceedingly difficult, and in some cases, impossible.

I have to assume that once the card brands are ready to roll-out their OWN mobile payment infrastructures, the transition will happen much faster. This must involve alternatives to EMV, and any solution must be scalable, and future-proofed, so they’ll need a couple more years to get themselves sorted.

The card brands employ a lot of VERY smart people, and I have to further assume that there are entire departments dedicated to digging them out of the hole they have spent decades creating. From the physical infrastructure (PEDs, back-end servers, credit cards etc.) to sector dependencies (PSPs, acquirers, service providers etc.)  the credit card payment ecosystem is enormous, and enormously complicated. The transition of plastic to mobile will take a long time, but I think the brands have a lot to offer in the space if they decide to play fair.

In the end, mobile applications will rule the day, at least until the next thing comes along. It most certainly won’t take 60 years like the cards-to-mobile transition – and I suspect will involve some sort of implant – but entire fortunes are there for the taking in this space. The functionality, convenience, and yes, even the safety of mobile applications mean that they will be the next big thing. Competition will be massive, which can only benefit the most important factor; the consumer.

For the purposes of this blog, I’m going to assume the rumours are true, but if they’re not, both the premise and the message to large retail is still largely valid.

Apparently, Target will be replacing their current point of sale / terminals with a Verifone ‘solution’ capable of Point to Point Encryption (P2PE), and I assume, EMV and NFC as well. So it wasn’t bad enough that they lost 40M credit card numbers – the repercussions of which will cost them millions – they are now going to spend even more multi-millions to continue to accept the root cause of their troubles; the credit card.

Yes, the new Payment Entry Devices (PEDs) may encrypt the cardholder data from the swipe onwards, and this MAY take the large portion of the authentication channel out of scope for PCI, but nothing fundamentally has changed. The only significant payment channel is a custom built, exceedingly expensive system that can only accept credit cards. I estimate that $25,500,000 would be required to replace the PEDs alone (1,700 locations X 30 lanes per store X $500 per PED)!

Forget the fact that they will also have to pay for the P2PE service, as well as fundamentally change every business process relating to payments, they will STILL have to pay the card brands astronomical sums in fees! Their 2013 net revenue was ~$73 billion, so let’s say (conservatively), 15% was credit card revenue, and that Target have a preferred interchange rate of 1%, that means in 2013 alone, Target paid the card brands $109.5 MILLION just for the ‘privilege’ of letting the customers use a credit card.

$25.5M + $109.5M = $135M, how many innovations in payments could that fund? Or more to the point; how many alternative methods of payment AUTHENTICATION could that fund which would vastly improve the security of the transactions, and render the card brands’ 60+ year old technology obsolete once and for all?

Now imagine if they got together with Walmart, and Metro, and Aldi, and Costco and the rest of the world’s top 10 retailers, who, using the above maths, pay the card brands a combined $1.7 BILLION in fees, just how much influence do you think they would have?

And that’s really the point; the retailers don’t seem to know just how much power they have. They in fact hold ALL the cards, but not one of them wants to be the first to play them for fear of losing the competitive edge to the others. If they could only put aside their differences for a while, they could, all by themselves, create the necessary momentum to change the way we perform non-cash payment on a global basis.

The card brands won’t do it, it’s 100% of their business, the banks won’t do it, they make their own profits, and no-one else who has a vested interest in the status quo will make any effort to provide alternatives. Can’t say as I blame them, business is business, and it’s not as though the average consumer is clamouring for choice. But the retailers, they have by far the most to gain, and they have by far the most direct influence on how people shop.

Someone has to go first, and Target now have the perfect opportunity to spend their money future-proofing their payment infrastructure, but only if they finally understand that payments are NOT a core function, selling stuff is, and that their customers will adopt ANYTHING that’s cheaper, easier, and safer.

They have an image to fix, but this is not the way to go about it.

You may be asking if these are not the same thing expressed different ways, but I make the following distinctions:

Loving what you do is about the field you are in, the detail of the day-to-day, or your chosen industry sector. For example; nurses, fire fighters, teachers, research scientists, professional athletes and so on, all love what they do. They love it whether or not they are the best at it, and would keep doing it even if it meant they will never be highly successful in material terms.

To love doing what you’re good at means that it does not matter the field you are in, it is not a passion in and of itself. It means that you are doing something at which you excel, thoroughly enjoy, and would keep doing regardless of the industry sector in which you currently find yourself.

It has taken me 46 years to realise that I have not missed out on anything by not having a passion related to any topic. I always envied people who knew from the age of 6 they wanted to be a dentist, or a soldier, or what not. To me, NOT having a passion meant I was destined to only ever be average at something, because I assumed that without passion, I would never have the energy or interest to be the best.

I don’t even have a hobby.

Recently however, I came to the realisation that there are at least two forms of passion; passion-in-the-thing, and passion-in-the-process. Passion-in-the-thing relates directly to loving what you do (e.g. nurse), and passion-in-the-process relates to loving to do what you’re good at (e.g. fix broken things). One is not better than the other, but while passion-in-the-thing usually becomes obvious at a very early age, passion-in-the-process can go a lifetime without being realised.

If you let it.

I am 100% in the passion-in-the-process camp, which will become obvious when I make the following statement; I actually don’t care about information security.

What?! (you gasp) You write a blog that positively DRIPS with passion (or angst, depending on your point of view), how can you say you don’t care?!

Because it’s not information security I care about, it’s the PROCESS of simplifying a difficult concept until it’s available and understood by those who need it that gets me going. Simplifying is a passion, and helping people and organisations get the BENEFIT of security is a passion, security itself is not. I could just as well be in advertising (for example) and love my job, but I’m neither creative enough, nor do I have the patience / inclination to start my career all over again.

Why this is so exciting to me, and why I bothered to write this blog in the first place, is that ANYONE can do what they’re good at! In my experience, only a few people ever find a true passion for something specific, and fewer still make a career out of it, but if you can take the WHAT out of the equation, and replace it with HOW, this becomes available to everyone. I think I’m right in saying that, almost by definition, there is no scale in passion, you have it or you don’t (like Billy Connolly’s “F&%$ off, he hinted!“). This makes both forms of career passion equal.

Actually, I should say that everyone who makes the effort to understand themselves can do this, but so few do. I touched upon this in one of my earlier blogs; Never Follow the Money, but I missed the point when I suggested that more introspection is required to find the things you’re good at, and to focus on those. Yes, you should absolutely do that, but unless you accept passion-in-the-process as an equal alternative to passion-in-the-thing, you will probably still be discontent with your choices. Perhaps assuming that your life will really only start when you find someTHING you love.

It does not have to be a thing.

Finally, the best part about all of this is that it’s NEVER too late in your career for you to discover either of these passions, but only passion-in-the-process is something you can work towards right now, today, you just have to stop using a lack of passion-in-the-thing as an excuse not to get what you want, whatever that may be.

[If you liked this article, please share! Want more like it, subscribe!]