Anyone who has read my blogs knows that I am very critical of credit cards and EMV as payment technologies. I am also equally critical of the card brands themselves for attempting to spread their use when there are so many other more convenient, safer, cheaper , and future-proofed options out there. With mobile applications, e-wallets, and whatever comes next, the piece of plastic with which we are all so familiar will die in its current form.

Then two products come along and I find myself having to adjust my thinking …somewhat. I still think the card brands are wrong, but I have reached my own internal compromise based on one difficult truth; I have become so enamoured with innovation, that I have lost touch with the only question that’s relevant;

Is it functional?

To me, there is no innovation without practical application, and no function without benefit and use. In other words, innovation is great, but if it’s not adopted, AND makes things better, it’s just a fad.

The two products that caused this revelation are pinCode and Coin:

pinCode is an awesome little product that covers a gamut of authentication mechanisms in a credit card sized token, and Coin allows you to load multiple credit / debit cards on – you guessed it – a credit card sized token.

Each has a fundamental flaw; pinCode cannot replace multiple cards, Coin does not authenticate payments.

Now imagine if you could combine the two.

You would no longer need multiple pieces of plastic you would have just one. Whether you load your credit cards, debit cards, branded, non-branded, or any other form of electronic payment information, it would now all be in one place, with authentication mechanisms built in that would cover every provider.  No more chip and PIN, pinCode takes care of that, and no more thick wallets, Coin takes care of that.

Added benefits;

  1. The bluetooth technology in Coin could be adapted for non-NFC contactless payments, as well as its existing security feature of alerting you if the card is more than x feet away
    o
  2. Backwards compatibility with magnetic stripe only terminals, but each bank could add authentication mechanisms with the pinCode functionality
    o
  3. Continued use of existing credit accounts, but now without the need to issue credit cards. The information contained on a credit card magnetic stripe or the EMV integrated circuit (IC) can just as easily be sent or downloaded as long as the authentication is sound
    o
  4. Chip and PIN would be unnecessary globally. Therefore no requirement for expensive payment terminals, leading to a massive expansion of payment technology to emerging markets / micro-merchants
    o
  5. Every bank can be its own payments scheme and neither the cards, payment terminals, or back-end systems are tied to any particular card brand or region
    o
  6. Your ‘credit card’ can now be used for multiple authentication requirements; from a physical security pass, to 2 factor authentication, to call centre mutual authentication
    o
  7. Carrying a ‘spare’ credit card is now so much simpler. As a frequent traveller, I not only have a spare credit card, I have FOUR spare credit cards just in case (Visa Credit, Visa Debit, MasterCard, Amex). Being able to replace all the credit cards with a vastly improved one, as well as not having to worry about it being stolen makes me drool

However, and back to my original point, this MAY end up prolonging the life of the card brands, but even I can’t deny that there are literally hundreds of millions of people who are already used to carrying little pieces of plastic. As long as this ‘interim innovation’ can instil more security, greater functionality, and perhaps a little more competition, then so be it.

Mobile applications and smartphones will rule the day eventually, and the combination described above will actually begin the process of educating people that electronic payments and phones will no longer be as separate as they are now.

This is the perfect gap-filler between present and future, and it all points back to where it began; authentication.

 

 

If you are reading this while on public transportation, at a bus stop / train station, look up, and look around. How many people are looking at a mobile device of some kind? 40%? 50%?

Now, how many of those are children? Or if you’re a parent, does your child have a smartphone? A PS3/Xbox? And finally, how much time do you think these kids are spending on those devices?

It’s bad enough that I, a 46 year old ‘technology professional’ spend an inordinate amount of time plugged-in and not exercising, it’s quite another to see a 10 year old who’s overweight and completely disconnected from the world around them.

So, whether you are proponent of the Internet of Things or not, I see it as a perfect opportunity to ensure that children see technology as the privilege it is, and not as an expectation, and certainly not as something to be taken for granted. No child has earned the right to waste away in front of an electronic device, they can do that later if the wish, and once they are out on their own paying their own bills. Like me.

The proposition: With innovations around micro-sensors, geo-location and a whole host of other inputs, it should be relatively trivial to measure the amount of exercise your child is getting on a daily basis, and tie that directly into the amount of ‘play time’ they get on their smartphones or video games. The more exercise they do, the more time they have, and when your time is up, the video games are locked out, and your smartphone reverts to phone only.

You could even build in an ‘management station’ where parents could set tasks, chores, grade requirements etc, and the more the child does, or the better they perform, it all works its way into more time playtime on their electronics. Of course, this will all need to be fun as well, there’s no point in teaching the next generation that exercise is itself a boring chore, but every child has to learn that everything has a price, even if that ‘price’ is something that’s actually good for them.

It would however, be very important not punish a child that finds a way to beat the system. Any creative method they have to ‘cheat’ is an indication of a burgeoning talent. For example, a child who..:

  • …gets their friends to wear their sensors to exercise on their behalf shows someone with creativity, influence, and leadership skills.
  • …works out how to ‘double up’ on their sensor input shows skills in problem solving, efficiency generation and engineering.
  • …hacks the system and re-wires either the input mechanism or the underlying application is going to start the next Google.

While you clearly can’t allow their breaking of the rules to continue, gearing their e-playtime bonuses to rewards for solving similar challenges is a way to make the whole thing not only fun, but a learning lesson as well.

Children are extraordinarily creative when not suppressed by adults, so why not let them have at it while at the same time ensuring that they stay healthy?

Obviously this technology would have just as many benefits to adult health as well, and I have literally dozens other ideas for its application, but I’ll leave that to people with a little more time on their hands. I think a company name of e-PlayTime would work very well…

Analogy: A family member needs surgery, and you have two doctors in a side-by-side bake-off. One is respected, enormously experienced, and expensive. The other is fresh out of residency, inexperienced, and cheap.

Whom do you go for?

Unless you’re a sociopath, you pay for the one with the greatest expectation for success. So by a similar (though far less life threatening) extension, why would you cheap out on your choice of QSA? Or any consultant that matter?

Not only that, you probably expect the same results from every QSA, right? They all went through the standard training, so they should all be the same, right?

Are all doctors the same?

Like any profession, you have a MINIMUM standard to achieve before you start. For QSAs it’s 5 years in security (no-one lies on CV’s/resumes, right?), OR a CISA/CISM/CISSP (anyone can read a book and pass a multiple choice test), AND pass the QSA test. I can, quite literally, take ANY person and get them to a point they can pass that test in one week.

Instead of focusing the QSA test on their domain knowledge (networking, encryption, policy formation etc.) it focuses on merchant / service provider levels and a bunch of other stuff that does not test the consultant’s security or auditing skills in any fashion that makes sense to me. Can they read a firewall ruleset to determine if they have met the intent of requirements 1.X? Can they look at a netstat and see if their OS configuration standards are being followed per requirements 2.x?

The answer to those questions is; not necessarily, and while I cannot think of one security consultant who is an expert on all 12 DSS sections (I suck at encryption and anything to do with coding for example), you need someone with real-world experience to measure your compliance against not only the standard, but its intent. And if that intent does not align with the goals of the business in question, the process falls apart.

When it comes to PCI, you’re paying for experience / guidance / been-there-done-that, otherwise you’re better served doing it yourself. At least you know the business better than the QSA ever will.

I wrote something resembling a white paper on Selecting The Right QSA For Your Business a few months ago, and will be building on this process over the next few months. Anything is simple if you know how to do it, but that’s the point; YOU probably don’t know how to do PCI, nor would you then know the right questions to ask to find someone who does.

This may sound like I’m trying to push you into hiring only the expensive guys, but that’s not it, it’s never just about the money, it’s about VALUE for, and appropriate USE of, money. The issue most often is that businesses choose their QSA based on price. They didn’t want to do PCI compliance in the first place (believe me, no-one WANTS to do PCI), and therefore settled for the lowest bidder.

In my fairly significant experience, the cheapest QSA up front rarely ends up being the cheapest in the end. These are the top 5 things to watch out for, and reflect the SOPs of some of the less scrupulous vendors;

  1. Scope Creep – A proposal written in such a way that you THINK you’re buying what you need, but you end up having to buy additional services from them to finish the job;
    o
  2. Cheap Labour – You get what you pay for, and if you pay pennies, you’ll get the least experienced QSA at their disposal (this one serves you right by the way);
    o
  3. Pushing Other Services or Products – Some of the larger QSAs have entire suites of products and services they try and push your way. They will sell the QSA for cheap hoping to massively up-sell/cross-sell the more profitable managed services / products etc. This is permissible under the SSC regs., but hardly best practice, and in some cases even ethical, especially when the products don’t even support your compliance;
    o
  4. Lack of Appropriate Guidance – Achieving PCI compliance the first time is a project, staying complaint is a process. At no time during the assessment should there be roadblocks that are a direct results of the QSA’s inexperience. Projects that should take months often take years, and the additional costs can be significant;
    o
  5. The True Cost of Compliance – Usually the most significant cost of a PCI project is the labour cost of internal resources. Performed correctly, PCI can have significant benefits in terms of improved security posture, but unless the resources are used efficiently, the cost to the business can be very significant, especially in terms of availability for initiatives related to transformation or innovation.

In the end, you will get what you pay for, and if you have not chosen your QSA based on best-fit, you deserve what you get. Choosing a QSA / consultant is relatively simple, and I believe that It Takes A Consultant, To Hire A Consultant.

If you need help, do your homework, then ask the opinion of someone with zero vested interest.

[If you liked this article, please share! Want more like it, subscribe!]

After giving the title question a little thought, you probably fall into one of three camps:

  1. You were immediately able to choose which one you preferred based on your own interpretation of the two emotions, or;
  2. You were confused because you can’t separate one from the other, or;
  3. You immediately chose one because you think it leads to the other

There are no wrong answers here, this is way too personal an issue, but I have been pondering the difference between the two for a while now, and in light of one fact; I have be happy more times than I can count, but have been content only once.

I’m lucky, I’m genetically predisposed to being happy (see Can Happiness be Genetic?). Not all the time obviously – just ask anyone who’s ever worked for me – and quite frankly, I’m glad. No offence if you’re one of them, but people who are always happy are irritating, especially the ones who are clearly faking. I’m happy when my wife makes pancakes, or her queso sauce, so a good day is never far away!

But contentment, that’s something completely different, and I can remember the one time I was content in great detail. I won’t bore you with full detail, but I was driving down the DC Beltway, alone, and this strange feeling came over me. At first I was a little nervous and almost pulled over, but then I realised what it was and managed to revel in it for about 10 seconds before it went away.

That was 20 years ago.

The only reason I share that is because I could not help but think that being content is the ultimate feeling, and thought how great it would be if everyone felt that way all the time. But then it occurred to me that there is one other human trait that will probably never allow for permanent contentment in any but a select few; curiosity. Not just basic curiosity, like; Who won the World Cup in 2010? But the deep down human curiosity that has driven our species to create, to explore, and to question our very existence.

I now feel that to be content, you must either have no curiosity  (or are basically just lazy and unimaginative), or be in a position that you are doing every day the things at which you excel, and enjoy. The reason so few of us ever ARE content is that we have settled for a life focused on the wrong things, and have allowed the human habit of compartmentalising to pigeon hole us into mediocre lives with neither contentment at the end, nor as much happiness as we deserve on the way.

Example 1; I don’t work hard for money, I work hard so that I don’t need more money to take financial worries off the table. Money itself should never be the goal.

Example 2; I care nothing for titles, and my self-worth is not driven by having any form of power over others, but I have seen people stay in jobs they hate because they got a fancy title and hollow respect. Not more money, or even more responsibility, just the title.

The only way I will ever be content again is if I have the freedom to do every day what I do best. I know I’m good at simplifying things, as well as making things that are inefficient, efficient. I also know that I’m absolutely crap at being diplomatic in the face of ignorance, and my impatience with office politics has led me to starting my own business out of necessity, not choice. It is therefore my responsibility to myself to create the environment best suited for me, and it’s clear that that will never happen following someone else’s dream, or worse, their greed.

In hindsight, I have never taken a backward step in my personal life or career, because I was always very much aware that wherever I ended up, I would use whatever skills I have to their maximum effect, and just as importantly, downplay or avoid the things I will never do well. Some say that’s happiness, and perhaps they’re right, but I think that doing the things that make you happy more than the things you don’t, IS contentment. Of a fashion anyway.

Curiosity, ambition, and a whole host of other attributes that we humans have, all seem to be the very antithesis of contentment, but I disagree, it’s focusing those attributes in the wrong direction(s) that’s the problem. You owe it to yourself, and yes, to those who care about you, to find contentment in whatever form that takes for you.

Finally, I think that every bit of happiness I feel means I’m doing something right, so while contentment is probably a far off place, I at least know I’m on the right path.

 

PS – For the curious, the answer is Spain.

Well, here it is, and I just can’t figure out why I’m actually disappointed. I saw the draft, I knew there could be no radical changes, yet somehow I was expecting a little more than this. I guess the phrase; “It is what it is.” is actually appropriate this time, and not just the recourse of people who have neither the vision nor the abilities to make positive change.

In the downloads section is the spreadsheet PCI DSS v3.0 – Mapping to v2.0_v07NOV13.xlsx, which is the final v3.0 standard, mapped back to v2.0 (my mapping, not the SSC’s), with my comments.  Help yourself.

For those of you who helped take your organisation through v2.0, and are worried about what v3.0 means to you, don’t be. You may have seen a bunch of articles about how it’s so much more detailed, how it’s going to take longer to assess, or how you should be taking every training course under the sun to get to grips with it. Don’t believe them.

It’s not that different, and if any organisation tries to gouge you for more money off the back of it, fire them. The ONLY reason to accept more services from your security service providers it to meet your BUSINESS goals as dictated by your risk and business continuity management programmes. As I have stated too many times; in terms of a security programme done properly, PCI compliance starts in the wrong place, ends in the wrong place, and is only relevant to cardholder data, which means the rest of your business may left exposed. So if you DO buy more pen testing / scanning / consultancy etc, do so for your business, not for PCI.

The less scrupulous QSAs and QSACs may point to the additional validation effort as a reason for raising their prices, but if they had been doing their jobs properly under v2.0, the difference is minimal. This effort has been required for at least 2 years under the SSC’s RoC scoring mechanism, not to mention the intent of the standard in the first place.

So what this really means to for the next three years is business as usual (BAU). Not the; we’re-doing-the-right-thing-for-our-business BAU, but the; this-is-no-different-so-let’s-ignore-the-opportunity-to-do-the-right-thing-for-our-business BAU. If there is any lesson that has been ignored more than the need to automatically cover compliance in a business-wide security programme, I don’t know what it is.

Service providers, payment gateways, PSPs, and of course, QSAs, all have a vested interest in the status quo when it comes to PCI. Whether it’s for marketing purposes, competitive advantage, or nearly the entire revenue source, PCI now has a life of its own. Given its 3 year life-cycle, and the impossibility of radical changes DURING that cycle, it will never break out of its limitations and be the driver for enterprise-wide good security practices that it could so easily have been.

Just a few small adjustments could have brought it more in line with what every business SHOULD be doing:

  1. Risk Assessment – Bring it to the very forefront in terms of importance. Instead of shoving down in section 12, the so-called ‘paperwork’ section, it should be a prerequisite to even begin the compliance program. Every known good practice, enterprise-wide, business saving security framework starts with a risk assessment, why not PCI?
    o
  2. Policies and Procedures – If you don’t know how policies and procedures not only form the foundation upon which any security programme is founded, and how they represent the entire security CULTURE of an organisation, maybe you should consider changing fields.
    o
  3. Security Awareness Training – Built on the policy and procedure foundation, and represents the single most effective way to reduce risk in ANY organisation. It can also be one of the cheapest.
    o
  4. Formation of a Governance Committee – This does not have to be the enormously complicated structure it may sound, it can be just one representative from each department meeting on a monthly basis to discuss the business. The business side wants more profits, the technical side wants to help enable that profit. If BOTH sides are made aware of each other’s needs, security will finally be performed appropriately, and not because of some external driver.
    o
  5. Make the CEO accountable for compliance – I cannot believe this one has never been introduced. It’s the CEO who could solve almost every issue experienced by organisations faced with achieving PCI compliance, yet it’s delegated to the people without either the influence, the budget, and often the expertise to do so. As much as possible in a non-government regulation, make the CEO personally accountable for compliance failures, or don’t be surprised when organisations lie to their assessor to make the whole thing go away.

Except for the last two, these things are IN the standard, and have been from the beginning. All, that needed to be done was increase their importance, provide PROPER guidance related to their position within accepted good security practice frameworks, and let the CEO know that if they fail to provide the correct support for the programme that THEY will be responsible for losing their credit card acceptance ‘privileges’. Maybe that will get their attention.

Gone way over my word limit, so I’ll end with my favourite phrase; Security is not easy, but it CAN be simple.

PCI compliance is no different, not ‘even’ v3.0.