It was inevitable I suppose, that once the dust had settled somewhat the lawsuits would commence. It’s America after all. It’s not bad enough that Target have already spent millions on this event, and will spend millions more patching the problems and covering the losses, now the banks want a piece. The BANKS!

These same banks have MADE millions off credit card transactions over the years, and now that the downside of their venture has reared its ugly head they go crying to the courts to whine about how unfair this all is. I dare say that eventually some of these plaintiffs will be the very Issuers that have managed to block EMV for so long.

Not that EMV would have prevented the breach mind you, it would have made no difference, but the monetisation of the breach would have been far more difficult. My thoughts on why EMV was never rolled out in the US – and never SHOULD in my opinion – is here; Why the US Will Not Adopt EMV (Chip & PIN).

Then there will be the QSA and MSS companies, and the integrity-less leaches who will jump all over this to try to steal the Trustwave client base. They will point to the breach and say that the Trustwave QSAs didn’t do their job, missed something, or worse, that they lied. The fact is that not one QSA or MSS in the WORLD following the PCI DSS as written could possibly find every hole in ANY client’s infrastructure, let alone one the size of Target.

I’m not saying that they did their jobs perfectly, I don’t know if they did or not, but I CAN say that they were not watching EVERY system and EVERY individual, EVERY minute, of EVERY day, which is what it would have taken to prevent the breach. The QSA looked at a justified SAMPLE of systems ONCE in the course of a year, that’s what a PCI assessment is, and the MSS would only be monitoring a fraction of the network traffic.

And then of course there are the journalists covering this story. It’s news, no doubt about that, but HOW it’s told will have repercussions. There are actually very few people in the world who can have a truly valid opinion on this matter, and fewer still who are the people actually writing the stories, which means that most of what you will see is based on either the facts only (yeah, right), or what sells. Decisions get made on sensational stories every day, sadly this will also be the case here.

This entire case is not some lessons-learned exercise, nor should it be used to crucify the named participants, this is an indictment against credit cards and the credit card companies themselves who have done too little for too long to innovate away from the current technology. Card numbers are a liability, EMV is a joke, and PCI is smoke and mirrors.

It’s time for them ALL to go away and allow the true nature of payments to shine. Identity Management will rule the day, not plastic.

I am probably someone with the most reason to jump on the bash-Trustwave bandwagon, but if I don’t – who for many reasons IS one of the people that can have a valid opinion – then maybe you shouldn’t either.

Of course, if Trustwave WERE found to be negligent, then I take most of this back, just not the part about credit cards going away.

Leave a Reply

Your email address will not be published. Required fields are marked *

You may use these HTML tags and attributes:

<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <s> <strike> <strong>

This site uses Akismet to reduce spam. Learn how your comment data is processed.