Important News:SafeLogic's CryptoComply Achieves FIPS 140-3 Validation for 28 OEs and Receives Certificate #4781! Read the blog post!
The SafeLogic Blog
It’s Shopping Season!
December 4, 2013 •Ray Potter
It’s definitely that time of year. Black Friday, then Cyber Monday… It’s Shopping Season!
I can practically hear the delivery drones buzzing overhead, bringing lots of toys for nice kids of all ages.
The naughty kids, however, are having even more fun. Cyber Monday shopping is like, well, Christmas for hackers. Pinging e-tailer servers and seeking vulnerabilities like unencrypted payment systems is even better than peeking inside advent calendars. The treasure inside is likely to be much more lucrative, you can bet on it.
The sheer number of transactions this time of year gives the advantage to the malicious, and the secretive nature of holiday presents is really just a gift to the criminals. How many times have you heard this: “Sweetie, don’t look at the credit card bill until January, I don’t want to spoil the surprise!” Well, I’ll tell you what the real surprise is - trying to identify and remember each of those umpteen line items on last month’s statement when you finally get around to reviewing it. How easy would it be to not notice a few relatively small purchases?
It’s just not reasonable to think that consumer-level audits are a reasonable level of protection. It is our responsibility to move up the stack and safeguard at the payment system level. The Payment Card Industry Data Security Standard (PCI-DSS) demands encryption for full compliance, but the program itself is not mandated by the US government and is voluntary for participation. The PCI Security Standards Council invests a lot of effort into the program and they’ve made a ton of progress, but there is still a great deal of work left to be done. For example, FIPS 140-2 completely satisfies the Data Security Standard, but is not an explicit requirement. As you well know, that leaves a lot of leeway for participants to cut corners and reach compliance while still containing vulnerabilities.
SafeLogic will be devoting resources to pursuing more accountability, higher participation, and an increase in FIPS-validated encryption in PCI-DSS in 2014, so stay tuned for more information. In the meantime, do your part as a consumer – shop with retailers who participate in PCI-DSS, review your own statements, and report any suspicious activity. The more information that you can provide to your bank or credit card provider, the better our chances will be to identify the holes in the system. We must all help fix the problem and expose potential vulnerabilities.
And if we succeed, our devious counterparts in the future will have to resort to low tech options to disrupt our holidays… like shooting down those delivery drones!
Ray Potter
Ray Potter is the Founder of SafeLogic, which was spun off from his previous venture, the Apex Assurance Group consulting firm. He brings over 20 years of security and compliance experience, including leading teams at Cisco and Ernst & Young, to the operations team at SafeLogic. Ray loves playing guitar and flying airplanes.
Popular Posts
Search for posts
Tags
- FIPS 140 (112)
- FIPS validation (85)
- Encryption (70)
- cryptography (68)
- NIST (62)
- CryptoComply (60)
- SafeLogic (58)
- Industry News (54)
- cryptographic module (51)
- Conversations (49)
- CMVP (48)
- RapidCert (46)
- compliance (41)
- Ray Potter (33)
- SafeLogic News (33)
- Event (27)
- federal (27)
- CAVP (23)
- Cybersecurity (23)
- FIPS 140-3 (21)
- OpenSSL (16)
- government (14)
- FedRAMP (13)
- post-quantum cryptography (13)
- CryptoCompact (12)
- Cryptology (12)
- DoD (12)
- RSA (12)
- healthcare (12)
- partners (12)
- NSA (11)
- PQC (11)
- Cloud (9)
- security (9)
- CMMC (8)
- Suite B (8)
- testing (8)
- whitepaper (8)
- Approved Products List (APL) (6)
- HITECH (6)
- ICMC (6)
- lab (6)
- CEO (5)
- NIST 800-171 (5)
- NIST 800-53 (5)
- OpenSSL 3.0 (5)
- iOS (5)
- procurement (5)
- C3PAO (4)
- Common Criteria (4)
- HITECH Act (4)
- OpenSSL 3.x (4)
- TLS 1.3 (4)
- deadline (4)
- encrypt (4)
- innovation (4)
- procure (4)
- public sector (4)
- Air Force (3)
- BSAFE (3)
- DFARS (3)
- HIPAA Safe Harbor (3)
- HITECH Safe Harbor (3)
- OpenSSL 1.1.1 (3)
- POA&M (3)
- magazine (3)
- queue (3)
- transition (3)
- 3PAO (2)
- ACVP (2)
- BAA (2)
- CIO (2)
- CSP (2)
- Cyber Defense Magazine (2)
- Defense Industrial Base (2)
- Entropy Source Validation (2)
- HIPAA security controls (2)
- Historical Status (2)
- MFA (2)
- OpenSSL 1.0.2 (2)
- SPRS (2)
- StateRAMP (2)
- entropy (2)
- excellence (2)
- finance (2)
- founder (2)
- gold (2)
- leader (2)
- maturity (2)
- overlap (2)
- pilot (2)
- rsa conference (2)
- solution (2)
- sponsors (2)
- sunset (2)
- vendor (2)
- year (2)
- Active Status (1)
- Alliance for Digital Innovation (1)
- Android (1)
- CIO Prime Views (1)
- DHS (1)
- DIU (1)
- DIUx (1)
- DOJ (1)
- DoDIN APL (1)
- FCA (1)
- FIPS Compliance (1)
- FISMA (1)
- GSA (1)
- HITRUST (1)
- Matt Cornelius (1)
- Matthew Cornelius (1)
- Maturity Model (1)
- NCCoE (1)
- OMB (1)
- SLED (1)
- SP800-131A (1)
- SP800-90A (1)
- TLS 1.1 (1)
- background (1)
- best (1)
- co-founder (1)
- codies (1)
- congress (1)
- cybertech (1)
- education (1)
- elliptic curve cryptography (1)
- extended (1)
- faq (1)
- fintech (1)
- fiscal (1)
- fiscal year (1)
- fraud (1)
- globee (1)
- hill (1)
- interview (1)
- kratos (1)
- libgcrypt (1)
- national cybersecurity strategy (1)
- opportunities (1)
- parallel (1)
- profile (1)
- public (1)
- representatives (1)
- reseller (1)
- senate (1)
- senators (1)
- simplify (1)
- state (1)
- stealth mode (1)
- story (1)
- terminology (1)
- trophy (1)
- whistleblower (1)
- whistleblowing (1)