<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Angels of security &#187; pci</title>
	<atom:link href="http://angelsofsecurity.com/blog/tag/pci/feed/" rel="self" type="application/rss+xml" />
	<link>http://angelsofsecurity.com/blog</link>
	<description>Musings of an infosec renegade</description>
	<lastBuildDate>Tue, 02 Aug 2011 19:01:53 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>RAM skimmers</title>
		<link>http://angelsofsecurity.com/blog/2009/12/10/ram-skimmers/</link>
		<comments>http://angelsofsecurity.com/blog/2009/12/10/ram-skimmers/#comments</comments>
		<pubDate>Fri, 11 Dec 2009 03:26:53 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[compliance, investigations, regulations, and legal]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[pci]]></category>
		<category><![CDATA[ram scraper]]></category>
		<category><![CDATA[Verizon data breech report]]></category>

		<guid isPermaLink="false">http://angelsofsecurity.com/blog/?p=545</guid>
		<description><![CDATA[In Verizon Business&#8217; most recent data breach investigation report they mentioned a new class of malware which I&#8217;d never heard of before but found interesting &#8211; RAM scrapers. The basic idea is that they grab data straight from RAM. Verizon goes on the conclude that the recent increase in the use of encryption and limitations [...]]]></description>
			<content:encoded><![CDATA[<p>In Verizon Business&#8217; most recent <a href="http://www.verizonbusiness.com/resources/security/reports/rp_2009-data-breach-investigations-supplemental-report_en_xg.pdf">data breach investigation report</a> they mentioned a new class of malware which I&#8217;d never heard of before but found interesting &#8211; RAM scrapers. The basic idea is that they grab data straight from RAM. Verizon goes on the conclude that the recent increase in the use of encryption and limitations on what data can be permanently stored (mostly thanks to PCI), scammers have had to start looking to other areas to gain access to unencrypted data. I guess this shouldn&#8217;t really surprise anyone too much &#8211; we already know that for every measure there is another countermeasure. This is also another good example of <a href="http://angelsofsecurity.com/blog/2008/06/18/1024-bit-rsa-key-circumvented/">Shamir&#8217;s third law of cryptography</a> &#8211; &#8220;Cryptography is typically bypassed, not penetrated&#8221;.</p>
]]></content:encoded>
			<wfw:commentRss>http://angelsofsecurity.com/blog/2009/12/10/ram-skimmers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TJ Maxx fires whistleblower</title>
		<link>http://angelsofsecurity.com/blog/2008/05/29/tj-maxx-fires-whistleblower/</link>
		<comments>http://angelsofsecurity.com/blog/2008/05/29/tj-maxx-fires-whistleblower/#comments</comments>
		<pubDate>Fri, 30 May 2008 02:47:05 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[news]]></category>
		<category><![CDATA[pci]]></category>
		<category><![CDATA[security through obscurity]]></category>
		<category><![CDATA[TJ Maxx]]></category>

		<guid isPermaLink="false">http://angelsofsecurity.com/blog/2008/05/29/tj-maxx-fires-whistleblower/</guid>
		<description><![CDATA[A few other people have been all over this already, but TJ Maxx, victims of a rather large electronic break in a few years ago, has recently fired an employee for revealing many of their lax security policies. The issues he raised were not small ones either: Security was so lax at the TJ Maxx [...]]]></description>
			<content:encoded><![CDATA[<p>A few other people have been all over this already, but TJ Maxx, victims of a rather large electronic break in a few years ago, has recently <a href="http://www.theregister.co.uk/2008/05/23/tjx_fires_whistleblower/print.html">fired an employee</a> for revealing many of their lax security policies. The issues he raised were not small ones either:</p>
<blockquote><p>Security was so lax at the TJ Maxx outlet <a href="http://www.tjx.com/contact/storemap.aspx?sid=08-624" target="_blank">located in Lawrence, Kansas</a>, that employees were able to log onto company servers using blank passwords, the fired employee, Nick Benson, told <em>The Register</em>. This policy was in effect as recently as May 8, more than 18 months after company officials learned a massive network breach had leaked the details of more than 94 million customer credit cards.</p>
<p>Other security issues included a store server that was running in administrator mode, making it far more susceptible to attackers.</p>
<p>My store manager even posted the password and username on a post-it note.</p></blockquote>
<p>Lest anyone think this employee started off on the wrong foot, he did try to tell management first, but to no avail. It was only afterwards that he mentioned these things in public. Now whether he should have done this or not is clearly a matter that could be the subject of much debate. The issue which I feel more strongly about is the way TJ Max responded.</p>
<p>Firing this employee is, in my opinion, the worst form of <a href="http://en.wikipedia.org/wiki/Security_through_obscurity">security-through-obscurity</a>. Rather than realizing that lax policies lead to security problems, they think that it&#8217;s the <em>revelation </em>of lax policies that lead to security problems. A simple root cause analysis should reveal that it&#8217;s the policies, not their revelation, which is the source of security weaknesses, and it&#8217;s time for TJ Maxx to wake up.</p>
]]></content:encoded>
			<wfw:commentRss>http://angelsofsecurity.com/blog/2008/05/29/tj-maxx-fires-whistleblower/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

