Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Payment Card Data Theft: Tips For Small Business
Newest First  |  Oldest First  |  Threaded View
catvalencia
50%
50%
catvalencia,
User Rank: Apprentice
8/12/2014 | 5:14:32 AM
Re: Square & iphones
Very informative! Information regarding one's card, such as card numbers and so forth, should be kept hidden, such as shredding statements or blacking out sensitive information before throwing them away. Another good tip is to constantly monitor the account. Check statements thoroughly and promptly and report any suspicious purchases immediately. Source: Credit Card Fraud

 
KateN232
50%
50%
KateN232,
User Rank: Apprentice
7/21/2014 | 10:52:20 AM
Re: Square & iphones
The Cloud And Big Data as an important part of small business

Using of big data and the cloud have great influence on practically each business industry. It allows companies of all sizes to serve customers more effectively, analyze and improve business processes. Read more https://www.snappii.com/resource-center/cloud-big-data-important-part-small-business/
Robert McDougal
50%
50%
Robert McDougal,
User Rank: Ninja
7/18/2014 | 11:10:37 AM
Re: Square & iphones
I have to agree, I hope they read this.  Many of the small businesses that utilize square appear to use their personal devices.
GonzSTL
50%
50%
GonzSTL,
User Rank: Ninja
7/16/2014 | 12:21:17 PM
Re: Square & iphones
It would be beneficial to small merchants if card processing vendors suggest this practice to their clients, who do not normally hear or read about these little issues regarding their choice of payment systems. Since vendors already supply information to accompany their products, additional information like this would be valuable. Although the argument could be made that it would detract from the attractiveness of their product as a convenient addition to something merchants already use on a daily basis, it would serve to force the buyers to weigh the risk themselves, and at the very least, keep them informed.
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
7/16/2014 | 11:47:27 AM
Re: Square & iphones
I don't think the word has gotten out to the small  merchants that I've seen working with Square. Hopefully a few of them are reading this blog!
ChrisNuttMandiant
50%
50%
ChrisNuttMandiant,
User Rank: Author
7/16/2014 | 11:26:30 AM
Re: Square & iphones
Hey Marilyn,

I would definitely recommend that vendors use a dedicated device for carrying out card transactions.  Having a dedicated device would mean that only the application(s) required for the card transactions would be installed; reducing the likelihood that unnecessary third-party applications would reduce the security of the device.
GonzSTL
50%
50%
GonzSTL,
User Rank: Ninja
7/16/2014 | 10:13:14 AM
Re: Square & iphones
I would definitely suggest a cellular mobile device used exclusively for that purpose, and not for games, mail, etc. Additionally, if the card transaction is transmitted via the same network used by other computing devices, or if the mobile device connects to that network at all, then the PCI scope expands to include every device on that network.
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
7/16/2014 | 8:34:53 AM
Square & iphones
good information here, Chris. I found your suggestion about using a non-jailbroken iPad or iPhone with mobile card reader like Square or Stripe particularly noteworthy. I've seen a number of small merchants use Square with their personal iphone. So are you sayng they should have a dedicated phone solely for those transactions? 


More SolarWinds Attack Details Emerge
Kelly Jackson Higgins, Executive Editor at Dark Reading,  1/12/2021
Vulnerability Management Has a Data Problem
Tal Morgenstern, Co-Founder & Chief Product Officer, Vulcan Cyber,  1/14/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2020: The Year in Security
Download this Tech Digest for a look at the biggest security stories that - so far - have shaped a very strange and stressful year.
Flash Poll
Assessing Cybersecurity Risk in Today's Enterprises
Assessing Cybersecurity Risk in Today's Enterprises
COVID-19 has created a new IT paradigm in the enterprise -- and a new level of cybersecurity risk. This report offers a look at how enterprises are assessing and managing cyber-risk under the new normal.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-7343
PUBLISHED: 2021-01-18
Missing Authorization vulnerability in McAfee Agent (MA) for Windows prior to 5.7.1 allows local users to block McAfee product updates by manipulating a directory used by MA for temporary files. The product would continue to function with out-of-date detection files.
CVE-2020-28476
PUBLISHED: 2021-01-18
All versions of package tornado are vulnerable to Web Cache Poisoning by using a vector called parameter cloaking. When the attacker can separate query parameters using a semicolon (;), they can cause a difference in the interpretation of the request between the proxy (running with default configura...
CVE-2020-28473
PUBLISHED: 2021-01-18
The package bottle from 0 and before 0.12.19 are vulnerable to Web Cache Poisoning by using a vector called parameter cloaking. When the attacker can separate query parameters using a semicolon (;), they can cause a difference in the interpretation of the request between the proxy (running with defa...
CVE-2021-25173
PUBLISHED: 2021-01-18
An issue was discovered in Open Design Alliance Drawings SDK before 2021.12. A memory allocation with excessive size vulnerability exists when reading malformed DGN files, which allows attackers to cause a crash, potentially enabling denial of service (crash, exit, or restart).
CVE-2021-25174
PUBLISHED: 2021-01-18
An issue was discovered in Open Design Alliance Drawings SDK before 2021.12. A memory corruption vulnerability exists when reading malformed DGN files. It can allow attackers to cause a crash, potentially enabling denial of service (Crash, Exit, or Restart).