Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Payment Card Data Theft: Tips For Small Business
Newest First  |  Oldest First  |  Threaded View
catvalencia
50%
50%
catvalencia,
User Rank: Apprentice
8/12/2014 | 5:14:32 AM
Re: Square & iphones
Very informative! Information regarding one's card, such as card numbers and so forth, should be kept hidden, such as shredding statements or blacking out sensitive information before throwing them away. Another good tip is to constantly monitor the account. Check statements thoroughly and promptly and report any suspicious purchases immediately. Source: Credit Card Fraud

 
KateN232
50%
50%
KateN232,
User Rank: Apprentice
7/21/2014 | 10:52:20 AM
Re: Square & iphones
The Cloud And Big Data as an important part of small business

Using of big data and the cloud have great influence on practically each business industry. It allows companies of all sizes to serve customers more effectively, analyze and improve business processes. Read more https://www.snappii.com/resource-center/cloud-big-data-important-part-small-business/
Robert McDougal
50%
50%
Robert McDougal,
User Rank: Ninja
7/18/2014 | 11:10:37 AM
Re: Square & iphones
I have to agree, I hope they read this.  Many of the small businesses that utilize square appear to use their personal devices.
GonzSTL
50%
50%
GonzSTL,
User Rank: Ninja
7/16/2014 | 12:21:17 PM
Re: Square & iphones
It would be beneficial to small merchants if card processing vendors suggest this practice to their clients, who do not normally hear or read about these little issues regarding their choice of payment systems. Since vendors already supply information to accompany their products, additional information like this would be valuable. Although the argument could be made that it would detract from the attractiveness of their product as a convenient addition to something merchants already use on a daily basis, it would serve to force the buyers to weigh the risk themselves, and at the very least, keep them informed.
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
7/16/2014 | 11:47:27 AM
Re: Square & iphones
I don't think the word has gotten out to the small  merchants that I've seen working with Square. Hopefully a few of them are reading this blog!
ChrisNuttMandiant
50%
50%
ChrisNuttMandiant,
User Rank: Author
7/16/2014 | 11:26:30 AM
Re: Square & iphones
Hey Marilyn,

I would definitely recommend that vendors use a dedicated device for carrying out card transactions.  Having a dedicated device would mean that only the application(s) required for the card transactions would be installed; reducing the likelihood that unnecessary third-party applications would reduce the security of the device.
GonzSTL
50%
50%
GonzSTL,
User Rank: Ninja
7/16/2014 | 10:13:14 AM
Re: Square & iphones
I would definitely suggest a cellular mobile device used exclusively for that purpose, and not for games, mail, etc. Additionally, if the card transaction is transmitted via the same network used by other computing devices, or if the mobile device connects to that network at all, then the PCI scope expands to include every device on that network.
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
7/16/2014 | 8:34:53 AM
Square & iphones
good information here, Chris. I found your suggestion about using a non-jailbroken iPad or iPhone with mobile card reader like Square or Stripe particularly noteworthy. I've seen a number of small merchants use Square with their personal iphone. So are you sayng they should have a dedicated phone solely for those transactions? 


COVID-19: Latest Security News & Commentary
Dark Reading Staff 9/21/2020
Hacking Yourself: Marie Moe and Pacemaker Security
Gary McGraw Ph.D., Co-founder Berryville Institute of Machine Learning,  9/21/2020
Startup Aims to Map and Track All the IT and Security Things
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/22/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-25595
PUBLISHED: 2020-09-23
An issue was discovered in Xen through 4.14.x. The PCI passthrough code improperly uses register data. Code paths in Xen's MSI handling have been identified that act on unsanitized values read back from device hardware registers. While devices strictly compliant with PCI specifications shouldn't be ...
CVE-2020-5783
PUBLISHED: 2020-09-23
In IgniteNet HeliOS GLinq v2.2.1 r2961, the login functionality does not contain any CSRF protection mechanisms.
CVE-2020-11031
PUBLISHED: 2020-09-23
In GLPI before version 9.5.0, the encryption algorithm used is insecure. The security of the data encrypted relies on the password used, if a user sets a weak/predictable password, an attacker could decrypt data. This is fixed in version 9.5.0 by using a more secure encryption library. The library c...
CVE-2020-5781
PUBLISHED: 2020-09-23
In IgniteNet HeliOS GLinq v2.2.1 r2961, the langSelection parameter is stored in the luci configuration file (/etc/config/luci) by the authenticator.htmlauth function. When modified with arbitrary javascript, this causes a denial-of-service condition for all other users.
CVE-2020-5782
PUBLISHED: 2020-09-23
In IgniteNet HeliOS GLinq v2.2.1 r2961, if a user logs in and sets the ‘wan_type’ parameter, the wan interface for the device will become unreachable, which results in a denial of service condition for devices dependent on this connection.