Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
PCI Update Paves Way For Expanding Point-to-Point Encryption
Newest First  |  Oldest First  |  Threaded View
Some Guy
50%
50%
Some Guy,
User Rank: Moderator
7/2/2015 | 2:47:41 PM
It's an Arms Race .. How you can help
We can decry the inevitability of attacks, but what we can't do is accept that as the norm. It's an Arms Race; the next step is here; waiting to do nothing until a perfect solution presents itself is to commit a nirvana fallacy.

Here's where YOU can make a difference. On November 1st, if your credit card hasn't been updated to PIN & Chip (EMV) technology, vote with your pocketbook and move your credit so somewhere that does.
iNtHEmACHINE
50%
50%
iNtHEmACHINE,
User Rank: Apprentice
7/2/2015 | 12:16:09 PM
Re: Okay but...
"Low hanging fruit is the name of the game with hackers that are trying to make money from it."

Low hanging or stumbled apon is where the huge hacks have been, but money is the name of the game even if it's just a Nigerian scam or a few million numbers with expiration dates. Easy money is better, but money is money. If it's MY money I expect it to be secured.

"Good security only really attracts the security curious out there"

And making it harder does make it harder. What is security curious? <heh>

 
Whoopty
50%
50%
Whoopty,
User Rank: Ninja
7/2/2015 | 5:00:04 AM
Re: Okay but...
I know what you mean. It can make you feel a bit dispondent about security with how easy it often seems to bypass it. As long as it's difficult though, it should be relatively safe. Low hanging fruit is the name of the game with hackers that are trying to make money from it. Good security only really attracts the security curious out there. 
Blog Voyage
100%
0%
Blog Voyage,
User Rank: Strategist
7/2/2015 | 2:52:40 AM
Okay but...
"The goal is to make it harder for attackers to steal card data using POS malware tools like BlackPOS, Dexter, vSkimmer, and Backoff." Sure it will help, but hackers always have an advantage.


7 Tips for Infosec Pros Considering A Lateral Career Move
Kelly Sheridan, Staff Editor, Dark Reading,  1/21/2020
For Mismanaged SOCs, The Price Is Not Right
Kelly Sheridan, Staff Editor, Dark Reading,  1/22/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment:   It's a PEN test of our cloud security.
Current Issue
IT 2020: A Look Ahead
Are you ready for the critical changes that will occur in 2020? We've compiled editor insights from the best of our network (Dark Reading, Data Center Knowledge, InformationWeek, ITPro Today and Network Computing) to deliver to you a look at the trends, technologies, and threats that are emerging in the coming year. Download it today!
Flash Poll
How Enterprises are Attacking the Cybersecurity Problem
How Enterprises are Attacking the Cybersecurity Problem
Organizations have invested in a sweeping array of security technologies to address challenges associated with the growing number of cybersecurity attacks. However, the complexity involved in managing these technologies is emerging as a major problem. Read this report to find out what your peers biggest security challenges are and the technologies they are using to address them.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-5226
PUBLISHED: 2020-01-24
Cross-site scripting in SimpleSAMLphp before version 1.18.4. The www/erroreport.php script allows error reports to be submitted and sent to the system administrator. Starting with SimpleSAMLphp 1.18.0, a new SimpleSAML\Utils\EMail class was introduced to handle sending emails, implemented as a wrapp...
CVE-2019-1517
PUBLISHED: 2020-01-24
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.
CVE-2019-1518
PUBLISHED: 2020-01-24
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.
CVE-2019-1519
PUBLISHED: 2020-01-24
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.
CVE-2019-1520
PUBLISHED: 2020-01-24
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.