Showing posts with label PCI. Show all posts
Showing posts with label PCI. Show all posts

Thursday, April 16, 2009

Credit Card PINs No Longer Secure

As technology advances make it easier for customers to access their accounts and perform money movement transactions with credit and debit cards, the bad guys are using technology to steal the Personal Identification Numbers (PINs) that are issued to customers to help protect their accounts.

Feeling less secure yet?

It doesn't even matter anymore if the PINs are encrypted. Conventional wisdom held that once a customer keyed their PIN into an ATM or at a point-of-sale terminal, the transaction was secure as it went through the processing cycle, due to the encryption algorithms. The transaction would be received by your financial institution, decrypted, and processed. Viola!

PCI standards supported by the banks and credit card industry (which are ineffective as I've written about here and here) were supposed to prevent this kind of attack. Forcing encryption of the transactions and PINs was seen as a panacea. But as Bruce Schneier posited in his book Beyond Fear, when you think about implementing security controls into a system, you also need to contemplate what new weaknesses or gaps are created at the same time.

In this case of these encrypted transactions, the gap introduced is pretty clear - the hardware security module (HSM), a security appliance that resides on bank networks and switches to help encrypt and decrypt traffic as it passes through transaction processing.

Problem is, there are multiple HSMs among the various banking networks that the transaction passes through on the way from its origin to the customer's bank. Each of the HSMs might be different, and are managed by different firms or even contractors in some cases. The traffic needs to be decrypted as it passes through the HSM, then re-encrypted as it's sent on to the next HSM.

It's at these switching points that the crooks often trick the HSM into revealing the encryption details, PIN blocks, or keys, either because of configuration problems, vulnerabilities, or weaknesses in the HSM or its operating software. Once a PIN block is compromised, it's off to the races.

The HSM is but one attack vector - other methods of compromising transactions are old-school but equally effective, and there's always phishing attacks and compromising servers that contain the information, like the Hannaford breach. But the utter collapse of PIN numbers as an effective control is causing the industry to scramble as losses soar into the hundreds of millions of dollars.

It's time to look at integrated security solutions and secure networks for transaction processing, and a deep assessment is needed of all controls associated with financial dealings. With the large volumes of data gushing through the system, even a small leak can have catastrophic results.

PIN Crackers Nab Holy Grail of Bank Card Security


Friday, April 3, 2009

House Rips PCI Standard, Gets Kicked Out of Bed By Credit Card Industry

In another practical demonstration of how politics makes for strange bedfellows, the US House of Representatives threw a hissy fit this week concerning the ineffectiveness of the PCI Standard when it comes to actually protecting against real threats.

As background, the Payment Card Industry Data Security Standard (PCI DSS) was an elaborate framework designed by the credit card industry and foisted upon retailers and anyone else involved in credit card transactions to ostensibly protect against the various security threats that exist.


It's long been thought by many outside of the credit card industry that PCI was more about credit card companies looking to shift the burden (and expense) of credit card fraud and abuse to retailers, processors, and other groups, as instances of fraud have exploded due to technological advances exploited by fraudsters and the breakdown of geographic barriers that has allowed criminals from Eastern Europe, Russia, and China to become major players in both fraudulent transactions and money laundering via the sale of goods stolen via this process.


Turns out that little events like massive data breaches at Heartland and other processors has served to substantiate earlier claims that PCI was more for show than for actual protection, as a number of companies involved in breaches were either certified as PCI-compliant, or had robust PCI programs in place.


As with most disagreements, the truth probably lays somewhere in the middle. PCI isn't necessarily worthless, but it does have its limitations. Primarily, it's a static set of guidelines and requirements, and it's unreasonable to expect something static to address such a dynamic threat environment.

Similarly, there are challenges to applying the PCI framework across the spectrum of businesses that have skin in the game. Depending on the business type, transaction volumes, location, and other factors, certain threats are more high risk than others, and attempting to paint all entities with the same risk mitigation brush is foolish.


The House should probably look in the mirror a bit before they begin pontificating about PCI. It's pretty easy to connect the dots between lobbyists and campaign contributions from the credit card industry and the apparant ease that same group had in having their PCI recommendations breeze though the very same legislative body.

Congress has a conveniently short memory when it comes time to be publicly outraged about some issue or another, as we've seen with the financial crisis, AIG, TARP, and so on. Sadly, in almost every case, they are complicit in the problem at the very least, and often a major contributer to the root cause.


So what's the answer?

It comes down to a simple math equation. When it costs more in penalties resultant from a breach than it does to prevent one, businesses will step up their game. If I can spend $1 million to protect customer information, and only pay $10,000 in breach response costs and penalties, it doesn't take an accounting expert to know what most companies will do with their cost-benefit analysis.


If it costs $1 million to protect the data, and $5 million to compensate customers who have had their information lost or stolen, the equation shifts. It's suddenly a relatively good investment, and that spans all businesses. A $5 million penalty could put many small companies out of business, so it's in their own best interest to do a better job of data protection.


Until we're ready to face this reality, expect more pontificating and less protection.