<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Whitebunnywabbit &#187; pci-dss</title>
	<atom:link href="http://www.whitebunnywabbit.com/tag/pci-dss/feed" rel="self" type="application/rss+xml" />
	<link>http://www.whitebunnywabbit.com</link>
	<description>General Whitebunnywabbit is Watching you</description>
	<lastBuildDate>Thu, 12 Jan 2012 08:58:08 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>Is your card details safe?</title>
		<link>http://www.whitebunnywabbit.com/internet/0281/card-details-safe.html</link>
		<comments>http://www.whitebunnywabbit.com/internet/0281/card-details-safe.html#comments</comments>
		<pubDate>Tue, 17 Aug 2010 17:41:44 +0000</pubDate>
		<dc:creator>calhoun</dc:creator>
				<category><![CDATA[Internet]]></category>
		<category><![CDATA[card]]></category>
		<category><![CDATA[credit]]></category>
		<category><![CDATA[pa-dss]]></category>
		<category><![CDATA[pci-dss]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[ssl]]></category>

		<guid isPermaLink="false">http://www.whitebunnywabbit.com/?p=281</guid>
		<description><![CDATA[<p><p><a href="http://www.whitebunnywabbit.com/internet/0281/card-details-safe.html">Is your card details safe?</a>%%</p><p>Having been at a meeting today discussing a ePOS system, we were informed that new regulations were coming into play regarding storing of credit card information. In my bid to find out more about these new regulations i came across some disturbing information that earlier this year Argos had been storing credit card numbers along [...]</p></p><p>Created by <a href="http://www.whitebunnywabbit.com"> Whitebunnywabbit </a></p>]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.whitebunnywabbit.com/internet/0281/card-details-safe.html">Is your card details safe?</a>%%</p><p>Having been at a meeting today discussing a ePOS system, we were informed that new regulations were coming into play regarding storing of credit card information.</p>
<p>In my bid to find out more about these new regulations i came across some disturbing information that earlier this year Argos had been storing credit card numbers along with their card verification number inside source codes to customer emails. This seems to be a major breach of the PCI-DSS standard.</p>
<p>More to the point however changes do seem to be pending from the PCI council. The organization which deals with card securities has indicated nine new points are under consideration. The majority of the changes proposed however are for clarification purposes.</p>
<p>The link to the official release is below, if this applies to you feel free to have a look and prepare yourself for the next generation in security.</p>
<p>References<br />
<a title="Argos buries unencrypted credit card data in email receipts" href="http://forums.theregister.co.uk/forum/1/2010/03/05/argos_email_security_snafu/" target="_blank">The Register</a><br />
<a title=" 	 PCI Council to address secure coding, key management in PCI DSS 2.0" href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1518393,00.html?track=NL-102&amp;ad=781024&amp;asrc=EM_NLN_12266239&amp;uid=10112107" target="_blank">SearchSecurity.com</a><br />
<a title="Summary of Changes" href="https://www.pcisecuritystandards.org/pdfs/summary_of_changes_highlights.pdf" target="_blank">PCISecurityStandards.org</a></p>
<div class="al2fb_like_button"><div id="fb-root"></div><script src="http://connect.facebook.net/en_US/all.js#appId=181089105257561&amp;xfbml=1" type="text/javascript"></script><fb:like href="http://www.whitebunnywabbit.com/internet/0281/card-details-safe.html" layout="standard" show_faces="true" width="450" action="like" font="arial" colorscheme="light" ref="AL2FB"></fb:like></div><p>Created by <a href="http://www.whitebunnywabbit.com"> Whitebunnywabbit </a></p>]]></content:encoded>
			<wfw:commentRss>http://www.whitebunnywabbit.com/internet/0281/card-details-safe.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Rootkit breaches network security in India, Are you effected?</title>
		<link>http://www.whitebunnywabbit.com/internet/0116/rootkit-breaches-network-security-india-effected.html</link>
		<comments>http://www.whitebunnywabbit.com/internet/0116/rootkit-breaches-network-security-india-effected.html#comments</comments>
		<pubDate>Sun, 18 Jul 2010 15:49:55 +0000</pubDate>
		<dc:creator>calhoun</dc:creator>
				<category><![CDATA[Internet]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[pci-dss]]></category>
		<category><![CDATA[realtek]]></category>
		<category><![CDATA[root kit]]></category>
		<category><![CDATA[rootkit]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.whitebunnywabbit.com/?p=116</guid>
		<description><![CDATA[<p><p><a href="http://www.whitebunnywabbit.com/internet/0116/rootkit-breaches-network-security-india-effected.html">Rootkit breaches network security in India, Are you effected?</a>%%</p><p>In my role at work I recently had the opportunity to discuss with a expert in security aspects of the PCI-Data Security Standard in the context of storing credit card information. This covers amongst many other things, whom has access to the data. Our client has a team in India doing work for his site [...]</p></p><p>Created by <a href="http://www.whitebunnywabbit.com"> Whitebunnywabbit </a></p>]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.whitebunnywabbit.com/internet/0116/rootkit-breaches-network-security-india-effected.html">Rootkit breaches network security in India, Are you effected?</a>%%</p><p>In my role at work I recently had the opportunity to discuss with a expert in security aspects of the PCI-Data Security Standard in the context of storing credit card information. This covers amongst many other things, whom has access to the data. Our client has a team in India doing work for his site as well.</p>
<p>This means that when he comes round to getting pci-dss compliant he will have to factor in them into his equation.  Now I&#8217;m seeing that there&#8217;s been a pretty major security breach across India. This is one of the many factors one should consider when outsourcing work to beyond national borders.</p>
<p>The breach is in the form of a rootkit hijacking against certificates for drivers by Realtek whom quite commonly develop Ethernet cards for many manufacturers. Therefore there is a significant risk that your outsource partner could be effected.</p>
<p>References<a title="Spy rootkit goes after key Indian, Iranian systems" href="http://www.zdnet.co.uk/news/security/2010/07/16/spy-rootkit-goes-after-key-indian-iranian-systems-40089564/" target="_blank"><br />
ZDNetUK</a></p>
<div class="al2fb_like_button"><div id="fb-root"></div><script src="http://connect.facebook.net/en_US/all.js#appId=181089105257561&amp;xfbml=1" type="text/javascript"></script><fb:like href="http://www.whitebunnywabbit.com/internet/0116/rootkit-breaches-network-security-india-effected.html" layout="standard" show_faces="true" width="450" action="like" font="arial" colorscheme="light" ref="AL2FB"></fb:like></div><p>Created by <a href="http://www.whitebunnywabbit.com"> Whitebunnywabbit </a></p>]]></content:encoded>
			<wfw:commentRss>http://www.whitebunnywabbit.com/internet/0116/rootkit-breaches-network-security-india-effected.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

