Encryption Implementation Really Matters
Written by Walter ConwayAugust 26th, 2010
PCI Columnist Walt Conway wants to withdraw one point from last week's column while reinforcing the rest. To suggest that the key could be derived from encrypting too small and easily guessable a field was wrong. But the essence of the concern is that properly configured systems would not be vulnerable to this type of attack. How many retail chains do you know that who have properly configured security systems?
Retailers looking to purchase a product rather than develop one in-house have to be equally thoughtful. They should make sure the software vendors providing their POS applications have experts on cryptography as part of their development teams. It's not enough to ask what algorithm or key length the POS uses or even to check that the application is on the PA-DSS list of Validated Payment Applications without understanding the operational implications of how that application handles cryptographic functions.
This Story Is Only Available For Premium Subscribers. Click Or Login In Below To Read The Rest Of This Story.
Already a Subscriber? Login Here
Pages: 1 2
Leave a Reply
Readers, specifically those who want to comment on a story:
Our Comment SPAM system is getting very aggressive these days and has been blocking legitimate comments. If you post a comment and don't see it appear within 2 hours or so, can you please send a heads-up to customer-service@storefrontbacktalk.com? Ideally, please include the time you posted the comment. That will allow us to try and hunt for it. Thanks! P.S. We're working on fixing the system, but we don't want to lose any valuable comments in the meantime.
Our Comment SPAM system is getting very aggressive these days and has been blocking legitimate comments. If you post a comment and don't see it appear within 2 hours or so, can you please send a heads-up to customer-service@storefrontbacktalk.com? Ideally, please include the time you posted the comment. That will allow us to try and hunt for it. Thanks! P.S. We're working on fixing the system, but we don't want to lose any valuable comments in the meantime.
I have strong reservations about the 'individual' certification and posting of that information for merchants. Can you imagine the potential employee poaching that might occur? The implications when competitors can look up how many are certified with each of their competitors?
-Christine
