fhs
Volume 8, Number 30 -- August 19, 2008

ID Theft Case Put Focus on Credit Card Security

Published: August 19, 2008

by Alex Woodie

Is your credit card data safe? That's the question millions of people are asking themselves following the recently exposed international identity theft ring that allegedly stole more than 41 million credit card numbers. While security is a relative term, experts in the field of electronic payment systems, including Ira Chandler of i5/OS payment card software developer Curbstone, say the Payment Card Industry (PCI) Data Security Standard (DSS) provides good protection of sensitive data. Unfortunately, not everybody is following PCI DSS to the letter.

Earlier this month, the Department of Justice announced indictments on 11 people from the U.S., Estonia, Ukraine, Belarus, and China on charges of hacking into retailers' computers and stealing more than 41 million credit card numbers between 2003 and 2005 from TJX, BJ’s Wholesale Club, OfficeMax, Boston Market, Barnes & Noble, Sports Authority, and other major retailers. Only three of the suspects are in custody; the others remain at large.

According to the DoJ, the perpetrators drove around in their vehicles with laptops, looking for unsecured 802.11 "Wi-Fi" network connections, a technique called "wardriving." Once inside the networks, they installed programs to capture credit card and debit card numbers and other sensitive data as it flowed across their electronic payment processing networks, the DoJ says. Once in hand, the numbers were used to create counterfeit debit cards, which were used to withdraw tens of millions of dollars from ATMs.

The story has catapulted wardriving into the public lexicon, and turned innocent consumers into sentries on the perimeter of public protection. Instead of skipping light-heartedly into a local store to help drive the world economy, consumers now get a bit jumpy every time they see a bald dude in the parking lot, typing on a laptop from his rusty Chevy Citation.

If only it were that simple. But Chandler, who was an expert witness in an identity theft case involving one of the retailers mentioned above, knows it's not. "I know the reason some of these happen is not necessarily these guys wardriving, trying to find open Wi-Fi," he says. "It's not that simple. There's really a lot more to it."

There are many ways hackers can penetrate computer systems. Wired systems can be compromised through unsecured USB ports, or by guessing a username and a password. Modems can be eavesdropped on, revealing credit card information in plain text. For these reasons and others, Visa and the other credit card companies came up with the PCI DSS, a series of 12 tenants for retailers.

While the PCI process can be a giant headache for software vendors and integrators, merchants would be wise to follow the PCI DSS as closely as they can, Chandler says. "If they actually follow the 12 tenants, if they do the self-assessment questionnaire, then they will cover their exposures," he says. "If they would do it, they wouldn't have these problems. They're not doing it."

Hopefully, the retailers involved have turned off the Wi-Fi, and come into compliance with PCI. After all, it's been nearly two years since TJ Max first admitted to the wardriving problem. The fact that other retailers were targeted by the same group from 2003 to 2005 is just now becoming known.

But that doesn't mean there aren't other problems. In all likelihood, in two or three years from now, we'll be talking about the security weaknesses and instances of identity theft that are happening right now. Such is the case when companies are hesitant to talk about their security problems, even with the new state laws requiring them to inform customers whose identities have been put at risk.

So which vendors are more apt to handle your data in a careless manner and put you at risk of identity theft? According to Chandler, a lot of it has to do with the size of the company, which in large part determines what kind of computers they use, and how the system is architected.

Larger retailers that use larger servers like the AS/400, to perform credit authorizations for dedicated point of sale (POS) devices with hardened Windows- or Linux-based operating systems, such as those from IBM or Micros, are more secure, according to Chandler. "With the bigger merchants, everything's centralized. It all goes through the data center in each store," he says. Hacking into that central server is a lot tougher than hitting an individual POS.

Smaller retailers that run POS applications on top of a regular PC operating system, such as Windows, and use a card-swipe reader device with a network connection to perform credit authorizations, are less secure. In such circumstances, any underlying vulnerabilities of the non-hardened Windows OS could provide a crack for hackers to exploit.

It's also not a good idea to use your debit card at a service station, Chandler says. "Pumps are generally much less secure than anything else. Point of sale is generally pretty insecure as well, but gas pumps are the worst," he says. "Never use a debit card at a pump. The exposures are just too great."

As a developer of AS/400-based credit card authorization software, Chandler holds a certain bias against the PC and Windows platform. It's not that a Windows POS can't be made to be secure, he says. It's just harder. "Merchants take for granted that the integrators who sell and install and configure those things have their PCI interest at heart," he says. "They may be following the 12 tenants, but the merchants themselves may be defeating some of those things."

Even if the integrator installs a perfectly secure POS system, things like an unsecured Wi-Fi connection can spell doom for the retailer. "Now all of a sudden the most secure POS system goes to crap because no matter how you cover those 12 points within that island, if that island is connected and the rest of the mainland is not secure, you've got a bridge and you're in there and you're dead meat."


RELATED STORY

Putting the 'i' Back Into PCI



                     Post this story to del.icio.us
               Post this story to Digg
    Post this story to Slashdot


Sponsored By
SEAGULL SOFTWARE

White Paper: The Top 5 Myths of Screen Scraping

The term "screen-scraping" has a bad reputation. Yet next-generation screen-scraping software can be an application modernization solution that solves the problems green-screens present.

Don't let these myths prevent you from improving your business applications:

                                  1. Screen Scraping is only a Green-Screen in a Browser
                                  2. Keeping Host and GUI in Sync is Hard
                                  3. Screen-Scraping is a Maintenance Nightmare
                                  4. Screen-Scraping Projects Are Unmanageable
                                  5. You Can't do SOA with Screen-Scraping

Download this white paper to find out more.


Editor: Alex Woodie
Contributing Editors: Dan Burger, Joe Hertvik,
Shannon O'Donnell, Timothy Prickett Morgan
Publisher and Advertising Director: Jenny Thomas
Advertising Sales Representative: Kim Reed
Contact the Editors: To contact anyone on the IT Jungle Team
Go to our contacts page and send us a message.

Sponsored Links

ASNA:  Transform and revitalize web-faced and green-screen apps
COMMON:  Join us at the Focus 2008 workshop conference, October 5 - 8, in San Francisco, California
SkyView Partners:  Download Carol Woodbury's new security compliance book


 

IT Jungle Store Top Book Picks

Easy Steps to Internet Programming for AS/400, iSeries, and System i: List Price, $49.95
Getting Started with PHP for i5/OS: List Price, $59.95
The System i RPG & RPG IV Tutorial and Lab Exercises: List Price, $59.95
The System i Pocket RPG & RPG IV Guide: List Price, $69.95
The iSeries Pocket Database Guide: List Price, $59.00
The iSeries Pocket Developers' Guide: List Price, $59.00
The iSeries Pocket SQL Guide: List Price, $59.00
The iSeries Pocket Query Guide: List Price, $49.00
The iSeries Pocket WebFacing Primer: List Price, $39.00
Migrating to WebSphere Express for iSeries: List Price, $49.00
iSeries Express Web Implementer's Guide: List Price, $59.00
Getting Started with WebSphere Development Studio for iSeries: List Price, $79.95
Getting Started With WebSphere Development Studio Client for iSeries: List Price, $89.00
Getting Started with WebSphere Express for iSeries: List Price, $49.00
WebFacing Application Design and Development Guide: List Price, $55.00
Can the AS/400 Survive IBM?: List Price, $49.00
The All-Everything Machine: List Price, $29.95
Chip Wars: List Price, $29.95


 
The Four Hundred
Why Blade Servers Still Don't Cut It, and How They Might

Power Systems Memory Prices Slashed to Promote Virtualization

Database Modernization Still Unknown Territory

As I See It: God Bless Technology

Virtualization Adoption Skyrockets on Power Systems Iron

The Linux Beacon
What the Heck Is the Midrange, Anyway?

Intel Talks Up Larrabee X64-Based Graphics Engine

IBM's Q2 Server Sales: Let's Do Some Math

As I See It: Babes in Broadband

Gartner Is Projecting a Decline in IT Hiring This Year

Big Iron
Unisys: Crunch for the Last of the BUNCH

Top Mainframe Stories From Around the Web

Chats, Webinars, Seminars, Shows, and Other Happenings

Four Hundred Guru
Serving Up Spreadsheets

V6R1 Enhancements for Run SQL Scripts

Admin Alert: Common Mistakes When Failing Over to a CBU

System i PTF Guide
August 2, 2008: Volume 10, Number 31

July 26, 2008: Volume 10, Number 30

July 19, 2008: Volume 10, Number 29

July 12, 2008: Volume 10, Number 28

July 5, 2008: Volume 10, Number 27

June 28, 2008: Volume 10, Number 26

The Windows Observer
What Art Thou, Midori?

Microsoft Works to Put the Clamps on 'Exploit Wednesday'

Yahoo Shareholder Meeting Anti-Climactic

Gartner Is Projecting a Decline in IT Hiring This Year

Microsoft to Buy DATAllegro for Data Warehouse Appliances

The Unix Guardian
Sun Carbon Copies Another Q4 and Fiscal Year

Q&A with IBM's Ross Mauri: Talking Power Systems and Power7

Sun Delivers AMP Stack for Solaris and Linux, Windows Coming

As I See It: Babes in Broadband

SAP Profits Under Pressure in Q2, Software Prices Get Jacked

Four Hundred Monitor
Four Hundred Monitor's
Full iSeries Events Calendar

THIS ISSUE SPONSORED BY:

Bytware
Seagull Software
Profound Logic Software
Computer Keyes
Twin Data


Printer Friendly Version


TABLE OF CONTENTS
looksoftware Unveils iPhone Client for i OS Apps

ID Theft Case Put Focus on Credit Card Security

Original Beefs Up Report Compare Feature in iSeries Testing Tool

BCD Adds More Automation, Customization to PHP Tool

Pat Townsend Unveils New Name, New Windows Solution

News Briefs and Product Shorts:

Formtastic Gains More Flexibility in Managing i OS Output . . . XAware Boasts More Than 150,000 Downloads . . . Real Time Forensics from Log Data? ArcSight Says It's Got It . . . ISC Taps LANSA for App Modernization . . . Workplace Service Firm Licenses Lawson's i OS-based ERP . . .

Four Hundred Stuff

BACK ISSUES





 
Subscription Information:
You can unsubscribe, change your email address, or sign up for any of IT Jungle's free e-newsletters through our Web site at http://www.itjungle.com/sub/subscribe.html.

Copyright © 1996-2008 Guild Companies, Inc. All Rights Reserved.
Guild Companies, Inc., 50 Park Terrace East, Suite 8F, New York, NY 10034

Privacy Statement