120 likes | 259 Views
Security in Credit Card Transactions Banking Vietnam 2007 Hanoi, Vietnam 1 June 2007. Thomas Parenty Director, Information Security Services Hill & Associates Risk Consulting. Old Fashioned Fraud. New Faces of Credit Card Crimes. Britain’s largest fraud Potential loss of £17 million
E N D
Security in Credit Card TransactionsBanking Vietnam 2007Hanoi, Vietnam1 June 2007 Thomas ParentyDirector, Information Security Services Hill & Associates Risk Consulting
New Faces of Credit Card Crimes • Britain’s largest fraud • Potential loss of £17 million • 32,000 American credit card numbers • Cloned cards • Money Trail Poland, Estonia, Russia, Span, US, Virgin Islands
TJX: The Biggest Yet • $17 billion retailer Marshalls, T.J. Max, A.J. Wright, Home Goods • 45.7 million credit & debit card numbers • 1 year of transactions • (possibly 200 million numbers from 4 years) • Personal info on over 450,000 customers
Estimated Costs • TJX $24 million incident response $ 1 Billion remediation (over 5 years) $? Over 20 lawsuits • Banks $300 million to replace cards $? fraud
Climbing Through a Wireless Window • Wired Equivalent Privacy (WEP) not private
Setting Up Shop • Crack encryption • Intercept usernames and passwords • Create new computer accounts • Steal credit & debit numbers • Sell them on the Internet
PCI Data Security Standard • Technical controls Encrypt all administrator access Anti-virus and firewalls • Policy Do not store full track data • Testing Vulnerability & penetration • Qualified Security Assessors • Approved Scanning Vendors
Asian PCI Issues & Thoughts • Huge increase in interest this year • But, requirement or nice idea? • Negative consequences of not passing audit Remediation Reputation issues • PCI is a good, clear standard • Banks are financially responsible for the mistakes of others
Security in Credit Card TransactionsBanking Vietnam 2007Hanoi, Vietnam1 June 2007 Thomas ParentyDirector, Information Security Services Hill & Associates Risk Consulting