Hannaford Supermarket Breach Calls PCI Compliance Into Question
Andrew Conry-Murray writes on InformationWeek:
The latest exposure of millions of credit and debit card numbers by Hannaford Bros., a grocery chain with 271 locations in New England and Florida, raises new questions about the value of the credit card industry's controversial security rules, known as PCI. The Payment Card Industry Data Security Standard was put in place by major card brands, including Visa and MasterCard, to ensure that retailers take sufficient steps to protect customers' financial data. More than 3,600 U.S. retailers comply with--or are working to come into compliance with--the PCI program.
But retailers and security vendors know that PCI compliance is a slippery concept in terms of determining who is, and is not, up to par. And the Hannaford breach--in which 4.2 million credit and debit card numbers were exposed even as the company's Web site states that it "has been certified as compliant" with PCI--demonstrates to the rest of the world just how fluid this concept really is.
Bottom line, PCI compliance is mutable. While a compliance certification is valid for one year, a retailer may perform actions, or fail to perform actions, that take it out of compliance. On the one hand, this is sensible. PCI rules are like the dietary guidelines a doctor issues to a patient. It's not the physician's fault if someone with through-the-roof cholesterol ignores advice and eats like Homer Simpson.
More
here.
Visa Suspends Heartland: A Little Revisionist History?
Evan Schuman writes on StorefrontBacktalk:
Visa struck back at both Heartland on Thursday (March 12), suspending the data breach victim and removing it from Visa’s online list of PCI DSS compliant providers. Visa’s chief enterprise risk officer, Ellen Richey, told banks the news in an E-mail Thursday.
Richey described Heartland’s status as being “in a probationary period,” during which it can still accept payments, assuming it meets various new requirements. Heartland “is now in a probationary period, during which it is subject to a number of risk conditions including more stringent security assessments, monitoring and reporting. Subject to these conditions, Heartland will continue to serve as a processor in the Visa system.”
Heartland issued a statement Friday (March 13) that didn’t address Visa’s suspension, but was clearly prompted by it. “Heartland Payment Systems is pleased to continue our long relationship with Visa. Heartland is cooperating fully with Visa and other card brands and we are committed to having a safe and secure processing environment,” the statement said, which added that Heartland was certified as PCI-DSS compliant in April 2008 and “expects to continue to be assessed as PCI-DSS compliant in the future. We’re undergoing our 2009 PCI-DSS assessment now, which Heartland believes will be complete no later than May 2009 and will result in Heartland, once again, being assessed as PCI-DSS compliant.”
In Richey’s E-mail, she also referenced Heartland’s comments to Visa that it hopes to assessed PCI compliant soon. Heartland “will be relisted once it revalidates its PCI DSS compliance using a Qualified Security Assessor and meets other related compliance conditions.”
More
here.
Retail Security: 'Knee-jerk' Standards Compliance Isn't Enough
Tim Greene writes on NetworkWorld:
Businesses certified to be compliant with the Payment Card Industry Data Security Standards (PCI DSS) keep suffering data breaches, but the problem may be more with the way businesses address the requirements than with the PCI standard, experts told an Interop gathering.
Retail chain Forever 21, which last week revealed that nearly 99,000 customer payment cards may have been compromised, claimed it was PCI compliant, said John Pironti, the chief information risk strategist for Getronics.
“They claim to be PCI compliant, Hannaford’s [the supermarket chain that suffered a data breach] claimed to be PCI compliant,” said Pironti, who moderated an Interop panel on the subject of compliance.
But those firms may have restricted compliance auditors’ access to areas where they thought they would meet standards, said Jennifer Mack, vice president of Master Card Worldwide and a member of the PCI Security Council.
More
here.
PCI Survey Finds Some Merchants Don't Use AV Software
Jeremy Kirk writes on PC World:
Consumers face a greater risk of losing control of their data when doing business with smaller retailers, as many haven't made investments to comply with the Payment Card Industry's Data Security Standard (PCI DSS), according to a new survey.
The survey, which covered 560 U.S. and multinational organizations, asked respondents a variety of questions about their investments and deployment of technology to comply with PCI DSS, which was introduced in 2005. It's an industry standard created by major credit card companies that's designed to protect customer payment data.
The survey found that 55 percent of organizations only secured credit card information but not other data such as Social Security and driver's license numbers or bank account details. Also, only 28 percent of smaller companies between 501 to 1,000 employees comply with PCI DSS. That compares with more than 70 percent of large merchants with 75,000 or more employees that claimed they're compliant.
"If you go the larger organizations to do business, you are more likely to be secure today," said Amichai Shulman, CTO for Imperva, which makes security software for businesses to comply with PCI DSS. Imperva commissioned the survey from Ponemon Institute, a company that conducts research into privacy and information security policy.
The prime reason that companies don't comply with PCI DSS is cost, Shulman said. "They don't go to the effort to be compliant because it's all or nothing, so they currently do nothing," Shulman said.
More
here.
PCI: Not Just For Payment Anymore
Evan Schuman writes on StorefrontBacktalk:
As retail CFOs begrudgingly approve extensive dollars to help with PCI accreditation efforts—even though many IT departments are using those dollars for projects that primarily have little to do with security—many are discovering that a program designed to protect payment data will also do a fine job at protecting almost any other kind of data.
With CRM systems trying to interact with Web analytics, mobile databases, purchase and returns histories and tons of other non-payment databases, the amount of non-credit-card data that is at risk easily dwarfs Visa transactions.
The same common sense guidelines that are the soul of PCI—dealing with wireless, encryption, knowing what you're retaining and retaining only what you need—can be widely extended. But the same checklist mentality that is PCI's weakness also pigeonholes PCI into only being used for payment, which is silly.
More
here.
PCI Council to Merchants: Kiss Your WEP Goodbye
Bill Brenner writes on CSO Online:
The security savvy know WEP is full of holes and shouldn't be used. That's not stopping some merchants from doing just that.
As a result, the PCI Security Standards Council is mandating its eradication in the next two years. The first step toward that is some fresh language on wireless security in the next version of the PCI Data Security Standard (PCI DSS).
The council released a summary [.pdf] of PCI DSS Version 1.2 earlier this week and will officially launch it Oct. 1. Among other things, the council will remove references to WEP security and instead push organizations to use stronger forms of wireless network encryption. New WEP deployments won't be allowed after March 31, 2009, and current implementations must stop using WEP after June 30, 2010.
More
here.
Texas Mulls Bill That Would Make PCI Requirements a State Law
Jaikumar Vijayan writes on ComputerWorld:
Retailers and other entities accepting credit and debit card transactions in Texas may soon have a powerful new incentive for complying with the Payment Card Industry (PCI) data security standard mandated by the major credit card companies.
The state's House of Representatives last week voted 139-0 in favor of a bill that would formally codify PCI requirements into a state law that merchants would be obliged to comply with if passed. Under HB 3222 a breached entity will have to reimburse banks and credit unions the cost associated with blocking and reissuing cards if the merchant was not PCI compliant at the time of the compromise. It also provides a safe harbor against such liability for companies who are PCI compliant and get breached. The proposal needs to win approval in the state Senate before it becomes law.
More
here.
Merchants Putting PCI Certification Above Actually Improving Security?
Lisa Vaas writes on eWeek:
Security experts are starting to grumble about the Payment Card Industry Data Security Standard, saying that some merchants just want to get PCI-certified as cheaply and easily as possible—and that the PCI certification system is set up to help them do just that.
"The entire system seems to be set up not to find vulnerabilities," Jeremiah Grossman, chief technology officer and founder of WhiteHat Security, based in Santa Clara, Calif., and one of 135 security firms on the PCI Security Council's list of ASVs (Approved Scanning Vendors), said in an interview with eWEEK.
"We've had customers that wanted to debate the severity of certain issues because they needed to pass PCI. We sent them to another vendor we thought would pass them more easily. The last thing I want is a customer to get hacked on a vulnerability I didn't find."
More
here.
Insecure Branch Servers Suspect in Hannaford Breach
Robert Vamosi writes on the C|Net "D3F3NS3 1N D3PTH" Blog:
Details remain sketchy regarding Monday's announcement of 4.2 million credit card and debit cards exposed at a Maine-based supermarket chain. However, public comments made by Ronald Hodge, CEO of Hannaford Supermarkets, suggest that even with recent improvements in payment card transaction security, there may be holes.
The standards organization, PCI Security Standards International, was founded by American Express, Discover Financial Services, JCB, MasterCard Worldwide, and Visa International. In October 2007, they implemented the PCI Data Security Standard (PCI DSS), which includes, among other things, network specifications. Dr. Neal Krawetz of Hacker Factor Solutions said that PCI DSS allows for the storage of card numbers and expiration dates on a branch server. And that's what may be been compromised in this case.
More
here.
PCI Compliance and Terrorism
Via The PCI Compliance Blog.
We have read complaints on other blogs about the PCI standards, claiming they are a burden for merchants and software developers. But when considering the documented link between credit card fraud—which PCI DSS was developed to fight against—and terrorism, perhaps complaints about security standards will fall silent.
Kimberly Kiefer Peretti, Senior Counsel in the Computer Crime and Intellectual Property Secti on of the U.S. Department of Justice, recently wrote an excellent white paper, “Data Breaches: What the Underground World of ‘Carding’ Reveals” [.pdf] . In this paper, she gives a concise overview of large scale data breaches by skilled hackers—who is doing it and how, as well as the implications of these breaches.
One of Peretti’s most salient points comes in her discussion of how carding—activities surrounding the theft and fraudulent use of credit and debit card account numbers—is linked to other criminal behavior, including terrorism and drug trafficking.
More
here.
The Tangled Web of PCI Compliance
Richard Adhikari writes on internetnews.com:
Fear and loathing will dominate when Best Practice 6.6 of the PCI Data Security Standard becomes a requirement June 30.
The regulation requires that merchants dealing with debit and credit cards tighten up their security by both conducting application code reviews and installing Web application firewalls.
It was put forth by the PCI Security Standards Council, which issues, maintains and enforces the PCI security standards that govern payment account data security to which all corporations that deal with payment cards must adhere.
However, while stating that "proper implementation of both options would provide the best multi-layered defense", the Council says, in essence, that some merchants won't be able to implement both. The solution: select the best option for their needs. This is leading to compliance problems.
More
here.
PCI’s Grading System Is Failing
David Taylor writes on StorefrontBacktalk:
For months, retailers and Congress have been attacking retail security standards, but few realize that the problem is not in the standard itself. The problem is a grading system that causes most retailers to be out of compliance most of the time because the rules require 100 percent compliance. How often in school did you score 100 percent?
The system is oriented to forcing retailers to fail and it does this by being utterly insensitive to risk, which is surprising because the financial services industry runs on risk management. So if big finance runs on risk management, why are retail payment security rules running away from it?
At the recent Electronic Transactions Association (ETA) conference, Visa and MasterCard executives again defended the standard against industry and government criticisms that the standard is insufficient to prevent breaches. They cited instances where merchants (e.g., Hannaford) and processors (e.g., Heartland) who claimed to be PCI compliant were actually not compliant during the extended period of time during which the breach occurred. That happened because, from a technical perspective, “companies can fall in and out of compliance,” and because sometimes “the PCI assessment is not comprehensive enough,” according to the executives. From these statements, it sounds like the blame for why a “compliant” company can get breached is due to either technology or the assessors. But I maintain that the culprit in all of this is the grading system used to measure PCI compliance, and it’s time for a change.
More
here.
Hackers Test Limits of Credit Card Security Standards
Brian Krebs writes on Security Fix:
The number, scale and sophistication of data breaches fueled by hackers last year is rekindling the debate over the efficacy of the credit card industry's security standards for safeguarding customer data.
All merchants that handle credit and debit card data are required to show that they have met the payment card industry data security standards (PCI DSS), a set of technical and operational requirements designed to safeguard cardholder information from theft or unauthorized access.
Yet, some of the most notable data breach incidents last year targeted companies that had recently been certified as compliant with those standards, raising the question of whether the standards go far enough, or if entities that experienced a breach are falling out of compliance with the practices that led to their certification.
In a recent hearing on PCI standards at a House Homeland Security Committee panel, experts from the retail sector charged that the entire PCI scheme is only a tool to shift risk off the banks and credit card companies' balance sheets.
More
here.
Retail Group Takes a Swipe at PCI
Jaikumar Vijayan writes on ComputerWorld:
Simmering discontent within the retail industry over the payment card industry (PCI) data security standards erupted into the open this week with the National Retail Federation (NRF) asking credit card companies to stop forcing retailers to store payment card data.
In a tersely worded letter to the PCI Security Standards Council, which oversees implementation of the standard, NRF CIO David Hogan asked credit card companies to stop making retailers "jump through hoops to create an impenetrable fortress" to protect card data. Instead, "retailers want to eliminate the incentive for hackers to break into their systems in the first place."
More
here.
Visa Relaxes Retail Credit Card Security Threats
A Ziff Davis Internet article by Evan Schuman, via eWeek, reports that:
For more than a year, Visa has ominously warned large retailers that it would enforce a strict Sept. 30 deadline for many of the nation's largest retailers to either be certified that they comply with industry credit card security requirements or face fines and expulsion from discounted credit card fee programs.
But as the deadline has gotten closer—and the percentage of retailers certified as compliant is still quite low—Visa has been forced to back off, albeit slightly.
In an attempt to boost the number of Level 1 retailers certified compliant with the PCI DSS (Payment Card Industry Data Security Standard, often referred to simply as PCI), Visa in December unveiled a series of incentives to convince retailers into cooperating, given the lack of success that the threat of fines was having.
A big part of those incentives was offering compliant retailers sharply discounted credit card transaction fees in a program called the Visa PCI CAP (Compliance Acceleration Program).
This month, Visa has been quietly floating memos that will soften the pain for non-compliant retailers, as it's become clear that non-compliants will have strength in numbers come early October.
More
here.
Does The PCI Security Council Understand Security?
Ed Adams writes on StorefrontBacktalk:
The PCI Security Standards Council is made up of seemingly smart folks from the credit card brands and security industry. Unfortunately, this group of misfits is saddled with a myriad of competitive conflicts of interest and, worst of all, a complete misunderstanding of how to best protect card data and consumer identity.
The PCI DSS does an adequate job of defining audit procedures around policy, network segmentation, access controls, and perimeter defenses such as firewalls. It is woefully inadequate, however, in addressing the biggest risk to cardholder data: the application layer. Sure, there are some new requirements that are slated to take effect in June for web-facing applications, but those new requirements were rushed into the standard and obviously not well thought out.
More
here.
TJX Intruder Moved 80-GBytes Of Data And No One Noticed
Evan Schuman writes on StorefrontBacktalk:
Citing new information about the TJX data breach, attorneys suing the clothing retail chain amended their complaints on Thursday and wants a jury to evaluate TJX's security professionalism.
New details that emerged from documents filed in federal court Thursday include:
A TJX consultant found that not only was TJX not PCI-compliant, but that it had failed to comply with nine of the 12 applicable PCI requirements. Many were "high-level deficiencies," the consultant said.
"After locating the stored data on the TJX servers, the intruder used the TJX high-speed connection in Massachusetts to transfer this data to another site on the Internet" in California. More than "80 GBytes of stored data improperly retained by TJX was transferred in this manner. TJX did not detect this transfer."
In May 2006, a traffic capture/sniffer program was installed on the TJX network by the cyber thieves, where it remained undetected for seven months, "capturing sensitive cardholder data as it was transmitted in the clear by TJX."
More
here.
Most Companies Are Far Too Optimistic Regarding Security
Angela Gunn writes on BetaNews:
The Enterprise Strategy Group, which conducted the Database Security Controls study in conjunction with Application Security Inc., spoke in October to 179 IT decision-makers working in enterprise-class organizations (meaning those with 1,000 employees or more). The 27-item questionnaire inquired about security budgets, breaches, controls and audits.
It's not pretty. Tom Bain, director of marketing and communication for Application Security, notes that 84% of the companies surveyed said that all or most of their confidential data is protected...and 56% percent said they'd suffered at least one breach in the previous 12 months. Another 5% said they weren't sure or didn't know.
The picture's even more gruesome when you ask about failure to comply with standards such as PCI-DSS and Sarbanes-Oxley. Some 38% of the companies queries said they'd failed at least one audit in the previous twelve months, with 11% more unsure or not talking. 18% of those queried had failed a PCI audit; 11% missed SOX compliance; 16% fell down on HIPAA, GLBA or FISMA, and 21% managed to biff general security/IT internal checks.
"These companies aren't even taking non-optional measures seriously," said Bain, "let alone protecting sensitive data."
More
here.
Data Theft, Breaches: Where Do You Place the Blame?
Brian Fonseca writes on NewsFactor Network:
Gartner analyst Avivah Litan said that banks are not yet taking adequate measures to comply with the Payment Card Industry (PCI) standards. "There has not been a lot of enforcement at the bank level," she said. "All the enforcement scheduled has been on the processing and retailer side, so it has been unfair, frankly."
A panel of financial services and retail executives disagreed on which side bears the brunt of the burden to ensure compliance with the Payment Card Industry (PCI) Data Security Standard.
Executives from JPMorgan Chase & Co. and First Horizon National Corp. told an audience at Symantec Corp.'s Vision user conference here that high-profile data breaches at retailers like The TJX Companies Inc. are not originating from their side of the fence -- yet they must spend significant sums to make sure such incidents don't happen.
More
here.
More Heartland Details Leak Out (And Some May Be Trying To Leak Back In)
Evan Schuman writes on StorefrontBacktalk:
Details surrounding the Heartland data breach continue to dribble out, with one respected payment systems newsletter reporting that the forensic investigators Heartland brought in were Cybertrust and Neohapsis.
Heartland had tried keeping those names confidential, an effort that was succeeding prior to the Wednesday, Feb. 4 issue of The Nilson Report. That newsletter also quoted from a MasterCard alert, which provided new details about what was taken and when.
“According to a MasterCard alert, this sniffer program stole card numbers and expiration dates from credit and debit cards processed by Heartland from May 14, 2008, through Aug. 19, 2008, as the information entered Heartland’s payment switch,” the Nilson story said. “Only an estimated 5 percent of the stolen card numbers also included names. The malware was likely deactivated when Heartland conducted regular system upgrades as part of its PCI Data Security Standards (PCI DSS) compliance program, although it’s possible that the hackers shut it down to try and avoid being traced.”
In other Heartland news, it seems that officials there may be preparing to backtrack on some of the details they previously disclosed. Since Friday (Jan. 30), Heartland has been promising a written statement to clarify—and apparently back off from—some of the details they revealed in interviews. As of Wednesday (Feb. 4) night, no such statement had materialized, nor were Heartland officials willing to discuss what would be in the statement.
More
here.