Articles in the Interesting Category
Interesting, PCI News, Retailers, Vendors, application security, featured »
This one has some significant implications for software security and the role & responsibility of technology vendors. Here’s the link:
Radiant Systems and Computer World responsible for breach affecting restaurants – lawsuit
What’s most interesting to me in all of this is that fact that the restaurants seem to ‘get it’ - they understand the holistic impact of PCI on process, procedures, technology, etc. and, after being smacked around by the card brands for being the merchant where the breach occured, they have taken that holistic understanding and are working to hold …
Interesting, Vendors »
So everyone knows at this point that AT&T has acquired VeriSign’s global security consulting business. I’m not really sure why AT&T actually bought them although I’m sure that they have some sort of Grand Plan, much the same way that Verizon had when they acquired Cybertrust and all of the other companies that they bought over the years…
What seems to really happen is that these large firms that don’t have a focus on security see an opportunity and spend a bunch of money to acquire well-known brands and, far …
Interesting, PCI News, Retailers, headline »
PCI is just so damn interesting - it’s like a soap opera… Seriously - if you don’t have to deal with it everyday, I’m sure (as a retailer) that you count yourself lucky, but honestly it’s a hoot.
The game at hand is a combination of punishment and liability avoidance - the case of Hannaford is a good example. Just when you think it’s all over and Hannaford gets to pick up the pieces and move on, everything takes a new twist. Now the Maine Supreme Court is getting involved and …
Interesting »
Lawsuit: Heartland Knew Data Security Standard was ‘Insufficient’ | Office of Inadequate Security.
Interesting, PCI News, Vendors »
OK - I’ve got a couple of posts that I’ll be putting up shortly - one on some feedback from the PCI Community Meeting and one on that list of questions on PA-DSS. I’ll try to get them up this weekend (work has been crazy and I just haven’t found/committed the time to get these written), but here’s a link to a post this morning from Deke George on the NetSPI blog regarding acquisitions in the security space.
NetSPI Blog - Mergers & Acquisitions
Interesting »
This is a pretty funny list - although maybe more sad than funny due to the fact that it’s pretty dead-on…
Anton Chuvakin Blog - “Security Warrior”: Top PCI DSS Security Marketing Annoyances.
Interesting, application security, featured »
OK - so I’m not very ‘with-it’ apparently and didn’t really know what Squidoo was, but someone explained it to me and then convinced me to put up a PA-DSS compliance ‘lens’ on Squidoo. If you aren’t familiar with the site, it’s a collection of mini websites each of which provides some background, insight, education, whatever on specific topics as defined by the builder. In this case it’s some overview information on basic PA-DSS compliance and a centralized location for PA-DSS feeds and search results that keeps itself up-to-date without …
Conferences / Webinars, Interesting, featured »
This was actually the first time that I saw Bruce speak (which is odd since we live in the same metro area) and I must say that I’ve somewhat avoided him as I’m not a big fan of the whole celebrity-like, hyped-up thing (I still haven’t seen Forrest Gump and probably never will), but I thought this was a really good talk and I found myself pleasantly surprised.
Bruce Schneier: The Future of the Security Industry: IT is Rapidly Becoming a Commodity from David Bryan on Vimeo.
Conferences / Webinars, Interesting »
Thanks to David Bryan for getting these up! Here’s another video from the event - this one is the presentation on OpenSAMM - interesting and also very much geared towards development of security applications. I think this is a great approach, but I have to admit that the practicality is something that I wonder about…
Pravir Chandra: Software Assurance Maturity Model (OpenSAMM) from David Bryan on Vimeo.
Interesting »
ShackF00 » Your Hardest Infosec Problem: Getting People to Give a $@%&.


