Showing posts with label e-commerce. Show all posts
Showing posts with label e-commerce. Show all posts

Sunday, February 3, 2013

New PCI Guidelines for E-Commerce

New PCI Guidelines for E-Commerce

A new set of card data security guidelines for merchants and payments providers aims to address increasing risks unique to e-commerce environments. On Jan. 31, the Payment Card Industry Security Standards Council issued its PCI DSS E-commerce Guidelines Information Supplement, a set of guidelines for e-commerce security.

The guidelines relate to online infrastructures and how merchants work with third-party providers. Developed by the PCI E-commerce Security Special Interest Group, the 39-page resource includes recommendations about topics ranging from online risks associated with payments gateways to often-overlooked security gaps Web-hosting providers can inadvertently create.

Securing the Payments Chain
  • The guidance offers a checklist of security recommendations and reminders, such as:
  • Know where cardholder data is located within the merchant's infrastructures and those of the processors and vendors to which they outsource.
  • Regularly test software and applications to detect if card data or other information is being stored unintentionally.
  • Evaluate risks associated within e-commerce technology.
  • Review the network and database risks posed by outsourcing functions, such as payments processing and Web hosting to third parties.
  • Hire PCI-approved website scanning vendors to validate, on a regular basis, Internet-facing environments for compliance with the PCI Data Security Standard.
  • Define best practices for online payment application security.
  • Implement security training for internal staff.
  • Establish best practices for consumer awareness.
Evaluating Third Parties

The guidance reviews how merchants can work with third parties to address those risks and provides a checklist for easy-to-fix vulnerabilities related to: 
  • Online injection flaws;
  • Cross-site scripting, or XSS;
  • Online cross-site request forgery, or CSRF;
  • Buffer or temporary data storage overflows, which result when programs or processes attempt to store more data than they were designed to hold;
  • Weak authentication and/or session credentials; and
  • Application and software misconfigurations.

Saturday, October 6, 2012

It's your responsibility to protect your data on Facebook!

Marketers are Dying for Your Facebook Data

...and Facebook wants to help them get it. In fact, the social network giant -- now under pressure from stockholders to produce revenue -- has developed new functionality designed to help advertisers better find you on Facebook.

So long as you have voluntarily given your phone number or email address to a company, that company can now use it as a means for searching and locating you on Facebook.

Be sure to check and update your settings on Facebook (and other social sites), as new functionality is added frequently, threatening your assumption of privacy online. Speaking of Facebook, be sure you are aware of another change that could result in having your emails sent to Facebook.

In June, Facebook changed everyone's email address visibility settings to hide the email addresses we purposefully shared with friends, leaving just @facebook.com addresses.

For folks who did not change this back, and for folks using the new iPhones, running iOS 6, this could result in having the preferred email addresses being replaced by @facebook.com addresses...and having sensitive information saved to the Facebook systems (a far-from-secure system to keep email messages). 

See more about it here.

Friday, October 5, 2012

Facebook applications are not always safe!

Apps Dressing Up as Innocent Fun

Many people mistakenly believe that any application found on Facebook has been vetted by Facebook, and is therefore safe. False.

As this article on Facecrooks points out, anyone can create an app for publication on Facebook. Facebook users are also guilty of clicking through the permission screen, potentially missing key information on how the application's developers plan to access their Facebook information (for those that actually provide such information).

Take the time to read these screens thoroughly before clicking OK. If an app does not provide information about how they will use your information, then don't download; it's just not worth the potential problems, no matter how yummy fun the app sounds.

Wednesday, October 3, 2012

How much you care about your privacy?

Apps Come Back to Haunt You

Can you count your apps on one hand? Two? As smartphones have found their way into more pockets and purses, the tendency to become "app happy" has struck more than one consumer.

Often folks will download an app, input their personal information, allow it to track and store their locations, purchase behaviors -- heck, even account numbers -- and then forget all about it. Meanwhile, the application is running in the background gathering (and potentially sharing with third parties) the private and personal details of their lives.

Have you set an app to auto-broadcast your location to a social network? Here's hoping you remember that before you arrive at the amusement park on a "sick day." Does that pizza place auto-fill your credit card number when you order a pie online? That's one lucky thief who gets a hold of your smartphone. Make it a practice to review your apps often.

A good time to do this is now; delete the ones you are not using. A friend of mine was surprised to find she had accumulated over 200! Then, check again whenever you have an app ask you to download an update.

As those notices come in, don't just ask yourself if you'd like to update (which is an important step, as many apps improve their security and privacy standards with these updates); also ask yourself if that's truly an app you need to have on your smartphone, laptop or any other type of computing device you use.

Wednesday, April 7, 2010

6 Steps to Reduce Online Fraud

What Must Be Done to Protect Business Accounts

What can - and should - a banking institution do to help protect its business customers?

Current Fraud Trends

There are three variations of fraud that is commonly seen as particularly prevalent now:

First Party - where criminals open accounts and use them as pass-through accounts to move money. Additionally, there also may be legitimate business owners who are kiting -- they create additional float so they have additional line of credit. They're not meaning to defraud the bank, but creating float type of credit.

Internal - where employees sell information about a business' accounts to outside organizations. Another scenario is where the small business employee who is accessing the business accounts moves out money and then leaves town. One twist to detecting internal fraud is the possibility that employees who perform the transactions will muddy the trail by saying their account credentials were taken in a phishing email. They can almost use that as an excuse, and it can't be proven unless the business has internet web logs, So it is hard to prove if the employee was colluding with outsiders, or their account actually was phished.

Third party - where most of the warnings are coming in via phishing, social engineering or spear-phishing. There are even infected webpages that can compromise a user's PC. Criminals attack the business, compromise the online credentials and move money out of the accounts.

Areas to Improve Security

Many institutions impose transaction limits as a way to stop fraud. This is a "stop gap measure" and these additional steps should be followed:

Account Level Check - Look at the types of transactions that are happening -- what is typical behavior, logins, when they happen. Then if they start logging in at night or over weekend, that's a red flag to hold transactions until you can talk to the business owner, stopping fraud from taking place. The key is to use analytics to scope "out of the ordinary" transactions. Look across all of the customer's behavior to spot what is unusual for that account holder.

Create Unique Account User IDs - Make sure users all have different log-in identification. Do not let them use the same user name and password. There should be a unique user names for each person in order for the institution to be able to create unique profiles of use for each of the users. This is similar to the PCI requirements; for anyone who accesses data, they each need a separate log-in.

Dual Control - Have two unique users approve transactions. If you can implement that, it goes a long way in reducing the chances of criminals stealing from the SMB account with a single user logon, and it also stops the threat of internal fraud as well.

Multi-Factor Authentication - Even though this solution is susceptible to man-in-the-middle and man- in-the-browser attacks, it is still an effective layer of protection. A lot of times business owners will ask 'I have so many users on the account' how many tokens will I need?' You need a unique token for every user."

SMS Messaging - This out-of-band message to users and account owners is important. It can be bypassed if a criminal can get into and change numbers or email contacts. But an institution can get around that by contacting the old number or email when a change is requested to verify that it was the account holder -- not a criminal -- making that request. This is something that banks already do with address changes. You need to realize that criminals will go in and change email and phone number contact information, so it is a heads-up that something is taking place.

IP-Email Address Controls - Only allowing certain email address/IP locations to go to the bank's online website to do transactions is another good control to put in place. It can be overcome, but it is another good layer of control. What's the risk that someone has just changed their phone and email contact information and is coming in from another email IP location to make these transactions? If they're coming in from another IP address, by looking at the risk, the institution can stop and look at it and question the transaction.

Thursday, December 6, 2007

Can Consumers’ Infected Systems Harm you?

Buyer at your website can infect your system…

Who knows what evil lurks in the heart of computers? If you have an e-commerce server, your system could be in infected by malware from a consumer’s machine. Hackers can plant what’s called a bot on a machine that activates when the computer begins an SSL connection. Once the bot is in process, it is able to hijack the session or conduct a “man in the middle” attack, which would mean the hacker could execute remote code on the server.

The results can vary, from instigating denial-of-service attacks to stealing passwords. The solution is simple, however when you want to protect sensitive data such as employee records or bank account information, build a tiered architecture. That way, even if a hacker has access to a Web server, safeguards prevent it from communicating with the next machine in the hierarchy. You can solve most of those problems with perimeter controls.