Commentary - Channel Insider
Empowering the next generation Channel
 

Bull’s Eye Awards
Nominations Open for Channel Insider 2009 Bull’s Eye Awards
Nominations are now open for the Channel Insider 2009 Bull’s Eye Awards, which recognize excellence in customer service, technology prowess, business acumen, channel leadership, communications and community building, and innovation among vendors, solution providers, distributors and channel services companies.



Sponsored Links
  • Control VM Sprawl, What You Don’t Know Can Hurt You
  • FREE Sophos Encryption Tool: Encrypt, compress and share files easily
  • LSI 6Gb/s Portfolio Expands to Include SATA+SAS HBAs
  • Reduce the cost of managing your mobile workers.
  • Find out 7 Ways to Drive Data Center Efficiency
  • SonicWALL breaks through network and email gridlock
  • Save up to 40% on calling costs with Avaya Aura™



  •  

    CardSystems Solutions Becomes a Cautionary Tale

    in Commentary


    Article Rating:starstarstarstarstar / 0
    Article Views: 533

    Rate This Article:
    Add This Article To:
    Opinion: eWEEK.com's Larry Loeb writes that everyone has a purpose. But some people—and companies—exist mostly to provide a warning for others. That's the role CardSystems Solutions appears to have been destined for.

    Poor old CardSystems Solutions got thwacked in the head with a major trout this week by Visa and American Express.

    Both companies said that they would no longer do business with the ACH (automated clearing house). MasterCard has given CSS until the end of August to demonstrate compliance with MC's standards or face the same cutoff.

    It doesn't look good for CardSystems's long-term survival unless it can pull a rabbit out of the proverbial hat—and soon.

    You'd think that just because CSS screwed around with hundreds of thousands of credit-card accounts, that the credit-card industry would enforce the normal penalty of a wrist-slap and continue business as usual. Or at most, impose some token monetary penalty. Not this time. The industry pulled the plug.

    This sends message(s) to the entire ACH infrastructure. The first is "We're serious."

    Resource Library:
    Never before has an ACH been blackballed for security malfeasance. Never. This kind of action by the credit card companies is groundbreaking in its scope.

    The second message is "Wake up, you could be next."

    All of the ACH players have to be nervous right about now. The 12-step program mandated by the Payment Card Industry Data Security Standard, which was introduced late last year, is about to be enforced by the card companies.

    The standard means that "best practices" for IT, not just "acceptable practices" have to be used by anyone in the supply chain.

    That means an ACH has to spend money for IT upgrades and revisions, which will standardize the IT practices for all of the card-issuing companies. Some of the ACHs won't be ready to comply so fast. They've been dragging their feet on this, hoping it will go away. It won't.

    The Lesson

    In a way, CSS did everyone a favor. It showed how flawed our current financial IT infrastructure is in everyday practice.

    Microsoft plans to buy secure messaging company. Click here to read more.

    No one ever heard of CSS before the problems arose. You won't hear about many places that have even worse security policies in place until something goes wrong and they get caught with their firewalls down. The root problem of all of this is that our current financial system confuses identification with authorization. A social security number was always envisioned to be something that was for SS purposes only, not as something that served as an identification/authorization token.

    But Federal law has changed. USC 405 [C] and subsequent sections state that it's just fine for any state or government agency to require an individual to provide their SSN: "[...] for the purpose of establishing the identification of individuals affected by such law [...]." Pretty clear.

    Some businesses have come to rely on the SSN as a unique identifier for someone (and by inference a token for authorization), and this will have to stop if we are ever to have a secure financial infrastructure.

    After a series of high-profile data thefts, experts rethink network security. Click here to read more.

    This may be hard to do, but we will know that a real change has happened when this kind of screw-up happens in the future and nobody really cares because it won't adversely affect them.

    Larry Loeb was consulting editor for BYTE magazine and senior editor of WebWeek. He serves as a subject matter expert for the Department of Defense's Information Assurance Technology Analysis Center, and is on the American Dental Association's WG-1 and MD 156 electronic medical records working groups. Larry's latest book is "Hackproofing XML," published by Syngress (Rockland, Mass.). If you've got a tip for Larry, contact him at nospamloeb-pbc@yahoo.com.

    Check out eWEEK.com's for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzer's Weblog.



    Discuss CardSystems Solutions Becomes a Cautionary Tale
     
    >>> Be the FIRST to comment on this article!
     

     
     
    >>> More Commentary Articles          >>> More By Larry Loeb
     


     


    [ci] feeds
    XML
    Add Channel News, Product Reviews, Trends and Analysis to your RSS newsreader or My Yahoo!


    HTML PLAIN TEXT

    Keep on top of news for VARs and Resellers with CI's Weekly Newsletter and Alerts.

     


    CHANNEL RESOURCE CENTER
     
     
    Enterprise Mobility Zone
    The Enterprise Mobility Zone (EMZ) blog is a tool designed to help senior IT executives discuss, create and deploy next-generation mobile strategies in their organizations.
    Go beyond yesterday's tactical approach to mobility!
     
    Build A More Efficient Data Center
    Demands are growing but budgets are not. Solve your pressing IT issues using the resources you already have. Determine which technologies can help you drive efficiencies and how they are applied. Gain a quick ROI on new initiatives
    Find out how
    Let Enterprise TechBrief do the work for you. Aggregated content, tech news, product reviews, vendor updates, how-to’s—all you need to boost your efficiencies and cut costs, all from one place.
    enterprisetechbrief.com