Do the Payment Card Industry Data Standards Reduce Cybercrime?
The US House of Representatives Subcommittee on Emerging Threats, Cybersecurity and Science and Technology is holding a hearing today on the subject: "Do the Payment Card Industry Data Standards Reduce Cybercrime?". Witnesses include representatives from the US Department of Justice, the Payment Card Industry Data Security Standards Council, Visa Inc., Michaels Stores, and the National Retail Federation. A webcast is available.





PCI is a joke. It is just a method for shifting liability for the credit card companies. Security can not be voted on by committee and make it solid. One of the big problems is the credit card companies expect merchants and software manufacturers to pick up the tab - they make the big money, let them do it.
What needs to happen is a new credit paradigm needs to appear...ex pay pal.
The problem is that there is no 100% secure solution and there never will be. This is a lot like the drug war...you can not win, all we can do is mitigate breaches. To be truly proactive you need individuals monitored by experts and IT firms.
Having dealt directly with the creation and integration of credit card software systems...the easiest breech is social engineering. My use was not malicious, but I learned if I knew the right things to say to the credit card companies support/employees I would be told whatever I needed.
The fish stinks from the head down...
Posted by: Angelos | April 05, 2009 at 11:35 PM