Friday, February 27, 2009

PCI QSA Training - Assess, Remediate, Reassess ?

I was speaking with a friend and colleague today about his experience with the most recent PCI training and what I found out was, well, interesting to say the least.

On the topic of independence and thoroughness, the SSC is apparently suggesting that it is acceptable to have an individual QSA:

  • Perform the assessment.

  • Remediate the issues in the environment.

  • Re-assess the environment in subsequent years.


In my opinion, you may as well have the merchant or service provider simply self-assess at this point, because the QSA's objectivity is all but gone.

Anyone who has ever gone through QSA training and has spent any time doing work in the infosec space will tell you that the training materials are fairly simple, and the test is a walk in the park.

In fact most QSAs will tell you that they haven't learned anything substantially new by virtue of becoming a QSA. For the most part, the certification only enables them be the examiner of record on paper.

In other words, no special knowledge required, zero objectivity, and lots of multi-year managed service contracts between QSAs and merchants.

Its not hard to see why things like Heartland and RBS are happening. The ROC has become less honest than the tax return.

Monday, February 23, 2009

Tsunami #2 - The New Mystery Cardholder Data Breach

Visa and Mastercard are currently holding conferences with a number of large issuing banks, discussing what appears to be a another Heartland-like breach of another major payment processor. They have not announced who got hacked as of yet, but if I were a betting man, I would put my money one of the TSYS acquirees (ie Vital) or TSYS itself.

Any other bets?

Thursday, January 22, 2009

Dissecting the Heartland Compromise

You know, alot of people have been discussing the fact that what appears to be the biggest credit card compromise to date was reported to the public on inauguration day, and how this is an attempt to bury the news in all the other hype.

What is more interesting however, are the sketchy details that we have about what actually happened.

The supposed facts according to Heartland (per Brian Kreb's article)

  • Heartland does "not know" how long the breach has been taking place.

  • The company processes 100 Million transactions per month.

  • Malware was involved.

  • Data was being sniffed.

  • The company is claiming that full track data was not compromised.


There have been alot of suggestions that this was an "inside job," but I am skeptical.  It is unlikely an employee of the organization wrote the perfect custom malware solution to rip the company off, and established a relationship with some overseas criminal mastermind to offload hundreds of millions of card numbers.

I think that more likely, someone at Heartland didn't set up host-based security properly in addition to the perimeter being soft, and the systems in question didn't get included as part of the PCI sample set, so noone caught it.

Furthermore, the data obviously wasn't being encrypted in transit - by Heartland's own admittance -it was grabbed off the wire.

In as far as the malware is concerned, File Integrity Monitoring (required by PCI) should have caught this. Also, the required IDS/IPS solution should have seen a bunch of weird stuff going out over the wire.


What will the overall 'lesson learned' from this breach be?

My prediction: Data Loss Prevention products are going to be required at ingress/egress points on the cardholder environment. Another prediction: This will be released as a clarification / addendum before the next dot release of the DSS (1.3).