Monday, December 3, 2007

Security tidbits from the past month...

Web applications and Microsoft Office are the current major pain-points:

http://www.washingtonpost.com/wp-dyn/content/article/2007/11/29/AR2007112900062.html?wpisrc=newsletter

"Developers aren't using secure coding techniques to create Web applications, giving hackers an opportunity to tap the rich databases of information connected to them, according to SANS, a computer training and security organization."


The TJX hack just keeps getting worse:

Update: TJX Victim Tally Rises to 94M
http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=306333&intsrc=news_ts_head
"In an affidavit, the bankers said that "TJX continues to downplay the seriousness of the situation."

Details emerge on TJX breach
http://www.boston.com/business/globe/articles/2007/10/25/details_emerge_on_tjx_breach/
"Spokespeople for Visa and MasterCard said they wouldn't comment on the matter, or on a Visa official's estimate of losses to banks that issued cards to be between $68 million to $83 million."

"Visa fined TJX's card processor $880,000 last summer, and said it would continue to fine the retailer's card processor $100,000/month, for TJX's role in the worst data breach in the payment industry's history, according to documents filed in federal court Oct. 26."

VISA Fined TJX Processor for Security Breach
http://www.eweek.com/article2/0,1895,2208927,00.asp
TJX IT staff knew about the vulnerabilities, but continued to ignore them because they wanted to save money...

TJX violated nine of 12 PCI controls at time of breach, court filings say
http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9044321&intsrc=hm_list
"these additional facts materially support the claim that TJX's
conduct generally" violated laws governing unfair trade practices,
they said.

Court filing: TJX was warned about lax security before massive breach
http://www.mercurynews.com/business/ci_7290184