Wednesday, April 22, 2015

The Key that Unlocks Esperanto

   

The Key that Unlocks Esperanto

Posted by on in Smart Encryption
     
As any student or traveler can attest, learning a new language is hard. How about making one up?
Esperanto will take over Lille, France this summer. Esperanto will be the backbone of discussions, debates and entertainment at this event in the north of France, a place quite prideful of its own language. The linguistic oddity that is Esperanto was one person’s vision in the 1880s of a unifying, global language. It has survived world wars, mistrust and the era of “OMG”. Unlike the languages bubbling out of “Star Wars” or “Lord of the Rings”, it’s not propelled by an entertainment component. Esperanto is also spoken by a relatively small number of folks.
b2ap3_thumbnail_Flag_of_Esperanto.svg.png
Can encryption key management learn something from the seldom spoken language of Esperanto? (Esperanto flag image courtesy of Wikipedia.)
I was drawn to reading up on Esperanto from my unabashedly nerdy love of code and programming languages. (The broad appeal of code has teachers pushing for students to “speak” in terms of hardware and software as a language education imperative.) In an industry plagued by made up norms and half-baked standardization, the security side of coding and programming shouldn’t lose sight of its intentions in creating a computerized parallel to Esperanto.
In encryption key management, a “language” I feel fairly fluent in, I fear that for many users we’ve replaced flow and communicative elements with a whole bunch of ways to swear and confuse. There is an inherent problem with mass, single instances in the security field when it comes to encryption keys. To get around that, we create multiple, obscured copies of keys to encrypt and decrypt information that needs to be secured. That is starting to add up to a lot of keys for some businesses – and a lot of stress. In looking at how businesses in the U.K. were handling the avalanche of keys, Techworld wrote: “once the bedrock of security, keys and certificates now elicit anxiety. This is perhaps not surprising given the growing number of attacks in which they have been compromised or undermined in a more general way by vulnerabilities such as last year’s Heartbleed. The average U.K. organization in the survey tended 25,500 keys and certificates, with 4 percent of IT staff saying they had no idea where all of this was kept.”
When a key becomes easy to use, it sometimes becomes too easy, opening up security gaps like those exposed recently with one RSA key. When it’s too hard you get things like a product we recently saw advertised that touted so many keys that it comes with a feature for a key manager manager. Or, more likely, end users and knowledge workers avoiding encryption whenever possible, including when it’s necessary.
As much as people fret and flaunt the encryption side of security, it’s the keys which make that function intelligent. Tilt the equation in either direction and you’ll nullify the reason your company is using encryption in the first place. Right now, we’re coming across a lot of businesses big and medium-sized going the route of the Key Management Interoperability Protocol, or KMIP. It’s not a perfect communications standard, but it at least allows for secured options within encryption practices. Languages that thrive tend to create new ways to share without removing the backbone of communication. How many slang terms do we use in mainstream discussions?
While subtle, our key management dialect could benefit from strengthening what works and easing on the standardization of faulty or abused methods. And you know what they say: you can’t encrypt in Esperanto. At least I think that’s what they say. My Esperanto is rusty.
Last modified on

Compliance officer awarded $1.5 million under SEC whistleblower program

Compliance officer awarded $1.5 million under SEC whistleblower program

The Securities and Exchange Commission announced an award Wednesday of about $1.5 million to a compliance professional who provided information for an enforcement action against the whistleblower’s company.
The award went to a compliance officer "who had a reasonable basis to believe that disclosure to the SEC was necessary to prevent imminent misconduct from causing substantial financial harm to the company or investors," the SEC said.
The whistleblower will receive between $1.4 million and $1.6 million, the agency said.
Wednesday's award is the second the SEC has made to an employee with internal audit or compliance responsibilities.
In September last year, the SEC awarded about $300,000 to a company audit and compliance employee who complained to the SEC after the company didn't act on the same information.
After that award, Sean McKessy, chief of the SEC’s whistleblower office, said employees who perform internal audit, compliance, and legal functions can be eligible for an SEC whistleblower award "if their companies fail to take appropriate, timely action on information they first reported internally.”
Whistleblower awards can range from 10 percent to 30 percent of the money collected in a successful enforcement action with penalties of more than a $1 million.
By law, the SEC has to protect the confidentiality of whistleblowers and can't disclose information that might directly or indirectly reveal their identities.
Since the launch of its whistleblower award program in 2011, the SEC has paid more than $50 million to 16 whistleblowers who provided "unique and useful information that contributed to a successful enforcement action."
Andrew Ceresney, chief of the SEC’s enforcement division, said in a statement Wednesday: “This compliance officer reported misconduct after responsible management at the entity became aware of potentially impending harm to investors and failed to take steps to prevent it.”
*     *     *
The SEC's redacted Order Determining Whistleblower Award Claim (Securities Exchange Act of 1934 Release No. 74781 and Whistleblower Award Proceeding File No. 2015-2) dated April 22, 2015 is here (pdf).
________
Richard L. Cassin is the publisher and editor of the FCPA Blog. He can be contacted here.
- See more at: http://www.fcpablog.com/blog/2015/4/22/compliance-officer-awarded-15-million-under-sec-whistleblowe.html#sthash.dMXHchRM.dpuf

Tuesday, April 21, 2015

PCI DSS Version 3.1 - What's New?


PCI DSS Version 3.1 - What's New?

Troy Leach of PCI Council Explains New Version of Standard

By , April 17, 2015.
  
Troy Leach, PCI Security Standards Council
Troy Leach, PCI Security Standards Council

Listen Now

00:00
00:00
00:11
The PCI Security Standards Council has just published a new version of the Payment Card Industry Data Security Standard that calls for ending the use of the outdated Secure Sockets Layer encryption protocol that can put payment data at risk. What must security leaders know about PCI 3.1 and its supporting guidance? Troy Leach of the PCI Council offers insights.

The reality about PCI version 3.1? It primarily boils down to removing one cryptography example three times from the published standard. But that small step indeed signals a giant leap forward in payment card security.

The new guidance removes the Secure Socket Layer encryption protocol, and early versions of Transport Layer Security, as examples of strong cryptography, and calls for use of a current, secure version of TLS.
It's unusual for the PCI Council to issue a mid-year update, but this one is critical, Leach says.
"We recognize that since the last time we published our standard in November of 2013, NIST and other subject matter experts have come out and said that the [SSL] protocol itself has been deprecated," Leach says. "So, we recognized that there was a need to move away from that example."
The PCI Council is giving covered entities until June of 2016 to complete the migration, and Leach encourages these organizations to start their risk assessment process now.
"We're asking the community to have the due diligence to do proper risk management of the situation, make an assessment of whether they are at risk, and then make their strategy progressive, so that they identify the top risks first, eliminate those, and then move forward," Leach says.
In an exclusive interview about PCI DSS 3.1, Leach discusses:


Leach also will be discussing PCI DSS version 3.1 at RSA Conference 2015 in San Francisco.
In his role as CTO and lead security standards architect for the PCI Council, Leach has developed and implemented a comprehensive quality assurance program. Before joining the council, he led the incident response program at American Express, where he reviewed more than 300 cases of account data compromises. Over the past 18 years, he has held positions in systems administration, network engineering, IT management, security assessment and forensic analytics.
Follow Tom Field on Twitter: @SecurityEditor

Monday, April 20, 2015

Target, MasterCard Settle Over Breach

Target, MasterCard Settle Over Breach

Retailer Offers Issuers a Total of Up to $19 Million

By , April 16, 2015.                                                               
Target, MasterCard Settle Over Breach          
 

Target has agreed to pay a total of up to $19 million to issuers of MasterCard payment cards over losses and expenses they incurred as a result of the retailer's massive 2013 breach.
See Also: Breaking Down Ease-of-Use Barriers to Log Data Analysis for Security
The settlement announced April 15 is contingent on issuers of at least 90 percent of the eligible MasterCard accounts accepting their offers by May 20. If sufficient issuers accept the offer, Target says they'll be paid by the end of June.
   
"This settlement provides our issuers a reasonable resolution of the Target data breach event," says Eileen Simon, MasterCard chief franchise integrity officer. "The timely reimbursement of costs and losses under the agreement delivers MasterCard issuers a faster and more certain resolution to the event, while reinforcing our commitment to maintain the integrity of industry security standards."
MasterCard, in a statement, says issuers that choose not to accept this offer will have their claims determined by MasterCard internal processes and may receive more or less than the amounts offered in this settlement, depending on various factors. Those include MasterCard's final determinations of their claims and the outcome of any litigation that Target might file to challenge claim awards to issuers outside of this settlement.
Target also is in negotiations with Visa for a breach-related settlement. "Visa takes very seriously our responsibility to work closely with its acquiring clients and Target to resolve this event," Visa spokesman Jake Standish says. "Visa continues to analyze all relevant information to ensure we reach a resolution that is accurate and fair to all Visa clients and participants in the payments system and we are committed to addressing and resolving this case expeditiously."

Reaction to Settlement

William Murray, an information security and technology consultant, says everyone benefits from the MasterCard settlement, even consumers. "The cost to Target is much less than that of extended litigation," he says, adding that the length for the two sides to reach a settlement seems reasonable. "I am pleasantly surprised at how quickly it has been done," he says. "Just clarifying the issues is time consuming. Arriving at an agreement in this time demonstrates good will on the part of all parties."
But Jim Nussle, chief executive of the Credit Union National Association, contends the settlement took too long. "It is about time that Target steps up to its responsibilities in this breach," Nussle says. "And it is long overdue for merchants to start living up to their responsibilities in protecting customers' sensitive information by adopting higher security standards."
Dan Berger, chief executive of the National Association of Federal Credit Unions, says the size of the MasterCard settlement was disappointing. "While we appreciate that the settlement attempts to hold Target somewhat accountable, we were hoping it would be more than just pennies on the dollar," Berger says. "We believe that this demonstrates the reason why Congress must act to protect consumers' financial information by enacting stronger standards and holding retailers and merchants directly accountable for their data breaches."
As Target and MasterCard announced their settlement, the House Energy and Commerce Committee passed a data breach notification and security bill that calls on companies to take "reasonable security measures and practices" to secure the personally identifiable information of customers (see National Data Breach Notification Bill Advances).
Target says the 2013 breach compromised at least 40 million payment cards and might have caused the pilfering of personal information from as many as 110 million people. The retailer has reported that its breach costs have totaled at least $252 million so far, with $90 million covered by insurance.
The retailer last month announced a pending $10 million settlement of a consumer lawsuit. Target and MasterCard did not immediately respond to requests for further comment.
Follow Eric Chabrow on Twitter: @GovInfoSecurity

Sunday, April 19, 2015

CMS Administrator: ‘We Need to Adjust and Make Things Easier’


CMS Administrator: ‘We Need to Adjust and Make Things Easier’

APR 17, 2015
      
We’ve only scratched the service on using technology to improve care, access and quality, the acting administrator of the Centers for Medicare and Medicaid Services said Thursday at HIMSS15, and to continue along that path three main actions need to be accomplished.
Speaking in Chicago at the annual conference, Andy Slavitt also called for names of organizations setting up barriers to interoperability. He said care providers and patients should feel all of the investments made in technology, what he called a care dividend. “The taxpayer has invested billions…We have stages and rules and measures,” he said. “What matters is can technology produce more time and capacity for care providers to improve care to patients.”
Also See: Data Blocking Hampers Interoperability, ONC Says
“We have a great need for modern infrastructure with healthcare,” Slavitt added as the second action point. “For health care to be truly as great as we deserve, it needs far better infrastructure in critical places.”
He said the healthcare system needs to adapt and learn using technology. “We can do with a little less innovation in shareables and wearables,” he said to applause, “and more focus on opportunities to improve healthcare infrastructure.”
The final point, Slavitt told attendees, is one of the greatest concerns—interoperability. He recalled a visit earlier this week to a qualified healthcare center with some of the greatest electronic medical records and quality control in the country. Yet, physicians couldn’t follow patients who left to go to a specialist. It is “not acceptable for taxpayers, it is not acceptable to us,” he said. “I’m asking a great deal more of [the] innovation system. It’s time to get down to business and advance the gains of the last five years.” In return, Slavitt said the government will get better at listening and adapting and being a “more solution oriented partner.”
“As you implement, we need to adjust and make things easier for you,” he added, and pledged for CMS to be clearer in its goals and expectations so “you know where to invest based on how we will reimburse.”
Naming Names
Slavitt said CMS wants to know of every example, small and large, when someone willfully or in some way sets up barriers to interoperability. “We want to know about them,” he said. “I’d like to know about them and I’d like to have conversations with people participating in that and understand what is going on.”
It is not so much a matter of technology as it is a matter of commitment, he added. “I want to make sure we are happy as a team and it is a public service to hear about the issues and confront them.”
Slavitt concluded that the industry is moving to a level where as you walk the halls of a clinic people are feeling improvements being made and he looked to the HIMSS audience to help. “It is going to be this group of folks and companies you represent and how well you work together,” he said. “We have momentum, but I fear if we don’t get urgent about it, it won’t happen quickly enough

Local merchants not ready for more secure ‘chip and PIN’ cards    

           


Massive data breaches at retailers like Home Depot and Target are finally pushing credit card issuers to adopt the technology known as “chip and PIN” which is much more secure than the magnetic swipe strips used in the United States.
The technology, which uses an embedded computer chip and a personal identification number, has been successful in Canada, Australia, Europe, and elsewhere. In the United States, a new industry standard is pushing widespread use of chip-based cards by October. Banks and merchants that fail to adopt the technology by then will become liable for the costs of fraud that result from data breaches, rather than issuers such as Visa and Mastercard.

Knowing this was on the horizon, I was curious to find out if Greater Boston was ready for this transition. To make this determination, I simply tried to make purchases with the chip portion of my credit card at every store I visited — and kept a chart of my experiences. At more than a dozen brand-name chains and local mom-and-pop merchants, I inserted the chip portion of the card into the terminal to see if it would process my payment.
In the majority of cases, the clerk behind the counter had no clue what I was doing. Once I saw that the chip wouldn’t allow me to buy my items, which happened with every transaction, except one in a Lexington sandwich shop , I asked the clerks if I could pay with the chip. They almost always looked annoyed and instructed me to swipe; I think they thought I had gone mad.
At a Watertown grocery store, the clerk told me, firmly, three times to use the swipe. At my local post office, they asked questions and were intrigued by how I was trying to pay.
At a RadioShack in Waltham, the clerk confidently told me “Yeah, I know what NFC is,” even though the chip-and-PIN technology has nothing to do with near field communications, which allows you to wave your card or smartphone to pay. A woman behind the counter at a local shoe store said, “We get lots of European customers who try to use their credit cards that way.”
Then there was the time I thought I could use my new chip card abroad. I was standing in the international terminal at Logan Airport waiting for my flight to London to board; it dawned on me that my new chip-enabled card had arrived without a PIN.
While that wouldn’t pose a problem in the US, in the United Kingdom, cards with chips are always used with a PIN. I called my bank’s toll-free number to get my PIN. I was told that I had already received the number in the mail — nearly 20 years earlier when I first got the card. That slip of paper had obviously long since disappeared.
My findings were that the Boston area is representative of the rest of the country. Hardly anyone is ready for chip-and-PIN. Merchants certainly aren’t, even though roughly 600 million chip-based cards will be sent to American customers by the end of this year according to the Smart Card Alliance, a group of financial, technology, and other companies promoting the adoption of chip technology.
Store clerks are not trained to accept them, and point-of-sale terminals don’t have the right software. I would guess that most people reading this haven’t received the most basic instruction on how to use them, even if they have already received the new card in the mail.
Smaller countries, with fewer banks and credit card issuers, have taken four years or more to make the transition from magnetic strips, so I believe it will be years before we are all paying with the chip portion of our cards. If you’ve received a chip-and-PIN card, don’t count on using it effortlessly anytime soon. Once we do make the leap, we should see some big changes — hopefully in the form of lower rates of credit card fraud and smaller effects from data breaches.

Joram Borenstein is a vice president at NICE Actimize, a company based in Boston that makes financial crime and fraud prevention software.

Thursday, April 16, 2015

EMEA: KPN pushes Blackphones for security, encryption 0

EMEA: KPN pushes Blackphones for security, encryption 0
KPN’s CIO Jaya Baloo wants everyone to “live long, laugh a lot and encrypt everything.”
Speaking at the International NCSC One Conference in The Hague, Baloo said encryption was essential for protecting the freedom of expression.
Baloo also praised the Blackphone, a secure smartphone designed by Silent Circle that can encrypt voice calls. On April 15, KPN became the first operator in the world to sell the Blackphone in its stores.
In the U.S., both the FBI and the National Security Agency have criticized efforts by companies such as Google and Apple to encrypt information on phones, saying it would hinder efforts to catch criminals and terrorists. At the conference, Baloo railed against such efforts.
“Democracy and civil rights should protect you with real standards,” she said. “Police and prosecutors should be able to substantiate why they want to eavesdrop on someone. If they cannot, they should not have that ability.”
The Dutch telco’s strong focus on privacy comes from hard experience, according to VentureBeat. In 2012, a hack forced KPN to shut down e-mail service to 2 million users.
Baloo, a security expert, was brought on board shortly after that shut-down to help shore up security. The partnership with Silent Circle started with an effort to improve security inside the company, and when the Blackphone was developed it seemed like a natural extension to offer it to KPN customers.
More telecom news from Europe, the Middle East and Africa:
• Nokia offers $16.5 billion for Alcatel Lucent in merger deal.  The Finnish ICT company Nokia announced on April 15 that it has entered into a memorandum of understanding with France’s Alcatel-Lucent. Under the terms of the deal, Nokia will make an offer for all the equity securities issued by Alcatel-Lucent for a total value of $16.5 billion. On the same day, Nokia also announced that it would be initiating a “review of strategic options” for Here, its mapping and navigation unit. Options include possible divestment.
• Telekom Slovenije stake sale receives only one bid. On April 13, Slovenia’s asset manager reported it had received only one binding offer for the telecom’s assets, without naming the bidder or the amount. However, sources told Bloomberg that the private equity firm Cinven had placed the bid. Telekom Slovenije is estimated to have a market value of $824 million.
• MTN Group plans to buy Nigeria’s Visafone – report. Sources told Reuters that MTN Group is working on a deal to buy Visafone Communications in Nigeria, which is home to the largest mobile market in Africa. MTN is already the leading operator in Nigeria with a 44% market share, according to the Nigerian Communications Commission. The country’s rapid mobile growth is outpacing network investment, and recently Nigeria’s consumer protection agency threatened operators delivering poor services with criminal prosecution.
Want to know more? Check out our EMEA coverage, and follow me on Twitter!