Quantcast StorefrontBacktalk » Blog Archive » Editor’s Note: Very Sad News
advertisement
advertisement

Editor’s Note: Very Sad News

Written by Evan Schuman
October 28th, 2009
Like this story? Share it
To share this story with people in your social network, please click on the network icons below.

We’re heartbroken to have to report to our readers that our esteemed PCI Columnist, David Taylor, passed away on Tuesday from a sudden heart attack. A private memorial service is being held in New York and Dave’s family is asking for donations to the American Heart Association.


Dave spent much of his time running the PCI Knowledge Base, which he launched after a distinguished career as a Gartner analyst. I personally had the pleasure of working with Dave on many projects, panels and podcasts and found his keen observations and sense of humor to be most rare. He called his shots honestly but went out of his way to be kind. Dave’s column was an instant hit with subscribers, as it gave him a forum for his observations and for his wry take on life. We’ll miss him without limit and the industry has lost one of its brightest voices.


advertisement

21 Comments | Read Editor’s Note: Very Sad News

  1. Walt Conway Says:

    I, too, was shocked and deeply saddened to hear the news of Dave’s passing. I had the great privilege of working with Dave on the PCI Knowledge base. We did a couple of webinars together, and we spoke just the other week making plans for him to join me at a PCI workshop in the Spring. Dave had an irascible wit, and he never followed our plan/script during a webinar…doubtless to the great benefit of everyone who ever listened! Dave was knowledgeable, professional, and a keen nose for what was real and what wasn’t. Like many others, I learned much from Dave, and I shall miss him terribly.

  2. David Dorf Says:

    Sad news indeed. Dave was a nice guy and did much to help our industry. He will be missed.

  3. Rafael Rosado Says:

    I am shocked and saddened to hear this. May God accept David in His Kingdom!

    Dave had a true passion for PCI (and very vocal as well regarding his opinions). He started the PCI Security Interest Group in Dallas recently as he moved into the area and I was honored to have the opportunity to meet him personally.

    I even saw him recently at the PCI SSC Regional Meeting in Las Vegas and he seemed full of life and energy. Just another demonstration that our time in this life is short and we don’t know the time or moment that we will be summoned.

    Dave will definitely be missed in the industry.

  4. Richard Mader Says:

    David was a gentleman, and the PCI expert. Always willing to share his time and information. He played a key role in the development of the NRF-ARTS PCI best practices and spoke at several of our event.

    Shocked and saddened by this news, he will be sorely missed.

  5. Barb DeYoung Says:

    Dave will be missed for his realistic view of information security and his perspective on what was important. The time we spent talking PCI during a survey convinced me he was an important voice in the efforts to improve the standard. We had a great conversation, with plenty of the humour mentioned above. He will be missed.

  6. Mike Dahn Says:

    I never met Dave in person but we spoke on the phone many times over the years and I’m happy to have known him, even if through distance.

    I know his desire to make this world a better place will be missed. I am very sad to hear about this shocking news. He was a good man from what I knew of him and hope his family the best in this hard time.

    I think you can say his influence in the payment card industry can be seen by his numerous connections and the people who called him a friend.

  7. Della Lowe Says:

    When I heard about Dave’s death this morning I was really saddened. Dave was not only smart and passionate about his work but he was also generous with his time. There was never a time I called Dave for clarification or information on the PCI standard or the retail industry that he did not give fully of his attention and knowledge. He was an important voice and will be missed greatly both as a business colleague and a friend.

  8. Chris Rallo Says:

    I have had the pleasure of working with Dave on several PCI initiatives. He will be missed greatly.

  9. Kenneth Says:

    Worked with Dave Taylor at NRF last year and at Cisco PCI virtual Event. He will be missed.

    My condolences to the family.

  10. Wasim Ahmad Says:

    Very sad, our thoughts go out to his family. We really enjoyed reading David’s insightful analysis. We’ll miss his blog.

  11. PCI Security Standards Council Says:

    All of us at the PCI Security Standards Council are deeply saddened to hear of David’s passing. David was a vocal proponent of strengthening payment security and played an important role in increasing the market’s knowledge of PCI Standards and issues.

    While we did not always agree with his opinions, the constructive and thoughtful debate David fueled helped elevate awareness of the need for improved payment security. His presence in the payment ecosystem will be sorely missed.

    We wish to express our deepest condolences to David’s family, friends and colleagues.

    Bob, Troy, Ella – PCI SSC

  12. Robert Udowitz Says:

    David’s insights along with his quick wit made the PCI Knowledge Base so important to the industry. His contributions will be missed and never forgotten. My heart goes out to his family.

  13. Philip J. Philliou Says:

    What a loss – such sad news. May his memory be eternal.

    Phil Philliou

  14. Charles Crawford Says:

    My compliments, Evan, on your hear-felt tribute to Dr. Dave Taylor. Dave was a good friend of ours at EPX and the entire data security community and leaves a huge void.

    Dave, a long-time Gartner Group senior analyst earlier in his career, became one of the best known and most respected subject matter experts on cardholder data security and, of late, a specialist on emerging technologies such as credit card data tokenization and so-called “end to end” encryption. Dave was an unapologetic “academic researcher at heart.” His public expressions tended to always start with the words “…according to our research…” Yet, the scope of his intellect such that he always took his audience well above the minutiae and spoke clairvoyantly to the trends and meanings of complicated and conflicting information. We enjoyed his strong, pull-no-punches, gadfly opinions and amazed that he could take sides, yet somehow remain so steadfastly unbiased in his analyses.

    Dave’s pioneering resource site, http://www.pciknowledgebase.com, is his legacy to those who seriously concerned about consumer data security — whether vendors, professional PCI QSAs, CIOs, CSOs or academics. The site is a substantive touch-point for detailed knowledge of PCI – with its illustrious “Panel of Experts” and in depth research reports involving hundreds of thorough interviews conducted over months and years. For his memory, and the community the Knowledge Base served, let’s hope his family finds a way to continue what he started.

    Those who had the good fortune of getting to know Dave a bit on a personal level, found in him a warm and outgoing personality, boundless energy and good humor… a quick wit, and a nice thing to say about almost everyone he knew.

  15. Marcus M Shaw Says:

    I’m one of his High School Classmates. We still communicate among our graduating class of 1970 in Clarksville Indiana on a sight developed for us. His passing has been noted and I’m sure we will remember him fondly for his tenure with us during those times. He will be sorely missed. Thank you all for the kind words you have given him in your industry.

  16. Bill McNee Says:

    I had the honor and pleasure of working with Dave for many years at Gartner Group in the 1990s. He was key member and leader of the research team that helped build the business. I remember him most as a deep expert in eCommerce, business applications and an early pioneer in understanding the importance and value of the internet to businesses of all types and sizes. I am not surprised to read that he went on to be a pioneer in other areas, such as the PCI industry. He had a keen mind, and the ability to cut through the hype and provide great value for our customers.

    But what I most remember about Dave was his wry sense of humor. He built a tight team – and I could tell they all enjoyed working together, in an especially collegial way. He was a mentor to many, and will be sorely missed.

    Bill McNee
    Founder/CEO
    Saugatuck Technology
    and Gartner Alum (1988-2000)

  17. Tyler Hannan Says:

    Rest in Peace.

    -tyler

  18. Branden Williams Says:

    I’m going to miss the lively discussions that he hosted and participated in. The PCI world suffered a huge loss. My team & I want to convey our deep sorrow at this news.

  19. Steve Sommers Says:

    Very shocking and very sad. My thoughts and prayer’s are with him and his family.

  20. Richard Haag Says:

    I am saddened to hear of Dave’s passing. I remember some long discussions with him when he launched the PCI knowledge base. I was very impressed with his professionalism and straight forward approach and enjoyed watching the PCI knowledge base flourish. My condolences to the family, Dave will be missed.

  21. Jennifer Fischer Says:

    I just heard of Dave Taylor’s passing and am very saddened by the news. I’ve known Dave for many years and recently saw him at the PCI SSC’s community meeting in Vegas. He was a tireless advocate for data security, and I always found our discussions incredibly insightful, energetic and constructive. Dave added a great deal to the dialogue, and he will be missed. Sincere condolences to his family, friends and colleagues.

Leave a Reply

Newsletter

Quickly catch-up on the latest in E-Commerce and Retail Tech with our free weekly newsletter, with urgent bulletins as news merits.
advertisement

Most Recent Comments

What’s The Rush For New PCI Call Center Requirements?

And I have not heard anyone mention the impact on companies who provide quality improvement services. Many merchants hire quality improvement companies to review their audio recordings to provide guidance on how to improve their sales staff’s effectiveness in customer service and sales retention. PCI Council needs to rethink this requirement until there is a widely available commercially viable solution. Read more...
Another ridiculous decision where regulators don't think critically enough about the unintended consequences of their decision. This will be a huge problem for the credit and collections industry. We have to keep all recorded calls for other reasons not related to cc information. We can't purge all of our calls and we don't have the technology to not record part of the conversation. Even if we did, I am not sure we could afford it. Read more...
This "clarification" is causing a lot of panic with large FS clients who now appear to be non-compliant after spending 7 figure sums on their compliance programs. The only alternative to call recording would now appear to be some sort of IVR/push button type interrupt to take card data away from the contact centre. The council is a position to force that sort of process and technology change and this may backfire on them and the vendors that lobbied hard for this clarification. Read more...
PCI council has made a one-sided decision; They should have done a much more in-depth research that could have provided more insight on what regards to the implications of such decision. Read more...

Will Old OS Cause PCI Violation? No, But Marketing Still Says So

This is an interesting issue, because there's more to it than what's apparent on the surface. PA-DSS requires supported and patched operating systems and other software components (e.g., databases, libraries, Java, etc.) per PA-DSS 7.1.b and 8.1, and the option for compensating controls simply isn't there. Merchants can make use of compensating controls for most PCI DSS requirements, but only when legitimate constraints exist and only in ways that meet the intent and rigor of the requirement and go above and beyond the other PCI DSS requirements. Read more...
Why would one automatically upgrade to a "new" OS -- some of the older versions of certain OS-es are more stable and more robust than the crap being peddled today. This is yet another clear example of PCI SSC being out of touch with reality. Rather than requiring a "current" OS, the requirement should be to demonstrate the OS in use is stable and robust, and is adequately hardened against threats. Read more...
There are compensating controls that encrypt the swipe at the driver level as it enter the PC, there are hardware encrypting card swipes so the cardholder data is already encrypted before it comes to the PC -- either of these, especially the second, would remove the OS entirely from a cardholder data risk profile. Read more...
In my opinion, the only thing the vendor did wrong was they didn’t know of that FAQ entry. Even if they did, it changes nothing about the need for merchants to update software that no longer receives updates. Read more...

MasterCard Blinks, Drops Dec. 31 Level 2 PCI Deadline

Reciprocity between MasterCard and Visa was always been a factor in Acquirer merchant level assignments. The brief removal of reciprocity generated a great deal of interest in being able to be classified at a lower level in MasterCard's world. Nevertheless the return of the reciprocity language in the December changes did not effectively create any new Level 2 merchants, but it DID dash the hopes of a lot of them.... :-( Read more...
Let's given them credit??? For being idiotic in the first place? Not on your life! Everyone has just had to scramble and include the costs of the previously announced M/C requirement in their 2010 budgets, and start negotiating with the QSAs for the additional services. All for naught! Read more...
"A bunch of Level 3 and Level 4 merchants just became Level 2s". Is this an accurate statement? MasterCard & Visa have historically included the caveat "or is a Level X in another brand" in their level setting criteria. MasterCard appeared to back way from this in the June pronouncement, and have simply returned to the status quo. Have Acquirers have been tracking and reporting merchants at separate levels by brand? Read more...
I stick by my comment (quoted in the column) about a bunch of L3 and L4 merchants becoming L2s and requiring an onsite. To me, what made MasterCard's original requirement for an onsite assessment for L2s palatable was that they took away their reciprocity provision. That is, they seemed to focus on larger merchants with over a million MasterCard trans/year. With reciprocity in place, a lot of smaller merchants are pulled into the onsite requirement. Rather than causing confusion, I think reciprocity will lead to additional work for processors and acquirers. Read more...

Retailers Sue POS Vendor, Questions Raised Where PCI Duties Stop

I would add a couple more questions: "did the breach involve the use of the default passwords?" (The story doesn't say.) And "were the default passwords used by Computer World to remotely administer the store systems?" "where is the PCI auditor in all this?" Did the restaurant group think they didn't need an audit because Radiant was (mis)representing Aloha as PCI compliant? How is a retailer or even a PCI auditor to know otherwise? A PCI auditor is not necessarily a qualified computer forensic investigator capable of finding the card data on the hard drives. They can only base a decision on information given to them by others. Read more...
There are so many holes in the process it will be difficult to pin blame on just one constituent. It is ridiculous that the technology exists to better secure these transactions (PIN, EMV, etc) yet banks won't use them. Only the banks or government can force this change, and retailers will suffer until then. Read more...
A major issue in this case will be if the restaurants had any support agreements in place with Computer World and if so what those agreements say. In my experience many single unit/small operators choose to skip the support agreements in favor of a "pay as you go" arrangement. In this scenario I can't imagine how the POS VAR can be held responsible for a system they don't own nor exclusively manage. Read more...
There is a big difference in having the POS installation guide say "make sure you set this password because the security of your CHD depends on this" vs. a POS application not storing the CHD in the first place. Traditionally only the merchant was liable for breaches and PCI related fees (fines). Maybe dragging some of the vendors into the liability mud fight will open the eyes of some of these vendors. Read more...

Should Credit Card Transactions Be Free? There May Be A Way

Here in the Netherlands, where the population is notoriously penny-pinching, credit card acceptance is amazingly low. It's both a result of the consumer not wanting to pay interest on everyday purchases as well as merchants not giving up a slice of the action. It is both legal and common to pass the processing fee onto the customer as a surcharge. Now things are moving to leave the credit cards behind: mobile phone payments are becoming more and more common here, and the transaction fees are minimal. Parking and entertainment (movie/concert tickets, nightclubs) have been amongst the first, and it's rapidly gaining momentum because the market has been hungry for the convenience at a price it is willing to pay. Read more...
"Free" is an illusion. Don't charge one person but charge double to someone else. I am very skeptical on anyone who says that advertising will create valid cashflow. Just look at the advertising struggles in a TiVo world. And if you sell your customers data, just be warned that the one group that might have issue with that are you customers (which to me is very important to cashflow. Read more...
Another factor not mentioned here is the impending costs that the processors and issuers are going to incur when someone decides on an end-to-end encryption method, and it then becomes government mandated. I can guarantee that this is a when question and not an if question. The back-end networks are pretty antiquated right now, and it's going to cost billions to replace everything. The cost of tech may be going down, but the cost of replacing millions of servers and hardware, and creating new, proprietary, software is still really expensive. Read more...
Accepting credit cards are not "risk-free" for merchants, contrary to Jim's comments above. Chargebacks are an expense - both in terms of actual transaction reversals and costs associated with managing the process. Chargeback rules and expenses can be everything from a thorny issue to an onerous expense for some merchants, especially for convenience stores that allow customers to pay for gasoline at the pump, or other retailers that allow in-store self-checkout options. Read more...
I've wondered for years why the price of transactions has been so high. Phone companies long ago started offering unlimited calling for flat rates because they understood that in many cases it cost more to report on the transactions (calls) than it did to fulfill them. Read more...
If a home-owner defaults on the mortgage, who is taking the risk? The bank making the loan to the consumer or the person selling the house? It is obviously the bank that takes this risk and is rewarded for that risk through interest rate charges. In my mind, we have mixed together two distinct and unrelated transactions. Read more...
The one big factor not mentioned in this article is who will take over the risk ? Taking credit cards is risk free to merchants and the issuing Banks take the risk if a customer defaults on the payments ! If you had a "interchange free" payment system will the merchants assume the risk ? Also, if there isn't enough profit for the issuing banks they will stop issuing credit cards which will in turn kill our economy. Read more...

The Dangerous Out-Of-Scope PCI Charade

If tokens are ever deemed in-scope, then where does the line stop? I ask this because it would mean that all timestamps, sequential number, random numbers or any other piece of information that may or may not be used to generate a token is within scope -- all data a POS uses and stores, not just payment data. Read more...
Having the ability to do both Tokenization and End to End Encryption (not mere point to point) can have tremendous scope and risk reduction benefits and agility to adapt to change in this fast moving compliance landscape. Being able to have both on tap from a single platform is a solid approach to avoiding the pitfalls. Read more...
But the consumer walks into a particular retail chain, gives their payment card to someone wearing that chain's uniform and the card is swiped. If, six months later, there's a breach and that card was misused, it's the retailer who will in the spotlight. They're the deep pocket and, therefore, the target. If the consumer is angry and wants to cut off business, it will hit the retailer. Therefore, if the retailer is going to end up being blamed no matter what, they have to stay involved. Read more...
True, that someone may be storing a token-to-PAN cross reference. But that would be the bank, not the retailer. If the bank is not sure they can keep their data secure, then there are bigger problems to be addressed than bringing tokens into scope. Read more...
Good general point, Steve, but for the record, not all tokenization is done the same way. Many tokens are associated with lookup lists that allow for them to re-matched to the card data if it's needed, such as for a chargeback. A token doesn't have to be decryptable (is that a word?) for there to be a way to access the original data. Read more...
The out-of-scope argument is very valid but in reference to tokens, the premise of temporarily out-of-scope or abruptly deemed in-scope is flawed. Conway was quoted “anything that could be made unreadable can, in various ways, be made readable again,” this statement is true when talking about encryption technologies (all encryption technologies) but not so with true tokens. True tokens are in no way related to the original data other than as a reference key. Read more...