<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Retail Data Breach Victim Rolls Back The Tech Clock</title>
	<atom:link href="http://www.storefrontbacktalk.com/securityfraud/retail-data-breach-victim-opts-to-roll-back-the-tech-clock/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.storefrontbacktalk.com/securityfraud/retail-data-breach-victim-opts-to-roll-back-the-tech-clock/</link>
	<description>Techniques, Tools and Tirades about Retail Technology and E-Commerce</description>
	<lastBuildDate>Fri, 19 Mar 2010 23:24:36 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Michael Cherry</title>
		<link>http://www.storefrontbacktalk.com/securityfraud/retail-data-breach-victim-opts-to-roll-back-the-tech-clock/comment-page-1/#comment-64106</link>
		<dc:creator>Michael Cherry</dc:creator>
		<pubDate>Mon, 02 Nov 2009 12:46:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.storefrontbacktalk.com/?p=4081#comment-64106</guid>
		<description>Excellent article. The Retail IT Community (my community) got ahead of itself and new safer solutions are needed. My community did a better job when we designed wholesale banking and brokerage electronic funds transfer systems (EFTS).  

Michael Cherry
Cherry Biometrics Inc.</description>
		<content:encoded><![CDATA[<p>Excellent article. The Retail IT Community (my community) got ahead of itself and new safer solutions are needed. My community did a better job when we designed wholesale banking and brokerage electronic funds transfer systems (EFTS).  </p>
<p>Michael Cherry<br />
Cherry Biometrics Inc.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kiril Alexiev</title>
		<link>http://www.storefrontbacktalk.com/securityfraud/retail-data-breach-victim-opts-to-roll-back-the-tech-clock/comment-page-1/#comment-64067</link>
		<dc:creator>Kiril Alexiev</dc:creator>
		<pubDate>Mon, 26 Oct 2009 18:28:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.storefrontbacktalk.com/?p=4081#comment-64067</guid>
		<description>Merchant payment technologies have become very sophisticated and allow various networks or products to link seamlessly so that users can benefit from straight-through processing.  But integration of various products and networks poses a unique problem: are these linkages done right and are there vulnerable points that are outside the security mechanisms of each component.  PCI represents one attempt to standardize security procedures for payments but standardization cannot catch all weak points.  Thus somethings rolling back in time can help merchants avoid what Cheers Liquor Mart experienced.  A better solution would be to have IT security technician on staff and mandate annual security audits to look for ways to troubleshoot or improve the end to end security of an integrated system.  Or said in other words: using a typewriter to avoid computer viruses on your word processing equipment is not a long  term solution in the century of automation ...</description>
		<content:encoded><![CDATA[<p>Merchant payment technologies have become very sophisticated and allow various networks or products to link seamlessly so that users can benefit from straight-through processing.  But integration of various products and networks poses a unique problem: are these linkages done right and are there vulnerable points that are outside the security mechanisms of each component.  PCI represents one attempt to standardize security procedures for payments but standardization cannot catch all weak points.  Thus somethings rolling back in time can help merchants avoid what Cheers Liquor Mart experienced.  A better solution would be to have IT security technician on staff and mandate annual security audits to look for ways to troubleshoot or improve the end to end security of an integrated system.  Or said in other words: using a typewriter to avoid computer viruses on your word processing equipment is not a long  term solution in the century of automation &#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steve Sommers</title>
		<link>http://www.storefrontbacktalk.com/securityfraud/retail-data-breach-victim-opts-to-roll-back-the-tech-clock/comment-page-1/#comment-64061</link>
		<dc:creator>Steve Sommers</dc:creator>
		<pubDate>Thu, 22 Oct 2009 16:00:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.storefrontbacktalk.com/?p=4081#comment-64061</guid>
		<description>I question whether rolling back to dial up terminals is really more secure? Yes, it is a quick fix that will most likely close the current breach vector but it does bring back it own set of risks. I&#039;m not aware of any dial up terminal that supports encrypting the data as it is sent to the modem. I’m also not aware of any processor &quot;dial up&quot; spec that supports encryption. While the card brands and PCI have added loopholes for unencrypted dial up traffic, there is a big grey area if the merchant uses a VoIP phone solution - in which case you might be introducing unencrypted traffic on a public network.</description>
		<content:encoded><![CDATA[<p>I question whether rolling back to dial up terminals is really more secure? Yes, it is a quick fix that will most likely close the current breach vector but it does bring back it own set of risks. I&#8217;m not aware of any dial up terminal that supports encrypting the data as it is sent to the modem. I’m also not aware of any processor &#8220;dial up&#8221; spec that supports encryption. While the card brands and PCI have added loopholes for unencrypted dial up traffic, there is a big grey area if the merchant uses a VoIP phone solution &#8211; in which case you might be introducing unencrypted traffic on a public network.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris</title>
		<link>http://www.storefrontbacktalk.com/securityfraud/retail-data-breach-victim-opts-to-roll-back-the-tech-clock/comment-page-1/#comment-64059</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Thu, 22 Oct 2009 06:32:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.storefrontbacktalk.com/?p=4081#comment-64059</guid>
		<description>I swear I&#039;d do my best to initiate the comeback of the Carrier Pigeon if I knew it would do any better for network security :-)</description>
		<content:encoded><![CDATA[<p>I swear I&#8217;d do my best to initiate the comeback of the Carrier Pigeon if I knew it would do any better for network security :-)</p>
]]></content:encoded>
	</item>
</channel>
</rss>
