Jeffrey Schiller  
Networking, Security and Cavies  
 
   
 

 

Home Page

Download my PGP Key

Building Secure Websites

Fluffernutter, Our Rabbit

Some Pig Faces!

Bretton Woods

Powers of 10

Dilbert on the Value of Research

Blog Entries

New Baby Pig
Feb. 13 2010

Deja Vu: Risks for Back Doors in Systems
Jan. 24 2010

The Cloud: Cool and not Cool
Jan. 22 2010

QR Codes
Dec. 9 2009

I've moved my Blog
Nov. 21 2009

Jeff's Laws
July 31 2009

We Don't need a new Internet
Feb. 15 2009

What's Wrong with this Picture
April 16 2008

Internet Identity
May 8 2007


What's Wrong with this Picture

OK, so how does a credit card work? Well let’s see. We have a number, which we need to keep secret. If a “bad guy” learns it, they can use it to charge against us and otherwise impersonate us.

However in order to use it we need to share it with individuals and organizations that we have no fundamental reason to trust! What’s wrong with this picture?

Yet, for years before the Internet boom, this business practice worked fine. Perhaps that was because in the event of fraud, it was easier to track it down as shared numbers couldn’t be zapped across the globe in a matter of seconds. There was “friction” in the transfer of information.

But the Internet has made the friction go away. So now we have attackers breaking into servers and stealing millions of card numbers. We have attacks where numbers are stolen quasi in-flight. There will be more ways card numbers are stolen in the future.

The payment card industry has attempted to address merchant security with its security standards. But these standards have to recognize practical limitations, so they leave holes (and in some cases they require steps that are costly, but add minimal security). The problem is once you have standards such as this, it isn’t about security anymore, but about compliance. You hear of companies who have positions with titles such as “Chief Compliance Officer” Yet compliance doesn’t ensure security. In fact it can reduce it because it doesn’t value actions that improve security but do not improve compliance!

But let’s get back to the fundamentals. What’s Wrong with this Picture? There is a fundamental disconnect when we have a secret value that we *must* share widely. We need a better solution. And they are out there... but it will require a major change in how credit cards work. So the question is, how much more money needs to be lost and how many more people need to be inconvenienced before the trade-off leans toward solving this fundamental disconnect?

Add a Comment

Entries (RSS)