Join the Community

23,447
Expert opinions
42,338
Total members
313
New members (last 30 days)
178
New opinions (last 30 days)
29,126
Total comments

Information Security

The risks from Cyber cime - Hacking - Loss of Data Privacy - Identity Theft and other topical threats - can be greatly reduced by implementation of robust IT Security controls ...

Retired Member

Retired Member 

Mobile Doesn't Have to Mean Insecure

In my last blog, I stated that security is the number one concern for retail bank customers and investment bank managers. In fact, at one time or another, nearly all of our investment banking clients who are considering building mobile applications for their employees have asked, “what if they lose their iPad on the Tube?” – a good question. I thi...

/security

Retired Member

Retired Member 

Are compromised certificates the root of all Evil?

I returned from holiday to find another attack vector has raised its ugly head. Reading the latest news, at least two hundred fraudulent SSL certificates (and oossibly over five hundred) have been issued from a trusted root certificate authority (CA). In this case, it appears that Diginotar, the Dutch trusted third party has been breached and spoo...

/security /regulation

Lachlan Gunn

Lachlan Gunn Executive Director at European Association for Secure Transactions

Heat from your fingers could disclose your PIN at an ATM

Thermal cameras can apparently detect heat signatures from your fingers on the keys after you have left an ATM. The degree of heat residue can also indicate in which order you touched them! This technology will not work effectively on metal key pads, only on plastic ones, and the successs window is limited. The message "cover your PIN when ma...

/security

Lachlan Gunn

Lachlan Gunn Executive Director at European Association for Secure Transactions

Do you get SMS alerts for debit card transactions?

Does your bank provide SMS alerts for debit card transactions? If it does, do you use the service? According to an article in the Times of India, with effect from July 2011, the Reserve Bank of India (RBI) has made it mandatory for ALL Indian banks to provide this service to debit card holders, and all debit card holders are required to register t...

/security

Retired Member

Retired Member 

Comparing Mobile and Contactless Payments

As we have seen, contactless payments are beginning to move into the mainstream. As my colleague Mark Carpenter has previously noted in a blog, support for contactless transactions is moving out from the metropolis, even to the rarefied environs of his country retreat. According to Visa Europe, in 2010 it alone issued 10 million contactless card...

/payments

Retired Member

Retired Member 

Assessing Risk? Ask a pigeon.

I was recently browsing, when I came upon an interesting article. It was discussing the Monty Hall problem. For those of you who don’t know, this problem is based on a US quiz show and has caused a huge amount of debate at various times in the past. The idea is as follows. A contestant is asked to look at three closed doors and told behind tw...

/security /regulation

Retired Member

Retired Member 

The PCI SSC Publish Virtualisation and Cloud Advice

I have just been reading the new guidance provided by the PCI SSC on Virtualisation. This document has been long anticipated, having been pre - announced at the PCI SSC User Forum back in October 2010. The document includes advice for local virtualised servers and environments as well as advice for those merchants considering a wholesale switch t...

/security /regulation

Retired Member

Retired Member 

Security: Be very worried NATO uses hbgary

I have to speak out. You must remember hbgary, the company which apparently conspired with BoA/DOJ on ways (some illegal) in which to tackle wikileaks? Well they were allegedly hacked by a 16yr girl in retaliation for their unethical actions and the CEO subsequently quit. The company emails & files for ...well several years... are circulating o...

/security

Retired Member

Retired Member 

Are you prepared for World IVP6 day?

As I ask the question I can hear the thud of exasperation from overworked network administrators. Surely not another awareness day or preparatory day for the masses; haven’t network administrators enough work to handle. Well, I suspect they do, however World IPv6 Day does have a serious intent. World IPv6 Day is scheduled for June 8th and

/security /regulation

Retired Member

Retired Member 

Have you looked under the virtual mat?

I wonder what the Japanese is for “when you are in a hole it’s usually a good time to stop digging?" I read the new Sony press release with some bemusement; the one with regard to the loss of 25 million further customer details from Sony Online Entertainment. The release had the following statement: Information from an outdated database

/security /regulation

Now Hiring