Join the Community

22,348
Expert opinions
44,252
Total members
380
New members (last 30 days)
158
New opinions (last 30 days)
28,791
Total comments

Latest expert opinions

clear
clear
Stephen Wilson

Stephen Wilson Managing Director at Lockstep Consulting

National security implications of weak hotel databases

The Destination Hotels & Resorts cyber security breach is not the first report of credit card details being stolen from hotel databases. Hotels are a fantastic target for identity thieves. Hotel databases don't just hold credit card numbers and billing addresses (which are held for weeks in advance of a stay and for weeks afterwards to secure...

/security /regulation

Stephen Wilson

Stephen Wilson Managing Director at Lockstep Consulting

Lateral business cases for EMV in the US

The announcement that a US credit union will be the first to issue EMV cards proves there is more than one way to make the business case for chip. The United Nations Credit Union says it wants its customers to be able to use their cards when travelling. Too often we're told that chip is uneconomical in the US because of the huge cost to upgrade a...

/security

Stephen Wilson

Stephen Wilson Managing Director at Lockstep Consulting

Done nothing wrong and yet ...

For those who are cynical about privacy, this case should provide food for thought. If a banker is able to make these sorts of backroom, opaque and biased determinations about a customer on the basis of what's publicly known about them, then the possibility of discrimination is immensely greater if warped decision makers like this had access to pr...

Stephen Wilson

Stephen Wilson Managing Director at Lockstep Consulting

US cardholders can take different paths with chip

I'm excited by the advent of chip cards aimed at travellers. One of the red herrings that hold up the chip card rollout states-side is that merchant enablement will cost billions. That's true, but you don't need to swap out any merchant equipment to create some immediate value propositions for US-issued chip cards. The Gemalto announcement is ...

Stephen Wilson

Stephen Wilson Managing Director at Lockstep Consulting

Don't be so cynical about privacy

Reports of the death of privacy abound, but they're premature. There are certainly those who, on the sly, would seek its demise, for privacy tends to get in their way. Like politicians on a post 9-11 national security bender, or Internet entrepreneurs who seek to monetise their eye-in-the-sky knowledge of their customers' habits. They're all tryi

/security /regulation

Stephen Wilson

Stephen Wilson Managing Director at Lockstep Consulting

If US banks still need convincing on chips ...

If only we could get our collective heads around the problem of assuring the pedigree of online information -- be it credit card numbers, or simply name and address -- the ROI for chip cards would be plain to see. Observation:$100B worth of fraud is ID related Premise: To prevent personal data being replayed behind the backs of its owners, those da...

Stephen Wilson

Stephen Wilson Managing Director at Lockstep Consulting

Kaspersky and his Internet Passport: surely he jests

OMG. Eugene Kaspersky wants an Internet Passport because he says "anonymity causes security headaches and should be outlawed". This is madness. The social repurcussions are surely obvious, while it's not clear what problem it might solve. Most cybercrime is actually linked to an excess of arbitrary identification, with inadequate safe...

/security /regulation Online Banking

Stephen Wilson

Stephen Wilson Managing Director at Lockstep Consulting

Maybe security designers need to live with human nature

OK, so people generally reveal too much about themselves. They tend to be more trusting than security advisers would like them to be. So, where to next? Some will view this video with alarm and will conclude that the huge investment in public awareness hasn't been enough. Perhaps they will advocate even more training and education. But others mi...

Stephen Wilson

Stephen Wilson Managing Director at Lockstep Consulting

End to end Encryption will not dent black market

Randy Vanderhoof of the Smart Card Alliance speaks a great deal of common sense about end-to-end encryption. It won't do anything to prevent replay attacks, nor to take the value out of stolen ID data. All it does is protect data-at-rest at intermediaries, and data-in-motion through a portion of the payment processing chain. So the black market ...

Stephen Wilson

Stephen Wilson Managing Director at Lockstep Consulting

Hotel databases and identity thieves

Hotel databases are a fantastic target for identity thieves. Hotels don't just hold credit card numbers and billing addresses (which are held for weeks in advance of a stay and for weeks afterwards to secure incidentals), but for many customers the hotel also has their home address, driver licence number, airline memberships, and ... drum roll .....

/security

Now Hiring