The Security Samurai

Necessity is the plea for every infringement of human freedom. It is the argument of tyrants; it is the creed of slaves - William Pitt

My Links

Post Categories

Archives


Random Family Guy Quotes

Blog Stats

.Where I Work

General Blogs I Read

Security Blogs I Read

Useful Articles

Merchants Blame Software for Security Issues - from the WSJ

The Wall Street Journal had a good article summing up credit card data theft over the past few months. The common theme: all of the merchants stored data they shouldn’t have and then found ways to blame the software they were using. Shifting the blame has never been easier. People generally trust the companies they do business with, otherwise they would go elsewhere, and they have been trained to fault IT products. All you have to do is say it’s the computer’s fault, and end of story, but it shouldn’t be. How do features end up in software products? As a general rule, our customer’s pressure the sales team for features, sales puts pressure on the IT department to build it, and application developers comply. I can think of very few times where application developers have added features just for the hell of it. So who is to blame, the customer or us, the developers of software?

I tell developers it’s not about assigning blame…not yet anyway. Who has the time? If the business community is not going to drive us to write more secure software, we can take it upon ourselves to do so. Sure every company says it wants to implement better security, but how many actually do? I have a lot of respect for Microsoft now (I used to only trust Linux servers for security) because of how radically things have changed over there. I remember the days when you could read about a vulnerability in a Microsoft product every single day on Slashdot. Now, products whose market share is, in the words of Peter Griffin, “some kind of fraction I can't even measure” have more exploits that are found than all MS products combined.

As for the breaches as of late, after reading the WSJ I read a couple of other news articles and found a few interesting tidbits. For example, Polo Ralph Lauren is notifying 180,000 General Motors MasterCard holders that their cards had been compromised. Those must have been some mighty picky thieves to only steal MasterCards bearing the General Motors logo. I will go out on a limb and say the bank that offers the cards, HSBC, is forcing the retailer to notify at least its customers. The worst part about the whole thing is that the software they used from Datavantage stored Track II data. This is used in actual card swipe transactions and serves no purpose afterwards except if it is stolen, in which case it is used to create credit card clones.

Several Banks have sued BJ’s wholesale club for storing the same data that Polo Ralph Lauren did. What was BJ’s response? Well to sue IBM of course. After all, they made the software. Unfortunately, the only direct evidence the banks have, is a newspaper article, something IBM is pointing out while at the same time maintaining their contract with BJ’s shields them from liability. It really would be interesting to see what happens, but as far as I can tell, these lawsuits will go no where.

Then there was DSW Shoe Warehouse, with 1.4 million credit card transactions stolen using software from NCR. Each company is claiming the other screwed up as the software can optionally delete information after the transaction has been processed. Where will it all end…

posted on Thursday, April 28, 2005 12:00 AM

Feedback

# qine rqmfdpn 5/19/2007 3:21 AM ycqrw@mail.com

yulg htgvy ulpnic dqhwjk vmtqkba gakbc tnfykmioq

# make money 5/23/2007 4:10 AM fzlmi@hotmail.com

Cool site. Thank you!!!




# guitar tab 5/23/2007 12:18 PM vzljuna@hotmail.com

Good site. Thank you!!!




# hardware 5/30/2007 5:59 PM tsmf@hotmail.com

Good site. Thank you.

# hydrocodone 10 325 6/4/2007 4:39 AM xfrycej@hotmail.com

Cool site. Thanks:-)

# hydrocodone 10 325 6/4/2007 4:39 AM xfrycej@hotmail.com

Cool site. Thanks:-)

# soma drugs 6/4/2007 6:26 AM aixw@hotmail.com

Cool site. Thank you:-)

# remington 870 express super magnum 6/5/2007 3:56 AM spzh@hotmail.com

Nice site. Thank you:-)





# electric airsoft machine gun 6/5/2007 8:13 AM frbivso@hotmail.com

Very good site. Thanks!!!











# electric airsoft machine gun 6/6/2007 3:43 AM glwhcbj@hotmail.com

Cool site. Thank you:-)











# buy or sell used gun 6/7/2007 8:20 AM kswlaj@hotmail.com

Cool site. Thanks!











# game hentai online 6/7/2007 10:40 AM ywjhkng@hotmail.com

Very good site. Thank you:-)








# hentai gif galleries 6/7/2007 2:12 PM vwxcb@hotmail.com

Very good site. Thanks.











# next day tramadol 6/7/2007 3:41 PM sfqk@hotmail.com

Very good site. Thank you!

#  generic vicodin 6/8/2007 3:35 AM dpsu@hotmail.com

Nice site. Thank you!!!

# diazepam dose 6/10/2007 3:26 PM abkst@hotmail.com

Very good site. Thank you:-)

# insurance policy 6/11/2007 6:03 AM sewmpu@hotmail.com

Cool site. Thank you!

# supplemental insurance 6/11/2007 3:09 PM oenc@hotmail.com

Good site. Thank you!

# vision insurance 6/12/2007 3:37 AM arhxy@hotmail.com

Cool site. Thank you.

# cialis online 6/13/2007 5:34 AM yvfs@hotmail.com

Nice site. Thanks.



















# loan application 6/19/2007 3:03 PM qvnmyi@hotmail.com

Cool site. Thank you!!!



















# bad credit personal loans 6/21/2007 12:30 AM udeohp@hotmail.com

Nice site. Thank you!!!



















# jackets 6/22/2007 12:26 AM mutlwo@hotmail.com

Good site. Thank you!!!



















# shoe shops 6/22/2007 5:21 PM kclzu@hotmail.com

Cool site. Thank you:-)



















# buy phentermine adipex 6/23/2007 12:48 AM lpxzj@hotmail.com

Good site. Thank you!

# grand caravan se review 6/23/2007 10:17 PM hfsjt@hotmail.com

Very good site. Thank you:-)



















# prescription of soma 6/26/2007 4:00 PM lcdpu@hotmail.com

Nice site. Thanks!

# krups moka 6/26/2007 10:30 PM aycsoeb@hotmail.com

Cool site. Thank you.



















# hentai images forum 6/27/2007 6:09 AM qopt@hotmail.com

Cool site. Thanks:-)











# arabs to buy control of usa ports 6/27/2007 7:36 AM mqckevp@hotmail.com

Cool site. Thanks!



















# online mortgage 6/27/2007 1:27 PM hxvia@hotmail.com

Very good site. Thanks:-)

# repairs 6/27/2007 5:32 PM amyqi@hotmail.com

Very good site. Thanks!



















# a590 6/27/2007 10:23 PM prawzem@hotmail.com

Nice site. Thanks!!!



















# xanax anxiety 6/28/2007 2:05 AM mbqwgr@hotmail.com

Nice site. Thank you.

# sometimes people leave you halfway through the wood 6/28/2007 10:44 AM ltcvwxh@hotmail.com

Cool site. Thank you!!!



















# motores 6/29/2007 2:50 PM fiadner@hotmail.com

Very good site. Thank you!!!



















# lennox heating and cooling systems 6/30/2007 2:19 AM ciluj@hotmail.com

Nice site. Thanks!



















# buy phentermine online 6/30/2007 8:04 AM zvjktyl@hotmail.com

Nice site. Thanks.

# order cialis online 7/1/2007 12:45 AM trub@hotmail.com

Very good site. Thank you!!!

# walkee talkee 7/1/2007 12:57 PM mrot@hotmail.com

Good site. Thank you:-)



















# interest mortgage 7/1/2007 4:41 PM tnuep@hotmail.com

Nice site. Thanks:-)

# levitra comparison 7/3/2007 12:54 AM dipvwcu@hotmail.com

Cool site. Thank you!!!

# purchase xanax 7/3/2007 7:34 PM uihn@hotmail.com

Cool site. Thank you.

# alprazolam dosage 7/3/2007 8:30 PM zsywcuv@hotmail.com

Nice site. Thank you!

# amperion 7/3/2007 10:08 PM bjuqxew@hotmail.com

Nice site. Thank you.



















# phonex 7/3/2007 10:14 PM yqlfw@hotmail.com

Cool site. Thank you!!!



















# rxes27 7/5/2007 3:31 PM mnsd@hotmail.com

Cool site. Thanks!



















# xanax xr 7/6/2007 9:32 AM nyrs@hotmail.com

Good site. Thank you.

# phentermine information 7/7/2007 4:25 AM pgwzec@hotmail.com

Cool site. Thanks.

# bank loan 7/8/2007 1:09 AM uwek@hotmail.com

Good site. Thank you:-)

# alprazolam medication 7/8/2007 10:47 AM kvbanx@hotmail.com

Good site. Thanks.

# online pharmacy phentermine 7/11/2007 6:29 PM ktap@hotmail.com

Good site. Thank you:-)

# maxis caller ringtone 7/12/2007 4:34 AM qsoikma@hotmail.com

Very good site. Thank you!!!

# re: Merchants Blame Software for Security Issues - from the WSJ 7/15/2007 10:51 AM Stratos

interesting

# re: Merchants Blame Software for Security Issues - from the WSJ 7/15/2007 12:59 PM Nikolaos

Nice!

# re: Merchants Blame Software for Security Issues - from the WSJ 7/15/2007 9:45 PM Angelos

Cool!

# re: Merchants Blame Software for Security Issues - from the WSJ 7/15/2007 10:36 PM Haralambos

Nice...

# re: Merchants Blame Software for Security Issues - from the WSJ 7/16/2007 3:34 AM Silvanos

Cool.

# re: Merchants Blame Software for Security Issues - from the WSJ 7/16/2007 8:16 AM Anaklets

Sorry :(

# re: Merchants Blame Software for Security Issues - from the WSJ 7/16/2007 8:35 AM Iannis

Interesting...

# re: Merchants Blame Software for Security Issues - from the WSJ 7/16/2007 5:33 PM Tzannas

Cool.

# re: Merchants Blame Software for Security Issues - from the WSJ 7/16/2007 9:25 PM Theofanis

Nice...

# re: Merchants Blame Software for Security Issues - from the WSJ 7/17/2007 12:05 AM Giorgos

Sorry :(

# Hi people! Great job! Please visit my site too:,Hi people! Great job! Please visit my site too:,Good site 7/17/2007 1:19 AM Cathy,Cathy,Hi people! Great job! Please visit my

Hi people! Great job! Please visit my site too:

# re: Merchants Blame Software for Security Issues - from the WSJ 7/17/2007 8:55 AM Cosmo

Cool!

# re: Merchants Blame Software for Security Issues - from the WSJ 7/17/2007 4:41 PM Panayotis

Nice

# re: Merchants Blame Software for Security Issues - from the WSJ 7/17/2007 9:29 PM Stratos

Interesting...

# re: Merchants Blame Software for Security Issues - from the WSJ 7/17/2007 9:30 PM Vangelis

Sorry :(

# re: Merchants Blame Software for Security Issues - from the WSJ 7/18/2007 1:20 AM Antonis

Sorry :(

# re: Merchants Blame Software for Security Issues - from the WSJ 7/18/2007 6:11 AM Marinos

Sorry :(

# re: Merchants Blame Software for Security Issues - from the WSJ 7/18/2007 8:55 AM Vassilis

Cool.

# re: Merchants Blame Software for Security Issues - from the WSJ 7/18/2007 3:06 PM Giorgos

Sorry :(

# re: Merchants Blame Software for Security Issues - from the WSJ 7/19/2007 2:22 AM Agias

Cool.

# re: Merchants Blame Software for Security Issues - from the WSJ 7/19/2007 3:06 AM Vardis

Sorry :(

# re: Merchants Blame Software for Security Issues - from the WSJ 7/19/2007 8:46 AM Argyros

Sorry :(

# re: Merchants Blame Software for Security Issues - from the WSJ 7/19/2007 6:33 PM Yioryios

Nice!

# re: Merchants Blame Software for Security Issues - from the WSJ 7/19/2007 6:35 PM Michalis

Nice

# re: Merchants Blame Software for Security Issues - from the WSJ 7/19/2007 11:58 PM Antonios

interesting

# re: Merchants Blame Software for Security Issues - from the WSJ 7/20/2007 6:49 AM Kymon

Cool!

# re: Merchants Blame Software for Security Issues - from the WSJ 7/20/2007 9:43 AM Efstratios

Nice

# re: Merchants Blame Software for Security Issues - from the WSJ 7/22/2007 11:40 PM Aristides

Interesting...

# re: Merchants Blame Software for Security Issues - from the WSJ 7/23/2007 4:46 PM Augustinos

Cool...

# re: Merchants Blame Software for Security Issues - from the WSJ 7/24/2007 4:17 PM Iakovos

Nice

# re: Merchants Blame Software for Security Issues - from the WSJ 7/25/2007 1:08 AM Thanasis

interesting

# re: Merchants Blame Software for Security Issues - from the WSJ 7/26/2007 7:44 AM Arsenios

Sorry :(

# lorus titanium chronograph 7/26/2007 1:05 PM lptang@hotmail.com

Nice site. Thank you!



















# re: Merchants Blame Software for Security Issues - from the WSJ 7/26/2007 8:43 PM Aristotelis

Interesting...

# re: Merchants Blame Software for Security Issues - from the WSJ 7/27/2007 12:56 AM Dmitris

Nice...

# re: Merchants Blame Software for Security Issues - from the WSJ 7/27/2007 1:38 AM Kimon

Cool!

# re: Merchants Blame Software for Security Issues - from the WSJ 7/27/2007 12:28 PM Metrophanes

Nice...

# re: Merchants Blame Software for Security Issues - from the WSJ 7/27/2007 8:10 PM Loukas

Cool!

# comme des garcons 7/28/2007 7:38 AM sechdy@hotmail.com

Cool site. Thank you.



















# re: Merchants Blame Software for Security Issues - from the WSJ 7/28/2007 12:27 PM Sebastianos

interesting

# re: Merchants Blame Software for Security Issues - from the WSJ 7/28/2007 7:53 PM Neophytos

Cool!

# re: Merchants Blame Software for Security Issues - from the WSJ 7/29/2007 2:08 AM Nathanael

Cool...

# re: Merchants Blame Software for Security Issues - from the WSJ 7/29/2007 8:32 AM Alexis

Cool!

# re: Merchants Blame Software for Security Issues - from the WSJ 7/29/2007 4:20 PM Ahmed

Nice...

# re: Merchants Blame Software for Security Issues - from the WSJ 7/29/2007 11:00 PM Athanassios

interesting

# re: Merchants Blame Software for Security Issues - from the WSJ 7/29/2007 11:07 PM Alexios

Cool!

# re: Merchants Blame Software for Security Issues - from the WSJ 7/30/2007 3:30 AM Kristion

Nice!

# re: Merchants Blame Software for Security Issues - from the WSJ 7/30/2007 8:02 AM Tasos

Nice!

# re: Merchants Blame Software for Security Issues - from the WSJ 7/30/2007 8:41 AM Herakles

Sorry :(

# re: Merchants Blame Software for Security Issues - from the WSJ 7/30/2007 12:26 PM Georgios

Nice!

# re: Merchants Blame Software for Security Issues - from the WSJ 7/31/2007 12:27 AM Lefteris

Nice

# re: Merchants Blame Software for Security Issues - from the WSJ 7/31/2007 9:05 PM Odysseus

interesting

# re: Merchants Blame Software for Security Issues - from the WSJ 7/31/2007 9:58 PM Sterghios

Cool...

# re: Merchants Blame Software for Security Issues - from the WSJ 8/2/2007 7:05 AM Constantinos

Cool.

# re: Merchants Blame Software for Security Issues - from the WSJ 8/3/2007 2:48 AM Damianos

Nice...

# re: Merchants Blame Software for Security Issues - from the WSJ 8/3/2007 4:04 AM Theologos

Sorry :(

# re: Merchants Blame Software for Security Issues - from the WSJ 8/3/2007 6:13 AM Hippocrates

Cool.

# re: Merchants Blame Software for Security Issues - from the WSJ 8/3/2007 2:53 PM Martinos

Cool.

# farmer's insurance 8/3/2007 11:31 PM tsgkju@hotmail.com

Cool site. Thank you!

# farmer's insurance 8/3/2007 11:31 PM tsgkju@hotmail.com

Cool site. Thank you!

# re: Merchants Blame Software for Security Issues - from the WSJ 8/4/2007 11:22 AM Costas

Sorry :(

# re: Merchants Blame Software for Security Issues - from the WSJ 8/4/2007 12:54 PM Tataki

Nice!

# online mortgage 8/4/2007 2:50 PM sdikcgh@hotmail.com

Very good site. Thanks!!!

# mortgage funding 8/4/2007 9:03 PM zjgmp@hotmail.com

Very good site. Thank you!

# current mortgage rates 8/4/2007 9:27 PM hroktm@hotmail.com

Good site. Thank you.

# re: Merchants Blame Software for Security Issues - from the WSJ 8/5/2007 5:41 AM Theodore

Cool...

# re: Merchants Blame Software for Security Issues - from the WSJ 8/5/2007 12:03 PM Panos

Nice!

# florida mortgage rates 8/5/2007 4:41 PM tbimkv@hotmail.com

Nice site. Thanks!

# re: Merchants Blame Software for Security Issues - from the WSJ 8/5/2007 6:09 PM Theodore

Nice...

# re: Merchants Blame Software for Security Issues - from the WSJ 8/5/2007 8:49 PM Anastassios

interesting

# re: Merchants Blame Software for Security Issues - from the WSJ 8/6/2007 7:54 AM Manolis

Nice!

# re: Merchants Blame Software for Security Issues - from the WSJ 8/6/2007 9:01 AM Konstantinos

Interesting...

# re: Merchants Blame Software for Security Issues - from the WSJ 8/6/2007 11:03 AM Christoforos

Nice!

# re: Merchants Blame Software for Security Issues - from the WSJ 8/7/2007 9:13 AM Andreou

Nice!

# re: Merchants Blame Software for Security Issues - from the WSJ 8/7/2007 10:37 AM Thaddaios

Nice...

# re: Merchants Blame Software for Security Issues - from the WSJ 8/7/2007 4:04 PM Aristotelis

interesting

# re: Merchants Blame Software for Security Issues - from the WSJ 8/7/2007 10:35 PM Valerios

Cool...

# re: Merchants Blame Software for Security Issues - from the WSJ 8/8/2007 5:25 PM Solon

Nice...

# re: Merchants Blame Software for Security Issues - from the WSJ 8/8/2007 9:43 PM Arsenios

Cool.

# re: Merchants Blame Software for Security Issues - from the WSJ 8/8/2007 11:10 PM Romanos

Sorry :(

# re: Merchants Blame Software for Security Issues - from the WSJ 8/9/2007 5:33 AM Alexandros

Sorry :(

# re: Merchants Blame Software for Security Issues - from the WSJ 8/9/2007 6:39 AM Yiorgos

Nice...

# re: Merchants Blame Software for Security Issues - from the WSJ 8/9/2007 9:18 AM Dionyssios

Cool.

# re: Merchants Blame Software for Security Issues - from the WSJ 8/10/2007 4:53 AM Konstandinos

Cool...

# re: Merchants Blame Software for Security Issues - from the WSJ 8/10/2007 11:22 PM Kostas

Cool...

# re: Merchants Blame Software for Security Issues - from the WSJ 8/11/2007 5:54 AM Emmanouil

Sorry :(

# re: Merchants Blame Software for Security Issues - from the WSJ 8/11/2007 6:46 AM Arion

Nice

# re: Merchants Blame Software for Security Issues - from the WSJ 8/11/2007 1:21 PM George

Cool.

# re: Merchants Blame Software for Security Issues - from the WSJ 8/12/2007 5:39 AM Herakles

Cool...

# re: Merchants Blame Software for Security Issues - from the WSJ 8/12/2007 12:35 PM Michalis

interesting

# re: Merchants Blame Software for Security Issues - from the WSJ 8/12/2007 5:20 PM Gerasimos

interesting

# re: Merchants Blame Software for Security Issues - from the WSJ 8/12/2007 9:36 PM Tzannas

Cool.

# re: Merchants Blame Software for Security Issues - from the WSJ 8/13/2007 12:17 AM Vasilios

Nice...

# re: Merchants Blame Software for Security Issues - from the WSJ 1/15/2008 11:37 PM Spiro

Nice

# re: Merchants Blame Software for Security Issues - from the WSJ 1/15/2008 11:39 PM Alexis

interesting

# re: Merchants Blame Software for Security Issues - from the WSJ 1/15/2008 11:41 PM Iason

Cool.

# re: Merchants Blame Software for Security Issues - from the WSJ 1/15/2008 11:43 PM Makis

Nice...

# re: Merchants Blame Software for Security Issues - from the WSJ 1/15/2008 11:45 PM Odysseus

Cool...

# re: Merchants Blame Software for Security Issues - from the WSJ 1/15/2008 11:47 PM Dion

Nice!

# re: Merchants Blame Software for Security Issues - from the WSJ 1/15/2008 11:49 PM Fanos

Interesting...

# re: Merchants Blame Software for Security Issues - from the WSJ 1/15/2008 11:51 PM Grigoris

Nice...

# re: Merchants Blame Software for Security Issues - from the WSJ 1/15/2008 11:53 PM Sotiris

Interesting...

# re: Merchants Blame Software for Security Issues - from the WSJ 1/15/2008 11:55 PM Panayotis

Cool!

# re: Merchants Blame Software for Security Issues - from the WSJ 1/15/2008 11:58 PM Yannas

Sorry :(

# re: Merchants Blame Software for Security Issues - from the WSJ 1/15/2008 11:59 PM Nathanael

Nice...

# re: Merchants Blame Software for Security Issues - from the WSJ 1/16/2008 12:02 AM Lambro

Interesting...

# re: Merchants Blame Software for Security Issues - from the WSJ 1/16/2008 12:04 AM Fotis

Nice!

# re: Merchants Blame Software for Security Issues - from the WSJ 1/16/2008 12:06 AM Euaggelos

interesting

# re: Merchants Blame Software for Security Issues - from the WSJ 1/16/2008 12:08 AM Milos

Cool.

# re: Merchants Blame Software for Security Issues - from the WSJ 1/16/2008 12:10 AM Konstantinos

Cool.

# re: Merchants Blame Software for Security Issues - from the WSJ 1/16/2008 12:12 AM Nikolaos

Cool!

# re: Merchants Blame Software for Security Issues - from the WSJ 1/16/2008 12:14 AM Ivan

Nice...

# re: Merchants Blame Software for Security Issues - from the WSJ 1/16/2008 12:16 AM Stratis

Nice

# re: Merchants Blame Software for Security Issues - from the WSJ 1/16/2008 12:18 AM Aristides

Nice...

# re: Merchants Blame Software for Security Issues - from the WSJ 1/16/2008 12:20 AM Odysseas

Interesting...

# re: Merchants Blame Software for Security Issues - from the WSJ 1/16/2008 12:22 AM Zacharias

Cool.

# re: Merchants Blame Software for Security Issues - from the WSJ 1/16/2008 12:24 AM Lambro

Nice!

# re: Merchants Blame Software for Security Issues - from the WSJ 1/16/2008 12:26 AM Hristos

interesting

# re: Merchants Blame Software for Security Issues - from the WSJ 1/16/2008 12:28 AM Costa

Nice...

# re: Merchants Blame Software for Security Issues - from the WSJ 1/16/2008 12:30 AM Fanos

Nice...