Credit Card Data Vulnerable to Derivation Attacks Despite PCI DSS Compliance
By
kodbraker
Slow-proofed and worth the wait. Worth its weight in flour.
Summary
The article discusses how credit card data can be stolen or derived even from PCI DSS compliant ecommerce websites. The author shares a personal experience of having their card compromised despite the merchant following industry security standards. It explains the vulnerabilities in how credit card numbers are stored and displayed, and how brute force-like attacks can derive valid card numbers from partial data visible on UIs and receipts.
Key quotes
· 3 pulledThese days, storing and showing what's visible on UI's and receipts are highly standardized and regulated by the industry standards such as PCI DSS.
And even when you save your card on an ecommerce website, which strictly follows the PCI DSS, your card can still be stolen - or derived. As it happened to me.
PCI DSS is the widely known and implemented industry standard for defining bare-minimum security measures that should be taken when handling sensitive banking data such as credit cards.
You might also wanna read
Prompt Injection Attacks: The Top Security Threat Hijacking AI Chatbots
Prompt injection attacks are a critical security vulnerability in AI systems where hidden instructions within user data (like emails or docu
Quantum computing's security threats demand urgent preparation from IT professionals
The article discusses the impending quantum computing revolution and its dual nature: promising transformative advances while simultaneously
zdnet.com·10h agoCISA warns security teams of wave of attacks targeting software supply chain credentials
CISA has issued a warning urging security teams to check for software development compromises, specifically regarding a wave of attacks targ
Security Researchers Expose Weak Encryption in Canon Enterprise Printers
During a network security assessment, security researchers discovered that Canon enterprise printers configured with default administrator c
securityboulevard.com·1d agoNew browser-based side-channel attack uses SSD activity analysis to spy on users
Researchers have discovered a new browser-based side-channel attack that can spy on users by analyzing SSD (Solid State Drive) activity thro
arstechnica.com·1d agoCISA Contractor Exposed AWS GovCloud Credentials on Public GitHub Repository
A contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository until recently that exposed
