Tech Talks Daily

680: Magecart Malware - Is It Time to Question the Effectiveness of PCI DSS?


Listen Later

A quick look at the recent news headlines reveales that the payments industry has been under attack. When I delved deeper into this story, I found a recent survey that also revealed that a mass majority (84%) of payments industry professionals believe payments fraud is going to get worse – and soon.

Smaller companies that process online payments are enlisting the help of payment processors - like Stripe, Square, or PayPal - to help them meet stringent compliance standards like PCI DSS. But are they opening themselves up into a security risk?

“The fact that the malware targets sites using a variety of payment gateway providers calls into question the effectiveness of PCI DSS security standards for online businesses, in particular, the absence of a requirement for businesses to know and manage all third-party code present on their sites and apps,” wrote Michael Bittner, digital security and operations manager at The Media Trust.

tCell researchers discovered that hackers can use Cross Site Scripting (XSS) to steal payment information. Any web application component (like a chat window) can become a possible attack vector, but very few non-payment-related components will have recognized the need to implement a PCI-style deep security program.

This is no longer just a theoretical attack -- recently this approach was used on Magento e-commerce customers. And the British Airways hack used this same approach as well.

I invited Matthew Gast from tCell onto my daily tech podcast to find out more about what companies can do to protect customers visiting their website or application from Cross Site Scripting (XSS) 

...more
View all episodesView all episodes
Download on the App Store

Tech Talks DailyBy Neil C. Hughes

  • 5
  • 5
  • 5
  • 5
  • 5

5

197 ratings


More shows like Tech Talks Daily

View all
HBR IdeaCast by Harvard Business Review

HBR IdeaCast

177 Listeners

a16z Podcast by Andreessen Horowitz

a16z Podcast

1,040 Listeners

The Twenty Minute VC (20VC): Venture Capital | Startup Funding | The Pitch by Harry Stebbings

The Twenty Minute VC (20VC): Venture Capital | Startup Funding | The Pitch

519 Listeners

Software Engineering Daily by Software Engineering Daily

Software Engineering Daily

621 Listeners

The Official SaaStr Podcast: SaaS | Founders | Investors by SaaStr

The Official SaaStr Podcast: SaaS | Founders | Investors

175 Listeners

The TWIML AI Podcast (formerly This Week in Machine Learning & Artificial Intelligence) by Sam Charrington

The TWIML AI Podcast (formerly This Week in Machine Learning & Artificial Intelligence)

441 Listeners

Fintech Insider Podcast by 11:FS by 11:FS

Fintech Insider Podcast by 11:FS

186 Listeners

Gartner ThinkCast by Gartner

Gartner ThinkCast

112 Listeners

Super Data Science: ML & AI Podcast with Jon Krohn by Jon Krohn

Super Data Science: ML & AI Podcast with Jon Krohn

298 Listeners

NVIDIA AI Podcast by NVIDIA

NVIDIA AI Podcast

331 Listeners

DataFramed by DataCamp

DataFramed

267 Listeners

Practical AI by Practical AI LLC

Practical AI

192 Listeners

Big Technology Podcast by Alex Kantrowitz

Big Technology Podcast

454 Listeners

Business Breakdowns by Colossus | Investing & Business Podcasts

Business Breakdowns

353 Listeners

The AI Daily Brief (Formerly The AI Breakdown): Artificial Intelligence News and Analysis by Nathaniel Whittemore

The AI Daily Brief (Formerly The AI Breakdown): Artificial Intelligence News and Analysis

491 Listeners