Tech Talks Daily

680: Magecart Malware - Is It Time to Question the Effectiveness of PCI DSS?


Listen Later

A quick look at the recent news headlines reveales that the payments industry has been under attack. When I delved deeper into this story, I found a recent survey that also revealed that a mass majority (84%) of payments industry professionals believe payments fraud is going to get worse – and soon.

Smaller companies that process online payments are enlisting the help of payment processors - like Stripe, Square, or PayPal - to help them meet stringent compliance standards like PCI DSS. But are they opening themselves up into a security risk?

“The fact that the malware targets sites using a variety of payment gateway providers calls into question the effectiveness of PCI DSS security standards for online businesses, in particular, the absence of a requirement for businesses to know and manage all third-party code present on their sites and apps,” wrote Michael Bittner, digital security and operations manager at The Media Trust.

tCell researchers discovered that hackers can use Cross Site Scripting (XSS) to steal payment information. Any web application component (like a chat window) can become a possible attack vector, but very few non-payment-related components will have recognized the need to implement a PCI-style deep security program.

This is no longer just a theoretical attack -- recently this approach was used on Magento e-commerce customers. And the British Airways hack used this same approach as well.

I invited Matthew Gast from tCell onto my daily tech podcast to find out more about what companies can do to protect customers visiting their website or application from Cross Site Scripting (XSS) 

...more
View all episodesView all episodes
Download on the App Store

Tech Talks DailyBy Neil C. Hughes

  • 5
  • 5
  • 5
  • 5
  • 5

5

200 ratings


More shows like Tech Talks Daily

View all
This Week in Startups by Jason Calacanis

This Week in Startups

1,301 Listeners

The Twenty Minute VC (20VC): Venture Capital | Startup Funding | The Pitch by Harry Stebbings

The Twenty Minute VC (20VC): Venture Capital | Startup Funding | The Pitch

545 Listeners

WSJ Tech News Briefing by The Wall Street Journal

WSJ Tech News Briefing

1,651 Listeners

The a16z Show by Andreessen Horowitz

The a16z Show

1,107 Listeners

Software Engineering Daily by Software Engineering Daily

Software Engineering Daily

630 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,025 Listeners

Super Data Science: ML & AI Podcast with Jon Krohn by Jon Krohn

Super Data Science: ML & AI Podcast with Jon Krohn

308 Listeners

NVIDIA AI Podcast by NVIDIA

NVIDIA AI Podcast

347 Listeners

Y Combinator Startup Podcast by Y Combinator

Y Combinator Startup Podcast

233 Listeners

Practical AI by Practical AI LLC

Practical AI

211 Listeners

Big Technology Podcast by Alex Kantrowitz

Big Technology Podcast

512 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

140 Listeners

Business Breakdowns by Colossus | Investing & Business Podcasts

Business Breakdowns

353 Listeners

Bloomberg Tech by Bloomberg

Bloomberg Tech

68 Listeners

The AI Daily Brief: Artificial Intelligence News and Analysis by Nathaniel Whittemore

The AI Daily Brief: Artificial Intelligence News and Analysis

680 Listeners

Consulting the Future by Neil C. Hughes

Consulting the Future

0 Listeners

Startup Builders & Backers by Neil C. Hughes

Startup Builders & Backers

0 Listeners

IT Infrastructure as a Conversation by Neil C. Hughes

IT Infrastructure as a Conversation

0 Listeners

AI at Work by Neil C. Hughes

AI at Work

0 Listeners

The Business of Cybersecurity by Neil C. Hughes

The Business of Cybersecurity

0 Listeners

Business Technology Perspectives by Neil Hughes

Business Technology Perspectives

0 Listeners

Conversations from the Show Floor by Neil C. Hughes

Conversations from the Show Floor

0 Listeners