PCI, Compromising Controls and Compromising Security

DEF CON 18

Presented by: Jack Daniel
Date: Sunday August 01, 2010
Time: 12:00 - 12:50
Location: Royale 2-3-4
Track: Track 1

PCI at DefCon? Are you on drugs? Sadly, no- compliance is changing the way companies "do security", and that has an effect on everyone, defender, attacker, or innocent bystander. If you think all that 0-day you've heard about this week is scary, ask yourself this: if a company accepts credit cards for payment, which is a more immediate threat- failing an audit or the possibility of being compromised by an attacker? That is one of the reasons "they" do not listen to "us" when we try to improve security in our environments- as real as they are, our threats are theoretical compared to failing a PCI assessment. Systems are hardened against audit, not attack. Sadly, this is often an improvement, but this can also reduce security and provide a template for attackers. This panel will discuss and debate strengths and weaknesses of PCI, expose systemic problems in PCI-DSS, and propose improvements.

Jack Daniel

Jack Daniel is old, and has a Unix Beard, so people mistakenly assume he knows stuff. He makes no attempt to correct this gross misunderstanding. Jack has proven himself to be an inciteful moderator on compliance topics. He has many years of network and systems administration experience, and a bunch of letters after his name. Jack lives and breathes network security as Community Development Manager for Astaro.


KhanFu - Mobile schedules for INFOSEC conferences.
Mobile interface | Alternate Formats