Showing a license/id to a shopping website, worth it? [duplicate]

I’m wondering if anyone here has ever decided to show their driver’s license or ID of any sort to be able to shop at a website. I was personally asked to do this along with a facial verification. I was thinking if I were to show my driver’… Continue reading Showing a license/id to a shopping website, worth it? [duplicate]

PCI-DSS Compliance: SSL Tunneling Credit Card Information Through A HTTPS Mobile/Residential Proxy Service to A Destination Service

If a PCI compliant service decides to SSL-Tunnel credit card information via an independent residential/mobile proxy service to a destination payment service, would this protocol still be PCI compliant?
Since the credit card information is… Continue reading PCI-DSS Compliance: SSL Tunneling Credit Card Information Through A HTTPS Mobile/Residential Proxy Service to A Destination Service

Credit Card Online Fraud: Suspicious Payment Dates with CCbill payement solution [closed]

I recently encountered a credit card online fraud issue and need your insights to better understand what might have happened. On the 6th of this month, I noticed multiple unauthorized payments towards different websites. However, what’s pe… Continue reading Credit Card Online Fraud: Suspicious Payment Dates with CCbill payement solution [closed]

Heads Up CEO! Cyber Risk Influences Company Credit Ratings

More than ever, cybersecurity strategy is a core part of business strategy. For example, a company’s cyber risk can directly impact its credit rating.  Credit rating agencies continuously strive to gain a better understanding of the risks that companies face. Today, those agencies increasingly incorporate cybersecurity into their credit assessments. This allows agencies to evaluate […]

The post Heads Up CEO! Cyber Risk Influences Company Credit Ratings appeared first on Security Intelligence.

Continue reading Heads Up CEO! Cyber Risk Influences Company Credit Ratings

Should I allow CVC of 000 in our system? [duplicate]

I’ve reviewed multiple threads on reasons why 000 should be allowed and why it shouldn’t:
All 0s (zeros) in a bank card’s CVC code
https://news.ycombinator.com/item?id=18768801

In summary, reasons 000 should be allowed:

  • Poor validation (validation bug) due to a lazy programmer since CVC should be a string, not an int, so this is a bug that needs to be fixed
  • If threat is brute force, a system only using values 001-998 is less secure than one using 000-999

Reasons 000 as a CVC should not be allowed:

  • Bias in guessing matters as much as bias in generation, with users who are trying to pass a fraudulent transaction will highly guess the CVC with values 000 and 123
  • A system such as a booking one will be connected to other brokers whose systems may have poor validation so 000 is blocked on purpose from the top
  • According to Bard, its response to “Is accepting a CVC of 000 considered PCI compliant?” is “No, accepting a CVC of 000 is not considered PCI compliant”.

I am leaning towards NOT allowing a CVC of 000 due to it not being PCI compliant.

Continue reading Should I allow CVC of 000 in our system? [duplicate]