dimanche 10 octobre 2010

Man's quest-Foil hackers


Robert Carr, founder and CEO of Heartland Payment Systems (HPY-news-people) terror is still fresh. In December 2007, the wily hackers broke into the Heartland's servers and the use of the United States Government estimates is 130 million credit card numbers. Heartland makes card swipe.txt machines and the software that saves your 15-digit numbers, Visa and MasterCard (MA-news-people) you can use to review entries-the company, that is to say, which depends on the bulletproof waistcoats and computer networks. Notice of breach (on the inauguration of Barack Obama in the morning) sent a Heartland's stock to nosedive, two months, $ 3.60 $ 18. As a result of the credit card companies and legal settlements: 139 million dollar (it recovered from 31 million dollar insurance carrier). "The worst thing that can happen in the event of a breach of an undertaking is to get treatment," says Carr, 64. "It seemed like a good possibility, we cannot survive."

Alive, it is. Princeton, n.j., headquarters Heartland is the middleman recruits traders, many of them in the case of small enterprises. Say you spend $ 100, a pair of shoes. Merchant may keep the $ 97.50, and the rest would go to the granting of the Bank ($ 1.65); processors, Heartland (50 cents); Visa and MasterCard (35 cents). (Heartland is a different process and check out in the annex.)Although the Heartland to lose 55 million dollars, pretax group, 1.7 billion dollar revenue (from 70 billion dollars for free drive) on Mar 31, Robert Dodd analyst Morgan Keegan, where, for 12 months thinks the company easily reached pre-breach 2008 levels, as set out in the next year, will earn $ 70 million pretax group or more--if the market share of consumer spending and extract. warehouse is at the level of pre-hack rebounded.

Heartland delivers approximately 70% of its revenue in interchange fees-paid-to the banks that issue credit and debit cards per, the amount of which shall be determined in accordance with the Visa and MasterCard, based on the size of the trader and transaction types.

Now Carr, whose purpose is to make sure what happened to her, he will not working its customers. 2009 Study research company Javelin Strategy estimated that the identity of the pay by credit card companies, payment processors, traders and consumers of 54 billion dollars annually.

May Heartland began to take the firmware package is known as E3, which scrambles your credit card numbers is baloney, as soon as the card is Jones who swiped $ and maintain encryption, such as data sloshes over the network. Cost: € 269 traders estimated point-of-sale costs $ 58 magnetic field of the machine and a card reader. System (in which Carr dubbed his "Tylenol tamper-resistant Cork") works only in processing hardware company guarantees the Heartland to pay all fines and criminal investigations on the basis of the cost of a merchant, if the system has been violated. This promise, has its own self-insurance backstopped.

Carr also include a Pulpit, browbeaten by credit card companies into forcing their credit card processors and traders, as the case may be, their own security run-of-the-mill firewalls and updated antivirus software.National Retail Federation considers merchants used 1 billion dollars in 2009 security audits.The Heartland passed one of these-it meant a lot-is."These checks provide false sense of security," says Carr, who called on competitors (such as they feasted his disenchanted customers) to join an industry group that share concerns and Government for the fiscal year."Before that infringement could you hear about six months after the date on which it occurred," says John Kirkpatrick, Chief Information Officer at TransFirst, payment processor, Hauppauge, N.Y. "now we can share information, check the mutual järjestyksensä."

Any vulnerability lies in the fact that information has to be decrypted is transferred to the Heartland's system with visa and MasterCard, such as credit card companies to accept only unencrypted data, if not a link (which may or may not be in the context of the telecom more than 2 000 or so miles) would be infringed. Heartland's competitors are operating, the complete process is called tokenization, which allows credit card numbers, and then move on to the network key, which is not a mathematical your credit card number. Carr inventory is an early win pesticides established E3. "I have never seen a company uses a security incident breached so aggressively, "says Avivah Litan, analyst with Gartner."On the other hand, self serving, but it's been a good security awareness. "

Special offer: free trial issue of Forbes


View the original article here

commentaires

0 Responses to "Man's quest-Foil hackers"

Enregistrer un commentaire

 

Copyright 2009 All Rights Reserved Revolution Two Church theme by Brian Gardner | Blogger template converted & enhanced by eBlog Templates