<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Silver Tail Blog &#187; credit cards</title>
	<atom:link href="http://silvertailsystems.wordpress.com/tag/credit-cards/feed/" rel="self" type="application/rss+xml" />
	<link>http://silvertailsystems.wordpress.com</link>
	<description>Fighting against business logic abuse.</description>
	<lastBuildDate>Fri, 18 Dec 2009 12:11:53 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='silvertailsystems.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/577fb613fda4531b5f1cbba10427b2bb?s=96&#038;d=http://s.wordpress.com/i/buttonw-com.png</url>
		<title>Silver Tail Blog &#187; credit cards</title>
		<link>http://silvertailsystems.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://silvertailsystems.wordpress.com/osd.xml" title="Silver Tail Blog" />
		<item>
		<title>Heartland response &#8211; Minimizing the damage of breached data</title>
		<link>http://silvertailsystems.wordpress.com/2009/01/27/heartland-response-minimizing-the-damage-breached-data/</link>
		<comments>http://silvertailsystems.wordpress.com/2009/01/27/heartland-response-minimizing-the-damage-breached-data/#comments</comments>
		<pubDate>Tue, 27 Jan 2009 18:43:17 +0000</pubDate>
		<dc:creator>Mike Eynon</dc:creator>
				<category><![CDATA[Data Loss]]></category>
		<category><![CDATA[Online Fraud]]></category>
		<category><![CDATA[collaboration]]></category>
		<category><![CDATA[credit cards]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://silvertailsystems.wordpress.com/?p=196</guid>
		<description><![CDATA[Bruce Schneier often talks about the response to data breaches, like the recent Heartland incident.  In a recent post, Bruce discussed how data breach notification laws encourage companies to improve their security.
While I&#8217;m all for encouraging companies to improve their security and see how breach notification laws can help with that, now that a breach [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=silvertailsystems.wordpress.com&blog=5811723&post=196&subd=silvertailsystems&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Bruce Schneier often talks about the response to data breaches, like the recent Heartland incident.  In a <a title="Schneier on notification laws" href="http://www.schneier.com/blog/archives/2009/01/state_data_brea.html" target="_blank">recent post</a>, Bruce discussed how data breach notification laws encourage companies to improve their security.</p>
<p>While I&#8217;m all for encouraging companies to improve their security and see how breach notification laws can help with that, now that a breach has occurred, the next step should be to try to minimize the subsequent damage.</p>
<p><img class="alignleft size-full wp-image-199" title="breach" src="http://silvertailsystems.files.wordpress.com/2009/01/breach.jpg?w=126&#038;h=106" alt="breach" width="126" height="106" />One method for minimizing data loss might be a bit controversial, but could also have a major impact on identifying the use of the stolen cards.  Here&#8217;s the idea (try not to judge it until you read the rest of the post): The credit card companies that cancel the impacted cards should privately publish the canceled card numbers to merchants.</p>
<p>This probably needs more explanation.  If the credit card companies had a certain set of merchants where they had very good working relationships &#8211; maybe some of the large online merchants, for example &#8211; they could give those merchants the list of card numbers that had been canceled.  Then those merchants could look for the canceled cards being used and flag that activity &#8211; and anything associated with it &#8211; as suspicious.  Since it is likely the bad actors will use the cards in batches and they won&#8217;t know which cards were canceled versus which were not, this is one way the credit card companies could help minimize the damage to the merchants.</p>
<p>Some people may be concerned about the privacy of credit card companies sending out credit card numbers.  There are three things to keep in mind about this.  First, the credit card numbers they would send out would not have any other information associated with them &#8211; they would just be card numbers.  Second, since the cards themselves would have been canceled, they are no longer owned by any person but are, instead, owned by the credit card companies themselves.  So there shouldn&#8217;t be any privacy concerns.  Third, I am not advocating that the card numbers be published on the internet for everyone to see.  Instead, they should be delivered via a secure mechanism only to merchants that are well known, trusted, and are interested in using them to take action.</p>
<p>What would be the right way to make this collaboration happen?</p>
 Tagged: collaboration, credit cards, Data Loss, Online Fraud, security <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/silvertailsystems.wordpress.com/196/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/silvertailsystems.wordpress.com/196/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/silvertailsystems.wordpress.com/196/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/silvertailsystems.wordpress.com/196/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/silvertailsystems.wordpress.com/196/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/silvertailsystems.wordpress.com/196/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/silvertailsystems.wordpress.com/196/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/silvertailsystems.wordpress.com/196/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/silvertailsystems.wordpress.com/196/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/silvertailsystems.wordpress.com/196/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=silvertailsystems.wordpress.com&blog=5811723&post=196&subd=silvertailsystems&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://silvertailsystems.wordpress.com/2009/01/27/heartland-response-minimizing-the-damage-breached-data/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/dec8eceef440805596b4b905e4b72181?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Mike Eynon</media:title>
		</media:content>

		<media:content url="http://silvertailsystems.files.wordpress.com/2009/01/breach.jpg" medium="image">
			<media:title type="html">breach</media:title>
		</media:content>
	</item>
	</channel>
</rss>