Blog

Recent Posts

  • Situation: New Year's Party 2008 - Now Tell Me What You Do Again?

    Dec 30, 2008
    Being in the software industry for more than 18 years, I’ve rarely been successful at explaining what I do to family and friends. They know I do something with computers but it stops there. They have no idea what B2B, MFT, ERP, SCM, or any of the other TLAs (three letter acronyms) that I refer to means.
    Read full post >
  • Gap in PCI DSS for Credit Card Pre-authorization Makes Encryption Key Rotation More Important

    Dec 09, 2008
    The Payment Card Industry’s Data Security Standard (PCI DSS) requires that Primary Account Numbers (PANs) be encrypted when stored, and specifically notes that track 2 data including CVV information never be stored. While this works great for transactions where the credit card is charged immediately - like at a point of sale - it causes a problem for companies that take credit card information at the time of sale but do not actually charge the payment until a later date. An example of this includes the situation where credit cards are not charged until a product is actually shipped from the retailer or manufacturer.
    Read full post >