<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Finance on OpTe.ch</title><link>https://www.opte.ch/tags/finance/</link><description>Recent content in Finance on OpTe.ch</description><generator>Hugo</generator><language>en</language><copyright>&amp;copy; Mike Oertli</copyright><lastBuildDate>Fri, 07 Feb 2014 13:21:05 -0700</lastBuildDate><atom:link href="https://www.opte.ch/tags/finance/index.xml" rel="self" type="application/rss+xml"/><item><title>Credit Cards With Increased Security, Work Offline</title><link>https://www.opte.ch/news/credit-cards-with-increased-security-work-offline/</link><pubDate>Fri, 07 Feb 2014 13:12:48 -0700</pubDate><guid>https://www.opte.ch/news/credit-cards-with-increased-security-work-offline/</guid><description>&lt;p&gt;For years countries outside the United States have used a system called &lt;a href="http://en.wikipedia.org/wiki/EMV" target="_blank" rel="noreferrer"&gt;EMV&lt;/a&gt; for their credit cards. The short version is that there is a chip inside the card that authenticates the transaction, plus the users has to enter a PIN instead of signing the receipt*. This has some major benefits. The biggest is security, and after the Target credit card leak I think that&amp;rsquo;s becoming more important to everyone. If someone steals your credit card number, they&amp;rsquo;ll still need your PIN to make charges.&lt;/p&gt;</description></item><item><title>Target Credit Card Breach</title><link>https://www.opte.ch/news/target-credit-card-breach/</link><pubDate>Mon, 20 Jan 2014 17:31:02 -0700</pubDate><guid>https://www.opte.ch/news/target-credit-card-breach/</guid><description>&lt;p&gt;The breach of data from Target (along with Neiman Marcus and reportedly a few more) seems to be getting worse by the day. There are some things I find highly concerning.&lt;/p&gt;
&lt;h3 id="first-some-facts" class="relative group"&gt;First, some facts. &lt;span class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100"&gt;&lt;a class="group-hover:text-primary-300 dark:group-hover:text-neutral-700" style="text-decoration-line: none !important;" href="#first-some-facts" aria-label="Anchor"&gt;#&lt;/a&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ol&gt;
&lt;li&gt;Attacks started on November 27, 2013 (just in time for Black Friday).&lt;/li&gt;
&lt;li&gt;The attack went unnoticed until December 15, 2013, over two weeks later.&lt;/li&gt;
&lt;li&gt;Hackers got names, addresses, email addresses, and phone numbers of 70 million people; 11GB of data total.&lt;/li&gt;
&lt;li&gt;Siphoned data has been sent to Russia and who knows where else from there.&lt;/li&gt;
&lt;li&gt;Attackers used a &lt;a href="http://www.wired.com/threatlevel/2014/01/target-malware-identified/" target="_blank" rel="noreferrer"&gt;RAM scraper&lt;/a&gt; to capture un-encrypted data from point-of-sale systems after the credit card swipe, but before it was encrypted and sent to a central location for routing to the credit card companies.&lt;/li&gt;
&lt;li&gt;Target and Neiman Marcus both passed all annual compliance testing for their handling of credit card data by the credit card industry standard (&lt;a href="http://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Security_Standard" target="_blank" rel="noreferrer"&gt;PCI-DSS&lt;/a&gt;).&lt;/li&gt;
&lt;li&gt;A &lt;a href="http://www.wired.com/threatlevel/2010/03/tjx-sentencing/" target="_blank" rel="noreferrer"&gt;similar attack&lt;/a&gt; happened in 2005.&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id="why-does-this-keep-happening" class="relative group"&gt;Why does this keep happening? &lt;span class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100"&gt;&lt;a class="group-hover:text-primary-300 dark:group-hover:text-neutral-700" style="text-decoration-line: none !important;" href="#why-does-this-keep-happening" aria-label="Anchor"&gt;#&lt;/a&gt;&lt;/span&gt;&lt;/h3&gt;&lt;p&gt;The short answer is pretty simple, as disappointing as it is. The industry standard is subpar, retailers are too cheap to upgrade, and people are frequently reactive in nature. Now there&amp;rsquo;s something to react to, let&amp;rsquo;s see if it works.&lt;/p&gt;</description></item></channel></rss>