controlgap.com

Posts about:

cryptography (2)

7 Things You Can Do To Deal With The Recent Format Preserving Encryption (FPE) Compromise | blog,pci,cryptography | Control Gap

Barely a year after NIST approved Format-Preserving Encryption (FPE) based on AES they've issued a news release that one of the approved modes has been broken. Since FPE is actively deployed within the payment industry this will have implications for payment security and users of this technology. But how bad is the problem? And if you happen to be affected, what can you do?

Read More

Why the Apple vs. FBI Dispute Is A Good Thing

The Internet and mainstream media has been ablaze with articles and opinion pieces about the dispute between the FBI and Apple over an iPhone used by one of the San Bernardino terrorists. The issue has polarized public opinion and drawn attention to longstanding tensions over access by law enforcement. The issue is complex and the implications are far reaching. The resulting debate is a good thing because it makes us think.

Read More

PCI Security Standards Council set to kill off SSL in PCI DSS/PA-DSS 3.1 updates | blog,pci,cryptography | Control Gap

The PCI council has released an announcement that they are preparing an updated version of the PCI DSS (v3.1) and PA-DSS (v3.1), where they will be detailing several clarifications and changes to requirements. One of the major changes that will be included in v3.1 is that all versions of SSL are no longer considered acceptable as “strong cryptography”. The bulletin from the council states that adherence to PCI DSS v3.1 and PA-DSS v3.1 standard will be immediate with future-dated requirements to allow organizations time to implement changes.

Read More