Google Site Search

Google
 
Showing posts with label DataProtection. Show all posts
Showing posts with label DataProtection. Show all posts

Monday, June 11, 2012

LinkedIn has a wake up call

All the IPO fun news - soaring personal assets - increasing cash pile must have gone a bit sour at LinkedIn now. They have probably started living on earth now, like the rest of us. I am referring to http://blog.linkedin.com/2012/06/09/an-update-on-taking-steps-to-protect-our-members/  and http://www.nytimes.com/2012/06/11/technology/linkedin-breach-exposes-light-security-even-at-data-companies.html

I have been a LinkedIn member since inception. It feels like close to decade+. I respect and utilize their services on a daily basis. Their advances in technology primarily big data analytics impresses me.

But when customers/users provide you their information, then it is of utmost importance to safeguard it. LinkedIn failed to do that. But they are not alone. Everyday, we hear some data breach. The fundamental problem is that there is no easy way to secure anything. Passwords are useful to achieve the minimum level of security, with minimum set up. But they are not the best forms of security. Working toward preventing data breaches should be part of a daily routine.

The blog post from Vicente is very assuring. In the next few years, LinkedIn will probably have fewer news reports about data breaches. Hopefully, Ganesh Krishnan (from my alma mater, BMSCE) can shine.

What LinkedIn needs to do is take their advances in big data analytics into security intelligence. Salting/Hashing passwords is just the first step. You should incorporate device registration as well as use security analytics to thwart future breaches. Please be the first to show us the way with big data security analytics.

Good Luck to LinkedIn!

(Now can we please do something about the "Who viewed your profile?" leaks on LinkedIn on mobile apps?).

Thursday, April 16, 2009

Is PCI-DSS the panacea to Data Protection woes?

Looking at the battering that PCI-DSS has gone through at a recent US Government Congressional hearing, one might assume that PCI-DSS is just not sufficient for protecting customer data. The congressional hearing is discussed here.

The question should not be WHETHER it is sufficient for protecting customer data, the real issue is are there any other efforts in the industry to define something along the lines of PCI?

PCI is the first standard that has been drawn by the council that includes banks and the credit card companies and is a strict requirement for any entities processing credit card transactions at a large scale. Now, the standard has some rules and requires the expertise of security auditors to evaluate the state of any entity.

Again, the quality of auditors is also critical to the success of the standard. There is a need to work further on the standard to figure out the loop holes and opportunities for improvement, based on the real world experiences from credit card breaches that have happened ever since the standard was introduced.

There is no second chance to any vendor who loses customer data. It is just not reputation that is at stake, it costs MONEY. :(