mastodon.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
The original server operated by the Mastodon gGmbH non-profit

Administered by:

Server stats:

361K
active users

#pci

3 posts3 participants0 posts today

#железо #вопрос

А существует какой-то стандарт (или хотя бы логическое объяснение) расположения монтажа компонентов на #PCI-карточках?

Почему в подавляющем большинстве случаев они встают в tower как бы вверх ногами?

Так меньше пылится или просто «исторически сложилось? 🤔

@rf
@ru
@Russia
@russian_mastodon

Alright, #infosec crew! ✌️

So, PCI DSS v4... that deadline's closing in fast, isn't it? 😳

A&F dropped some serious insights on this: We're talking Script Security, Change Detection, Vendor Risks... the whole shebang!

Look, CSP alone just ain't gonna cut it, sorry not sorry. 🤷‍♂️ Third-party vendors? They're often the number one back door. Gotta check those dependencies, seriously!

Compliance isn't a "set it and forget it" kind of deal. You need constant monitoring, folks! ☝️

And let's be real: Who here has actually mapped out their entire PCI DSS v4 plan? 🤔 Or are you still stuck playing Minesweeper? 😂

Replied in thread

@RedPacketSecurity In today’s digital world, businesses must comply with various cybersecurity regulations to protect sensitive data and avoid legal penalties. Understanding and implementing these regulations can be complex, but it’s essential for data security, customer trust, and business continuity.

Key Cybersecurity Regulations to Consider:
✅ blpc.com/cyber-security/hipaa-
✅
✅
✅ DSS
✅ 2

B&L PC Solutions, Inc.HIPAA Compliance Service Long Island, NYProtect patient data with industry-standard security. Contact B&L PC for HIPAA compliance services on Long Island to ensure privacy and avoid penalties.

Hey everyone! Big news: the PCI DSS 4.0 deadline is coming up fast! This time, DMARC is becoming mandatory for *anyone* handling credit card data. I know, it sounds like a pain, but trust me, it's *super* important. Phishing is still a massive threat, unfortunately. 🙄

So, what's the deal with DMARC? Think of it as a bouncer for your inbox. It helps block those sneaky, fake emails. Seriously, without DMARC, your company's basically an open invitation for cybercriminals. 🚪

A lot of folks are probably thinking, "Nah, doesn't apply to me." Nope! Even small businesses *have* to implement DMARC. It's a must-do! 💪

Now, I'm curious: Do you guys already have DMARC set up? And if you do, what tools are you using? Let's share some insights! 🤔

Διαθέτουμε 1,25 δισ. € για διασυνοριακά έργα ενεργειακών υποδομών.

Αυτά τα έργα κοινού ενδιαφέροντος (ΕΚΕ/ΕΑΕ) θα συμβάλουν στην απανθρακοποίηση, ολοκλήρωση της αγοράς & ανταγωνιστικότητα.

🔗 europa.eu/!HtQ7kw

#EnergyUnion #EnergyInfrastructure #PCI #PMI
---
nitter.privacydev.net/EEAthina

Really had to read this article for my current project:

Raynaud et al. 2023 “Performance and limitations of linkage-disequilibrium-based methods for inferring the genomic landscape of recombination and detecting hotspots: a simulation study”

peercommunityjournal.org/artic

peercommunityjournal.orgPerformance and limitations of linkage-disequilibrium-based methods for inferring the genomic landscape of recombination and detecting hotspots: a simulation study

Key Management Lifecycle
Best Practices

Failure to securely manage #cryptographic keys may lead to security breaches and data loss. There are also various regulatory requirements and guidelines related to key management, such as #PCI #DSS, #GDPR, #HIPAA, and #NIST which ensure the confidentiality, integrity, and availability of sensitive data and systems that use cryptographic keys.

This document provided by Cloud Security Alliance serves as guidance for enterprise technologists and service providers to effectively and securely manage cryptographic keys throughout the key management lifecycle.

s3.amazonaws.com/content-produ

The PCI-DSS spec requires that card numbers (PANs) are hashed with a "keyed hash" to render them unreadable and suggests HMAC, CMAC or GMAC. Putting aside issues of nonce reuse in GMAC, surely you at least want the hash to be a PRF for this usecase? GMAC seems like such a weird choice here, especially as PANs are short, so GMAC is unlikely to have much of a speed advantage.