I was speaking with a colleague at a large financial institution. The topic: can organizations “push” information (e.g., bank statements) to consumers via email and still be compliant with the FFIEC guidelines (on the insufficiency of single factor authentication)? After thinking about it, I believe the question is broader: Is security adequate when p ...
I’ve been working with smart cards for a most of a decade, and there is a relatively new spin on the technology that merits discussion – the personal portable security device (PPSD). It combines the USB smart card form factor and USB flash memory on a single platform. Unlike older USB devices that had both components but functioned in a standalone man ...
In my March 10, 2008 blog entry “Short and to the point, if not so sweet” regarding the electronic capture and publication of medical records, I discussed how we frequently mask or defer basic issues by focusing our attention on something else. As Dr. Molly Coye stated in USA Today regarding the potential misuse of medical records: “But those are human actions. ...
Using the 2008 RSA conference as its platform, Hitachi announced the acquisition of majority shares in M-Tech. The new formed company will operate under the name Hitachi ID Systems and be rolled into Hitachi’s information security portfolio. Hitachi ID Systems will operate as a subsidiary of the Hitachi parent company.
Some of you may have read that the proprietary symmetric key cryptographic algorithm of the MIFARE Classic card has been broken. The MIFARE Classic card is used in physical access control systems (PACS) and contactless payment systems (including tollway and public transportation systems). By some estimates, there are 500 million MIFARE cards deployed worldw ...