Paul’s Security Weekly (Video)
Technology
Version 4.0 of the Payment Card Industry Data Security Standard (PCI DSS) puts greater emphasis on application security than did previous versions of the standard. It also adds a new “customized approach” option that allows merchants and other entities to come up with their own ways to comply with requirements, and which also has implications for application security. Specifically, PCI DSS 4.0 requires that by March 31, 2025, more testing of public-facing applications related to payment processing or other activities be considered “in scope” for compliance. Generally, any system that touches payment-card data is in scope for PCI DSS compliance, whether or not the system or function is public-facing. We'll talk through what organizations should have gotten done by March 31, 2024, and what needs to happen by March 31, 2025.
Segment Resources: https://info.obsglobal.com/pci-4.0-resources
Show Notes: https://securityweekly.com/psw-825
Interview with Bill Cheswick - PSW VAULT
L0pht Heavy Industries Panel - PSW Vault
Plain Text Keystrokes, WPBT, One Packet Exploits, & Sock Puppets! - PSW #787
Spotlight on Penetration Testers - Vlad Gostomelsky - PSW #787
Post-Exploit, Vocal Passports, Will it Run DOOM!?!, & Coldplay Lyrics in Firmware - PSW #786
Generative AI Security Implications, Protecting Web Applications - Liam Mayron - PSW #786
Texas A&M Prof Fails, Windows Vs. iPhones, Cobalt Strike on Mac, & SHA-1 in Shambles - PSW #785
Artificial Ignorance & Pen Testing - Kevin Johnson - PSW #785
SBOMbshells, Honeytokens, Fixin It in the Future, & Immortal Modems - PSW #784
Mastering Penetration Testing: Critical Tasks & Essential Tools for Success - Paula Januszkiewicz - PSW #784
No Pr0nHub 4 U, HTTP Lock Status, Selling Hacking Tools, & Chrome Drops HTTP Lock - PSW #783
Pen Testing Techniques and Jurassic Malware - Rob Fuller - PSW #783
Hack All The Things With Flipper Zero - Kaitlyn Handelman - PSW #782
SSD AI/ML, Salsa for your Software, Hacking Smart TVs with IR, & Getting Papercuts - PSW #782
Under the Weather (Taxonomy?), Beating Roulette, Monitoring Macs, & XBMC Glory Days - PSW #781
Supply Chain Security - Ivan Arce - PSW #781
Stolen Cred Bizarre, US CyberSec, Stealing Cars With Headlights, & AI Censorship - PSW #780
Social Engineering & Conquering Impostor Syndrome - Billy Boatright - PSW #780
Rorschach, QNAP, We Got Hacked, SystemD, UTF-8, & Grub2 Music - PSW #779
Cybersecurity Workforce Development - Sin Ming Loo - PSW #779
Create your
podcast in
minutes
It is Free
Insight Story: Tech Trends Unpacked
Zero-Shot
Fast Forward by Tomorrow Unlocked: Tech past, tech future
Lex Fridman Podcast
Elliot in the Morning