Fpe

This Week's [in]Security - Issue 207 | insecurity | Control Gap
9 min read

This Week's [in]Security - Issue 207 | insecurity | Control Gap

Welcome to This Week’s [in]Security. Magecart exfiltration. More FPE Weakness. Big-Hacks: Exchange Hack. F5 Attacks. SolarWinds. New breaches:...

Read More >
This Week’s [in]Security – Issue 104 | insecurity | Control Gap
8 min read

This Week’s [in]Security – Issue 104 | insecurity | Control Gap

Welcome to This Week’s [in]Security. This week: NIST FPE update may render some deployed solutions weak, NIST formalizes TDES sunset, Magecart...

Read More >
NIST Update to Format Preserving Encryption Standard affects PCI Use Cases
4 min read

NIST Update to Format Preserving Encryption Standard affects PCI Use Cases

Last month NIST announced they were seeking feedback on a proposed updated guidance for FPE. More formally this is SP 800-38G rev 1 "Recommendation...

Read More >
This Week’s [in]Security – Issue 101 | insecurity | Control Gap
7 min read

This Week’s [in]Security – Issue 101 | insecurity | Control Gap

Welcome to This Week’s [in]Security. This week: detailed alert on trending e-commerce attack methods, PCI glossary for small business, PCI seeks...

Read More >
7 Things You Can Do To Deal With The Recent Format Preserving Encryption (FPE) Compromise | blog,pci,cryptography | Control Gap
2 min read

7 Things You Can Do To Deal With The Recent Format Preserving Encryption (FPE) Compromise | blog,pci,cryptography | Control Gap

Barely a year after NIST approved Format-Preserving Encryption (FPE) based on AES they've issued a news release that one of the approved modes has...

Read More >
Must (FPE) be distinguishable from cardholder data for PCI?
3 min read

Must (FPE) be distinguishable from cardholder data for PCI?

Previously we looked at Format Preserving Encryption (FPE) its characteristics and suitability for application in solutions intended for PCI DSS. To...

Read More >
What is Format Preserving Encryption and is it suitable for PCI DSS?
4 min read

What is Format Preserving Encryption and is it suitable for PCI DSS?

Format Preserving Encryption or FPE is recent technology that is beginning to show up in payment solutions with the promise of simplifying PCI DSS...

Read More >