<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Dave Hogan doesn&#8217;t know PAN</title>
	<atom:link href="http://chaordicmind.com/blog/2009/08/07/dave-hogan-doesnt-know-pan/feed/" rel="self" type="application/rss+xml" />
	<link>http://chaordicmind.com/blog/2009/08/07/dave-hogan-doesnt-know-pan/</link>
	<description>Mixing childlike wonder with adultlike understanding</description>
	<lastBuildDate>Wed, 14 Jul 2010 23:42:41 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=abc</generator>
	<item>
		<title>By: Weekend Redux &#8211; 08.09.2009 &#171; Security Stallions Blog</title>
		<link>http://chaordicmind.com/blog/2009/08/07/dave-hogan-doesnt-know-pan/comment-page-1/#comment-98</link>
		<dc:creator>Weekend Redux &#8211; 08.09.2009 &#171; Security Stallions Blog</dc:creator>
		<pubDate>Mon, 10 Aug 2009 02:50:23 +0000</pubDate>
		<guid isPermaLink="false">http://chaordicmind.com/blog/?p=77#comment-98</guid>
		<description>[...] Whether of not you&#8217;re a fan of PCI it&#8217;s always a good idea to know both sides of the story.  In that case the post over on Chaordic Mind is some enlightened reading and, if true, makes Dave Hogan (CIO of the National Retail Federation) look like, well, kind of a schmuck. [Dave Hogan Doesn&#039;t Know PAN] [...]</description>
		<content:encoded><![CDATA[<p>[...] Whether of not you&#8217;re a fan of PCI it&#8217;s always a good idea to know both sides of the story.  In that case the post over on Chaordic Mind is some enlightened reading and, if true, makes Dave Hogan (CIO of the National Retail Federation) look like, well, kind of a schmuck. [Dave Hogan Doesn&#39;t Know PAN] [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: admin</title>
		<link>http://chaordicmind.com/blog/2009/08/07/dave-hogan-doesnt-know-pan/comment-page-1/#comment-94</link>
		<dc:creator>admin</dc:creator>
		<pubDate>Fri, 07 Aug 2009 19:43:25 +0000</pubDate>
		<guid isPermaLink="false">http://chaordicmind.com/blog/?p=77#comment-94</guid>
		<description>Cranston, what I find ironic is that the NRF is telling the world that the card brands ate trying to shift risk, when in reality it is the card brands that are trying to protect innocent merchants from the failures of compromised merchants.

The card brands are ostensibly trying to help some NRF merchants from others who suffer data breaches.  Instead of helping out his constituency he puts ALL of the blame on others.

I didn&#039;t hear Dave say much about this in his testimony or 60 Minutes spot.</description>
		<content:encoded><![CDATA[<p>Cranston, what I find ironic is that the NRF is telling the world that the card brands ate trying to shift risk, when in reality it is the card brands that are trying to protect innocent merchants from the failures of compromised merchants.</p>
<p>The card brands are ostensibly trying to help some NRF merchants from others who suffer data breaches.  Instead of helping out his constituency he puts ALL of the blame on others.</p>
<p>I didn&#8217;t hear Dave say much about this in his testimony or 60 Minutes spot.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cranston Snoard</title>
		<link>http://chaordicmind.com/blog/2009/08/07/dave-hogan-doesnt-know-pan/comment-page-1/#comment-93</link>
		<dc:creator>Cranston Snoard</dc:creator>
		<pubDate>Fri, 07 Aug 2009 17:35:27 +0000</pubDate>
		<guid isPermaLink="false">http://chaordicmind.com/blog/?p=77#comment-93</guid>
		<description>Actually, the card companies COULD do more on fraud and could provide means which lower the exposure to merchants.  

The card companies can&#039;t use the &quot;we can&#039;t provide a one size fits all solution&quot; excuse for not doing more when they themselves are basically inflicting a one size fits all requirement with PCI DSS.

While a one-size-fits-all solution won&#039;t work, they certinly could try harder to provide some different sizes of solutions based on the current merchant levels.</description>
		<content:encoded><![CDATA[<p>Actually, the card companies COULD do more on fraud and could provide means which lower the exposure to merchants.  </p>
<p>The card companies can&#8217;t use the &#8220;we can&#8217;t provide a one size fits all solution&#8221; excuse for not doing more when they themselves are basically inflicting a one size fits all requirement with PCI DSS.</p>
<p>While a one-size-fits-all solution won&#8217;t work, they certinly could try harder to provide some different sizes of solutions based on the current merchant levels.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.435 seconds -->
