* Posts by Tiger Bay Cyber

2 publicly visible posts • joined 23 Oct 2015

TalkTalk offers customer £30.20 'final settlement' after crims nick £3,500

Tiger Bay Cyber

Tokenisation

Tokenisation means that somewhere there is a Service that handles the tokenisation requests from TalkTalk applications, the service maps the Cardholder's Primary Account Number to a Token. This mapping will be held in a secure Token Vault. If you have the right permissions, you can ask the Tokenisation Service to detokenise the PAN e.g. back to the original 16 digit number on the front of the card.

The key question for me is was this a Tokenisation Service run by TalkTalk? Or implemented by their payment provider or Bank / Acquirer? If it is managed by a competent third party then TalkTalk applications would be unlikley to be able to ask for a PAN to be detokenised.

I do not see Tokenisation being better that Encryption, it offers similar protection but in a different way, poor implementation can screw both up.

TalkTalk: Hackers may have nicked personal, banking info on 4 million Brits

Tiger Bay Cyber

New EU Data Protection Regulation

The draft EU Data protection regulation should sort that out €100M or 5% of global turnover fine for a serious breach (assuming this does not get watered down in the behind the scence horse-trading / lobbying).