Feb 08

This is not your grandfather’s winter games. Every Olympic city makes major investments in technology, security and infrastructure in the 21st Century, and the Vancouver Winter Games are no exception.  The Olympic Cauldron will be lit on February 12, 2010. And yet, the hard work began immediately after Canada was selected to host the 2010 Winter Olympics back in 2004.

Want some examples?

1)      Technology companies are certainly talking about their unique role in these Games.  Green technology is a central element. Check out this Canadian website on technology related to the Olympics.

2)      Stopping terrorism is essential. One article back in 2005 estimated that the security budget would be about $177 million with a 50-50 split between the federal and provincial governments, but USA Today called actual security spending to be closer to $1 billionMore than 1000 security cameras are in place for the Winter Olympics.

3)      Infrastructure development has been important. There are plenty of stories online about the people behind the scenes who make the Olympic Games happen. There are also stories about the technology being used. If you look hard enough, you’ll find just about every big IT company is involved in some way. One example is Sun, but AT&T and others are right there as well.

4)      The economic development aspects and wider role of the Olympics can be seen in YouTube videos like this one.

5)      The role of the city mayors and Vancouver Government overall has been a huge part of this story.

Bottom line, this is big business. Just like the involvement of the South African Government in preparing for the 2010 World Cup in June, the Vancouver Olympic Games required an incredible investment in everything that we do in government technology every day. The difference is the scale, and the number of people watching.

So when you watch that beautiful opening or closing ceremony, when the US Hockey Team is skating to victory or those international downhill skiers fly past your TV screen, remember the technology and security infrastructure that made it all possible.

Let the games begin…

Feb 08

If you own a bank account or use credit cards, chances are you’ve heard the term “PCI compliant.” But you probably don’t know what it means.

The term is heard more and more frequently these days as data breaches at merchants like TJX, parent of TJMaxx, and payment processors Heartland Payment Systems and RBS WorldPay land millions of card records in the hands of hackers. Criminals are using the data to make purchases and withdraw money from accounts of unsuspecting victims who did nothing wrong; they just owned a card.

It’s a huge and growing problem. More than 80 percent of data stolen in breaches is payment card data, according to the 2009 Verizon Business Data Breach Report.

CNET asked Bob Russo, general manager of the PCI Security Standards Council, to explain what is being done to keep criminals from accessing consumer payment card data.

Q: So, what does the PCI Security Standards Council do?

Russo: The council was formed in September 2006 by the five major credit card brands, Visa, MasterCard, American Express, Discover, and JCB [Japanese Credit Bureau]. It was formed because each one of the brands has their own compliance programs and they still do, but they all use this standard as the foundation for their programs. There was a time when you could pick up the phone, call one brand, ask a security question, get one answer, call another brand, ask the same question, and get a different answer. They all now use the standards that we manage as the foundation for those compliance questions.

What is the standard exactly?

Russo: It’s the PCI, which stands for Payment Card Industry, data security standard. It’s a set of 12 requirements that cover six goals. It’s very prescriptive. It says not only that you need to be secure but also it tells you how to become secure. It’s more about security than compliance. The goals are things like building and maintaining a secure network, protecting cardholder data and regularly monitoring and testing the networks. That’s the main standard. We manage three different standards. The first one covers everything from the physical security to logical security.

The second standard is PADSS, Payment Application Data Security Standard. These are for payment applications a merchant would buy off the shelf. For example, if you went to a restaurant and you ordered your meal and the waiter used a touch-screen terminal, that puts the order in the kitchen and it’s tied to an ordering database. The application also takes the credit card at the end of the meal. We make sure these applications aren’t storing prohibitive data, such as data on the magnetic strip on the card. If they stored that data and someone got a hold of it then they would be able to clone credit cards. There are literally thousands of applications out there and when it’s compliant with the standard it is listed on our Web site.

“We have seen no evidence that if someone were compliant that they would have been breached. The standard is working. You only read about the one, two, or four big breaches that happen. You don’t hear about the thousands of merchants who aren’t getting breached because they are compliant.”

–Bob Russo, general manager, PCI Security Standards Council

The last piece we manage is called PTS, PIN Transaction System. Anytime you enter a PIN number, for example, this standard would take effect. It looks at those PIN entry devices so when you go to a large department store and you buy something and you use a debit card they’ll hand you a PIN pad and you key in your number. We certify those devices as well as unattended payment terminals, such as those used at gas station [islands], ticket kiosks, and transit systems, like the Boston underground.

via PCI compliance: What it is and why it matters (Q&A) | InSecurity Complex – CNET News.

Feb 08

LOCUS OSLOCATION BASED OPERATING SYSTEM – Multiple widget desktops designed around a location or activity ie Kitchen, Office, Car- Automatically switches between desktops with GPS and wi-fi mapping- Simplified Collections menu allows browsing via function rather than application. All rights for the icons used in this interface belong to their respectful owners.

Please contact me if you have designed any of the icons so I can credit you appropriately.
Note: This interface was designed before iPhone 3.0, Palm Pre, Android etc, making the ideas original at the time :

via Locus OS on the Behance Network.

preload preload preload