WEP
Last Post: March 12, 2010:
-
As to the previous post about WEP still in the retail sector, completely disagree with the post implying that it is still ubiquitous. My bread and butter in the 2 years before the PCI compliance deadline were all retailers. However as to the previous post about WEP being disallowed in a PCI compliant business is wrong, it only requires strong encryption, and as I mentioned I have a customer that still uses WEP, however the application that they use creates, an SSL session from the STA to the server, strong encryption, with mutual authentication and PCI compliant. Heck I have some non-retail customers that are so paranoid that they maintain a separate physical network for their WLAN and then connect it to the LAN via a firewall, even though they?re using WPA2 enterprise.
Btw I know the former CIO of TJX who just happened to be on watch when they got hacked, and it couldn?t have happened to a nicer guy!
Anyone remember, wasn?t it a Symbol 4131 running WEP?
- 1