Home Blog Page 171

Privacy Framework for XR and Spatial Computing Domain Launched

XR

After VR, AR, and Mixed Reality (MR), Extended Reality (XR) and Spatial computing are gradually becoming the newer frontiers of advancements in the space of information technology and going by the Hyponnen Theory, anything connected to the internet is vulnerable to cyberattacks. Privacy is among the major concerns raised on XR.

XR expands the definition of personal information that must be protected, including biometrically-inferred data, which is especially prevalent in XR data pipelines. You need to consider new rights for data subjects — ​the people whose information is collected and used—​to know what’s being collected, how it is used, and how it is shared. Immersion into XR experiences often calls for a breadth of sensitive information to be available to XR hardware, and here informed consent is of paramount importance.

To address this growing concern, the XR Safety Initiative (XRSI), an organization dedicated to help build safe immersive environments, has released the XRSI Privacy Framework Version 1.0. to help individuals and organizations address a comprehensive set of privacy needs, enabling more innovative and effective solutions to improve privacy in the Extended Reality (XR) and Spatial Computing domain.

“Emerging technologies, such as XR and Spatial computing, are transforming the way humans connect, create, commerce, and heal. This technological shift has the potential to expand our capabilities, enhance wellbeing, and influence every aspect of our lives. We must proactively address the privacy, safety, and deeper societal risks it brings along,” Kavya Pearlman, Founder and CEO of XRSI, told CISO MAG in an exclusive interaction.

“While we have not even fully addressed the cybersecurity challenges with existing technologies, a whole new wave of emerging technologies including virtual augmented and mixed reality (collectively known as XR), Brain-computer Interface (BCI) and rollout of 5G communication infrastructure is bringing a whole new set of novel cybersecurity challenges that we need to address as soon as possible,” she had suggested in an earlier interview with CISO MAG.

The framework is a free, globally accessible baseline rulebook built by bringing together a diverse set of experts from various backgrounds and domains, including privacy and cybersecurity, cloud computing, immersive technologies, artificial intelligence, legal, artists, product design, engineering, and many more.

Setting a Baseline

The privacy framework also incorporates privacy requirements drawn from the General Data Protection Regulations (GDPR), National Institute of Standards and Technology (NIST) guidance, Family Educational Rights and Privacy Act (FERPA), Children’s Online Privacy Protection Rule (COPPA), and other evolving laws. It is designed to adapt and include novel requirements as new regulations come into effect.

Google Cloud Levels-up Confidential Computing with Latest Updates

Google Cloud, Google Cloud Confidential Computing

Google has always believed in abiding by its users’ confidentiality concerns and rights. However, when it comes to data in its cloud, Google found its customers worrisome with the company’s confidentiality quotient. How can someone be confident about something they cannot see? To answer this, the technology giant launched its Confidential Computing Portfolio in an attempt to ensure data security. The first offering of Google Cloud’s Confidential Computing Portfolio – Confidential VMs – was launched in July 2020 as a beta. Google Cloud has now taken a step ahead and expanded its portfolio by introducing the beta version of the Confidential Google Kubernetes Engine (GKE) Nodes and made the previously launched beta of Confidential VMs generally available.

 Key Highlights 

  • Confidential GKE Nodes is the second product in Google Cloud Confidential Computing portfolio and will enable users to configure and run the entire GKE cluster using Confidential node pool. The GKE cluster will support all existing GKE features utilizing hardware memory encryption with AMD SEV hardware, leveraging Confidential VMs capability underneath.
  • Confidential VMs will become generally available soon and will include new product updates, including audit reports, new Identity and Access Management (IAM) tools, integrations with other enforcement mechanisms and vTPM support.

Making the Container Workloads Confidential

Google has notably seen its customers modernizing their existing applications and build cloud-native ones whose foundation is based on GKE. Thus, Google thought of delivering a new level of confidentiality and portability for containerized workloads. Google Cloud Confidential GKE Nodes are built on the same foundation as Confidential VMs. It allows users to keep their data encrypted in memory with a dedicated node-specific key that is generated and managed by the AMD EPYC processor.

Confidential GKE Nodes enable users to configure their GKE cluster to only deploy node pools with Confidential VM capabilities underneath. Google Cloud explains, “Clusters with Confidential GKE Nodes enabled will automatically enforce the use of Confidential VMs for all your worker nodes. GKE Confidential Nodes will use hardware memory encryption powered by the AMD Secure Encrypted Virtualization feature used by AMD EPYC™ processors, which means that your workloads running on the confidential nodes will be encrypted in-use. “

Making Confidential VMs Generally Available

Google Cloud already employs multiple isolation and sandboxing techniques as part of their cloud infrastructure and architecture security. However, with Confidential VMs, users can now protect the confidentiality of their most sensitive data in the cloud even while it is being processed. Confidential VMs leverage the Secure Encrypted Virtualization (SEV) feature of 2nd Gen AMD EPYC™ CPUs. With this technology adoption, the users’ data stays encrypted while it is being used, indexed, queried, or trained on.

Google has also reportedly worked closely with the AMD Cloud Solution engineering team to ensure that the VM’s memory encryption does not interfere with its performance metrics and instead match up with those of the non-confidential VMs.

With features such as real-time encryption, lift and shift confidentiality, detection of APT attacks, and optimized performance, the possibility of expansion of Confidential Computing technology has broadened.

CIPL and DSCI Stress on Enabling Cross-border Data Transfers Between India and U.S.

American Cybersecurity Literacy Act

The Data Security Council of India (DSCI) and the Centre for Information Policy Research (CIPL) have jointly released a report on enabling responsible cross-border data transfers between India and the U.S. with regard to India’s proposed Personal Data Protection (PDP) Bill. The report, “Enabling Accountable Data Transfers from India to the United States,” is intended to inform the Joint Parliamentary Committee’s review of the PDP Bill and Indian Government officials working on a potential future trade deal with the U.S. It also highlights the importance of accountable data processing mechanisms to govern data flows between the countries.

The Report Aims to:

  • Outline relevant provisions of the PDP Bill in Chapter VII (Restriction on Transfer of Personal Data Outside India) and section 50 on Codes of Practice that apply to transfers of data from India to the U.S.
  • Evaluate the PDP Bill’s transfer provisions in light of established mechanisms for cross-border data transfers in other global data protection regimes
  • Consider available options to govern India-U.S. data flows

According to the DSCI, the report suggested two practical options to enable data flows between India and the U.S. in line with the PDP Bill. These include:

Certifications and Codes of Practice: India can enable data flows to the U.S. by including certifications and codes of practice as data transfer mechanisms in the PDP Bill, which could become interoperable with other certification schemes and codes, including the APEC Cross-Border Privacy Rules (“CBPR”) and EU GDPR certifications and codes of conduct.

Adequacy Finding: India could facilitate transfers to the U.S. through the PDP Bill’s existing provision authorizing adequacy findings for data transfer purposes. Tools to facilitate such a finding could include an India-U.S. trade agreement specifying a commitment to recognize or elaborate upon relevant transfer mechanisms coupled with a formally binding cooperation agreement or MOU between the Indian Development Partnership Agreement (DPA) and the U.S. Federal Trade Commission (FTC).

The report was launched after a virtual roundtable discussion between the government officials of both the countries including Dr. Rajendra Kumar, Additional Secretary, Ministry of Electronics and Information Technology; Betsy Border, Counsel for International Consumer Protection, U.S. Federal Trade Commission; and James Sullivan, Deputy Assistant Secretary for Services Industry and Analysis U.S. Department of Commerce.

Rama Vedashree, CEO, DSCI, said, “Given the importance of U.S. geography for India’s tech industry, which is estimated to touch close to $100 billion this year,  DSCI and CIPL have undertaken the development of this report to propose potential mechanisms to facilitate data flows between the two countries; it also analyses potential challenges in transferring data outside of India under the context of the PDP bill 2019. We hope the report recommendations inform the privacy discourse in India, and the concerned stakeholders, especially the Joint Parliamentary Committee, in its deliberations, and also MeitY and Ministry of Commerce as they work towards growing India’s digital economy and the tech sector.”

Markus Heyder, Vice President and Senior Policy Counselor, CIPL, said, “In finalizing the PDP bill, India has a real chance to shape the data flow landscape it wants to participate in for the coming years. To ensure continued and responsible flow of data between both India and the U.S., India should seek to enable certifications and codes of practice that can be made interoperable with other global accountability and transfer schemes. India should also think about making an adequacy finding for CBPR certified entities, whether that is via an India-U.S. trade agreement or other means. By addressing these issues, the joint Parliamentary Committee will prevent unnecessary barriers to data transfers for the Indian economy while ensuring effective data protection for its citizens.”

Given India’s growing IT capabilities, digital exports represent a major export sector for the country. Cross-border data transfer is of critical value as India looks forward to updating its data privacy policy.

Do More with Less! SMBs Proactively Address Cybersecurity Challenges

Cybersecurity Investment Estimated to Grow up to 6% in 2020

Small to medium-sized businesses (SMBs) are procuring security tools to prevent cyberattacks with limited cybersecurity budgets and resources. According to the “SMB IT Security Report”  from Untangle, a provider of comprehensive network security for SMBs and distributed enterprises, SMBs are continuing to do more with less, with 38% of SMBs allocating $1,000 or less to their IT security budget, in comparison to 29% in 2019 and 27% in 2018. The report also revealed that 78% of SMB employees are working remotely, with an estimated 56% suggesting some positions will be permanently remote going forward.

“SMBs are proactively putting tools in place to combat attacks and limit their vulnerabilities even though they continue grappling with limited security budgets and resource constraints. However, dealing with these challenges during a work-from-home shift has created gaping vulnerabilities within an organization’s networks and adds another challenge to an already overburdened IT department,” the report stated.

Key Findings

  • Nearly 32% of SMBs identify budget as their greatest barrier, followed by employees who do not follow IT security guidelines (24%) and limited time to research and understand emerging threats (13%)
  • SMBs rank firewalls (82%), antivirus protection (57%), endpoint security (48%), archiving management and backup and VPN technologies, (47%), and Web filtering (40%) as the most important features when considering which IT security solutions to purchase
  • While SMBs have adopted a hybrid on-premises/cloud-based IT infrastructure for business applications, with a small percentage increase of cloud deployments compared to last year, most SMB’s (71%) have their firewall on site rather than in the cloud
  • Around 45% indicated that they have adjusted or reevaluated their IT security roadmap based on recent security breaches and ransomware attacks
  • Of those SMBs surveyed and who experienced a data breach within the last 12 months, 15% were able to stop the attack or any unauthorized access before sensitive data was extracted.

Scott Devens, CEO at Untangle, said, “As the abnormal becomes our new normal, SMBs need to approach remote work by using a combination of cloud-based applications and on-premises solutions to keep employees and systems safe, and ensure business continuity. SMBs should be looking for technologies that incorporate multi-layered network security tools and a hybrid network infrastructure, such as SD-WAN, to avoid large-scale network vulnerabilities, regardless of budget and resource size.”

1 in 3 SMBs Rely on Free Cybersecurity Tools

A similar research from BullGuard revealed that one in three small businesses with 50 or fewer employees rely on free or consumer-grade cybersecurity tools. The research also pointed out that one in five companies do not use any endpoint security whatsoever. The research, which surveyed small businesses in the U.K. and the U.S., suggested that nearly 43% SMB owners are not prepared for a potential cyberattack or breach leaving their most sensitive financial, customer, and business data at risk.

Imposter Scams Continue to be a Growing Concern for Senior Citizens: DoJ

Senior citizens data

The U.S. Department of Justice (DoJ) issued a fraud alert asking people to be vigilant when providing any sensitive information over the phone. The agency stated that cybercriminals are falsely representing themselves as DOJ authorities to obtain personal information from the call recipients as part of an imposter scam. The warning came after the Office of Justice Programs’ Office for Victims of Crime (OVC) received multiple complaints from individuals stating that they have received calls from unknown parties claiming to be from the DoJ.

Fake DoJ Investigators

According to the National Elder Fraud Hotline, scammers are calling elderly citizens to obtain personal details or leaving a voicemail with a return phone number, which directs them to a recorded menu and then to an operator claiming to be a DoJ’s investigator. The investigator further tries to trick the users into giving away their personal details. The National Elder Fraud Hotline is a resource created by OVC for people to report fraud.

OVC Director Jessica Hart, said, “Phone scams are an ugly and pervasive act of victimization. The scams being reported to our National Elder Fraud Hotline are especially heinous because they show the perpetrators are preying upon one of the most vulnerable segments of our society – the elderly. As if this were not despicable enough, the scammers do so pose as employees of the Justice Department, usurping public trust in the agency that serves as a bastion of fairness and lawfulness while these scams exploit the elderly for financial gain. The first step to identifying these criminals is to have their crimes reported.”

Cybercrimes Targeting Older Adults

Recently, the FBI warned users to be vigilant about online romance scams, in which cybercriminals exploit people looking for romantic partners on dating websites, apps, or social media networks. The agency noticed that the majority of the victims of romance frauds were single adults over the age of 55 in Utah, Idaho, and Montana. The FBI’s Internet Crime Complaint Center (IC3) stated that confidence frauds incurred huge financial losses to victims when compared to other cybercrimes. The IC3 received nearly 100 complaints from victims reporting more than $1 million in losses to romance scams in Idaho last year. Nearly 20,000 complaints related to romance scams were reported to IC3, with losses of more than $475 million.

Microsoft Fixes 129 Vulnerabilities in its September Patch Tuesday

Brand Phishing Attacks

Microsoft’s September Patch Tuesday saw the technology giant releasing updates to address 129 vulnerabilities: 23 of which were deemed critical, 105 were important, and the rest were moderate in severity. The latest Patch Tuesday addressed vulnerabilities in Microsoft Windows, the Edge browser, ChakraCore, Internet Explorer, SQL Server, Office and Office Services and Web Apps, Microsoft Dynamics, Visual Studio, Exchange Server, ASP.NET, OneDrive, and Azure DevOps.

The most critical ones identified in the Patch Tuesday include:

  • SharePoint (CVE-2020-1200, CVE-2020-1210, CVE-2020-1452, CVE-2020-1453, CVE-2020-1576, CVE-2020-1595)
  • SharePoint Server (CVE-2020-1460)
  • Graphics Device Interface (CVE-2020-1285)
  • Dynamics 365 systems (CVE-2020-16857, CVE-2020-16862)
  • Media Audio Decoder (CVE-2020-1593, CVE-2020-1508)
  • COM for Windows (CVE-2020-0922)
  • Text Service Module (CVE-2020-0908)
  • Codecs Library (CVE-2020-1319, CVE-2020-1129)
  • Camera Codec Pack (CVE-2020-0997)
  • Visual Studio (CVE-2020-16874)

Among the vulnerabilities were a crop of RCEs in Microsoft Office products, which particularly concerns students and teachers during the time of COVID-19 and e-learning. “Some of the most severe vulnerabilities in this month’s release include a pair of remote code execution flaws in Microsoft SharePoint and a critical vulnerability in Microsoft Exchange Server. CVE-2020-1210 is a vulnerability in SharePoint due to a failure to check an application package’s source markup. To exploit this flaw, an attacker would need to be able to upload a SharePoint application package to a vulnerable SharePoint site. This vulnerability is reminiscent of a similar SharePoint remote code execution flaw, CVE-2019-0604, that has been exploited in the wild by threat actors since at least April 2019,” stated Satnam Narang, Staff Research Engineer at Tenable, in a recent release to CISO MAG.

He added, “CVE-2020-1576 is another SharePoint flaw patched this month that’s also similar to CVE-2020-1210.CVE-2020-16875 is a memory corruption vulnerability in Microsoft Exchange Server due to improper handling of objects in memory. Exploitation of this flaw would simply require an attacker to send a malicious email containing the exploit code to a vulnerable Exchange server. This vulnerability would allow the attacker to run arbitrary code, which could grant them access to create new accounts, access, modify or remove data, and install programs.”

System administrators are advised to review the threat posed by RCE vulnerabilities as they could be exploited on Windows or SharePoint to corrupt or erase system data.

NetWalker Ransomware Gang Holds Argentina’s Immigration Agency at Ransom

covid-19 malware ransomware, netwalker ransomware

Argentina’s immigration agency, Dirección Nacional de Migraciones (DNM), suspended operations for over four hours after its systems were attacked by NetWalker ransomware. In order to free up the affected computers, the operators demanded $4 million worth Bitcoins in ransom. As per a local media report from Infobae, the government authorities said that they “will not negotiate with the hackers and neither are they too concerned with getting that (compromised) data back.”

 Key Highlights 

  • Hackers attacked Argentina’s immigration agency, Dirección Nacional de Migraciones (DNM) in the last week of August.
  • The immigration offices and control posts throughout the country had to be pulled offline for nearly four hours.
  • The SICaM system (Integrated Migration Capture System) used to track international crossings was heavily affected.

In the early hours of August 27, 2020, the DNM’s tech support started receiving multiple calls from various offices stating they were not able to access their Microsoft suite-based files (eg. Word, Excel). On closer inspection, the support team found that their computer systems, including Microsoft applications and shared folders, were hit by a computer virus, which incapacitated their operations. The IT team promptly took precautionary measures to contain the spread by shutting down their central server, which led to the four hours long service outage.

A Million Dollar Ransom Demand

According to the information shared by Bleeping Computers, NetWalker ransomware gang first demanded a ransom of $2 million in exchange of the decryption key. However, with no response from the government authorities, the gang decided to tighten the screws by increasing their ransom demand to 355 Bitcoins (accounting to nearly US$4 million) and releasing a sample of the leaked and encrypted data on the Tor site hosted by the cybercriminals.

Argentina: A Ransomware Hot Bed?

On July 18, 2020, an Argentine telecommunication services provider, Telecom Argentina, reportedly fell prey to a ransomware attack. The effects of the attack were first noticed when the Telecom’s employees started facing issues and lag in their systems while accessing the company’s VPN (virtual private network). The internal security systems instantly set-off the alarms but not before the ransomware was installed in over 18,000 workstations. According to reports and screenshots shared over Twitter, the ransomware gang demanded a ransom worth $7.5 million in Monero (XMR) cryptocurrency. Looking at the similarities in the modus operandi, some of the experts believe that the two attacks could have common perpetrators, although it is just an assumption.

Palo Alto Networks Partners with Net Friends to Boost Security Platforms

Cybersecurity firm Palo Alto Networks is partnering with managed IT services provider Net Friends to deliver exclusive access to its enterprise-grade product suite for businesses of all sizes.

Palo Alto Networks covers several segments like firewalls, cloud-monitoring and compliance, endpoint protection, and threat detection services. Based in North Carolina, Net Friends provides comprehensive managed IT services, IT security and strategy solutions to organizations.

Net Friends has built its managed service offerings around Palo Alto’s network security tools, including their firewalls and extended detection and response platform (Cortex XDR). The latest partnership allows Net Friends to deliver access to Palo Alto’s Advanced Threat Protection and DNS Security firewall subscriptions, Endpoint Protection products, and Cloud Application Security (Prisma) services.

John Snyder, President and CEO of Net Friends, said, “Net Friends first purchased six Palo Alto firewalls to protect our data centers and offices back in 2013, and we have been observing how they have stayed miles ahead of every other firewall or endpoint protection vendor in the market by prioritizing investments in security features. We have uncovered so many solutions we can bring to our customers.”

Recently, Palo Alto Networks also entered into an acquisition agreement with risk management and digital forensics consulting firm Crypsis Group in a proposed deal of $265 million. The acquisition strengthens Palo Alto’s security platform Cortex XDR by combining with Crypsis Group’s security consulting and forensics capabilities and enables in collecting rich security telemetry, manage breaches, and initiate rapid response actions. Palo Alto is also planning to integrate Crypsis Group’s processes and technology into Cortex XDR to further enhance its ability to safeguard organizations at every stage of the security lifecycle.

China Unwraps its Global Data Security Initiative

global data security initiative

In the recent past, China has been heavily scrutinized by countries like the U.S., India, and Australia for waging a cyberwar against their public, private, and critical infrastructure. The U.S. first cornered China with the Huawei cyber espionage claims and later with the TikTok data exfiltration accusation. Amidst all these accusations and allegations, Beijing has maintained that it has not crossed any lines of data sovereignty and shall continue to do so. Reassuring these words, Chinese Foreign Minister, Wang Yi, has unveiled China’s initiative that will set global standards on data security.

Wang Yi was addressing a global digital governance seminar in Beijing on September 8, 2020, where he introduced this initiative in a bid to bring all nations on the same page. He made his intentions clear as to what the initiative must include by talking about how technology firms must avoid creation of backdoors in their products and services that could allow data to be exfiltrated illegally. Wang Yi also urged the participants to respect the sovereignty, jurisdiction, and data management rights of other countries.

Wang Yi said, “Global data security rules that reflect the wishes of all countries and respect the interests of all parties should be reached on the basis of universal participation by all parties.” Taking an indirect jibe at the countries pointing fingers at it, he also added, “Some individual countries are aggressively pursuing unilateralism, throwing dirty water on other countries under the pretext of ‘cleanliness’, and conducting global hunts on leading companies of other countries under the pretext of security. This is naked bullying and should be opposed and rejected.”

The Need for a Global Data Security Regulatory Body

In a recent exclusive interview with Nikhil Korgaonkar, Regional Director, Arcserve India & SAARC, we asked him how multiple region-specific regulatory bodies restrict the growth of businesses and if there really is a need for a single data protection and privacy body. Korgaonkar said, “Businesses are reeling under the challenge of what we call compliance fatigue. GDPR in Europe; HIPAA, SOX, and FACTA in the U.S.; the California Consumer Protection Act, which came into force earlier this year; LGPD in Brazil; there is a multitude of compliance regulations that businesses face today. According to an estimate, CISOs spend 30% of their time dealing with compliance issues, an indication of how much productive mind space is being consumed by the fragmented regulatory landscape. There is certainly a need for a universal regulatory body and policy relating to data protection and privacy.

For that to happen, however, all the countries will need to come up with the same level of data security preparedness and understanding. It will have to be a symphony where each player plays their part to bring out a well-coordinated piece, which is music to everyone’s ears.”

New “Baka” Skimmer Designed to Evade Detection: Visa

one million card data exposed

Payment cards provider Visa has warned its users about a new credit card skimming malware dubbed “Baka” that can evade traditional detection methods. The skimmer was discovered by Visa’s Payment Fraud Disruption (PFD) division while analyzing a command and control (C2) server, which also found seven C2 servers hosting the Baka skimming kit.

Baka: The Unique Skimmer

Along with the basic features offered by various skimming kits, the Baka skimmer has certain advanced capabilities that helps it bypass security scanners. In addition, the skimmer can erase itself from the victim’s device’s memory after exfiltrating data.

“The most compelling components of this kit are the unique loader and obfuscation method. The skimmer loads dynamically to avoid static malware scanners and uses unique encryption parameters for each victim to obfuscate the malicious code. PFD assesses that this skimmer variant avoids detection and analysis by removing itself from memory when it detects the possibility of dynamic analysis with Developer Tools or when data has been successfully exfiltrated,” Visa said.

Indicators of Compromise

Visa observed the following seven domains hosting the Baka skimming kit:

Domain Names jquery-cycle[.]com

b-metric[.]com

apienclave[.]com

quicdn[.]com

apisquere[.]com

ordercheck[.]online

pridecdn[.]com

According to Visa’s PFD division, the skimmer performs five operations after it is injected.

  1. Generate a decryption function to decrypt the list of fields from which the skimmer will steal data.
  2. Skim the targeted fields every 100 milliseconds. When the attacker generates the skimming script for a victim, they specify which fields are targeted.
  3. Check if the skimmer found data every 100 milliseconds. This function then calls for data exfiltration and sets a flag called “this.load” indicating the skimmer successfully exfiltrated data.
  4. Check if the script should send data to the exfiltration gateway every 3 seconds. If the captured data flag is set, the exfiltration gateway URL is decrypted using the current victim merchant’s domain name as the key. The script then encodes the skimmed data into the GET parameters of the exfiltration URL.
  5. The last operation that is scheduled is a clean-up function. If data is exfiltrated, the clean-up function removes the entire skimming code from memory to avoid detection.

Mitigation Measures

  • Institute recurring checks in eCommerce environments for communications with the C2s.
  • Ensure familiarity and vigilance with code integrated into eCommerce environments via service providers.
  • Closely vet utilized Content Delivery Networks (CDN) and other third-party resources.
  • Regularly scan and test eCommerce sites for vulnerabilities or malware.
  • Regularly ensure shopping cart, other services, and all software are upgraded or patched to the latest versions to keep attackers out. Set up a Web Application Firewall to block suspicious and malicious requests from reaching the website.
  • Limit access to the administrative portal and accounts to those who need them
  • Require strong administrative passwords (use a password manager for best results) and enable two-factor authentication.
  • Consider using a fully hosted checkout solution where customers enter their payment details on another webpage hosted by that checkout solution, separate from the merchant’s site. This is the most secure way to protect the merchant and their customers from eCommerce skimming malware.