{"id":2052,"date":"2014-06-04T15:49:11","date_gmt":"2014-06-04T21:49:11","guid":{"rendered":"http:\/\/www.whitefirdesign.com\/blog\/?p=2052"},"modified":"2014-06-04T15:49:11","modified_gmt":"2014-06-04T21:49:11","slug":"trustwave-is-untrustworthy","status":"publish","type":"post","link":"https:\/\/www.whitefirdesign.com\/blog\/2014\/06\/04\/trustwave-is-untrustworthy\/","title":{"rendered":"Trustwave is Untrustworthy"},"content":{"rendered":"<p>When it comes to IT\u00a0security companies, what we see over and over is that they have little to no\u00a0concern for\u00a0security (and also often have little to no understanding of proper security practices). So it isn&#8217;t surprising that despite <a href=\"http:\/\/www.zdnet.com\/complexity-targeted-attacks-to-drive-security-spend-to-67b-7000016717\/\">billions being spent on IT security<\/a>,\u00a0IT security continues to be in such poor shape. This leads to situation like the massive breach of Target&#8217;s systems last year. While that was big news, what didn&#8217;t get much attention was the company who declared Target compliant with standards for handling credit card transactions shortly before the breach, Trustwave. Trustwave has a <a href=\"http:\/\/www.startribune.com\/business\/252963011.html\">history of declaring companies compliant shortly before they suffer major breaches and for being lax in their assessments<\/a>.<\/p>\n<p>We recently spotted another example of their highly questionable practices of Trustwave. We were contacted about doing a <a href=\"http:\/\/www.whitefirdesign.com\/services\/joomla-15-migration.html\">migration of a Joomla-based website still running version 1.5<\/a>, for which <a href=\"http:\/\/docs.joomla.org\/Joomla!_CMS_versions\">support ended in September 2012<\/a>. While taking a look at the website, we noticed a seal for Trustwave Trusted Commerce:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-2053 aligncenter\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/06\/trustwave-trusted-commerce-logo.png\" alt=\"Trustwave Trusted Commerce Logo\" width=\"105\" height=\"54\" \/><\/p>\n<p>Considering that the website is running software that is no longer supported and therefore cannot be considered secure, we were curious to see if Trustwave was claiming it was secure. It would be quite\u00a0easy for them to find that the website is running Joomla 1.5 if they wanted to as the source code of every page on the website the following line is included:<\/p>\n<blockquote><p>&lt;meta name=&#8221;generator&#8221; content=&#8221;Joomla! 1.5 &#8211; Open Source Content Management&#8221; \/&gt;<\/p><\/blockquote>\n<p>If you\u00a0click on the seal you get this page:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-2054\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/06\/trustwave-trusted-commerce-statement.png\" alt=\"Trustwave Trusted Commerce Statement\" width=\"500\" height=\"429\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/06\/trustwave-trusted-commerce-statement.png 500w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/06\/trustwave-trusted-commerce-statement-300x257.png 300w\" sizes=\"auto, (max-width: 500px) 85vw, 500px\" \/><\/p>\n<p>At the top of the page Trustwave\u00a0proclaims that &#8220;Your credit card and identity information are secure.&#8221;, which they shouldn&#8217;t be saying for a website that is running unsupported software.<\/p>\n<p>As we looked closer we noticed the small text disclaimer at the bottom of the page were they say\u00a0&#8220;Trustwave Holdings, Inc. makes no representation or warranty as to whether [redacted]\u00a0systems are secure from either an internal or external attack or whether cardholder data is at risk of being compromised.&#8221;. So they are basically telling you that despite saying &#8220;your credit card and identity information are secure&#8221;, there not actually saying that at all.<\/p>\n<p>It is highly inappropriate for them to mislead the public like they are doing with this seal, but unfortunately our experience is that this kind of thing is considered acceptable in the security industry.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>When it comes to IT\u00a0security companies, what we see over and over is that they have little to no\u00a0concern for\u00a0security (and also often have little to no understanding of proper security practices). So it isn&#8217;t surprising that despite billions being spent on IT security,\u00a0IT security continues to be in such poor shape. This leads to &hellip; <a href=\"https:\/\/www.whitefirdesign.com\/blog\/2014\/06\/04\/trustwave-is-untrustworthy\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Trustwave is Untrustworthy&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[25,19],"tags":[],"class_list":["post-2052","post","type-post","status-publish","format-standard","hentry","category-bad-security","category-joomla"],"_links":{"self":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/2052","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/comments?post=2052"}],"version-history":[{"count":3,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/2052\/revisions"}],"predecessor-version":[{"id":2057,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/2052\/revisions\/2057"}],"wp:attachment":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/media?parent=2052"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/categories?post=2052"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/tags?post=2052"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}