Home / Companies / Evervault / Blog / January 2024

January 2024 Summaries

6 posts from Evervault

Filter
Month: Year:
Post Summaries Back to Blog
Enclaves is a product designed to offer secure environments for running security-critical workloads, enabling users to verify the use of their personal data. The text details a comprehensive guide on structuring a product using Enclaves, exemplified through developing a mock key-sharing product that addresses the private key custody problem, particularly relevant in cryptocurrency contexts. This guide covers the entire process from understanding the problem to designing a solution using Enclaves, highlighting the technical aspects such as system architecture and the Enclaves Attestation process. It demonstrates the benefits for both users and providers, emphasizing security, trust, and user empowerment by ensuring private keys are managed securely, without direct user handling. The guide also includes practical advice for developers on implementing Enclaves in projects, underscoring the importance of open-source code and user attestation to maintain trust and security.
Jan 22, 2024 3,635 words in the original blog post.
Evervault, a Level 1 Service Provider specializing in FinTech and payment security, has successfully leveraged YubiKey technology to achieve PCI DSS v4 compliance, ahead of its mandatory implementation date in March 2024. Collaborating with Prescient Security, Evervault focused on integrating YubiKeys as a part of their multi-factor authentication strategy to mitigate brute force attacks, which traditionally require account lockouts. By using YubiKeys, Evervault addresses the PCI DSS v4 requirements for securing cardholder data while offering a user-friendly alternative to standard lockout mechanisms. This approach not only enhances security but also streamlines compliance processes by continuously improving and maintaining the security controls with less manual effort. The partnership with Prescient Security proved invaluable, enabling Evervault to implement a customized validation approach, which meets the standards of PCI DSS and provides a robust defense against unauthorized access, thereby reinforcing their commitment to state-of-the-art security and compliance in the payment industry.
Jan 18, 2024 1,637 words in the original blog post.
Evervault has launched significant data security features, including a Confidential Computing Solution powered by Enclaves, which are secure computing environments designed to protect sensitive workloads with enhanced data protection and ease of use. The company has also introduced customizable UI Components that allow secure collection and display of customer credit card data, rebuilt with a new styling API for greater control over their appearance. Additionally, Evervault has unveiled an Inspect API that provides metadata about encrypted values without accessing the plaintext, offering valuable insights for encrypted card numbers. The text also highlights the upcoming mandatory transition to PCI DSS v4 standards starting March 31, 2024, advising companies to prepare for these regulatory changes to optimize payment security and compliance strategies.
Jan 11, 2024 511 words in the original blog post.
Evervault has launched a new Confidential Computing solution alongside the general availability of Evervault Enclaves, aiming to enhance data security and compliance by simplifying the implementation of confidential computing. This technology creates isolated, secure environments for processing sensitive data, addressing the limitations of traditional perimeter defenses like network firewalls. Despite the potential of confidential computing, enterprise adoption has been slow due to the need for application refactoring and specialized development. Evervault's solution aims to overcome these challenges by making it easier to integrate confidential computing into existing workflows, offering features such as fully isolated environments, encrypted data processing within enclaves, verifiable code authenticity, and compatibility with Dockerfiles and Evervault's encryption products. This approach facilitates secure operations like cryptographic key management and healthcare data sharing, ensuring that sensitive data is processed and shared securely and in compliance with regulations.
Jan 10, 2024 1,139 words in the original blog post.
In this episode of Decrypt, Shane and John Hetherton, Head of Compliance at Evervault, discuss the transition from PCI DSS v3.2.1 to the more robust v4.0 and its implications for organizations handling online payments. The conversation highlights the key differences between the two versions, notably the shift to an outcome-based approach that allows organizations to customize their compliance measures, provided they meet the intended security outcomes. John shares his journey into cybersecurity, emphasizing the importance of understanding and adapting to evolving standards, and outlines Evervault's proactive steps in achieving early compliance with v4.0, which includes leveraging tools like Vanta for operational efficiency. The discussion also covers the challenges and considerations for organizations in migrating to v4.0, including the potential complexity of the new customized validation controls and the importance of reevaluating whether handling card data directly is necessary. The episode concludes with advice on engaging with QSAs and considering the strategic outsourcing of card data processing to reduce compliance burdens and associated risks.
Jan 09, 2024 4,160 words in the original blog post.
As of March 31, 2024, the Payment Card Industry Data Security Standard (PCI DSS) will transition from version 3.2.1 to the more robust version 4.0, which emphasizes a goal-oriented approach over prescriptive requirements while maintaining a high standard of security for handling Primary Account Numbers (PANs). This change affects organizations involved in processing online payments, such as SaaS applications and e-commerce platforms, which must comply to avoid fines. The shift to PCI DSS v4.0 provides a chance for businesses to reassess their handling of cardholder data, potentially reducing costs and enhancing security by adopting strategies such as descoping, which involves minimizing the Cardholder Data Environment (CDE) through methods like third-party encryption services. Organizations can choose between a lift-and-shift approach, which makes minimal changes to meet the new standard, or a more comprehensive reevaluation that may lead to long-term security improvements and easier compliance. Ultimately, the goal is not just achieving compliance but ensuring the responsible and secure management of cardholder data, with solutions like Evervault providing support for this transition.
Jan 03, 2024 1,480 words in the original blog post.