The end of the year usually brings with it the annual tradition of consulting the InfoSec "crystal ball" to create a list of prognostications of doom for the coming year. Let's start a new tradition of looking back at the things that brought improvements in the past year. It’s not often that we take a moment to think about what we in security are grateful for. And as we approach the time of year when all the security gurus bring out their crystal balls and prognosticate what the Big Bad of the coming year will be, I would like to take a moment to think about things that have happened in the past year that have been improvements. As I found so much news from this year to be grateful for, this represents my top five security-specific developments:The end of Windows XP support It’s not a good thing for security when people are using an operating system that is over a decade old. Windows XP was much beloved, and a lot of people had a very hard time letting it go, despite its many security issues. Microsoft ended support for XP this April, prompting people to (slowly but surely) finally get off the antiquated operating system. At the time of writing, the XP market share finally sank below 20 percent; and by web-usage, it now represents just over 11 percent. As the holiday shopping season approaches, I expect that we will continue to see its market share decrease. Major bugs lead to improvements Discovering major vulnerabilities is not generally good news. But if it brings to light years-old bugs and prompts people to fix them, it can be an improvement on the whole. We had three doozies this year: Heartbleed, Shellshock and Poodlebleed. The Heartbleed bug was the most recently introduced; it was only three-years-old. Shellshock, on the other hand, included versions of bash from 1989. Poodlebleed was a bug in 15-year-old software that was still in common use. These vulnerabilities existed for quite some time, and we don’t know how many times those bugs were used to attack people before this became common knowledge. But because of the massive outreach and coverage surrounding these events, a lot of people stopped using or supporting some seriously antiquated and vulnerable software. EMV adoption speeds up Last year’s Target breach was very bad news; as many as one-third of Americans were affected. But on the plus side, because this happened in such close proximity to other major breaches as well as a looming milestone for adopting EMV, this seems to have changed the prevailing attitude from dread to enthusiasm. In October, the White House announced the BuySecure initiative that unveiled tools to help consumers protect their payment card data. This included an announcement by Home Depot, Target, Walgreens and Walmart that they would start activating EMV terminals by January 2015, nine months in advance of the deadline. But major vendors are not the only ones at risk for card data theft. So as not to leave smaller vendors behind, in July Square announced that it is working on a version of its popular card reader that will accept EMV cards. Tokenization of credit card data. While EMV is an improvement over 40-year-old magstripe technology in use in the US, it is not a panacea. EMV is already 15-years-old, and while it does improve security at point-of-sale terminals, fraud may still be a problem when a physical card is not used. Given the increase in online and mobile payments, that’s a pretty significant hole. But people are looking beyond EMV towards the next layer to improve payment card security. In February, a group of 22 of the world’s largest banks called for tokenization of payment card data. And in September, this technology got a big boost as Apple announced Apple Pay, which will include tokenization. Improvements in Two-Factor Authentication (2FA) Last year seemed to be the year of 2FA, with a number of major sites and services adding this functionality to their user accounts. This year, that trend continues to pick up speed. This year, both Google and Apple announced improvements to their authentication offerings. After the iCloud leak in September, Apple increased the range of information protected when users add 2FA. In October, Google added support for a hardware device called Security Key, which is a stronger second factor of authentication.While there is a long way to go in security, it’s important to acknowledge victories. We can all point to horrible events in security, and many of those were allowed to pass with little change beyond the one affected vendor. As more people become aware of security, and feel the pain of its absence, they are demanding stronger improvements to protect them in the future. What are you thankful for in 2014? Related content opinion Of mice and malware Some of the most important training I got for a career in computer security research was not from a computer-related class, but in a biology class. While these two disciplines may seem entirely unrelated, the skills that are needed in both cases can By Lysa Myers Jul 03, 2019 6 mins Malware IT Skills Staff Management opinion Have we doubled the number of women in infosec? According to a recent (ISC)2 report, women now comprise 20% of cybersecurity workers. But without defining what jobs are being included, it’s unclear whether we’re truly making progress. By Lysa Myers Feb 11, 2019 5 mins Technology Industry IT Skills Staff Management opinion Has the word ‘breach’ has outlived its usefulness? When someone says a data breach has happened, it’s generally understood to mean that attackers have broken into a company and stolen sensitive information. But after a growing number of high-profile privacy gaffes, the definition of “brea By Lysa Myers Nov 28, 2018 5 mins Data Breach Technology Industry Data Privacy opinion Stop training your employees to fall for phishing attacks Training your employees how to recognize and avoid phishing only works if trusted emails don’t look the same as criminals'. By Lysa Myers Jul 10, 2018 4 mins Phishing Social Engineering Security Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe