4 ms·
Interesting. Were they storing/operating unsalted plaintext credit card info? I hope not.
by mangatmodi 6y ago
Interesting. Were they storing/operating unsalted plaintext credit card info? I hope not.
- fargo 6y agomost people do unfortunately
- InsomniacL 6y agoOnly a couple thousand had their Credit Card details stolen whereas nine million had information stolen. This sounds like they were able to access the database to steal customer information and plant code on the website to scrape any future transactions before the Credit Card information is encrypted in the database.
- Nextgrid 6y agoCredit card information is needed as-is to be able to make transactions so hashing (and thus salting) doesn’t apply. Encryption is the best you can do.