3 ms·
Ideally it’s not even stored…
by ericmay 1mo ago
Ideally it’s not even stored…
- tbrownaw 1mo agoWell at least they need it until they get back a success response from the bank/payment processor/whoever.
- Tangurena2 1mo agoIn the Heartland data breach, the custom malware that hackers wrote copied the mag stripe as it passed through the payment system. I got a new credit card after that broke (also after Target's breach was reported). Heartland did not store the card details at all. How it was discovered was some dumb luck when an auditor asked what seems like a dumb question. When you type dir or ls at a command prompt, it says something like "X files using Y bytes, Z bytes free". How do you know those numbers are true/correct? It turns out that the malware changed how the OS reported those numbers (falsely as it turned out). Heartland - #19, Target - #20 at: https://www.upguard.com/blog/biggest-data-breaches-us https://www.upguard.com/blog/biggest-data-breaches-us You may notice that the poster of the comment you are responding to is mentioned a lot on that page.
- CrazyMusicians 1mo agoThat's a pretty decent list of breaches. Never seen it before. Thanks for sharing. I can't believe they didn't mention the Ashley Madison breach, which affected more than 30 million people, ended countless marriages, and led to more than a few suicides.
- coredog64 1mo agoThey're typically stored as "tokenized" values. The tokenized version shares the type and the last 4 digits (so that you can share it with the customer to help them identify the card). You buy this capability from vendors and IIRC there's like 3 or 4 common vendors in the marketplace.