4 ms·
There are two CVV codes, CVV1 and CVV2. CVV1 is on the magstripe but not printed on the card. CVV2 is printed on the card but not on the magstripe (it's the thr
by phantom784 13y ago
There are two CVV codes, CVV1 and CVV2. CVV1 is on the magstripe but not printed on the card. CVV2 is printed on the card but not on the magstripe (it's the three digit code printed on the back).
It sounds like Target was storing the CVV1 code (which they shouldn't have been), but there's no way they could have the CVV2 code, since the POS computer never sees it.
This means that the stolen data could be used to make a cloned card for physical purchases, but couldn't be used for an online purchase (unless the online store doesn't ask for the CVV2).
See http://en.wikipedia.org/wiki/Card_Verification_Value http://en.wikipedia.org/wiki/Card_Verification_Value
- mirkules 13y agoIf the POS terminals were compromised, attackers could have retrieved CCV1 numbers at the point of reading the card. In other words, it's still possible Target complied with the PCI requirement of not storing CCV numbers. But since nobody knows how the attack happened, it's all just speculation.
- gergles 13y agoAt target, you insert your card into a device that fully captures it. It's quite possible they could photograph both sides/OCR to find your CVV2. (AFAIK they don't, but there certainly isn't "no way" they could have it.)
- igreulich 13y agoNot at all Targets. I worked at several stores (up through 2008), and still shop there. I have never seen a credit card machine at the stores I have been in contacted that fully captures a credit/debit card.