4 ms·
Target hackers stole encrypted bank PINs, according to source [video]
- fiberoptick 13y agoWhy were they storing the PINs?
- astrodust 13y agoI'm not familiar with the US system, but here in Canada you're not even supposed to get the PIN in the first place. The keypad is supposed to encrypt it and use it for one transaction only. Then that information is discarded. Storing PINs in any form is absolutely insane. People deserve to get fired for this.
- dlubarov 13y agoIt's the same here - pins must be encrypted by a tamper-resistant hardware pin pad (in this case Verifone's). I don't think Target was storing pins, which is prohibited regardless of encryption. It sounds like the attackers sniffed encrypted pins.
- panarky 13y agoThere's no evidence that PINs were stored on Target systems. PINs should be encrypted by the Verifone pinpad itself, using keys that were burned into the device by the manufacturer. If the attacker compromised the pinpad device, then it's possible for unencrypted PINs to be intercepted at the point of entry. If the POS device or the store network was compromised, then encrypted PINs could be harvested on the wire.
- ars 13y agoI think they got the PINs on the fly, as they were being entered.
- cynwoody 13y agoNot likely, given the large number of compromised cards. What is likely, and also not very significant, is that they intercepted encrypted PIN blocks along with unencrypted mag stripe data. Of course, if they managed to decrypt the encrypted PINs, that would be huge. But I highly doubt it. A PIN-pad is a tamper-resistant, self-contained systems that accepts the PIN from its key pad, encrypts it on the fly using secret keys burned in by the supplier, and uploads the entered PIN in the form of a fixed-length encrypted "PIN block" which can only be decrypted by the payment processor. Therefore, in order to get the PINs on the fly, the bad guys would have had to physically compromise a large number of POS terminals at a large number of stores at high risk of getting caught. That's not plausible. What is plausible is that they broke into Target's corporate network and tapped the transaction flow between the POS terminals and the payment processors. That would give them the mag stripes and any encrypted PIN blocks entered, but not the unencrypted PINs. There was a case† a few years ago in Rhode Island in which banks experienced a spate of disavowed ATM withdrawals. They noticed that the complaining customers had all shopped at a certain all-night Stop & Shop supermarket. Reviewing the supermarket's surveillance tapes, police observed a quartet of guys arriving during third-shift. One guy engaged the attention of the thin staff, while the other three swapped out PIN pads for hacked versions. They were caught when they returned to retrieve their haul (recorded by the hacked PIN pads). †http://fraudwar.blogspot.com/2007/02/could-arrest-in-stop-and-shop-data.html http://fraudwar.blogspot.com/2007/02/could-arrest-in-stop-an...
- lifeisstillgood 13y agoI had always assumed PINs never left the pad - for example in the UK the device appears to validate the PIN (quick) and then communicate with server (slower). I expected the PIN was encrypted on the chip, the chip told the device if I got it right and then the PIN was used similarly to a salt for the transaction authorisation . Is there a real flow online one can read?
- Havoc 13y ago>I had always assumed PINs never left the pad The local pads say something about "offline" during that process. Thats for pin & chip ones though - with Target it sounds like the magnetic strip was copied. The local cards don't require a pin for magnetic strip swipes.
- deleted 13y ago[deleted]
- jtokoph 13y agoMore misinformation in the video: She mentions that the CVV on the back was "fair game". The CVV is on the magnetic strip, but the code on the back of the card is the CVV2 which is not on the magnetic strip.
- tjohns 13y agoI though the one on the mag stripe was the "CVV1", whereas "CVV" was ambiguous and could refer to either? As far as most consumers are concerned, CVV or CVC is synonymous with CVV2, since that's what folks are asked to enter when shopping online. If you're not an engineer or work in the payment industry, you probably don't know CVV1 exists.
- nnnnni 13y agoIs this saying then that it only affects cards that were used in debit mode, not cards that were used in credit mode?
- kclay 13y agoSo wait, do we know when this data breach started and this means that if I used my chase card (not target card) as debit it could of been comprised?
- officialjunk 13y agoInteresting detective work here on the target credit card compromise: http://krebsonsecurity.com/2013/12/whos-selling-credit-cards-from-target/ http://krebsonsecurity.com/2013/12/whos-selling-credit-cards...