5 ms·
Why were they storing the PINs?
by fiberoptick 13y ago
Why were they storing the PINs?
- astrodust 13y agoI'm not familiar with the US system, but here in Canada you're not even supposed to get the PIN in the first place. The keypad is supposed to encrypt it and use it for one transaction only. Then that information is discarded. Storing PINs in any form is absolutely insane. People deserve to get fired for this.
- dlubarov 13y agoIt's the same here - pins must be encrypted by a tamper-resistant hardware pin pad (in this case Verifone's). I don't think Target was storing pins, which is prohibited regardless of encryption. It sounds like the attackers sniffed encrypted pins.
- panarky 13y agoThere's no evidence that PINs were stored on Target systems. PINs should be encrypted by the Verifone pinpad itself, using keys that were burned into the device by the manufacturer. If the attacker compromised the pinpad device, then it's possible for unencrypted PINs to be intercepted at the point of entry. If the POS device or the store network was compromised, then encrypted PINs could be harvested on the wire.
- ars 13y agoI think they got the PINs on the fly, as they were being entered.
- cynwoody 13y agoNot likely, given the large number of compromised cards. What is likely, and also not very significant, is that they intercepted encrypted PIN blocks along with unencrypted mag stripe data. Of course, if they managed to decrypt the encrypted PINs, that would be huge. But I highly doubt it. A PIN-pad is a tamper-resistant, self-contained systems that accepts the PIN from its key pad, encrypts it on the fly using secret keys burned in by the supplier, and uploads the entered PIN in the form of a fixed-length encrypted "PIN block" which can only be decrypted by the payment processor. Therefore, in order to get the PINs on the fly, the bad guys would have had to physically compromise a large number of POS terminals at a large number of stores at high risk of getting caught. That's not plausible. What is plausible is that they broke into Target's corporate network and tapped the transaction flow between the POS terminals and the payment processors. That would give them the mag stripes and any encrypted PIN blocks entered, but not the unencrypted PINs. There was a case† a few years ago in Rhode Island in which banks experienced a spate of disavowed ATM withdrawals. They noticed that the complaining customers had all shopped at a certain all-night Stop & Shop supermarket. Reviewing the supermarket's surveillance tapes, police observed a quartet of guys arriving during third-shift. One guy engaged the attention of the thin staff, while the other three swapped out PIN pads for hacked versions. They were caught when they returned to retrieve their haul (recorded by the hacked PIN pads). †http://fraudwar.blogspot.com/2007/02/could-arrest-in-stop-and-shop-data.html http://fraudwar.blogspot.com/2007/02/could-arrest-in-stop-an...
- lifeisstillgood 13y agoI had always assumed PINs never left the pad - for example in the UK the device appears to validate the PIN (quick) and then communicate with server (slower). I expected the PIN was encrypted on the chip, the chip told the device if I got it right and then the PIN was used similarly to a salt for the transaction authorisation . Is there a real flow online one can read?
- Havoc 13y ago>I had always assumed PINs never left the pad The local pads say something about "offline" during that process. Thats for pin & chip ones though - with Target it sounds like the magnetic strip was copied. The local cards don't require a pin for magnetic strip swipes.
- rcxdude 13y agoThe flow is not very simple, since the protocol is very complex. You are overall correct in that usually the PIN does not get sent off the card terminal (I'm not sure about never) What happens is that the PIN is sent to the card (usually plain-text, though it can be encrypted if card and terminal support it. An MITM attacker can downgrade this though). The card then reterns a plaintext 'yes' or 'no' to the pin being correct. If the pin is correct then it also sets a bit inside the MACed message which is sent to the banks indicating 'correct PIN entered'. However, since the PIN is not required for all transactions, it used to be possible (and may stiil be possible on some banks) to MITM attack this exchange in order to complete a transaction which the terminal thinks was PIN authorised but the card thinks was not, and the upshot being you could enter whatever pin you wanted and the transaction would go through. For more information, you can look up the EMV specification at http://www.emvco.com/specifications.aspx?id=223 http://www.emvco.com/specifications.aspx?id=223 (which is a huge slog to read, and there are many proprietary extensions). For the specific attack I mentioned, you can google 'chip and pin is broken'.
- dlubarov 13y agoChip cards aren't prevalent yet in the US, so the only way to validate pins is to send them (encrypted) to the issuer.