3 ms·
Is there any reason why these stores need to store the full magnetic stipe details of the card in the first place?
by magic_haze 13y ago
Is there any reason why these stores need to store the full magnetic stipe details of the card in the first place?
- ams6110 13y agoNowadays, no. However legacy systems abound.
- MartinCron 13y agoI would expect the credit card companies would require that they not store the entire card swipe data (or the PIN for that matter).
- magic_haze 13y agoThat is what I thought as well, but details on the Target hack suggests they managed to get hold of the cards' entire track data (I'm on my phone so can't link to the article directly, but it's on the same website as OP's link) I'm guessing NM has the same data policy.
- cstejerean 13y agoI'm not aware of the details, but they might have managed to store the track data because they intercepted it in transit, not because Target was storing it somewhere.
- ForHackernews 13y agoI thought the theory was that the target hack was targeted at POS card-readers, not recovering numbers after the fact from a database.
- cynwoody 13y agoIt was. But in order to pull it off on the scale they did, the bad guys must have broken into Target's corporate network. Apparently, the level of access they achieved allowed them to raid the marketing database as well as to hack large numbers of POS terminals to leak the card swipe data. The marketing database, BTW, contained name and contact information, but not credit card details. The bad guys might find it useful for phishing attacks.
- cynwoody 13y agoMerchants are required to scrub the card details as soon as the business need for them has passed. In the case of a retail store, I would think that would be as soon as the accept or decline response from the payment processor is received. To make a charge, the POS terminal packages the mag stripe data (and the encrypted PIN-block if doing debit) together with the POS terminal's ID, the amount to be charged, and maybe the CVV2 or the billing zip code, etc., into an HTTPS request to the payment processor. A second or two later, the payment processor responds, and the terminal completes the transaction. If that's how Target's POS terminals work, then the hackers probably managed to push a "software update" out to the terminals causing them to tee the data off to the hackers' server whenever a transaction was made. The reason the debit PINs were safe is that the PIN pads on which the customers enter their PINs are separate self-contained devices which encrypt the PINs before they leave the pad. Only the payment processor has the key needed to decrypt the PIN blocks, and PIN pads don't accept "software updates". PIN pads have been hacked in the past, but such attacks are far less scalable because they require modifying hardware at each affected POS terminal. The new news about Target breaching contact info for 70m customers simply confirms that the hackers had free reign on Target's corporate network.