11 ms·
Target's data breach bigger than first thought – more than 100M records
- rasengan 13y agoObligatory Bitcoin comment. ;)
- dubfan 13y agoBecause Bitcoin-related businesses have such a stellar security record...
- rasengan 13y agoI never mentioned Businesses. I said Bitcoin as in the protocol/blockchain. edit: To further clarify, if you use your CC, you have to give the merchant or processor all the data required to make a purchase. The protocol/idea itself is broken, just like automated ACH by an external third party. edit 2: To go further, think about when the social network sites used to ask for thr username and password you used in order to login to third part services to 'invite your friends'. That was clearly a security mistake at the idea level. Now most services hardened up a little and offer revokable API access so that your account credentials are not required by a third party and usually even access limits can be set on a per API key level basis.
- FireBeyond 13y agoSo you accept Bitcoin. Now you have to stand at the counter until the network gets enough confirmations… which can be upwards of 20 minutes. Doesn’t sound at all problematic...
- olefoo 13y agoThat's an implementation detail; particularly if there is some legal backing (government regulation of the good kind) for the transfer mechanism. Think something using the Ripple protocol backed by a bank fund that holds 1 dollar for every "coin" represented in the system. If transaction confirmations took less than 500 milliseconds and had at least two confirmations from a network that had some form of insurance against double spend (rare and very noticeable) and identity theft (more common, but also noticeable) and auth token theft (relatively common). You could have something that looked like a general purpose internet mediated payment mechanism of sufficient (but not perfect) security; that would be relatively backwards compatible with existing infrastructure and resistant to attacks that merely depend on access to stored data rather than controlling a distributed ledger.
- higherpurpose 13y ago> In other words, you may be at risk from this exposure even if you've never bought anything from Target. This is why we must push back against companies who not only want to "track everything" about their customers, but about their non-customers, too!
- cfinke 13y agobut about their non-customers, too! You would have had to have "interacted with Target", meaning that you gave them the information in the first place.
- cynwoody 13y agoYes. In order for Target to have the information mentioned, you would have needed to have bought something online from them or you would need to have a REDcard† or have filled in a survey or mailed in a refund request or phoned customer service. Merely having bought something in a store, even using a credit or debit card, would not result in that information being captured. Of course, Target will try to track you even if you don't provide them with contact information. E.g., if you use the same credit card across multiple visits, they won't have your contact information or even your full credit card number (which they aren't allowed to store). But they will be able to analyze what you bought over time, and that's valuable. †http://www.target.com/redcard/main http://www.target.com/redcard/main
- deathanatos 13y ago> [Target] won't have […] even your full credit card number (which they aren't allowed to store) They won't have my credit card number? Wasn't how got to this very discussion because they have my credit card number? > So far, Target says, it's determined that the breached data includes customer names, credit or debit card numbers, card expiration dates, and CVVs (cards' three-digit security codes).
- cynwoody 13y agoThey're only permitted to keep the full credit card number for as long a business need exists. For a hotel or a car rental agency, that might be days. But for a retail transaction, it is a couple of seconds: submit the charge, mag stripes (and maybe PIN-block) and all. Then receive back the accept or decline. Just a simple HTTPS request. They are only allowed to keep part of the PAN beyond that time frame (the BIN and the last four if memory serves). No expiration date. And no CVV (the one that authenticates the mag stripe data, not the three or four digit code you enter for online transactions). What the hackers must have done is to install malware on Target's POS terminals that was intercepting the full mag stripe data and making it available to the hackers. They must have gained free reign on Target's corporate network, allowing them to access the POS terminals remotely. The marketing database breach was just frosting on the cake.
- fsckin 13y agoThis is Bad News, seeing as Target is also tracking every thing you've ever purchased[0] and using it for marketing purposes. I wonder if they also got ahold of not just credit cards and PII, but also purchase history. I wonder why they're not using this information to contact their "guests" directly? Why should I need to read about this revelation on HN, when they know everything about me. [0] http://motherboard.vice.com/blog/target-knows-you-re-pregnant http://motherboard.vice.com/blog/target-knows-you-re-pregnan...
- FireBeyond 13y agoBecause if they did, the fall-out would be massive. Frankly, it’s not been all that bad, relatively speaking. A few news releases, leave it to the financial institutions to do the damage control, and the principle of diffusion does a whole lot to shield your reputation. In comparison, a letter to you from Target directly detailing their failure - not so good. no doubt they’re avoiding this unless utterly forced to.
- ricardobeat 13y agoI'm intrigued that reports on the event still fail to mention any technical details, where and how it happened. I remember reading speculation that the breach was actually in a third-party transaction processor within the financial system, which would be even worse...
- alexbilbie 13y agoCould someone please explain why Target were storing PIN numbers?
- cynwoody 13y agoThey weren't. They were uploading encrypted PIN blocks to their payment processor, and the bad guys captured those along with the mag stripe data. But encrypted PIN blocks are useless to a hacker. Target can't decrypt the PIN-blocks. Only the payment processor has the key. Unfortunately, this point seems to have escaped some of the media morons, who would rather write scare headlines than get it right. PINs are entered on separate keyboard devices, known as PIN-pads. A PIN-pad is a tamper-resistant subsystem that can be programmed to prompt the customer to enter the PIN on its separate little keyboard. The PIN-pad then encrypts the PIN, using keys which are preloaded by the payment processor, and provides the encrypted result to the POS terminal. PIN pads have been hacked† in the past, but the methods employed require physical access to the POS terminal and are thus no where near scalable to the level of the Target hack. †http://fraudwar.blogspot.com/2007/02/could-arrest-in-stop-and-shop-data.html http://fraudwar.blogspot.com/2007/02/could-arrest-in-stop-an...
- jey 13y agoWhy would there be ~40M credit/debit card records for a single day's transactions? Sounds more like they were hanging onto this information long-term for some reason?
- cynwoody 13y agoThe reports I've seen say 40m sets of card details for the full duration of the hack, which was about two and half weeks, not a single day. And I doubt Target was storing the data, as they don't have a legitimate business need. Businesses that do have such a need, such as hotels and car rental companies, are allowed to keep the data, but only subject to stringent security. It seems likely that the hackers broke into Target's network and found a way to install malware on the POS terminals, designed to tee the credit card info off to the hackers in real time (or perhaps log it to disk, where the hackers would come by and fetch it).
- fishstix55 13y agoEvery target pharmacy purchase.... Think about it...
- robbiewright 13y agoWhy isn't chip and pin mandatory in America?
- jsaxton86 13y agoI heard a rumor that it's because Visa/MasterCard don't want to update every point-of-sale terminal in the country.
- tadfisher 13y agoVisa and MasterCard are actually pushing for chipped cards. In 2015, all major card issuers are shifting fraud liability to merchants if they don't update their POS systems to handle chip & pin or chip & signature: http://en.wikipedia.org/wiki/EMV#United_States http://en.wikipedia.org/wiki/EMV#United_States
- dangrossman 13y agoMerchants already have complete fraud liability today, as they always have. If stores don't upgrade their hardware, their liability will be the same in 2015 as it is today. In 2015, if you implement EMV, and take a chip-and-pin transaction at the point of sale, and the card itself is counterfeit, then you won't be liable. If you don't support EMV, the liability will be the same as it is today. If you do support EMV, and the fraud is something other than a counterfeit card, the liability will be the same as it is today. It's almost as if they designed the incentive to create a talking point when selling the EMV hardware to retailers, without actually shifting any meaningful liability away from them, so the card brands and banks can continue suffering none of the losses due to fraud outside their merchants' reasonable ability to stop.
- tadfisher 13y agoI was under the impression that fraud liability for card-present transactions today lies with the bank or card issuer, not the merchant.
- 13y ago
- coldcode 13y agoI keep wondering if they captured unencrypted backup tapes.
- alexeisadeski3 13y agoIf this had happened to an internet retailer, the event would be touted as the turning point against online commerce.
- low_key 13y agoIn the past I purchased a bottle of Nyquil at Target. They wouldn't complete the purchase without scanning my drivers license. I was not feeling well at the time, so I complied. I'm curious if they stored the information from the magnetic strip on the license and, if so, was that information stolen as well? Also, if they did, is it legal for them to do so. I haven't even heard anyone from the news even bring this up, but I think it would be much more serious than the cc data.