4 ms·
One of the key parts of this for consumers to keep in mind is that this is a massive PCI violation. Target neglected many of the most basic requirements in ter
by reeses 13y ago
One of the key parts of this for consumers to keep in mind is that this is a massive PCI violation. Target neglected many of the most basic requirements in terms of network segmentation and data protection. Target is a large tier-one retailer. They had 3rd party audits to "guarantee" PCI compliance.
However, the 3rd party is usually a single 'auditor' who interviews the staff and looks at the network diagrams provided by the IT department. This information may be inaccurate to the point that it may not even exist.
The focus in these audits is almost always ecommerce. I'm sure Target's ecommerce site has been scoped very thoroughly. Almost every retailer is just as exposed. While every client I've worked with has (by the time I left) been PCI compliant on the ecommerce side, the internal networks are often completely flat, even across global locations. SOX is a joke as a result, as there is no separation of concerns.
- maxerickson 13y agoWhat lessons beyond "Even major retailers have serious security problems" should a consumer be worried about here? I don't know much about PCI compliance, but I don't get the idea that it is something I should have to worry about as a user of a credit card.
- derekp7 13y agoThe lesson is to have more than one credit card, because eventually the one you use regularly will be compromised -- even if you only use it at physical locations. And when it is compromised, you will have to get a replacement, which is an inconvenience (hence the need for a second card). Oh, and keep an eye on your statements. And if you use a debit card, you may be worse off -- when it is compromised, you will have bills bouncing until you can get it straightened out. Even more of an inconvenience. If you use a debit card, go to your bank and have them turn off the "feature" that lets you overdraft (and get charged a $35.00 fee each time). Set up a separate account (one that doesn't have a debit card), to use for all your bill payments, so at least that doesn't get behind if your main account is cleaned out.
- ars 13y agoAnd not just more than one card, but also make sure the cards are from different banks! It's also recommended to have a Visa and a Mastercard (but that's for an unrelated reason that a small number of merchants take one and not the other - and usually it happens at the worst possible place, like a taxi).
- cynwoody 13y ago>If you use a debit card, go to your bank and have them turn off the "feature" that lets you overdraft (and get charged a $35.00 fee each time). Better yet, have them issue you a new card that is only an ATM card and cannot be used without furnishing the PIN. That's what I did back in the 90s when "check cards"† were first introduced. I phoned the bank and asked if the Visa logo meant the card be used without a PIN. When they said yes, I told them to close the account. Instead, they said not to worry and sent me an ATM-only card in the next day's mail. I use my ATM card for banking only. Everything else goes on my AX (or DS or, in extremis, MC or VI). †https://www.usbank.com/checking/us-bank-visa-check-card-debit-card-faqs.html https://www.usbank.com/checking/us-bank-visa-check-card-debi...
- mr337 13y agoSeems like this was overlooked a little, but one could always use cash. I understand the reasons why cash can be inconvenient, but I doubt it it less hassle then dealing with a bank/CC company over fraudulent charges, associated overdraft fees, and all the crap. Now eCommerce transactions over the web is a different story.
- hga 13y agoIndeed; that's what I do for everything local that less than, say, $750, and it's remarkably worry free. No privacy issues either, no one has any idea exactly what I buy locally.
- gav 13y agoYou should really avoid using a debit card at all. There's numerous disadvantages, the main one is that that you generally have less protections against fraud, and even if you do, you may have to wait for the transactions to post before your bank can reverse them. There's no upside to using a debit card; get multiple credit cards and pay them off every month. There's also various upsides including more air miles/hotel points, cash back, travel insurance, etc.
- reeses 13y agoYou should not use any card that does not give you a 100% guarantee that you will not be held responsible for erroneous charges. It really doesn't matter the retailer – they almost all suck. The older the company or the faster its growth, the more you should worry. Push that worry onto Amex or your bank. PCI is surprisingly easy (and anyone can look it up at https://www.pcisecuritystandards.org/security_standards/documents.php?agreements=pcidss&association=pcidss https://www.pcisecuritystandards.org/security_standards/docu...). It's basically all about "data at rest," covering what can be stored, how it must be stored, and how it should be stored. If a merchant can't meet the requirements, then they are required to demonstrate "compensating controls" which can literally be "we have a project in place to fix this before the audit a year from now." "Data at rest" involves (in this case) credit card information stored on "disk" (SSD, etc.) for more than a short period of time. This generally excludes virtual memory, some queueing software, etc. If it touches the disk for ten seconds but is then wiped, you're compliant. Then there are a list of "musts". You must have firewalls protecting the internal network (and review the rulesets), documentation on any connectivity to cardholder data, dataflow diagrams, only allow essential traffic in the card info environment, wall off wireless access, have an IPS, change all vendor defaults on any devices that could possibly screw you, minimize server responsibility (so don't run your smtp relay on the machine that also encrypts your card info), rotate encryption keys every x days, don't store CID/CVV/track 2/full mag-tape data from the card, scan your systems for changes/compromise/unauthorized access, maintain nonreputable audit trails, etc. PCI is ratcheting down the requirements so that there is less room for interpretation. Previously, just using Oracle's obfuscation toolkit would be enough. This would protect you (more or less) if someone had access to your block device in raw mode or your data files in what-the-hell-is-your-dba-thinking mode, but an Edward Snowden could log in and SELECT all of your card info.
- maxerickson 13y agoBut why should a credit card user care about any of that (other than the easy disputing of erroneous charges)?
- reeses 13y agoBecause the world sucks. Many times, your cc provider will detect suspicious activity and freeze your account, but one of the common patterns of card theft is a validation phase followed by a "hammer it until it cries" phase. It's quite possible to have a few small charges show up on your account that you might miss because your overall bill seems fine. Usually, once the card is proven good, you'll get the lovely bill for a first-class flight to Qatar. I agree that a cc user should not have to care about any of this, but people responsible for protecting your money are not so responsible.
- csense 13y agoPay with cash when that option is available.
- raverbashing 13y agoI wouldn't be surprised if these auditors were like this or even worse: http://serverfault.com/questions/293217/our-security-auditor-is-an-idiot-how-do-i-give-him-the-information-he-wants http://serverfault.com/questions/293217/our-security-auditor...