TJX Breach Began With WEP Crack
An anonymous reader sends us to the Wall Street Journal for a detailed report on what is known to date about the TJX data breach. It seems that the loss of over 45 million credit card numbers and more than 450,000 SSNs, driver's license numbers, and military identifications began with someone using a "telescope-shaped" antenna at a wireless link at a Marshall's near St. Paul, Minnesota in July 2005. The link was encrypted using WEP, which had been known to be broken since 2001. The crackers who got into the TJX central databases are believed to be Romanians or Russians with ties to the Russian mobs. The eventual cost of the TXJ fiasco could exceed $1 billion — not including the numerous lawsuits filed against the retailer.
TJX - commonly known to American consumers as TJ Max and Marshalls retail stores. If you made purchases at these stores, you could be affected.
There's plenty of older hardware that doesn't have the processing power to do WPA, and has to rely on WEP. This is especially true for embedded devices (like print servers and bar code scanners) and PDAs. And for larger companies, replacing every single access point AND WiFi-device isn't a small thing.
Could you imagine being the IT manager who has to tell upper management that the big expense you added to the budget two years ago, which was supposed to last five years before being incrementally replaced, now has to be completely trashed and replaced in one go because the encryption turned out to not be safe?
The best thing many companies can do short term is to limit the damage, by restricting the use of WEP to data that they can afford losing. But even that requires admitting flaws, and is likely to get your head chopped off for bringing the bad news.