Slashdot Mirror


Largest Data Breach Disclosed During Inauguration

rmogull writes "Brian Krebs over at the Washington Post just published a story that Heartland Payment Systems disclosed what may be the largest data breach in history. Today. During the inauguration. Heartland processes over 100 million transactions a month, mostly from small to medium-sized businesses, and doesn't know how many cards were compromised. The breach was discovered after tracing fraud in the system back to Heartland, and involved malicious software snooping their internal network. I've written some additional analysis on this and similar breaches. It's interesting that the biggest breaches now involve attacks installing malicious software to sniff data — including TJX, Hannaford, Cardsystems, and now Heartland Payment Systems." One bit of good news out of this massive breach is that, according to Heartland's CFO, "The nature of the [breach] is such that card-not-present transactions are actually quite difficult for the bad guys to do because one piece of information we know they did not get was an address." Heartland just put up a press release on the breach.

168 comments

  1. WTF??? by canUbeleiveIT · · Score: 1, Insightful
    Brian Krebs over at the Washington Post just published a story that Heartland Payment Systems disclosed what may be the largest data breach in history. Today. During the inauguration.

    WTF??? What does the inauguration have to do with this? I suggest we go back to all Slashdot stories and insert what happened on that day. Examples:

    * Researcher says Linux is better than Windows on Friendship Day.
    * Researcher says Linux is better than Windows on Fall Equinox.
    * Researcher says Linux is better than Windows on Kwanzaa.

    1. Re:WTF??? by EvanED · · Score: 5, Insightful

      I would say it may have quite a lot to do with it... it's either a pretty big coincidence, or they are trying to bury the news by releasing it when the networks actually have something else to report on.

      What's your bet on?

    2. Re:WTF??? by amRadioHed · · Score: 5, Informative

      The implication is that they timed the announcement to occur when no one is paying attention.

      --
      We hope your rules and wisdom choke you / Now we are one in everlasting peace
    3. Re:WTF??? by oldspewey · · Score: 5, Insightful

      Today. During the inauguration. WTF??? What does the inauguration have to do with this?

      Well, somebody who is inclined toward cynicism might conclude that the company deliberately chose to release this information when public attention would be diverted elsewhere.

      --
      If libertarians are so opposed to effective government, why don't they all move to Somalia?
    4. Re:WTF??? by gravos · · Score: 0, Redundant

      "Identity theft protection is appropriate when there is enough personal information lost that identity theft is possible," he said. "In this case, the amount of information we know they did not get is long enough that except in very circumscribed cases identity theft is just not possible."

      Does anybody really believe this?

    5. Re:WTF??? by idontgno · · Score: 5, Insightful

      [Heartland Payment Systems President and CFO] Baldwin said Heartland worked to disclose the breach last week.

      "Due to legal reviews, discussions with some of the players involved, we couldn't get it together and signed off on until today," Baldwin said.

      "Legal reviews": "Holy crap, we're gonna get our butts sued off if this breach becomes a big news story! You have to delay this until we can start a war or something to distract the press!"

      "Will the inauguration hype of the first African-American President of the United States work as a distraction?"

      "Brilliant!"

      --
      Welcome to the Panopticon. Used to be a prison, now it's your home.
    6. Re:WTF??? by Anonymous Coward · · Score: 0

      Researcher says Linux is better than Windows on Kwanzaa.

      I would like to point out that Kwanzaa lasts a whole week--something can happen during it but you seem to think it's only the length of a day. If you're going to make a celebration the butt of your jokes, please at least pay some attention to it.

    7. Re:WTF??? by canUbeleiveIT · · Score: 2, Interesting

      Well, somebody who is inclined toward cynicism might conclude that the company deliberately chose to release this information when public attention would be diverted elsewhere.

      Ahh...now I get it. Still, there was that plane that landed in the Hudson a few days back, yesterday was MLK day, the Super Bowl will be in a couple of weeks. Not to mention that it would seem that it would be in their best interests to get the word out to minimize losses.

    8. Re:WTF??? by Bryan+Ischo · · Score: 3, Funny

      "Researcher says Linux is better than Windows on Pedantic Asshole day."

      There, is that better?

    9. Re:WTF??? by idiotnot · · Score: 4, Informative

      Same reason Clear Channel laid off 8% while this was going on. :-)

    10. Re:WTF??? by idontgno · · Score: 4, Interesting

      Not to mention that it would seem that it would be in their best interests to get the word out to minimize losses.

      Oh, they've already got that covered:

      Baldwin said it was not appropriate for Heartland to offer affected consumers credit protection or other identity theft protection services.

      "Identity theft protection is appropriate when there is enough personal information lost that identity theft is possible," he said. "In this case, the amount of information we know they did not get is long enough that except in very circumscribed cases identity theft is just not possible.

      In other words, "Yeah, technically it was a breach, but you know, not enough data got released for us to actually be provably liable. So if your CC gets raped, you know, it's not our fault. Really. Trust us. ;)"

      In related news, now we know what happened to the Iraqi Information Minister: He changed his name and became President and CFO of a large credit card payment processing company.

      --
      Welcome to the Panopticon. Used to be a prison, now it's your home.
    11. Re:WTF??? by fuzzyfuzzyfungus · · Score: 3, Funny

      Yeah, but that was good news...

    12. Re:WTF??? by idontgno · · Score: 5, Funny

      And Linux is always better than Windows on Slashdot, because every day is Pedantic Asshole day here!

      --
      Welcome to the Panopticon. Used to be a prison, now it's your home.
    13. Re:WTF??? by box4831 · · Score: 1

      On Slashdot, every day is Pedantic Asshole Day!

      --
      Miller Lite tastes like water that's somehow managed to rot.
    14. Re:WTF??? by Ambiguous+Coward · · Score: 1

      All of those other incidents (MLK day, super bowl, etc.) are in passing. They are temporary, at best. The inauguration is going to echo through the media for a loooong time to come. Even if someone publicly calls them out on this (more than just on /.) and there is an attempt to generate an uproar over this, in the end, the inauguration will far outweigh the breach when it comes to face-time in the news.

      I'm the cynical type, and I reckon they succeeded at hiding this one in plain sight.

      --
      Their may be a grammatical error, misspeling, or evn a typo in this post.
    15. Re:WTF??? by joelmax · · Score: 1, Redundant

      Exactly. Considering the media hype behind the inauguration of Obama, and considering the possible pr nightmare (And it does promise to be a pr nightmare) that this poses to heartland, I would have to say that this was pre-planned as a form of damage control.

    16. Re:WTF??? by bugs2squash · · Score: 4, Interesting

      The breach happened last year. What's the betting that the first customers know about it is when faudulent activity is showing up on their credit cards.

      The first instinct of Heartland is to save itself and the first instinct of the banks will be that it can rate jack its customers if the new activity has put them overlimit.

      Only after leaking of the news is inevitable and can no longer be delayed will Heartland grudgingly try to sneak it out under the radar and then in a general, untargeted sense, not directly to the customers involved. Nothing will be done to avoid spreading the pain to a card holder or to a vendor.

      I dare say most of the legal wrangling was in how to spin this as a justification to claim from TARP.

      --
      Nullius in verba
    17. Re:WTF??? by Ambiguous+Coward · · Score: 5, Interesting

      Well, somebody who is inclined toward reality

      No need to thank me.

      Also, FTFA:

      Heartland called U.S. Secret Service and hired two breach forensics teams to investigate. But Baldwin said it wasn't until last week that investigators uncovered the source of the breach...

      Meaning they knew about it long enough to hire some forensics teams, do the research, figure out where the breach came from, etc. and they finished all that up last week...and then decided to wait until NOON today to release the news to the public? Sorry, but that's plain bullshit, no cynicism involved. If they were interested in disclosure, they would've released the news sooner. At the very latest, they would've released it as soon as they found out how it happened (so they could say they had already closed the breach.)

      Instead, they wait until noon (they're a New Jersey company) when the inauguration is happening? Why not sooner in the day? Why wait until what would arguably be lunch time usually? Who discloses breaches at lunch? Answer: nobody. On the other hand, who discloses breaches during a HUGE national (and arguably international) event? Answer: someone trying to hide something.

      Again, I say inclined toward reality, not cynicism.

      --
      Their may be a grammatical error, misspeling, or evn a typo in this post.
    18. Re:WTF??? by Anonymous Coward · · Score: 0

      plane that landed in the Hudson a few days back

      Unless they planed the crash it would be difficult to time the press release to coincide with it.

      yesterday was MLK day

      It was? Guess I missed it.

      the Super Bowl will be in a couple of weeks

      That's another one that is easy for most people to miss.

      The inauguration has had much more hype and has more people "feeling good" than the other three combined. This was the perfect day to release bad news.

    19. Re:WTF??? by Bill,+Shooter+of+Bul · · Score: 3, Informative

      No, they are liable and are going to pay through the nose, but not for "identity theft". They will be responsible for improperly securing their network and permitting the theft of the cards. But identity theft is a different beast. No one will be able to sign up for new credit cards and or loans in the names of the people whose data was compromised.

      --
      Well.. maybe. Or Maybe not. But Definitely not sort of.
    20. Re:WTF??? by christianT · · Score: 1

      I don't think they were trying to implicate our new President in this with the title, it was more of an implication that those announcing it were trying to announce the breach while most of the nation was distracted by the inauguration in hopes that it might fall under the radar of the news media.

    21. Re:WTF??? by Anonymous Coward · · Score: 1, Funny

      good point. not even the Iraqi information minister would stoop so low....

    22. Re:WTF??? by flabbergasted · · Score: 0

      Your comments have nothing to do with reality. I read this story on line this morning before I left the house. That would have been about 9am EST--three hours before the inauguration. Since I scan the headlines for three news services before leaving, I can't say for certain which it was. Probably either the AP or NYT.

    23. Re:WTF??? by jdoverholt · · Score: 4, Interesting

      Incidentally, I got a call this morning about an hour before noon EST from Chase. They said they "received information" that my credit card information was compromised. The only suspicious charge was from November, which I didn't notice on my own. This is also the only time Chase has done anything but screw me, so I was pleasantly surprised that they were dealing with it so well. Now I see this and think "hey, I'm part of the largest ___ in history!" Sweet.

    24. Re:WTF??? by Landshark17 · · Score: 1

      The inauguration has absolutely nothing to do with this, but it's the biggest story today. No other story is going to get higher billing, so it's the best way to hide the story about how your company fucked up royally.

      --
      This sig is false.
    25. Re:WTF??? by RiotingPacifist · · Score: 2, Informative

      Thats nothing a certain middle eastern country broke it's fragile ceasefire, the night of the US election, that was more than just a good time to leak the news. TBH im surprised that a UK official got in trouble for saying 9/11 was a good day to get rid of bad news, this shit has been going on for years.

      --
      IranAir Flight 655 never forget!
    26. Re:WTF??? by LordSnooty · · Score: 2, Informative

      The point is still valid, whilst on a normal day the news networks might've been following up the news, gathering info, interviewing victims, instead all their resources are working on the Coronation, er I mean inauguration.

      My own government is guilty of the very same - "a good day to bury bad news" as the infamous leaked e-mail went. As he said, rooted in reality.

    27. Re:WTF??? by failedlogic · · Score: 1

      Their timing of the announcement is more than a little coincidental and at the least does nothing to help with their public image. Their main concern is that they don't want to lose their customers over this. By not revealing the names of the retailers involved, there won't be any public backlash from customers.

      Ok, so this *one* transaction company 100 million transactions/month. There are several other competing companies. This incident is the result of a data breach without accounting for daily fraudulent attempts/successes (for which we don't know the numbers). We also don't know how much money was lost. We need a better system.

    28. Re:WTF??? by Ambiguous+Coward · · Score: 2, Insightful

      My comments were based on the article itself. What more do you expect? The article claims the disclosure occured during the inauguration. Regardless, waiting for inauguration day is "interesting" enough.

      Also, just a little heads up: "nothing to do with reality" and "incorrect on the point of exact timing" are not synonymous. It will help lend credence to your position in the future if you learn the difference.

      --
      Their may be a grammatical error, misspeling, or evn a typo in this post.
    29. Re:WTF??? by Anonymous Coward · · Score: 0

      Oops. Moderated you over-rated, meant to select under-rated cause some bozo had modded you 'redundant'. Cant see how to undo it. Sorry.

    30. Re:WTF??? by jdcope · · Score: 2, Informative

      Cover up. Hell, even here in Portland, Oregon, the new mayor held a press conference today and said he lied about a sexual relationship with a teen boy.

    31. Re:WTF??? by tobiasly · · Score: 3, Interesting

      Same thing happened to me back in December. I too have a Chase credit card. My card got declined on a couple purchases so I called them about it. They knew exactly which charges were fraudulent and had already reversed them and closed the card so they could send another with a new number. Interesting that the charges were rather small.. a $5 Netflix charge, maybe a couple $20 or $30 charges, and out of the dozens of legitimate charges per month my wife and I make, they knew which ones were bogus.

    32. Re:WTF??? by Skrynesaver · · Score: 1

      As the banks are not giving out credit any more he's probably safe on this one for a while ;)

      --
      "Linux is for noobs"-The new MS fud strategy
    33. Re:WTF??? by Nathan+Baum · · Score: 2, Insightful

      im surprised that a UK official got in trouble for saying 9/11 was a good day to get rid of bad news

      She didn't get in trouble for saying it; she got in trouble because the media found out she said it.

    34. Re:WTF??? by Vr6dub · · Score: 1

      I was victim to this recently as well. A bunch of small charges and all purchases used my cell number and home address...even had some diet pills sent to my house. I though this was rather odd but I think a co-worker of mine nailed it on the head and said these people are probably using stolen card numbers to use with all these free laptop/ipod giveaways. You know, the ones that ask you to sign up for 5 "services" from their affiliates and get X number of friends to do the same to receive your free equipment.

      What's funny is that after I cancelled the card, I called some of these places up to have any accounts with them cancelled. Two of them showed no shame and asked that since I had already signed up (fraudulently), would I like to continue with their service since it had so many great things to offer.

  2. figures by Anonymous Coward · · Score: 1, Funny

    As soon as Barack Obama became President, the world started falling apart.

    I warned this would happen but you were just too damn proud to listen.

    Game over, man. Game over.

    1. Re:figures by hicks107 · · Score: 1

      Nice

    2. Re:figures by Anonymous Coward · · Score: 0

      No, no, its really suspicious because it happened the exact moment Dick Cheney stopped being VP.

  3. What a perfect time.. by Jonah+Bomber · · Score: 1

    ...to steal the Hope Diamond. http://www.southparkstudios.com/episodes/207897/

  4. Re:Burying the News? by philspear · · Score: 2

    If that was their plan, then that's a foolish one. It would have to be an EXTREMELY slow news day for this to get picked up on by the major news outlets, and even slower for most viewers to bother understanding it. And it's going to be picked up by people who are interested, like here, reguardless.

    Burying it effectively would be waiting for something like the newest release of some major open source software, or waiting until China or Australia or other nation did something major about censorship.

  5. Suckers by htnmmo · · Score: 5, Funny

    This is why I never go on the internet. It's just not safe.

    1. Re:Suckers by blair1q · · Score: 2, Funny

      Neither do I. Unless I'm posing as you.

    2. Re:Suckers by Anonymous Coward · · Score: 1, Informative

      Except that the large majority of payments that they process are from actual storefronts, not internet transactions. You're not safe anywhere, sucker.

    3. Re:Suckers by Nixoloco · · Score: 1

      Neither do I. Unless I'm posing as you.

    4. Re:Suckers by Anonymous Coward · · Score: 1, Funny

      Would have been so much funnier coming from htnmmo....

    5. Re:Suckers by Anonymous Coward · · Score: 0

      This is why I never go on the internet. It's just not safe.

      But your on the internet now.

    6. Re:Suckers by mgblst · · Score: 1

      Agreed, I stopped using computers years ago, never been happier!

    7. Re:Suckers by Roman+Mamedov · · Score: 1

      But your on the internet now.

      You have no way to know, he might as well be in the Slashdot hosting datacenter, reading the site from their LAN. :)

    8. Re:Suckers by aoheno · · Score: 1

      Awesome. Slashdot is available off the Internet! Now I can be safe too.

      --
      Her lips were softer than a duck's bill, but her quacks ...
  6. Re:First CC by Chabo · · Score: 1

    Hey, that's mine!

    --
    Convert FLACs to a portable format with FlacSquisher
  7. No Big Deal by Anonymous Coward · · Score: 0

    Obama will fix it.

    1. Re:No Big Deal by Anonymous Coward · · Score: 0

      Do I smell a new meme?

    2. Re:No Big Deal by Hordeking · · Score: 1

      That new meme is old news.

      I've been saying that for weeks.

      --
      Disclaimer: The opinions and actions of the US Gov't are in no way representative of those held by this author or its ci
    3. Re:No Big Deal by Hordeking · · Score: 1

      Actually, you're only smelling the unwashed masses as they exalt Obama.

      --
      Disclaimer: The opinions and actions of the US Gov't are in no way representative of those held by this author or its ci
  8. Missing Address by wiz31337 · · Score: 4, Insightful

    "The nature of the [breach] is such that card-not-present transactions are actually quite difficult for the bad guys to do because one piece of information we know they did not get was an address," Baldwin said.

    Because as we all know it is impossible to get someone's address by having only their full name and credit card number.

    They are trying to down play a very serious incident by disclosing the breach on a day heavily focused on the inauguration. Then they have the nerve to say "don't worry they didn't get your address" as if to say someone smart enough to embed malicious software which gathers credit card numbers is not smart enough to find someone's address. Common!

    --
    /whisper/ Thanks for the candy!
    1. Re:Missing Address by n0dna · · Score: 4, Informative

      Let's also not overlook that while some stores/merchants may have a policy to ask for address when doing Cardless Transactions, the processing houses (at least the ones I've used) will more than happily process the transaction successfully without anything more than the card number and the expiration date.

      Some processors will refuse to process transactions within the month that the card expires, but you simply add 4 years to the date and it'll go through just fine.

      The Credit Card companies have pushed very hard and very long to make credit transactions more painless than cash. You have to drop some safeguards to do that though.

    2. Re:Missing Address by Anonymous Coward · · Score: 0

      Common what?

      Perhaps you mean "come on"?

    3. Re:Missing Address by Anonymous Coward · · Score: 0

      Plus a lot of bad guys have set up shop to easily print credit cards, so even if they couldn't do "card-not-present transactions" it doesn't protect you much.

    4. Re:Missing Address by sorak · · Score: 3, Funny

      Hmmm...B.H. Obama. Jeffery, get out the phone book. We need to determine where this guy lives.

    5. Re:Missing Address by Anonymous Coward · · Score: 0

      Plus I personally know that some online businesses do not do the address checks. Some don't even check the CVV2 (that 3-4 digit security code on the back of the card.) Maybe Heartland requires it, but I doubt that.

    6. Re:Missing Address by NoobixCube · · Score: 1

      ID thief: Hi, I've moved recently, and I just wanted to check you guys have my new address.

      Every time I've done that with my bank, they've asked for my full name, date of birth, and account number (or if I go through the automated channel, the only ID I need is my phone or online banking pin). After those are provided, they tell me what address they have on file.

      --
      Admit it. You post strawman arguments as AC so you get modded Insightful for refuting them, rather than Troll
    7. Re:Missing Address by skuzzlebutt · · Score: 1

      Slightly OT, but FYI:

      Both of the first points are relative...it depends on the processor, and the product on which they are processing. The address verification (AVS) gives the merchant better pricing, but is not a mandatory knock-out rule with Visa/MC to get an authorization. Some processing platforms will force a reject if the AVS match fails, some will let it go through at the higher rate.

      The expiration is relative, too...some platforms do a literal verification, some just check to see if it matches [0-1][0-9][date(YY)-13] or some such logic.

      --
      My debut novel AMITY now available: http://jeremydbrooks.c
    8. Re:Missing Address by Anonymous Coward · · Score: 0

      The funny thing is.... you don't need anything more than a cc number, an expiration and a dollar amount to submit an electronic payment.

    9. Re:Missing Address by bastion_xx · · Score: 1

      And most velocity check systems will pick up on expiry skipping (+1/mo or +1/year) transactions. But yeah, you think agreements between card holders and the respective issuer is fine print, take a look at those between a merchant and an ISO/acquirer.

      AVS can get discount rates and/or better chargeback conditions for card-present transactions. To really get the best protection you need to use Verified by Visa or similar programs. Of course, they are a pain to implement, have horrible card holder participation, etc.

      Why we don't mandate smart card technology like Europe is beyond me.

      But as to the disclosure, most processors and acquirers operate fast and loose. And I'm talking about some of the big boys too. If I was doing PCI audits/reviews, I know I could find substantive findings at most everyone of those involved in card transactions.

    10. Re:Missing Address by Anonymous Coward · · Score: 0

      The criminals might look up the address, but then they use the info to change your contact info on the account so that you are not informed about the fraudulent activity.

    11. Re:Missing Address by bskin · · Score: 1

      Standard practice in the finance industry these days is to send a notification whenever an address is changed - to both the new and old address. It wouldn't stop them from making the transaction, but it would notify the cardholder that something is up and make it pretty easy to dispute charges.

      --
      hot foreign sheep.
  9. It's a blog post! by Reality+Master+201 · · Score: 1

    The guy posted to his blog about it. On the same day as the inauguration.

    Seriously, the tone of the summary is dumb as fuck. The press release is from today, as is the blog post. It's not even a fucking newspaper article.

    1. Re:It's a blog post! by whoever57 · · Score: 1

      The guy posted to his blog about it. On the same day as the inauguration.

      Did he? I would RTFA, but I've given up trying to read white-on-black web pages. Seriously, whoever thought that dense white text on a black background is easily readable?

      I'll agree that it is a little more readable on LCD monitors than it was on slightly old CRT monitors, but it still isn't easily readable.

      --
      The real "Libtards" are the Libertarians!
    2. Re:It's a blog post! by Reality+Master+201 · · Score: 1

      Dunno; I don't have much problem with white on black text. I prefer green or amber on black, though, but that's mostly nostalgia for the VT-220s I spent so much time in front of.

    3. Re:It's a blog post! by Anonymous Coward · · Score: 0

      From this day forward, all time will be counted from the moment of OUR MESSIAH'S inauguration. Tomorrow will not be January 21, 2009, it will be THE SECOND DAY OF OUR LORD, OBAMA!

    4. Re:It's a blog post! by Anonymous Coward · · Score: 0

      Did he? I would RTFA, but I've given up trying to read white-on-black web pages.

      But black on white is okay? Straight, or lesbian?

  10. what the bad guys didn't steal by Gary+W.+Longsine · · Score: 4, Informative

    Nearly every company that suffers a breach like this tries to assure people about what the bad guy's didn't manage to steal. Don't believe it. Even if it might be true at the strict technical level, it's still not relevant to the analysis of the severity of this issue. The bad guys already have databases full of names and addresses which they will cross reference against the data they stole.

    --
    If you mod me down, I shall become more powerful than you could possibly imagine.
    1. Re:what the bad guys didn't steal by noidentity · · Score: 2, Funny

      Come on, use the right word! They COPIED the data, not STOLE it, unless they really did delete it from the original server, in which case they would have noticed it missing immediately.

    2. Re:what the bad guys didn't steal by innocent_white_lamb · · Score: 1

      The bad guys already have databases full of names and addresses which they will cross reference against the data they stole.
       
      I think they're called telephone books.

      --
      If you're a zombie and you know it, bite your friend!
    3. Re:what the bad guys didn't steal by apoc.famine · · Score: 1

      And potentially any other data stolen anywhere else. Who's to say that these same individuals don't have a copy of the data from other big break-ins lying around.

      If they managed to buy one of those databases, suddenly they have a massive amount of data-mining information available to them.

      --
      Velociraptor = Distiraptor / Timeraptor
  11. "Actually quite difficult"? by MozeeToby · · Score: 2, Informative

    The nature of the [breach] is such that card-not-present transactions are actually quite difficult for the bad guys to do because one piece of information we know they did not get was an address.

    Because we all know that it's impossible to spoof the magnetic strip on the credit card.

    1. Re:"Actually quite difficult"? by Repton · · Score: 1

      I'm not sure what you mean ...

      The magnetic stripe doesn't have anything to do with card-not-present transactions. CNP basically means internet: you type in your name, card number, expiry date, possibly security code. It's not clear whether they got the security code, but I guess they did, otherwise the company would be touting that as another up-side.

      The magnetic stripe has its own security code, which is not printed on the card. This means that you can't make counterfeit cards given only knowledge of the number/expiry/name and the magstripe standards. However, according to TFA, "The data stolen includes the digital information encoded onto the magnetic stripe" so there's nothing stopping them running off counterfeit cards and hitting the shops.

      (well, chip-and-pin style smartcards would stop them, but I don't think you have those in the US?)

      --
      Repton.
      They say that only an experienced wizard can do the tengu shuffle.
    2. Re:"Actually quite difficult"? by drinkypoo · · Score: 1

      The point is that it's really amazingly easy to make a fake credit card that looks just like the real thing. The only hard part is the hologram and you can just get some holographic sticker and scuff the crap out of it and convince most people if you can distract them away with social engineering (and if the card works the first time.) Not that I would ever do this, I'm about as sneaky as Baby Huey.

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
    3. Re:"Actually quite difficult"? by new+death+barbie · · Score: 1

      You don't have to make a fake credit card, just rewrite the magstripe on an existing expired/stolen card.

      --

      It's supposed to be completely automatic, but actually you have to press this button.

    4. Re:"Actually quite difficult"? by drinkypoo · · Score: 1

      If you can make your own then the data can match the card... Stealing them works, but there's a short window of usefulness. Most people who wouldn't notice if their card is stolen don't have any credit left.

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
  12. Re:First CC by Anonymous Coward · · Score: 0

    Thanks, I needed a name and adress....

  13. needess to ask what OS .. by rs232 · · Score: 0, Troll
    --
    davecb5620@gmail.com
    1. Re:needess to ask what OS .. by Whuffo · · Score: 1

      And visiting that link brought up an "invalid security certificate" warning. Good old Microsoft - they can't even get their own servers set up right.

    2. Re:needess to ask what OS .. by jgtg32a · · Score: 1

      You do know that has nothing to do with the server itself right?

    3. Re:needess to ask what OS .. by rs232 · · Score: 1

      "You do know that has nothing to do with the server itself right?"

      Do you have any citations for that?

      'A piece of malicious software planted on the company's payment processing network that recorded payment card data as it was being sent for processing to Heartland by thousands of the company's retail clients'

      --
      davecb5620@gmail.com
    4. Re:needess to ask what OS .. by Whuffo · · Score: 1

      Did you check the security certificate that is being used by that Microsoft site before posting? I'm sure you understand what role these certificates serve in relation to https connections.

      Of course, the connection to their site might be being intercepted by aliens who are replacing a valid certificate with a bad one. Or maybe they're using an old skool coal fired server and forgot to shake down the clinkers.

      I'll just use Occam's Razor here - and the simplest explanation is that that server is running Windows and it wasn't configured correctly.

    5. Re:needess to ask what OS .. by Kalriath · · Score: 1

      Actually, they can. It isn't invalid at all, it was merely issued by Microsoft's certification authority (which itself has a CA certificate issued by GTE CyberTrust). The problem is your browser (my Firefox 3 didn't even blink twice at it).

      --
      For a site about things like basic rights, Slashdot users sure do like to censor "dissent".
    6. Re:needess to ask what OS .. by Kalriath · · Score: 1

      And this is somehow anything to do with the server? We're talking about a payment processor, who has to comply with PCI DSS. One thing that requires is that the server managing payment data be isolated from all the client PCs, and run appropriate security software etc. If anything, this is Heartland's fault (and their PCI assessors, of course). Nothing to do with Microsoft, who for the most part make good servers (even if everything else sucks).

      --
      For a site about things like basic rights, Slashdot users sure do like to censor "dissent".
    7. Re:needess to ask what OS .. by Fulcrum+of+Evil · · Score: 1

      Sure, if you want to be pedantic, but the rest of us include the software that the server is there to run and its config in server setup. Invalid security certs don't give me a warm fuzzy.

      --
      "We returned the General to El Salvador, or maybe Guatemala, it's difficult to tell from 10,000 feet"
    8. Re:needess to ask what OS .. by WiiVault · · Score: 1

      How did this get marked troll? I mean it is relevant what software was used when a system is breached isn't it?

    9. Re:needess to ask what OS .. by Cajun+Hell · · Score: 1

      Actually, that's an example of Firefox3 screwing up in a situation where every other browser (even Firefox2) does a better job. It ought to allow me to see the page, without "adding a security exception" and risking accidentally leaving the 'permanent' box checked.

      --
      "Believe me!" -- Donald Trump
    10. Re:needess to ask what OS .. by pallmall1 · · Score: 1

      Nothing to do with Microsoft, who for the most part make good servers...

      Damn straight. Just ask any malicious software author what their server platform of choice is.

      --
      3 things about computers: they're alive, they're self-aware, and they hate your guts.
    11. Re:needess to ask what OS .. by wastedlife · · Score: 1

      Perspectives is an excellent add-on for Firefox 3 that checks pages with self-signed certs from several locations and then bypasses the terrible Firefox 3 warning page if everything checks out. This is pretty effective at negating man-in-the-middle attacks.

      --
      Said, "It's just like dice but it's got more sides And it tells me who lives and who dies"
    12. Re:needess to ask what OS .. by Anonymous Coward · · Score: 0

      I apologize for bringing that despicable thing called reality into this, but you really need to get some perspective. Operating systems are not relevant to the story. The story is about an attempted cover-up of a massive data breach. It is not an excuse to scramble to find justification and validation for your own beliefs in operating systems.

      Now that we've covered the failure of reading comprehension, let's review it from a technical perspective. Heartland handles a huge number of transactions, and someone breached their network, knowing the internal layout of it. Now, I hate to break it to you, but regardless of OS, if someone cracks the outer layer of security and makes it inside, you're screwed. They could find a rogue machine and sniff all packets for weeks on end, then ship them home covertly and analyze them to try to find details. You'd need to have every box on the LAN side to be ultra-hardened. Security for many companies consists of a Big Ass Cisco Firewall and warning employees not to open suspicious email attachments. I'm sure Heartland's security policy is better (hopefully), but security is not this black and white issue that hinges totally on operating system choice. It is far more complicated than that, and the Slashdot rhetoric in this regard is one of sheer ignorance.

    13. Re:needess to ask what OS .. by skuzzlebutt · · Score: 1

      Hi, you must be new here. Welcome to-

      Fuck it.

      --
      My debut novel AMITY now available: http://jeremydbrooks.c
    14. Re:needess to ask what OS .. by Kalriath · · Score: 1

      Uh, Linux?

      --
      For a site about things like basic rights, Slashdot users sure do like to censor "dissent".
  14. Re:First CC by Janek+Kozicki · · Score: 4, Funny

    Then prove it - what is the security code on the back?

    --
    #
    #\ @ ? Colonize Mars
    #
  15. Obvious Troll is Successful? by mfh · · Score: 0, Troll

    What does the inauguration have to do with this?

    Nice troll! Wow.

    I'll bite, since it was a really good troll you posted.

    To answer your question, the best magician does his dirty tricks when everyone's attention is fixed on a good distraction. What better way to hammer into a site and steal all kinds of info when everyone is staring at a TV?

    I would be actually somewhat surprised if this was the only major crime committed today.

    --
    The dangers of knowledge trigger emotional distress in human beings.
    1. Re:Obvious Troll is Successful? by Anonymous Coward · · Score: 0

      RTFA, it happened a while ago. It's just they only just released a press release.

  16. This is why CC zero-liability is a good thing. by brunes69 · · Score: 1

    When stuff like this happens, it is not the consumers who end up paying, but Visa / MC - who end up putting pressure on these guys to get their act together.

    1. Re:This is why CC zero-liability is a good thing. by Chuck+Chunder · · Score: 4, Informative

      Some clueless person says this every time there is a story on credit cards.

      Visa/MC do not end up paying. Merchants on the receiving end of fraudulent transactions do. Visa/MC may even profit from it as the fees they charge merchants for chargebacks can be quite steep.

      --
      Boffoonery - downloadable Comedy Benefit for Bletchley Park
    2. Re:This is why CC zero-liability is a good thing. by __aagmrb7289 · · Score: 1

      And? Most of the time, the reason the chargeback happened is because the merchant didn't bother to follow procedures - they didn't validate the identity of the person using the CC.

    3. Re:This is why CC zero-liability is a good thing. by Todd+Knarr · · Score: 2, Informative

      Save that Visa and Mastercard rules prohibit the merchant from validating the identity of the person using the credit card. For instance, a merchant is prohibited from requiring the customer to present ID (such as a driver's license) before they'll take the card. If a merchant refuses to take cards without identification, Visa/MC will terminate their merchant account.

    4. Re:This is why CC zero-liability is a good thing. by nolen · · Score: 1

      If a merchant refuses to take cards without identification, Visa/MC will terminate their merchant account.

      You're right about the rules, but nine times out of ten, large retailers will deny you if you don't show ID, just because the clerks don't know better. Visa is not about to terminate the merchant account of a Macys or Best Buy. (Yes, I've even complained with Visa about it, but I have given up on this one.) They are allowed to check your signature against the card, of course.

    5. Re:This is why CC zero-liability is a good thing. by Achromatic1978 · · Score: 2, Informative

      Not quite. The merchant agreement typically states that the merchant cannot use ID to validate the identity ONLY for card purchases. If they check ID for check purchases, too, they'd typically be free to do so. It's essentially "you cannot do anything that makes it more inconvenient to the customer to purchase via our card than via other methods".

    6. Re:This is why CC zero-liability is a good thing. by Anonymous Coward · · Score: 0

      According to your sig now you have to change. :P

    7. Re:This is why CC zero-liability is a good thing. by kalirion · · Score: 1

      You're right about the rules, but nine times out of ten, large retailers will deny you if you don't show ID

      Let me guess, you're were buying tobacco, alcohol, or porn, weren't you? Or you look extremely creepy, since usually the retailer won't even look at the signature unless you buy an expensive big screen tv.

    8. Re:This is why CC zero-liability is a good thing. by nxtw · · Score: 1

      Not quite. The merchant agreement typically states that the merchant cannot use ID to validate the identity ONLY for card purchases. If they check ID for check purchases, too, they'd typically be free to do so. It's essentially "you cannot do anything that makes it more inconvenient to the customer to purchase via our card than via other methods".

      Same applies for cash, too, which isn't quite the same as writing a check.

      How many people would present identification for a cash purchase that wasn't age restricted?

    9. Re:This is why CC zero-liability is a good thing. by skuzzlebutt · · Score: 1

      Everyone pays. Consumers deal with losses and ID theft, merchants deal with lost customers and higher fees and time to deal with the issue, acquirers and issuers pay fines and fees and hire people to work the issues and fix the problems, the card brands have to pay people to sort through the problem, ensure the current regulations were adequate and who is at fault, hire lobbyists to keep themselves from being slammed in Washington. Everybody, at all points of the industry, loses.

      --
      My debut novel AMITY now available: http://jeremydbrooks.c
    10. Re:This is why CC zero-liability is a good thing. by Achromatic1978 · · Score: 1
      Yeah, that's an awkward one - on one hand if it was a mom and pop that relied on repeat business, you could play the "keeps our merchant fees down, we pass the savings on to you!" card, but that's dubious.

      But it is possible. :)

    11. Re:This is why CC zero-liability is a good thing. by pintpusher · · Score: 1

      slightly OT, but since I own an only-slightly-larger-than-mom-and-pop business, I have to say, this sort of thing is becoming a real consideration. 10 years ago, my business was 60/40 cash/cc, now it's reversed and getting worse (because of the ubiquity of debit cards, and those stupid commercials that try to make people feel bad for paying cash...how stupid is that?). I'm seriously considering giving a cash discount just to avoid or reduce the:

      1) costs of cc transactions
      2) the hassle of securly storing so much paperwork
      3) because cash is king!

      In reality, it'll probably never happen, but once in a while I think about it.

      --
      man, I feel like mold.
    12. Re:This is why CC zero-liability is a good thing. by Achromatic1978 · · Score: 1

      Just make sure you do it as a "discount for cash", not a "fee for CCs". The former, your merchant account is fine, the latter, you can be severely slapped. And by slapped I mean a fine levied by your merchant provider / revocation of your merchant facility.

    13. Re:This is why CC zero-liability is a good thing. by pintpusher · · Score: 1

      yeah, I'm aware. What's amazing is how many small shops do charge a fee, or a minumum amount, both of which are violations of the merchant agreement. I'm always curious how they get away with it... probably no one bothers to report it and life goes on.

      --
      man, I feel like mold.
    14. Re:This is why CC zero-liability is a good thing. by Anonymous Coward · · Score: 0

      No it's not Visa and MasterCard. Is is the Merchants. The Merchants pay everything. If a card is used fraudulently at bob's taco's, the money will come out of Bob's account once the breach is discovered and he will be out the money and the taco. He can sue if he wants. The Zero Liability protects consumers at the expense of the merchant.

    15. Re:This is why CC zero-liability is a good thing. by Cedric+Tsui · · Score: 1

      The merchants don't pay. Well, not exactly. Merchants are charged a certain percentage of each transaction. I believe it is 4%. Included in this is fraud insurance.

      When a stolen credit card is used, the amount lost is paid by the insurance.

      So, it's the merchants who pay. But it comes out of their regular expenses, which gets charged to the consumer.

    16. Re:This is why CC zero-liability is a good thing. by __aagmrb7289 · · Score: 1

      Fair enough - I forgot that they couldn't require the use of ID without doing so for all transactions (according to the credit card agreement) - however - they DO have the ability to check for matching signatures, which is something most do.

  17. who pays for security ? by rs232 · · Score: 1

    "When stuff like this happens, it is not the consumers who end up paying, but Visa / MC - who end up putting pressure on these guys to get their act together"

    It's the consumers who pay for it with higher charges to pay for things like the chip-and-pin upgrade. Similar to how the consumers pay for shop-lifting ..

    --
    davecb5620@gmail.com
    1. Re:who pays for security ? by brunes69 · · Score: 1

      Last I checked it didn't cost me anything to get my chip & pin card. The only people who pay are the ones stupid enough to carry a balance on their credit card. Darwin in action AFAIAC

  18. Nothing to do with the inauguration by Geoffrey.landis · · Score: 0, Troll

    Yeah, that was my take on it-- that "inauguration" headline has nothing to do with the actual story, and the data breach has nothing whatsoever to do with the inauguration. The inauguration is just there because, hey, all the news stories today have to mention it. It's, like, a rule or something.

    I don't think it's a rule that slashdot article summaries have to mention the inauguration even if it's not relevant to the story, though. Can't somebody here look at who wrote the summary and moderate them -1 irrelevant?

    --
    http://www.geoffreylandis.com
  19. solution to CC breeches .. by rs232 · · Score: 5, Insightful

    What's needed is a totally new kind of online financial transaction system. One that don't use card numbers. A dongle on the client connects to the server generates a one-time session key,and identifies itself to the server and displays a random Pin code, the customer then types it in to verify the transaction. The session is encrypted and the data sent can only be used for the one transaction, no repeat man-in-the-middle hacks ..

    --
    davecb5620@gmail.com
    1. Re:solution to CC breeches .. by lectos · · Score: 1

      *redirects transaction and inserts own transaction for spare parts at someone else's expense*

      *reports an error to original request so that they make a new request to server for another transaction*

      *builds robot girlfriend*

    2. Re:solution to CC breeches .. by ducomputergeek · · Score: 1

      Please mod parent up. I have mod points, but posted elsewhere. Having just gone through PCI compliance (which is frankly a joke), there needs to be a better system out there.

      --
      "The problem with socialism is eventually you run out of other people's money" - Thatcher.
    3. Re:solution to CC breeches .. by Hoi+Polloi · · Score: 1

      I was just thinking the same thing today. Blizzard is offering this for WOW players to protect accounts. A loss in convienience is a small price to pay at this point to address the ever growing insecurity (not to mention costs to businesses) of the credit card system.

      --
      It is by the juice of the coffee bean that thoughts acquire speed, the teeth acquire stains. The stains become a warning
    4. Re:solution to CC breeches .. by the_olo · · Score: 1

      That's what EMV and chip and PIN with end-to-end encryption is generally all about. All that US companies need to do is stop postponing it and finally make the switch to that technology like companies in many other countries already did.

    5. Re:solution to CC breeches .. by jrumney · · Score: 1

      Not quite what you are suggesting since it doesn't connect to the client PC so there's a lot more data entry required of the user, but these devices, widely deployed by UK banks, have a feature where they can sign transaction amounts and destinations. Some banks terms and conditions hint that their use might be extended to online shopping in the near future, which would be a great improvement over the horribly insecure "click here to change your password using the information that any fraudster already has" verified by visa system.

    6. Re:solution to CC breeches .. by Anonymous Coward · · Score: 0

      If you're going that route, why not use standard public/private key cryptography methods to encrypt the channel? And what's the point of the random PIN? It should be random (large) salt that is sent to the server - the random generator on the key has a unique salt that is also known to the server on the other end. If you want even more security, require a custom PIN # (like ATM) to also be entered.

      However, these systems are significantly more expensive than the simple magnetic stripe cards. Maybe with RFID it might be possible, but I have a feeling that the low-power requirements will mean shortcuts and compromised security.

    7. Re:solution to CC breeches .. by Anonymous Coward · · Score: 0

      Sure. Guys have dongles. What will women use? ;)

    8. Re:solution to CC breeches .. by bill_mcgonigle · · Score: 1

      The technology exists. The US credit card companies have zero incentive to implement it. They pass off all the costs of fraud to mostly their merchants and occasionally their cardholders.

      A well-funded insurgent could start making some headway, but then they'd finally have reason to switch. So, good luck getting that company funded.

      --
      My God, it's Full of Source!
      OUTSIDE_IP=$(dig +short my.ip @outsideip.net)
    9. Re:solution to CC breeches .. by jc42 · · Score: 1

      Hmmm ... I walked through the Barclays demo pages, and one thing I noticed was that the URL always started with "http://". So what's to prevent my ISP or anyone else along the data path from extracting all the data from the packets and adding it to their database? In particular, I noticed that the protocol involved typing in the recipient's account number and name, which could be useful data to anyone watching the conversation.

      --
      Those who do study history are doomed to stand helplessly by while everyone else repeats it.
    10. Re:solution to CC breeches .. by jrumney · · Score: 1

      I'd be very surprised if the real Barclays internet banking site used http.

  20. why were they even by bugs2squash · · Score: 1

    storing this information ?

    --
    Nullius in verba
    1. Re:why were they even by ducomputergeek · · Score: 4, Informative

      Because they are the ones processing the transactions. We don't use heartland, but when take online orders through our website, we don't store the credit card information, our CC Processor does. The processors are the one that actually run the transactions, take money from the customers account, take a percentage, then deposit to the merchants account. And they have to keep records of all that.

      In order for CC payment to work someone has to store that data somewhere.

      --
      "The problem with socialism is eventually you run out of other people's money" - Thatcher.
    2. Re:why were they even by cbiltcliffe · · Score: 2, Informative

      I don't think they were necessarily storing it, from the press release. To me, it basically says a network sniffer picked up network traffic on the wire. That can happen whether you store the info or not.

      --
      "City hall" in German is "Rathaus" Kinda explains a few things......
    3. Re:why were they even by Repton · · Score: 1

      This happened to a processing company called CardSystems a few years ago. After that, it came out that "CardSystems had been keeping data that it was contractually obligated to delete" (quoting wikipedia) and it lead to VISA and MasterCard firing the company.

      So what is different here?

      --
      Repton.
      They say that only an experienced wizard can do the tengu shuffle.
    4. Re:why were they even by bwindle2 · · Score: 1

      Maybe they sniffed something, but the Payment Card Industry Data Security Standards, which I'm sure someone as large as these guys must be forced to comply with and get regularly audited to, clearly requires all card-holder data be encrypted, either while on-disk or on-wire.

    5. Re:why were they even by cbiltcliffe · · Score: 1

      But it's got to be decrypted somewhere, in order to be used.
      Maybe the sniffer was on the computer at one end of the encrypted connection.

      --
      "City hall" in German is "Rathaus" Kinda explains a few things......
  21. Card not present transactions by CmdrPorno · · Score: 2, Informative

    This is BS. Anyone with a card terminal can key the number in, or the card could be cloned. I discovered that FIA categorizes keying the number into the terminal as a "card present" transaction, when I tried to dispute an unrecognized charge. They then use this as a reason that the charge was legitimate, even when the card was not in fact present.

    --
    Sent from my iPhone
    1. Re:Card not present transactions by Anonymous Coward · · Score: 0

      If the merchant selects "card present" on a manually keyed transaction, they are required to provide a manual imprint of the physical card to prove it was present if there is a dispute.

    2. Re:Card not present transactions by CmdrPorno · · Score: 1

      In my case, they didn't have or provide the manual imprint, but that didn't bother FIA (now MBNA).

      --
      Sent from my iPhone
  22. Donations to Obama by robert899 · · Score: 1

    One bit of good news out of this massive breach is that, according to Heartland's CFO, "The nature of the [breach] is such that card-not-present transactions are actually quite difficult for the bad guys to do because one piece of information we know they did not get was an address." Heartland just put up a press release on the breach.

    You could have donated to the Obama campaign using a credit card without a correct address. Google "obama AVS".

  23. AVS is optional by Archon-X · · Score: 1

    AVS is not necessary to process a transaction.
    Anyone with a merchant account has the full ability to control their scrub by adjusting their AVS settings, from full matching, partial or none at all.

  24. Biometrics: When, How by BoRegardless · · Score: 1

    We have been going through these issues for years. These problems are not created by consumers, but by the companies that want to legitimately take their funds in return for goods, yet the consumers wind up having their share of problems from this.

    At some point facial, iris, thumbprint readers (of pattern or blood vessels) or something is going to have to be implemented.

    Given that most computers/cellphones have cameras now, when will it happen?

  25. cancel and re-issue lots of cards? by Benjamin_Wright · · Score: 1

    Mass re-issuance of cards may not be the best response. In the TJX experience, the cost of re-issuing cards far exceeded the actual risk. Alternatives to re-issuance include tighter monitoring of and restrictions on affected card accounts. --Ben

    --
    Benjamin Wright, Dallas, Texas, benjaminwright.us
    1. Re:cancel and re-issue lots of cards? by cdrguru · · Score: 1

      I'd say it is up to the card company. Under no circumstances is it the cardholder's problem, and never could be. Also, it is unlikely any merchant that takes reasonable care is really going to be taken.

  26. The best lie... by rickb928 · · Score: 1

    "The nature of the [breach] is such that card-not-present transactions are actually quite difficult for the bad guys to do because one piece of information we know they did not get was an address."

    Hah.

    Addresses in card-not-present transactions can in fact be gotten, and if they use AVS then at the least the AVS data is readily available.

    In other words, you're getting pwned even if it was card-not-present.

    For those not in the know, most Internet transactions, phone orders, mail orders, and eBay/PayPal transcations are card-not-present. In fact, virtually all of the above.

    The quote from Heartland was just weasel-talk.

    --
    deleting the extra space after periods so i can stay relevant, yeah.
  27. First in a long line of discoveries to come by WillAffleckUW · · Score: 5, Interesting

    Those who claim to be perfect but never admit mistakes usually are covering up for massive mistakes.

    And the missing million emails we know of are just the observable symptom, as are the transactions in this health data breach.

    The old truisms of data security still apply:

    1. It's usually insiders that provided or passed on information used to get access.

    2. Those who cover up problems only create even larger problems, due to the system of trust.

    3. You can stop 99 percent of attacks with reasonable security measures, but a determined attacker willing to use human intelligence methods will almost always get through the other 1 percent - the trick is knowing what measures will dissuade the 99 percent and implement those, and use reporting to discover the other 1 percent instead of measures that will be defeated anyway.

    --
    -- Tigger warning: This post may contain tiggers! --
  28. Re:Undisciplined users by JustNiz · · Score: 1

    >> Users who install software on their workstations.
    >> In a perfect world, software makers wouldn't write software that demands that it run with administrator privileges.

    Both of the above statements seem to indicate that you're running MS Windows. If I were you I'd be thinking about how to change that.
    Linux has a much stronger security model and generally does not require users to run apps as root.
    Also, 99.999% of virusses are windows-only.
    Also, most basic users aren't even going to be able to get their favorite windows apps running under Linux anyay.

  29. Re:Undisciplined users by erroneus · · Score: 1

    Yes, I can dream of the day I could get users over to something else...

    Sometimes people are just stuck until something better comes along. But I'll say this much: When Autodesk starts making CAD for MacOSX again, I'm pushing for change.

  30. Re:First CC by skuzzlebutt · · Score: 1

    Thanks...I needed a new one to renew my 2600 sub.

    --
    My debut novel AMITY now available: http://jeremydbrooks.c
  31. Re:Burying the News? by skuzzlebutt · · Score: 1

    Well, considering the pummeling TJMaxx got for a smaller breach, they may be trying to keep their brand from becoming synonymous with some nefarious concept like 'security breach', 'stolen credit cards', etc

    --
    My debut novel AMITY now available: http://jeremydbrooks.c
  32. So? by cdrguru · · Score: 0, Flamebait

    OK, this means that many people will now have to cancel their credit card and get a new number. Wow. Maybe 10 minutes of time lost.

    Will these people be charged anything? No. Will there be any monetary loss at all to these people? No.

    Whom does this hurt the most? Merchants that deliver services over the web without any physical shipment and without adequate verification of the card before delivering to the thief. Anything that involves a physical shipment is likely to be stopped long before it makes it out the door.

    But of course this will be talked about as "identity theft" and that it will cost people lots of time and money. Sadly, the FBI now records all credit card fraud as "identity theft" which just makes people like Todd Davis rich.

  33. 100 million by Repton · · Score: 1

    Why are we assuming 100 million transactions?

    TFA says "100 million transactions per month". But they have no idea how long the malware was in place. It could have been a week; that's 25 million transactions. It could have been six months. Hell, the TJX breach happened over the course of several years (although they weren't stealing data continuously). It sound like it'll definitely be big, and it could be the biggest ever (TJX clocks in at around 45 million transactions stolen), but we don't have any idea how big.

    --
    Repton.
    They say that only an experienced wizard can do the tengu shuffle.
  34. Why don't merchants do more over this by jonwil · · Score: 1

    Given how much it costs merchants when someone issues a chargeback (they loose the money they got paid for the goods, they likely loose the goods AND they have to pay fees to Visa/MC/etc), why aren't the merchants doing more to pick up on fraudulent transactions? And why aren't they doing more to apply pressure to Visa/MC/etc to change the rules (e.g. get rid of the rules that make it harder for them to do ID checks etc to pick up the fraud)

    I have no clue how much money, say, Wal-Mart is out annually because of credit card fraud but they must be big enough to lobby Visa/MC for change. Or better yet, lobby the government to change the rules so that Visa/MC foot the bill for fraud instead of the merchants. Argue that since the merchants are prohibited by Visa/MC rules from taking these measures that would help prevent fraud, they shouldn't be liable for said fraud).

    In any case, merchants on the receiving end of a chargeback are the losers when it comes to credit card fraud so it would be in their best interest to use their lobbying power to fight for a better deal (or can Visa/MC out-lobby even the might of Wal-Mart?)

  35. It's 999, everyone knows that! by freaker_TuC · · Score: 1

    I'm smarter, so I just won't let you know the order of the numbers ...

    --
    --- I am known for the ones who want to find me on the net. Is that a privacy risk or a privilege? One might wonder..
  36. HUH?? CNP not hard to do? by new+death+barbie · · Score: 1

    "The nature of the [breach] is such that card-not-present transactions are actually quite difficult for the bad guys to do because one piece of information we know they did not get was an address."

    So... of the 300-million-plus transactions they KNOW have been exposed, NONE of them were card-not-present(CNP) transactions that included address verification data?

    Address verification data might not be enough for identify theft -- but then it might -- but it SURE as hell is enough to forge more CNP transactions. Oh, and by the way, a lot of CNP transactions would ALSO include the CVV2 on the back of the card.

    What are the odds that, out of 300 million transactions, SOME cards have been used in both card-present AND card-not-present situations? Simply match on card numbers, and poof! Magstripe *and* AVS *and* CVV2. That's the whole card security scheme, shot to hell. Pwned.

    --

    It's supposed to be completely automatic, but actually you have to press this button.

    1. Re:HUH?? CNP not hard to do? by stubob · · Score: 1

      Credit cards are a great example of security theater. It's like walking around with your root password written down in your wallet.

      Is there any technical limitation preventing an RSA-like dongle for verifying credit cards? Just like we're all accustomed to logging into VPN, you enter your user id, passpharse AND randomly-generated key. That way, even if the transmission is intercepted, the key is useless for the next translation.

      --
      Planning to be moderated ± 1: Bad Pun.
  37. Good and Bad are Relative by nutznboltz · · Score: 1

    As icky as this might sound, the longer it takes before we crash the higher the population.

    Crashing sooner involves fewer people suffering.

  38. This sucks... by hesaigo999ca · · Score: 1

    Again, no accountability for keeping personal info of people that trust your organization.
    I tell you no don't keep records of my cc in your db. You say, we can and will....is there not a police for this sort of thing? Sounds to me like this should be another one of Obama's point of interest while in office.

  39. Data Theft, Breach, Infection - a Solution? by johnfranks999 · · Score: 1

    Price Waterhouse Cooper and Carnegie-Mellonâ(TM)s CyLab have recent surveys that show the senior executive class to be, basically, clueless regarding IT risk and its tie to overall enterprise (business) risk. Data breaches and thefts are due to a lagging business culture â" and people arenâ(TM)t getting the training they need. For example: Microsoft patched for this virus 4 months ago. I like to pass along things that work, in hopes that good ideas make their way back to me, and as CIO, I look for ways to help my business and IT teams further their education. Check your local library: A book that is required reading is "I.T. WARS: Managing the Business-Technology Weave in the New Millennium." It also helps outside agencies understand your values and practices. The author, David Scott, has an interview that is a great exposure: http://businessforum.com/DScott_02.html - The book came to us as a tip from an intern who attended a course at University of Wisconsin, where the book is an MBA text. It has helped us to understand that, while various systems of security are important, no system can overcome laxity, ignorance, or deliberate intent to harm. Necessary is a sustained culture and awareness; an efficient prism through which every activity is viewed from a security perspective prior to action. In the realm of risk, unmanaged possibilities become probabilities â" read the book BEFORE you suffer a bad outcome â" or propagate one.