Slashdot Mirror


User: khanta

khanta's activity in the archive.

Stories
0
Comments
4
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 4

  1. Re:Software that Target uses on Encrypted PIN Data Taken In Target Breach · · Score: 1

    There is a case study on Target on the Microsoft website. That should point you in the right direction. I am sure I will get flamed for this, but Target is a victim as well here. They were attacked by criminals, and determined ones. I don't think the OS/Software version is what hurt them, I think the fact that they were not using encrypted terminals was the mistake. If you compromise a network, how hard is it to get malware that scrapes memory? A good regex that searches for PANs in POS process space seems like it would be very effective. POS vendors are supposed to make sure their software is handling card data securely, but they trust the OS they are running on. I would love to comment more.... Hopefully it will come out what happened, but most likely it was similar to TJX. Some misconfigured wireless or something to that effect. Get on the network, find some vulnerable systems. Pivot, Find the server that the POS boots of off. Infect. Site back and wait. As for the PIN data. I am not too worried.

  2. Re: Why are they storing this data anyway? on Encrypted PIN Data Taken In Target Breach · · Score: 2, Interesting

    Terminals encrypt PIN data inside the device. The terminals they use are PED certified. DUKPT is used, and the data should be safe. The PIN block should stay encrypted all the way to the processor. If it is decrypted it should be done in an HSM. The malware was most likely scraping memory on the POS and grabbing track data as it was passed from terminal to the POS. Then they somehow exfiltrated it out. Obviously they weren't using encrypted terminals. I don't think target stored this data centrally. Most likely just infected POS stations. My bet is at the source and they all booted up infected stations. Sorry for the terse responses.

  3. Re:Does this mean on Scientists Trap a Rainbow · · Score: 1

    Did you say BEES?!?!?!

  4. Breaking the law! on Taking My Freedom With Me to China? · · Score: 1

    After reading what you have said, I feel you are just looking for a way to break the law. There is no other way to put it. Circumvent, avoid, being surreptitious, clandestine, stealthy. It does not matter. As other people have posted, do not do it. There is no "Please stop that" letter or email, if you piss off the wrong people, you will not be happy. My advice, with that mentality, do not move to China. Good luck either way.