Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards
krebsonsecurity.com
krebsonsecurity.com
What is possessing Sonic to keep the number any longer than the period it takes to receive money from the CC company? And why is this period any longer than the 20 or so seconds it takes to process the card at a machine? Are all of these magnetic-only or do they store CC numbers with chip cards as well?
They don't. From the article:
"Malicious hackers typically steal credit card data from organizations that accept cards by hacking into point-of-sale systems remotely and seeding those systems with malicious software that can copy account data stored on a card’s magnetic stripe. Thieves can use that data to clone the cards and then use the counterfeits to buy high-priced merchandise from electronics stores and big box retailers."
"The last known major card breach involving a large nationwide fast-food chain impacted more than a thousand Wendy’s locations and persisted for almost nine months after it was first disclosed here. The Wendy’s breach was extremely costly for card-issuing banks and credit unions, which were forced to continuously re-issue customer cards that kept getting re-compromised every time their customers went back to eat at another Wendy’s."
That provides an interesting lesson for vendors doing CC transactions: card compromise does not impact repeat business, so don't worry about breaches.
This is why I think the merchant processors should be instead be doing this by some kind of transaction ID. I.e. send the refund amount to the processor with the transaction ID instead of sending a new transaction to the card. It's more secure, and less error prone since you could build in checks for the amount returned and other such bits.
If even that small risk of conflating two different customers is too high, you could go with a hash of the credit card number.
If you go with the hash, then don't ALSO store first 6/last 4. A typical credit card number is 16 digits, and one of those is a check digit. If someone gets a hold of the hash, and first 6/last 4, then there are only 100 000 possible values for the missing 6 digits (10^5, not 10^6, because for any guess for 5 of the digits there is only one possible 6th digit that will make the checksum work). Unless you use a very very slow hash function, brute forcing 100 000 possibilities will be quick.
Usually the first four is the issuer and whatever numbers signify the specific type of card. The next set is the bank, I think. The third set is, as I recall, the account number, and the last numbers equate to your routing number.
Actually, just the last eight digits should be adequate. Hash them with a salt based on the last name and collisions are very, very unlikely. Don't store them at all, just store the hashes.
Choose metadata that doesn't have such high financial value. Additionally, it's been years since I've been involved in e-commerce and the details are now foggy, but if I recall storing those addition credit card digits, even transformed, will prevent you from achieving the industrial certifications.
https://krebsonsecurity.com/2014/02/target-hackers-broke-in-...
While Target does store transaction information, they don't store the actual credit card info. That's why you need to provide the physical credit card to do a return, or they give you store credit.
It's possible Equifax was the only credit agency with enough information to require public disclosure... if Transunion doesn't have the right logs or monitors, they may never find out they've been breached, and nor will we.
At this point, I assume everything on a computer can become public.
One of the few times I don't enjoy been right, I'm fortunate in that I'm vanilla, FSM help people under repressive regimes or who hold opinions that worry those in authority wherever they are.
We managed to combine a panopticon with a Skinner box somehow and people like it because it's shiny.
So, your last sentence is true.
However, there are ways to secure things in a practical manner and ways to detect, and stop, intrusions - though those ways look nothing like they do in the movies.
There are practical ways to limit exposure and to make data exfiltration more difficult. There are layers and practices that can be put in place to make it more difficult to do and easier to notice.
They are expensive and they do impact efficiency and may impact efficacy.
The easiest way to avoid data exfiltration is to not store it in the first place. But, that means they are less able to track the consumer and then less able to do effective targeting of ads and things like that.
The bottom line is it is expensive to reasonably secure your systems and the penalty for not doing so is less than the profits being made from not securing their systems in a reasonable manner.
Without larger penalties, this is unlikely to change. Maybe, just maybe, enough people will be impacted to where they actually start imposing serious penalties for negligence or willfully neglecting security. Maybe...
Abstract: In this bleak, relentlessly morbid talk, James Mickens will describe why making computers secure is an intrinsically impossible task. He will explain why no programming language makes it easy to write secure code. He will then discuss why cloud computing is a black hole for privacy, and only useful for people who want to fill your machine with ads, viruses, or viruses that masquerade as ads. At this point in the talk, an audience member may suggest that Bitcoins can make things better. Mickens will laugh at this audience member and then explain why trusting the Bitcoin infrastructure is like asking Dracula to become a vegan. Mickens will conclude by describing why true love is a joke and why we are all destined to die alone and tormented. The first ten attendees will get balloon animals, and/or an unconvincing explanation about why Mickens intended to (but did not) bring balloon animals. Mickens will then flee on horseback while shouting “The Prince of Lies escapes again!”
A huge advantage of Apply Pay is that you get the security of a PIN without the hassle of entering a PIN -- or the risk of it being stolen during PIN entry. You just authenticate with your fingerprint or, soon, your face. (Please no comments speculating that this is less secure than a fingerprint. It's premature to say and unless you know something Apple doesn't, you're probably wrong.)
Another less understood advantage is that Apple Pay takes the strongest approach to tokenization, which makes it effectively immune to merchant hardware compromises. Even chip cards rely on the card readers at points of sale to handle tokenization, so a hacked reader could in theory leak PANs. On top of that, lots of merchants/processors don't even bother with tokenization, so it's a crap shoot with every merchant.
Apple Pay tokenizes when you enroll your card, so the PAN (primary account number) never passes through any merchant systems anywhere ever. This means the tokenized numbers that hackers could steal from merchants are useless outside of two-factor-secured Apple Pay.
You're right except when your bank is a bunch of consumer hostile idiots that still make you enter the PIN.
You are forgetting that tools like Apple Pay are not hassle free for most people, especially those outside of IT circles. Millions of people struggle to use anything beyond basic technology (American banks have even decided that PIN's are too confusing! A four digit number that has been common in the rest of the world for decades!). Combine that with other factors like fears of being caught with a flat battery or businesses that are reluctant to spend money on new POS devices - it's unlikely that plastic cards are going away anytime soon.
Also, I'm not sure entering a PIN is really any more hassle than using a phone as a payment device (I use Android Pay whenever I can due to the added security features but the POS readers are often incredibly slow).
And in terms of speed, are we living on the same planet? Chip-and-PIN is notoriously slow in the U.S. Apple Pay takes a second.
Also I'm not saying plastic will go away anytime soon. There will be legacy terminals. I'm saying Apply Pay and its ilk are superior to chip-and-PIN, a two decade old technology.
Are we? I assume you have never experienced the requests for support from tech illiterate relatives since childhood for assistance with VCR's, PC's, basic cell phones, printers, anything USB related in the 90's, scanners, cable boxes, modems, endless websites/web applications, and of course, smartphones. Demographic changes are shifting the definition of "average consumer" but boomers still dominate and many of them struggle with technology.
Chip and PIN is indeed slow in the US (I grew up elsewhere and travel regularly so it drives me insane) but the experience with Android Pay isn't necessarily faster or more convenient. Like I said, I use Android Pay whenever I can but I don't recall ever seeing another person using their smartphone to pay in a store.
A quick search seems to suggest this is more than just anecdotal:
http://fortune.com/2017/08/04/apple-pay-samsung-mobile-payme...
"Despite much publicity upon launch, Apple Pay, Samsung Pay, and Android Pay have struggled to gain traction," the analysts concluded. "Mobile wallet adoption has been underwhelming to date by nearly every objective standard, including initial penetration of smartphone users and repeat usage rate. While up to one-third of U.S. phone owners have enrolled in the payment plans, frequent usage is uncommon, the analysts said. Only 8%, 6%, and 3% of people use Apple Pay, Samsung Pay, and Android Pay at least once per week."
From the downvotes I assume it's a regional thing!
And did you just compare enrolling in Apple Pay to a VCR? All you have to do is point your camera at your card. That’s pretty much it. It is very consumer friendly.
I would use Apple Pay all the time if more of the places I frequent supported it.
My argument is not "merchant's shouldn't support chip-and-PIN." It's a fine fallback method. I'm just surprised Krebs mentioned that instead of Apple Pay.
Say what you want about Bitcoin, but it does solve credit card theft for good. If I could use my Bitcoin hardware wallet¹ to pay Sonic, I wouldn't be affected by this security breach.
¹ No Bitcoin theft has ever occurred on a hardware wallet thanks to their tamper proof isolation of private keys.
Also you completely ignored my point about hardware wallets making theft a non-problem.
Our discussion thread demonstrates that more education is needed around hardware wallets, as most people have no idea how they work or even that they exist.
This has never happened to me, and ive had a CC compromised a few times.
If someone steals your hardware wallet, what do you consider that?
When did cash get 2 factor auth?
All of the major wallets/traders use 2FA and all the hardware wallets have it too.
It's like saying... Well there's safes and banks for cash but its something that not everyone "enables" but you and I both know they use it.
Very little cash is stolen by pick-pockets or home burglars. People open their wallets because they fear pain, it doesn't matter how many locks are on the wallet.
relevant xkcd: https://xkcd.com/538/
Chip + Pin solves it even better by forcing the attacker to learn the pin for the card. We're not there yet in the US but once everyone has modern chip readers, adding pins will be trivial.
Also as a customer I'm not liable for these issues. The vendor is. With cryptocurrency, if there's a hack against me and my coins are gone, well, they're gone forever.
Sure beats giving up on cc's entirely for cryptocurrency, which comes with its own headaches and problems, especially Bitcoin which as a network wouldnt be able to cover 1 hour of credit transactions in the states.
That's not how chip cards work.
Credit cards are built on underlying currencies, offering easy short-term debt and a simpler payment process (compared to check/cash)... I expect that bitcoin credit cards are another prerequisite for consumer adoption.
This also roughly applies to chip-and-pin systems, where the chip holds the private key. They're both like cash in a wallet -- giving someone cash from your wallet doesn't give them the ability to magically disappear more money while your wallet's sitting beside your bed later that night.
Whereas with a (non-chip) credit card, once another party has your information just once, a theft can happen anytime from then until years later when the CC expires.
I need to point out that your comment ("idiots") is against HN guidelines ("be civil"): https://news.ycombinator.com/newsguidelines.html
Apple Pay and related solutions offer "tamper proof isolation of private keys" while still offering all of the consumer protections of cards, plus broad and growing acceptance via compatibility with standard contactless card terminals and POS systems.
True. On the flip side, most merchants are honest so chargebacks are rarely needed. It's a different tradeoff: credit cards open you to ID theft, which is a lot more prevalent than the need for a chargeback, so personally I prefer Bitcoin.
«accepted approximately nowhere»
Any new technology, such as Bitcoin or Apple Pay, has to start from zero. So it is an irrelevant argument anyway. Today Bitcoin is in fact accepted at about 160,000 merchants.
«very little incentive for merchants to add support»
Not true. The biggest, and arguably most important, incentive for merchants to accept Bitcoin is that it allows them to avoid chargeback fraud (payments are irreversible.)
Apple Pay & similar technologies are a huge step up from plain credit/debit cards. Really, it's important to recognize this. But they still have multiple drawbacks. For example, (1) it has transaction limits, (2) it isn't usable for person-to-person payments (eg. paying back lunch money to a coworker), (3) purchases are still subject to authorization so in a way you don't have 100% control of your own money (eg. the system could accidentally flag the transaction as fraudulent and prevent you from buying something.)
You also lose the convenience factor of that I don't need to care if a merchant is honest. If it's a merchant I haven't heard of it, I can just make the order without worrying too much (providing there are no obvious red flags) as there's very little risk. On the other hand, Bitcoin's irreversibly would mean I'd have to look into the company before ordering, and I'd probably avoid smaller merchants as a result.
> it allows them to avoid chargeback fraud (payments are irreversible.)
How big of an issue is this in practice? My gut reaction is most customers are honest so it's not big enough incentive to add another payment flow, but I've got no idea if that is accurate or not.
You are right. However, examine your pattern of purchases: if you are like the typical consumer, most of your purchases are made at the same merchants that you have been shopping at for years and already trust.
«How big of an issue is this in practice»
It's a huge issue in some markets (eg. online shopping.) I can't remember the stats but CC fraud actually has bankrupted some merchants because it is so prevalent. Dishonest clients are a lot more common than dishonest merchants. It's easy to understand why: by being dishonest, a merchant damages its reputation instantly, however if someone attempts to use a stolen CC and gets flagged, he would simply try another CC number or try another merchant.
And to say that virtually no merchant acceptance[1] is an “irrelevant argument” is laughable. Merchants have little incentive to spend money and effort to add support for an obscure payment method that virtually no one uses and likely never will, due to its reduction in consumer benefits. Apple Pay piggybacked the rollout of contactless terminals which gave it support at millions of locations out of the gate, and fully supports standard consumer protections and reward programs.
Finally, “person-to-person payments” is completely irrelevant to person-to-business transactions. But even in that corner Apple Pay will very soon be superior to any other method for “paying back lunch money to a coworker”. They are rolling out P2P this fall which supports all debit cards, is free, instantaneous, and you can spend the money right away at any Apple Pay merchant or send it to your bank account.
That cuts your argument down to just avoiding transaction limits and authorization at merchants you trust. Extremely narrow use case, so no way there’s going to be enough consumer interest to drive merchant adoption.
[1] https://www.bloomberg.com/news/articles/2017-07-12/bitcoin-a...
Yes there will probably be a minor uptick in merchants being dishonest. But I doubt it will be as bad as you make it to be. Many other factors push merchants to stay honest: legal repercussions, damaged reputation, etc.
«And to say that virtually no merchant acceptance[1] is an “irrelevant argument” is laughable»
Irrelevant was the wrong word. I meant illogical. Your argument is like saying in the early days of Blu-ray that "no one will buy Blu-ray discs because no one has Blu-ray players".
«Merchants have little incentive»
Second time you say it, second time you are wrong. I already pointed out their main (largest!) incentive to accept BTC is to avoid chargeback fraud. This fraud is a major problem for merchants. They can go bankrupt (eg. https://www.youtube.com/watch?v=6Chp12sEnWk&t=45m0s) or be drawn into costly suits with no way to recover the money (https://www.reddit.com/r/legaladvice/comments/5r9nqi/credit_...).
Apple Pay P2P will be riddled with roadblocks. For starters most people will not be able to use it as it requires a $500 device (iPhone). I guarantee you there will be transaction limits, delays in access to funds, etc. All things that Bitcoin solves.
Simply wishful thinking. If that were the case consumer protections never would have been a very interesting feature. But they are. Especially for ecommerce.
> Your argument is like saying in the early days of Blu-ray that "no one will buy Blu-ray discs...
No and I clearly stated otherwise. Apple Pay is more like launching a new disc standard that is compatible with millions of existing players already deployed, compared to one that requires brand new hardware and has fewer features. No contest.
You also ignored -- probably because it is in your interest to ignore it -- that the reason merchants have no incentive to adopt is that nobody uses it. Payments are a two-sided market. Advances need to offer benefits to both sides of the market. You've only cited an advantage to one side, the merchant, which comes directly at the cost of a regression in benefits to the other side, the consumer.
Bitcoin as it stands is a major regression in consumer benefits, and you've only managed to cite one extremely narrow case where it offers any advantage whatsoever (no transaction limits or approval step). This is nowhere near enough to offer a compelling value proposition to consumers.
As for P2P, your own use case was sending lunch money. You've offered nothing to suggest that Apple Pay won't dominate this category. You're also incorrect in your "guarantee" about delays in access to funds; they are debit transactions that process instantly.
People will pay in BTC only merchants that they already trust. Think high-reputation businesses like Amazon, Costco. Do you really think companies like that would start being dishonest if they accepted bitcoins?
«compared to one that requires brand new hardware»
No, accepting Bitcoin doesn't require new hardware. It's a software update to a website or to a point-of-sale.
«You also ignored -- probably because it is in your interest to ignore it -- that the reason merchants have no incentive to adopt is that nobody uses it»
You can continue writing they have "no incentive" but it doesn't make it true. This is the 3rd time you ignore it, and the 3rd time I point it out: their #1 incentive to accept BTC is to avoid chargeback fraud. Will I have to repeat it a 4th time?
As to "nobody uses it", I am not ignoring you, it is simply that you are wrong. Usage is growing: we got from 0 to 160,000 merchants in a few years, the transaction rate is doubling every 18 months (not due to speculation: https://news.ycombinator.com/item?id=15281860)
«Bitcoin as it stands is a major regression in consumer benefits»
It is a (small) regression, yes, no denying that, but it is far outweighed by the advantages: permissionless, near-instant international payments, no inflation, censorship-resistant, gives access to the underbanked/unbanked, etc.
As to Apple P2P, it is pointless to continue discussing it before it is rolled out and before we have a clear idea of its advantages and inconvenients. But I maintain my position that, if not delays, there will be transactions limits, and it also won't ever be used widely (for starters, only 2-3% of the world population has an iPhone.)
Bitcoin is very similar to cash in many respects, especially when compared to credit cards.
I doubt anyone would say this:
> Say what you want about cash, but it does solve credit card theft for good. If I could use my cash wallet to pay Sonic, I wouldn't be affected by this security breach
It's obviously true, but it's also trivial and pointless. Saying Bitcoin instead of cash doesn't change any of that.