Breach at Dickey’s BBQ Smokes 3M Cards
krebsonsecurity.com
krebsonsecurity.com
Makes me glad I never went there.
See: Starbucks and Seattle residents.
It's good that I don't live in Austin any more because I'd probably camp at Franklin's 24/7 and never leave. Although I don't know if or how Franklin works during COVID.
https://corporatefinanceinstitute.com/resources/knowledge/ot....
Here: better to just spell out "3 million", I reckon.
Is more universally understood I think. Also, seems like more work to write out 4MMM rather than 4b.
https://en.wikipedia.org/wiki/Metric_prefix
https://www.nist.gov/pml/weights-and-measures/metric-si-pref...
I also meant q for quadrillions, not a.
m (lowercase) means “milli-,” which certainly isn’t what you want.
There is a somewhat dated system of abbreviations that used be (and occasionally still is) used in finance-related matters inspired by the use of M in Roman numerals where M or m is thousands and MM or mm is millions; different sources disagree on whether MMM/mmm can also be used for billions in that system.
Recently, it's been displaced by a probably-SI-inspired (but not SI-correct, particularly as regards capitalization which remains optional) system of K/k and M/m thousands and millions (but billions are usually not G/g, I've seen B/b more frequently, with T/t for trillions.)
IMO the title could be less dense: "Data breach of 3 million cards at Dickey's BBQ"
Nice job, holding franchisees responsible. Dickey's won't have to answer for the actual breach because the franchisees also had poor security.
That's it. Occasionally they ask you to sign on the past or hit the ok button but usually not even that.
I've had a card number ripped off via an online retailer and Visa figured it out on the first fraudulent charge.
In the UK it's the store... unless they made you use chip and a PIN. Which is why they all use the chip and a PIN. Then it's the card provider, but it's not because the chip and PIN prevents fraud before that point. I think the card provider eats contactless payments because they encourage more of them so it adds up in the end.
Card holder liability on timely reported loss or stolen card is capped at $50 or something.
There is generally no chip and pin. Some older terminals hard crash on PINs on credit. Some older terminals hard crash on PINs exceeding 4 chars
Go on your Credit Card website and there will be a place to request that they send you the number.
I'm not 100% sure about the ATM though, I've never tried to use it, plus the interest rate for a cash advance is nuts.
Really? You say your pin code over the phone?
A security "password" for doing phone banking is different.
If you care about entropy, don't leave it up to users.
The automated phone system accepts number input, but the resulting rep may ask to verify.
My bank claims to not know the card pin(my dad forgot, he had to go to the bank and set a new pin after verifying it's him)
Not sure op meant the same thing or they literally providing their card pin over the phone which is a bit crazy
Debit Card, yes
Source: used to work adjacent to the fraud analysis group at a large bank.
If you can checkout some places without it, the card does not require a PIN, it provides it as an option.
So I think it's possible for a card to insist upon doing a PIN transaction if that's possible, while still retaining the ability to authorize a no-PIN transaction if the terminal says it doesn't do PINs.
It's also possible for the card or the terminal to have value-related thresholds, in line with the issuer's appetite for risk so e.g. maybe a bag of chips from a vending machine with no PIN is a risk the bank can live with, but a $3000 diamond engagement ring not so much.
Because the chip has (some) memory it can even have state, maybe one $1.50 bag of popcorn from an offline no-PIN terminal is fine, and so is two, but before you can do a third tiny off-line transaction you'll need to do a real transaction or visit an ATM or other online system with the card so it be reassured everything is on the up-and-up.
It's just American banks pressure Visa and Mastercard not to implement and so they get waivers after waivers to postpone implementation.
Here in Poland and everywhere else in the world PINs have been absolutely required on new cards for over a decade.
At every step Visa and MasterCard promotes highest possible level of security.
To give you an example, when implementing the terminal application you have to be able to support a range of CVMs (Cardholder Verification Methods) that might be presented by the card. The CVM list is a detail personalized on the card by the Bank, issuer of the card.
The algorithm actively promotes selecting the strongest authentication method that is supported by the card and always prefers PIN over signature (ie if PIN CVM is available it should not be possible to normally use signature).
This is verified during certification process and applications that don't meet this requirement fail certification.
There are also rules and internal memos which are sent to both acquirers and issuers, to which I have been privy to, which exert pressure on issuers to improve their security to deal with frauds. We were also regularly notified on new types of frauds detected and how to help preventing them.
The terminal application should also always prefers chip over magnetic stripe up to the point where magnetic stripe transaction is only allowed as a fallback after chip is found to be inoperable. So on a well implemented terminal you have to try chip first and only if it doesn't work the terminal should allow you to try with magstripe, if the magstripe says that the card is chip-capable.
Additionally, Visa and Mastercard both monitor rates of fallbacks (situations where magstripe is used with chip-capable cards) and issues penalties to entities that cross specific thresholds.
No doubt you've drunk the Kool-Aid but this isn't true. EMV rests heavily upon cryptographic protocols, we know the highest possible level of security is achieved for such protocols by publishing them for evaluation and improvement by independent researchers. EMV didn't do that.
There are many but here's a particularly low hanging piece of fruit that results from not having independent researchers looking over what you've done:
It is critical to the EMV design that the payment terminal picks unpredictable numbers. These aren't just nonces, where it only matters that they're different, they must be random or a relatively cheap (worth doing to forge credit card transactions) attack succeeds. So what do you suppose those standards documents require? You might even have read it.
The certification document says for testing read two of these "unpredictable" values. Ensure they are different.
Guess what lots of real hardware actually deployed in the wild does to achieve that requirement? It uses a counter. Because random numbers might sometimes not be different leading to a tiny chance of failing the mandatory test, but a counter will reliably pass the test even though it's insecure. Genius. So you go from "Hypothetical adversary needs to guess a large random number" to "It's just a counter" and attack cost falls from billions of dollars to a few cents per transaction on top of R&D.
The United States has legislation protecting credit card holders. It limits out-of-pocket expenses for any fraud to $50.
In practical terms, you notify your credit card company and they just remove the charge and there is no cost and very little hassle or drama.
A similar situation is probably car insurance and car theft.
I think because we have car insurance, we probably have higher levels of car theft. It has probably become sort of decriminalized because the harm is likely less and the insurance companies treat it as a cost of doing business.
Meanwhile 200 years ago horse thieves, who were probably not caught, did real damage to people even though the penalties of being caught was probably hanging.
As to fraud, you might be misunderstanding this. There are different types of fraud and not all are covered the same.
I don't know US legislation, but what you should know, legislation or not, Visa and Mastercard offer chargeback program (don't mistake with cashback) where you can notify your bank when the transaction was not authorized by you or when you have authorized but not received the service or the goods or services did not agree with the what you agreed with the merchant (ie. when you got blue shirt when ordered green one). This is NO QUESTIONS ASKED, ie. now it is up to the Merchant to prove that they are in the right and if they can't prove it, you are credited with the amount automatically.
Now, this happens when the transaction happened through Visa/Mastercard network.
When you are using the card at ATM this is fundamentally different thing. The ATM is most likely operated by your own bank or through an agreement with some other entity that is not Visa/Mastercard.
You can think of this, that the card functions as an identifier that can be used to run transactions using completely different systems.
Also there are a different kind of card called a debit cards (or an atm card). These are not credit cards and withdraw money from your bank account. They require a pin as well.
You can use a debit card to purchase something at a point of sale - but you must give a pin. The money is taken from your bank account (and visa/mastercard are involved)
However the vast majority of point of sale transactions are credit card transactions and go through the visa/mastercard network.
I used to have a debit card (decades ago) and had one fraudulent transaction. I called my bank, they credited me the money, investigated, and then made it final.
When you are shopping your card is used through Visa/Mastercard network.
When you are at ATM your card is used in a completely separate way, basically functioning as an identifier. The same way you can use phone number to log in to your google account even though it was not originally meant for it.
Also you mix debit/credit thing with other stuff. Debit and credit cards authorize the same way. The difference is how the transactions are processed at your bank, but this has nothing to do with whether the transaction is pin or signature.
The only time a pin is NOT required is if it goes through visa/mc. And you have protections.
Please read this:
https://www.daveramsey.com/blog/debit-card-fraud
The truth is this:
Merchants WANT you to be able to use your card - without thinking, with little friction and often. They make lots more money with this state of affairs than fraud takes away.
The first thing to know is that payment cards have two almost unrelated systems, named Authorization and Settlement. Authorization is about protecting the card company from crooked card holders by validating that the card holder authorized this transaction. It's optional, and it has some modern technologies like EMV (Europay/Mastercard/Visa the joint system known for the presence of a chip on your card) which could enable PIN verification if you wanted.
Settlement is the part that moves money from your account to a merchant's account, it's childishly simple and it is run almost entirely on the honour system like it was when it was invented last century. A merchant says card 1234 5678 9012 3456 was used to pay them $280, the card company either accepts that and moves $280 from the account associated with that card to the account for the merchant, or they refuse. The merchant can provide more information, but they don't have to and will usually get paid regardless.
The fancy modern technology for Authorization makes no difference to Settlement. If the bank receives a Settlement for a transaction supposedly made with a card you actually tossed into the mouth of an active volcano a month earlier, the only thing likely to stop that getting paid is if you call the bank and insist you made no such transaction, confident that the merchant doesn't have evidence to the contrary because duh, that card was destroyed a month ago.
Check your statements. Read every line item, dispute anything you don't recognise. Even if you use (for example) Apple Pay every single time, your bank is under no obligation to treat a $150 payment for scratch offs supposedly made with a mag stripe card on the far side of the country as suspicious and block it. They might, but they might not, that's on you.
The volume of fraud is driven by easy ways to steal a shared "secret" that should never have existed (a card number, the only thing truly needed for Settlement) and then use that to fraudulently obtain things of value. PINs don't really impact that, they're a defence against a much rarer crime - theft of the card. A pickpocket or burglar doesn't know your PIN. But pickpockets do not steal millions of cards at a time.
If you have a card, with a PIN, and you used that card, with a PIN, at Dickey's, there is every chance you're vulnerable as a result of this anyway. Do the crooks get your PIN? Nope. But chances are your priority wasn't keeping a four digit number secret but not losing your money.
At one point the card processors had a very nice crypto protocol called SET that kept the card numbers out of everyone’s hands. At the time the crypto was really overwhelming and it would take like twenty seconds to do all the math on a high end (for the time) processor. The other problem was that the reference implementation was done by an absolute c++ zealot who was furious he had to write the code in C so tens of thousands of lines of code was dedicated to implementing all the c++ features in C which pretty much made the reference useless except for interoperability testing.
Unfortunately the standard never took off and you can’t find it anymore.
The weird thing was that I’d get hit with an anti fraud decline getting gas in NY or Mass 50 miles from home, and it kept happening even after card replacement.
When you’re on a 14-24 hour drive, your options within 5 minutes of I95 are limited. There are some awesome options that need that criteria as well, but their hours often don’t match my travel schedule on that trip!
I was genuinely surprised when I went to college further up the east coast and found out the hate on tv shows was a real opinion. It definitely wasn't as good up north but not that bad. I'd heard the further from the east coast, and for some reason Richmond, the worse it gets, with California friends despising it.
In the pantheon of fast food as defined by me, only a New Jersey Turnpike Roy Rogers (may no longer exist) rates lower!
I think this is blaming the wrong people. I mean, do we really think some small fry BBQ restaurant franchisee can do adequate IT security now?
The issue is that credit card numbers are fundamentally insecure. We must move financial systems to a signed transactions model where private keys only live on secure hardware modules. This idea that we can have credit card numbers floating between consumers and merchants and payment processors and banks is nonsense.
I had to cancel my bank account to stop payments.
They can certainly follow instructions from their payment processor.
However, it seems that Dickey's corporate must also be to blame. Lots of small businesses in USA have old swipe-style readers, but rarely are they lumped together in a single giant hack like this.