Target hackers stole encrypted bank PINs, according to source [video]
chicagotribune.com
chicagotribune.com
As far as most consumers are concerned, CVV or CVC is synonymous with CVV2, since that's what folks are asked to enter when shopping online. If you're not an engineer or work in the payment industry, you probably don't know CVV1 exists.
Storing PINs in any form is absolutely insane. People deserve to get fired for this.
I don't think Target was storing pins, which is prohibited regardless of encryption. It sounds like the attackers sniffed encrypted pins.
PINs should be encrypted by the Verifone pinpad itself, using keys that were burned into the device by the manufacturer.
If the attacker compromised the pinpad device, then it's possible for unencrypted PINs to be intercepted at the point of entry.
If the POS device or the store network was compromised, then encrypted PINs could be harvested on the wire.
What is likely, and also not very significant, is that they intercepted encrypted PIN blocks along with unencrypted mag stripe data. Of course, if they managed to decrypt the encrypted PINs, that would be huge. But I highly doubt it.
A PIN-pad is a tamper-resistant, self-contained systems that accepts the PIN from its key pad, encrypts it on the fly using secret keys burned in by the supplier, and uploads the entered PIN in the form of a fixed-length encrypted "PIN block" which can only be decrypted by the payment processor.
Therefore, in order to get the PINs on the fly, the bad guys would have had to physically compromise a large number of POS terminals at a large number of stores at high risk of getting caught. That's not plausible. What is plausible is that they broke into Target's corporate network and tapped the transaction flow between the POS terminals and the payment processors. That would give them the mag stripes and any encrypted PIN blocks entered, but not the unencrypted PINs.
There was a case† a few years ago in Rhode Island in which banks experienced a spate of disavowed ATM withdrawals. They noticed that the complaining customers had all shopped at a certain all-night Stop & Shop supermarket. Reviewing the supermarket's surveillance tapes, police observed a quartet of guys arriving during third-shift. One guy engaged the attention of the thin staff, while the other three swapped out PIN pads for hacked versions. They were caught when they returned to retrieve their haul (recorded by the hacked PIN pads).
†http://fraudwar.blogspot.com/2007/02/could-arrest-in-stop-an...
I expected the PIN was encrypted on the chip, the chip told the device if I got it right and then the PIN was used similarly to a salt for the transaction authorisation .
Is there a real flow online one can read?
The local pads say something about "offline" during that process. Thats for pin & chip ones though - with Target it sounds like the magnetic strip was copied. The local cards don't require a pin for magnetic strip swipes.
However, since the PIN is not required for all transactions, it used to be possible (and may stiil be possible on some banks) to MITM attack this exchange in order to complete a transaction which the terminal thinks was PIN authorised but the card thinks was not, and the upshot being you could enter whatever pin you wanted and the transaction would go through.
For more information, you can look up the EMV specification at http://www.emvco.com/specifications.aspx?id=223 (which is a huge slog to read, and there are many proprietary extensions). For the specific attack I mentioned, you can google 'chip and pin is broken'.
The PIN-pad is a separate, black-box peripheral of the POS terminal. The POS commands it to read a PIN, and, when the customer finishes entering the PIN, the PIN-pad replies to the POS with a 16-byte (IIRC) encrypted block. The clear-text PIN never leaves the PIN-pad. The POS includes the encrypted PIN-block along with the mag stripe data and other info (such as the merchant account and the amount to charge) in its charge request uploaded to the payment processor. The payment processor then decrypts the PIN as part of the process of deciding whether to approve or decline the transaction.
>Is there a real flow online one can read?
Google for "PIN-pad protocol" or "DUKPT" (the encryption scheme commonly used).
But I am still confused as to who stored encrypted PIN numbers and why.
http://krebsonsecurity.com/2013/12/whos-selling-credit-cards...