A First Look at the Target Intrusion, Malware
krebsonsecurity.com
krebsonsecurity.com
I've had my card number fraudulently used twice via what I thought were reasonably safe websites with large volumes, SSL, etc. I've also had my card company call me a dozen times when I've bought large gifts or spent a few hundred dollars at a few stores in a row running errands a mile from home on a saturday morning. Perhaps some effort should be made towards better detecting true fraud at scale (i.e, "get rich quick" dvd's being purchased by a few hundred of your consumers in a short time) rather than what would be a typical IT dork's every so often spending spree before a holiday.
But its probably for an "is it in stock in a store near me", which might by tied into the inventory/ pos system.
Security implications aside if it was engineered that way it would make for highly variable response times and diminished reliability: not only would you have to make 50+ queries but those queries would have to be across a wan instead of being colocated.
Actually, they have my sympathy. Somehow I doubt the POS OS does any sort of signature verification. We might see that soon, however!
I've worked around some Retalix (NCR) POS software (mentioned in the article, though in Canadian stores) and I can safely say that the security posture of the software of theirs that I've seen is simply horrible.
Perhaps Target has newer stuff than what I've worked with, but I'm talking about VB 6 code running in XP embedded using a "database" back-end that amounts to some Btrieve database files on an SMB share marked "Everyone / Full Control". Getting remote code execution on the POS machines would be trivial.
I noticed that some Target stores have the Verifone MX925 [1] which seem to have been installed in the past year.
[1] http://www.verifone.com/products/hardware/multimedia/mx-925/
I wonder if there's more that hasn't hit the news, or if Target figured better safe than sorry on the notifications.