Credit Card Breach at California DMV
krebsonsecurity.com
krebsonsecurity.com
Insert cryptocurrency endorsement here -- or at least something else, because the current tech has hit a wall.
[0] http://en.wikipedia.org/wiki/Chip_and_PIN [1] http://en.wikipedia.org/wiki/3-D_Secure
EMV is a more secure than a trivially copyable magnetic stripe.
And 3-D Secure is a JOKE.
When you hack a PIN keyboard, all the transactions will still go through the merchant's account, and it's easy to catch the thief.
Yes, there are pin readers, either a fake keyboard or a camera.
edit: for the record, I believe EMV should be upgraded to put a display and PIN pad on the card itself
Second people need to have their wallets on their phones and know how to use it. That's more of a consumer education problem than a tech problem, though.
People say "with growth.. etc.. will be stable." But USD/EUR isn't all that stable and that has massive volume and resources in motion to keep it stable (http://www.fxstreet.com/rates-charts/usdollar-index/) (See 88 -> 74 in 10 months).
We can have "better credit cards". Most countries do.
Bitcoin at present has a massive theft rate. Clearly it alone doesn't solve that problem at all.
Still, I'm not saying that Bitcoin sucks and I disclaimed that I don't care one way or the other about Bitcoin up-front specifically to preclude predictable knee-jerk defensive replies like this. My claim is that "Bitcoin will solve this problem!" in response to every article about money is bullshit because we have Bitcoin and it still has problems, like a massive theft problem.
It's a problem of bad implementations, whether cloned credit cards or stolen wallet files. And Bitcoin doesn't keep me from writing bad implementations. In fact it may make it worse: financial companies that move dollars have a high startup cost because of the regulatory work. Because it can no longer be two guys in a garage, it becomes more likely that the chain of people that they have to hire and speak to has at least one competent member. Clearly not guaranteed though, you'd think that the DMV would have the resources to become competent if they wanted to.
Uh, yeah. I'm not a knee-jerk defender of Bitcoin, and my statement is not a defense of Bitcoin so much as a balanced evaluation of the weaknesses of all sorts of payment systems.
Bitcoin is actually worse in terms of security for the end user than the centralised systems we have now - with banks keeping ledgers of who paid what, who owns what, in charge of security and paying insurance etc. if money is stolen from banks, it is their responsibility to make it good, if they can't, the state steps in. Contrast that with the many bitcoin exchanges going bust. Ordinary people are not good at security (physical or digital), so keeping hoards of intrinsically valuable stuff at home without paying insurance is a terrible idea, and I'd argue that keeping hoards of intrinsically valuable stuff anywhere is a bad idea, and digital currencies have moved on from there.
Bitcoin is still trying to be a digital analogue to paper cash, so even if the protocol is not broken, the premise is.
Just the fact that it's digital puts Bitcoin into another realm entirely. I can make a bitcoin hoard so secure that only rubber hose interrogation will allow another access to it. It's also true that it would require concerted effort, or that I could do this improperly, or that I may already be subject to surveillance.
It used to be that ordinary people were hopelessly clueless about automobiles, up to the point that people hung bulbs of garlic under the hoods of their Ford Model T's to "fix" them. Now, while not everyone is an expert mechanic, there's all sorts of automotive knowledge floating around the culture.
Unfortunately, the sad truth is that we don't yet have the proper security infrastructure for even very knowledgeable people to be safe without constant, concerted effort. Expecting general security knowledge in today's world is like expecting widespread literacy in the days before the printing press.
Using virtual cards provides you a fine level of control over various features of the credit card and also protects your real credit card number. One can set up time limits (expiry date), set a monetary limit or make it a one time use card.
Virtual credit cards are also useful for dealing with service providers who make it hard to cancel their subscriptions (e.g. you have to call in and talk to a person to unsubscribe). With virtual credit cards, one can sign up freely and not have to worry about being continuously surreptitiously charged each month. Once the card expires or the transaction limit is exceeded, the service provider will be forced to close/suspend the account on their own.
Online payment is the only reason I have a (pre-paid) credit card, but it really doesn't need a credit card. I don't want/need "credit" and since it's online a "card" is useless. We already have e-banking for many things, why can't I use this for payment?
This is quite common in Sweden at least. It's called "direct payment" and works with the 3 biggest banks. The rules around disputes and chargebacks are muddier though. Debit/credit cards also have 3DSecure for password authentication.
edit: also, debit cards work 100% for online payment, there's no reason to apply for credit
Not likely to happen soon:
"The system is not sustainable but it may take decades until it collapses. Having multi billion budget credit card companies can shape legislation to stifle innovation that could reduce amount of fraud. Banks have no incentive to fix the system. The more fraud exists, the more obscure and complex services they can offer and the more effectively can justify their existence and demand higher fees."
http://www.securitykiss.com/resources/roboblog/credit_cards/...
I don't even want to use checks. I went to H&R block, tried to pay with a check to avoid giving my credit card details and they scanned the check's routing and bank number and stored that! Losing your bank info is more severe than credit card data because you have to close your account. Seriously bringing like a wad of cash next time I go to H&R block.
Additionally, any situation where you COULD pay in cash, you're not providing billing information to the merchant, so there's no risk of information compromise (aside from your name).
There are a lot of pro-consumer reasons to use a card. That, the ability to execute chargebacks in disputes, and rewards make for an attractive package. I personally get about 3.5 flights a year off of a credit mechanism that needs to be employed regardless, so not bad. Usually have fraudulent charges show up at least once a year though.
Just saying, charge backs should be used as a last resort, not in spite or without even contacting the merchant. They can negatively affect the consumer if the consumer abuses them.
Absolutely, but it remains a strong consumer protection. Certainly a 'plus' on the consumer side at the end of the day.
My bank allows me to register virtual "credit" card. It lasts 30 days(I can close it earlier also), I can have custom limit and making it takes around 2 minutes online. It costs i guess around 50cents per card. So by the time the card details leak from online shop, card is already useless.
And people wonder why the cashless society is five years away and always will be.
I write about six checks a year. Two of them are auto registration because their site is so horribly broken when it could be so amazingly easy. These people are able to send me a piece of paper in the mail with an access code. It should take 30 seconds to pay my registration online.
The entire DMV system has been so backwards I don't even know where I would start addressing it.
Something needs to be done to prevent this. I wonder if it would be feasible for the Credit card companies to do all the storage of card data as a service for retailers. Retailers would just store a reference token.
Until then my credit is frozen[1]
1. http://www.clarkhoward.com/news/clark-howard/personal-financ...
Amazon, being their own processor, probably stores their own numbers, but if Visa themselves would start tokenizing, that would be huge and awesome.
The retailer could immediately encrypt the CC number using Curve25519 and AES-256 as soon as they got it, requiring 48 bytes of storage. One or two more bytes (or a variable-length integer) would store which credit card company the token is good for. That way, each merchant can generate its own tokens without having to interact with the credit card companies, and any stolen tokens can only be used to make fraudulent charges with the same merchant from which they were stolen.
"It would be tragically easy for many retailers to not immediately encrypt the CC number using Curve25519 and AES-256 as soon as they got it, or take years to move to this, etc."
Although anything that, if properly used, would massively decrease the attack surface and localize the consequence of a breach, would be fantastic.
Right now the attack surface is just too damned big.
Hmmm, to prevent another Target, wouldn't each POS card acceptor need firmware or hardware changes to do this action "immediately"?
The encryption algorithms you use are the least interesting piece of the puzzle: Just use something strong enough. It's the key management, data flow, storage and access security (both physical and via computer) that this kind of thing falls apart on.
You really need security all the way from the reader, which is (sort of) what chip-and-PIN is.
It's typical of the HN ethos to want to take heroic steps to safeguard your personal data and to demand better of the people who handle it, but in the case of credit card numbers, it's really the industry's problem, not ours.
The fear was always, if there were a breach on our several hundred thousand credit card database it would be trivial to find out that it came from us and it would be VISA that would start litigation against us.
I'm lucky enough to never have had a credit card system that I wrote broken into so I couldn't tell you first hand.
If anyone wants to know how to make a secure credit card system, it's pretty simple:
1. Don't be creative - there are plenty of rock solid boring implementations that will encrypt your cards.
2. Don't get fancy with encryption or key storage and use strong encryption and a salt and you'll be fine.
3. Limit physical and administrative access to the servers to as few humans as possible.
4. Let the only code that decrypts the cards be the code that is literally right before your call to the gateway.
5. Tokenize your cards, even if it's for an internal project where you think everyone can be trusted.
EDIT: As a note, just follow PCI[0] to the letter and you'll end up pretty safe.
[0]https://www.pcisecuritystandards.org/documents/pci_dss_v2.pd...
Much less to worry about on your end as the tokens have no meaning outside the tokenization service.
Also, just to reïterate the point: When it comes to security, and you're not a crypto or security person, don't be creative and don't be fancy. Use what works.