Card Breaches at Car Washes
krebsonsecurity.com
krebsonsecurity.com
Maybe its because The Cuckoo's Egg is what got me into this field, but I cringe everytime I hear this. Its 25 years later and we are still getting breaches based upon using default credentials.
This isn't even a hard problem to solve, you have three options: 1. Do not have a default password and prompt the user for one during setup. 2. Do not have the same default on every device, create it automagically from a serial number or something. 3. Have the system be unusable for the intended purpose until the default password is changed.
But there is also a 4th option, the user somehow enables the support account.
But somewhere there's a series of folks that (1) engineered a symantec breach; (2) someone else either knew #1 or figured out how to get their hands on source; (3) security audited said source; (4) scanned the internet to find vulnerable servers; (5) pulled cards off those servers, and (6) sold them. It seems like there's more than enough technical knowhow here that these folks should be able to get software or security jobs, no? It doesn't seem like the card thieves make so much money that the reward / federal pound-me-in-the-ass prison ratio skews far enough.
And the more I read krebs, the more I think I should get a $2k limit credit card and use it for all purchases that aren't on amazon.
In my experience, jobs don't find you. By what mechanism do you think this would happen?
While I would not exactly position myself into computer security, I've got my share of borderline black-hat offers, although in all cases the other party believed that what they are doing is perfectly legal.
Let me repeat my advocacy of the virtues of cash for face to face transactions. I normally carry a bit over $400 in my wallet, and almost always use cash for everything up to, say, $800, and around or above that, a check if I can.
Also rewards the retailer with the 2-3% or so in processing charges they'd otherwise have to pay.
Unless the purchase is small, there's also a time cost in getting the signature, although that's small if the company is big enough to collect it with their POS terminal, and there's also back end reconciliation work to be done, manually if the place is small, like a non-chain restaurant.
No payment method is free of overhead and friction.
Credit cards mean a swipe (debit cards add a PIN, oh noes) and indemnity against the fraud that occasionally blows up.
Cash loses. Checks lose hard.
If there's a potential for a line, or a vendor who doesn't know me from Adam, as when I bought a water softener, I do use a credit card.
I personally think the overhead for routine use of cash is roughly equivalent to routinely using a credit or debit card, e.g. I don't have to keep track of all those purchases to reconcile them with my monthly statement. Carrying cash is no problem, counting change ... well, I grew up before credit card usage was routine, so it's second nature, and reorganizing the bills etc. takes very little time. It helps that I have a standard load out that's makes refreshing my wallet easy, as well as making change, at least half the time I provide exact change, or an amount that makes my return change easy. Doing the mental math also has its advantages.
Don't know how I've managed it, but I've never needed to do a charge back in 31 years of using credit cards. Certainly there's not much potential for fraud in my face to face translations.
My youngest bother and his wife used to regularly shop at Target; that turned out be a significant hassle due to the recent breach. Hmmm, and only I can quantify the value of increased peace of mind by limiting my exposure to credit card fraud.
Credit and debit cards also "lose".
The fact that you haven't needed to do a chargeback doesn't mean you haven't benefited from the existence of them. The fear of a chargeback forces merchants to act in your best interest.
What hassle did your brother experience with the breach did he not just have a replacement card mailed out?
It also took a long while for the breach to be realized, they might have had issues with bogus charges on their cards. And it would be at least two cards, one each for him and his wife.
If they had bogus charges it would have been dealt with the same as any credit card fraud. They would sign a statement that they didn't make the charges. The funds would be reversed and they'd be sent new cards.
The fact that they know its related to Target means they probably didn't have those issues.
You mean found the default credentials? That doesn't take much.
I'm slightly surprised that the gift cards scheme works as I don't see why there couldn't be a revocation list for gift cards circulated amongst stores that is added to when a chargeback occurs. Even if it doesn't it still exposes the criminal when buying the gift card.
Also gift cards have secondary (and probably more important) use for thieves. Giftcard is legitimately looking magstripe card that in many cases gets processed in same way as card payment, so you can just write stolen magstripe data onto giftcard and get something that does not raise suspicion (store clerk is not going to verify that card number matches or event that payment method matches).
EMV.
I know it's far from perfect, but it raises the bar considerably. You can't just clone EMV cards that way. The USA really ought to try to catch up with the rest of the world on this front.
"We have two Family Dollar stores in Everett and a bunch in the surrounding area, and these guys would come in three to four times a week at each location, laundering money from stolen cards"
You would have thought they would report them.
I wouldn't be surprised if many people in the service industries still see this type of multi card roulette daily.
I can imagine if the clerk did report his concerns, he'd likely be told they were good customers so why rock the boat....
Worked as a cashier about 10ish years ago. Never once saw multi card roulette.
Of course once in a while some people would say "20 on this card and 10 in cash." Never seen it with more than one card though. I almost never saw people get declined, I think it happened like 5 times total. It would be highly suspicious to me, especially coming from the same person!
Isn't the merchant liable for the chargebacks? Or in this case, who was footing the bill for this fraud?
Of course if it's that frickin' obvious what's going on then the merchant will find themselves under review and saddled with much higher fees after a while.
[1] http://www.seyfarth.com/dir_docs/publications/NEHT01120810.p...
>As a practical matter, the Court’s decision means that employers can- not safely take deductions for theft or damage to property unless fault and value have been determined by a court of law or government agency.
We have an incredibly secure and successful piece of remote access software (ssh) that is used on billions of computers and yet that sentence exists. It seems that sometimes it's not just an engineering problem.
Then again old versions of SSH are probably equally vulnerable.
It would seem that there is no substitute for having a real root who has responsibility for the system, though perhaps the comment from nuxi7 is a simple way to engineer around part of the problem. Sane defaults or in this case an explicit lack of defaults could be useful.
My father still uses a small pre-computer cash register to this day; I've had no luck convincing him to buy a new computerized one so he can accept credit cards.
You can still accept credit cards without a new register. It's just a different machine. They don't have to be integrated.
Almost every single doctor's office accepts credit card and exactly NONE of them have a register.
The way it works is you charge the card on a separate machine, type in the total, have them sign and put the slip somewhere and press "paid with credit" on the register if it is computerized or if it isn't then just ignore the register for that transaction.
Wonder what one of my IPv4 neighbors did to piss them off.