The Home Depot confirms payment systems breach
ir.homedepot.com
ir.homedepot.com
(2) Use BillGuard https://www.billguard.com/
(3) Review your transactions every week or so via a personal finance tool (I use https://www.mint.com/)
I don't particularly care if my payment credentials are compromised as it's highly unlikely a fraudulent charge would go unnoticed by me just using the advice above. It's quick, easy to set up, and stuff you really ought to be tracking anyway.
I only wish my bank (Wells Fargo) supported SMS alerts for transactions - if there's one thing I don't mind getting frequent notifications about, it would be this.
Starting in early 2013, as a result of a settlement of a class action by merchants, they no longer have to charge credit card users the advertised and marked price. They can advertise and mark the cash price, and charge a credit card surcharge of up 4% or the processing fees for that transaction (whichever is smaller).
Some states have laws that limit surcharging. There is a list in this Visa article about the post settlement rules: http://usa.visa.com/personal/get-help/checkout-fees.jsp
Losing or having a credit card compromised is pretty low on my list of real hassles.
If you use cash and it gets stolen, your money is just gone.
GnuCash has a list of OFX credentials for major banks. [2] In fact, there are tons of OFX open source libraries out there - I had luck with this one recently in Python. [3]
[1] http://en.wikipedia.org/wiki/Open_Financial_Exchange
[2] http://wiki.gnucash.org/wiki/OFX_Direct_Connect_Bank_Setting...
On its end, Yodlee is heavily regulated. Like a bank and sometimes even more: http://www.yodlee.com/yodlee-security/
That's only one part of the article though.
The only thing EMV would achieve is making this data slightly less valuable, but still worth it for the attacker. Replacing the EMV cards would also be more expensive by an order of magnitude.
tl;dr: if you use your EMV card on a compromised POS, you'll be as fucked as you'd be with a magstripe card. Your bank will be ten times as fucked.
Don't you need the printed CVV for that? Which isn't stored on either the magstripe nor the chip.
edit: 3DSecure would also help if banks cared to push it harder (for instance my bank now disallows all online debit card charges that don't use 3DSecure)
Also, in many cases the chips actually contain enough information to replicate the magnetic stripe. (Which is well, bad.)
[1] http://www.emvlab.org/emvtags/show/t57/ [2] http://www.emvlab.org/emvtags/show/t5a/
Edit: Even having the track 2 data won't do you any good in reproducing an EMV card. The only way reproducing a mag stripe EMV card is useful, is if it is used at a non-EMV terminal and mag stripe is the only option.
I believe Europe has complete banished mag stripe now.
http://en.wikipedia.org/wiki/Card_security_code Skip down to Types of Codes
And the CVV on the back, is different than the CVV stored on the magstripe/chip.
Secondly, if EMV was adopted in the USA, the stolen information would become useless because they wouldn't be able to use the data to produce fraudulent cards.
You still need the CVV code to use the card number in a card not present transaction. So not to your point, it is rather secure...
EMV would have helped immensely here, especially considering EMV compliant machines are held to PCI standards as well.
The attackers probably have my name/email address/mailing information, which kind of sucks.
Do you have a home depot CC?
The thing to do is to actually get stores to stop storing CC info at all. they should be able to process the payment and then forget the info at all so it never has to be stored so it can't be stolen. EMV is actually a move to force this as they'll no longer be able to get the number, just verify a transaction in theory.
I certainly hope they didn't compromise the PIN pads in the stores. That could be a Very Bad Thing.
[1] http://krebsonsecurity.com/2014/09/home-depot-hit-by-same-ma...
Banks are switching to the EMV system because they can place the liability on the merchant if a fraudulent transaction is performed through them when they could have required an EMV transaction (thereby preventing the fraud).
This is absolutely not acceptable, and I deplore how this has become the status quo. I reject these services and want nothing less than a full lawsuit.
I don't care about damages to me. I want the problem fixed. This Laissez-faire attitude towards online commerce security needs to end. Standards like PCI and PA-DSS are not enough. Corporations need to be liable for leaking everyone's information. A year of free credit monitoring is a slap in the face.
The PAN that belongs to your credit card company that was assigned to you by your credit card company was compromised and someone tried to defraud your credit card company using it. Yet it's you complaining, why?
You both have a point, but lean towards more punishment. This isn't something that should just be 'charged' away.
Possibly having your data leaked isn't enough of a harm for the courts to hear the lawsuit. If you can force a company to respond to a lawsuit based on the potential that they lost your data, what stops larger companies from suing smaller competitors constantly forcing them to prove they haven't leaked any data? They always could have leaked data.
- Go through your entire credit history over a six month period looking for illegitimate charges. (Many people, such as myself, use a single credit card for most of their payments -- that's thousands of transactions.)
- Wait a week for a new credit card to arrive in the mail, and hope none of your automatic payments try to charge the old card while you wait for the new one.
- Update all of your automatic payments. Doing it once would be one thing, but every time one these breaches happens?
None of these are the end of the world, but they're certainly not "no damages".
It seems unlikely that the attack would continue since the attackers have lost their cover, but the wording is a bit strange.
edit: "Chip and PIN" is taken directly from the sec filing that is linked.
the described deadline of october 2015 for the liability shift comes from banks[1] and not a US law or similar.
Don't excuse laziness.
I'd love to be told I'm wrong, and that this can be made into a chip+pin card without physically swapping the card.
Edit: Chip cards provide a Cardholder Verification Method List (CVML) to the terminal. The terminal then decides what method it'd like to use. Options are PIN online, PIN offline plain text, PIN offline enciphered, Signature, or No Authentication.
I've received two new cards in the last month with a chip in them - both were chip and signature.
The interesting part to me was it sounded like the managers explained to them that it was all the bank's fault. Not that Home Depot was too cheap and lazy to update their software. And ya got to talk about something while the paint's shakin
edit: Also, keep in mind that some retailers are running POSReady 2009 / POSReady 7, which may look just like Windows XP at first glance.
You can still get the magstripe data if you compromise the terminal, but the network will (eventually) reject magstripe transactions made by a chip-capable card in a chip-capable reader. You can get the transaction certificate for one transaction, but that TC is protected from replay attacks.