Home Depot breach bigger than Target at 56M cards
reuters.com
reuters.com
Home depot had a huge, huge security breach. Their stock price? Up 12 points from last year.
I'm not sure what it would take for people to really value a major security breach. The tech guy inside me is screaming, "why wouldn't you care about this?", but the regular guy inside me thinks, "who cares? the banks will handle any stolen credit card info."
The "regular guy" in me thinks, "Meh, I'll probably ending up paying 5 cents more for light bulbs because of this. Oh well."
I feel bad for the sysadmin/security guys at these companies, probably screaming for budget and not getting it. What do you think they're doing now? Helping some high paid IR consultant restore logs from backups. Good times!
Deleted comment
(In a year or so, stores that don't use EMV assume liability for fraud)
If the breach doesn't hurt earnings, why should the stock price move?
Is this a result of not using chip and PIN, relying on offline transaction processing or some weird subscription plan?
I understand that there would be a cost involved in implementing chip and PIN across the entire US and it may not solve the issue if they insist on having the card on file. Online credit card processing has been pretty much standard for the last ten years here in Denmark. Terminals are connecting to the credit card processor, either via an ISDN/ADSL/phone/GSM connection, everything is encryptet and the store never has anything expect the cardmask.
So why do companies like Target have the card information of their customers?
"The malicious software that unknown thieves used to steal credit and debit card numbers in the data breach at Home Depot this year was installed mainly on payment systems in the self-checkout lanes at retail stores, according to sources close to the investigation."
So it's not that Home Depot (i'm not sure this applies to Target) had the credit card info stolen from their servers. It's more that it was skimmed from their self-checkout machines, though by software though rather than hardware.
I mean there's "only" 350M people in the US. One in seven would have to have used a card at Home Depot (I know, people have multiple cards). Still seems unlikely to have 56M card skimmed in any reasonable timeframe.
The credit card processing is normally completely separate from the rest of the POS. The credit card "machine" communicates directly with the credit card processing company and just informs the POS that the transaction was completed.
You would need to break into the encrypted data sent from the credit card terminal to the processing company to get the card number.
Maybe I'm just completely ignorant about how this stuff works.
Target and Home Depot are doing something that they don't need to be doing to process payments, unless skimming is involved.
If skimming is involved: start moving to chip cards and drop the magnetic strip.
You can't checklist your way to good security.
Convenience.
Credit cards are based on a broken "pull money without permission" model.
The only way to get good security is to start with a system that doesn't suck; specifically, one that involves "pushing" money to an account rather than "pulling" it from an account.
Bitcoin got this right. So did the various non-CC services like Paypal and Venmo.
Additionally, because you authorise the exact amount on the iPhone, hacking the terminal to have it charge a higher amount than shown on its display is impossible.
As someone who has to cancel his cards once or twice a year due to unauthorized purchases, this sounds great! (I could go back to cash, hmmm......)
Funneling more cash to Apple?
For most companies, the mess that Home Depot is facing never occurs. Not because they were so successful at anticipating security holes, but because they were never targeted by a successful attacker.
Details have not been released (and may never be fully released) regarding the attack; but this is just food for thought.
Your cash can be stolen, lost, misplaced. No recourse. If you lose a credit card, you just call and get a new one mailed to you.
> Use paypal at as many online stores as possible.
I can't believe someone just recommended using PayPal on HN.
> Use prepaid debit cards elsewhere, don't keep much money on them normally, drain them and switch to another card every month.
Don't use debit cards to pay for things. Ever. Credit cards give you substantial consumer protections that you don't get from debit cards.
Bottom line: use credit cards everywhere you can. Find the best rewards program for you and rack up points. Check your account activity once a week. Report anything you don't recognize. If you're part of the social class to which credit cards are actually available, it's quite foolish not to use them.
A: This is simply not true any more. Most banks offer essentially the same level of protection for debit cards as for credit cards, the only issue with debit cards is that potentially you could have a period of time while still missing funds, but I've never seen that be an issue with any reputable bank within the last several years.
B: You must have missed the part where I talked about using "prepaid debit cards". If you are extremely paranoid you can only add money to them just prior to use, leaving them with a low balance most of the time.
C: The problem isn't just fraud and potentially having a period of time without funds available to you that should otherwise be there, it's also the enormous hassle of replacing a card (and updating everywhere you use that as a payment instrument such as amazon, your bills, etc.) That problem isn't improved at all by using a credit card vs a debit card.
Use bitcoin whenever feasible?
protecting yourself against custom malware like the type the article says infected home depot is not easy for tech companies, let alone non tech businesses.
I'm a cynic so I'm going with B.
(Actually, I may go with "C" which is "there are probably breaches that we just haven't heard of yet")
By the way, HD does not necessarily have the lowest price anymore--shop around.
Oh yea, your employees hate your company more than your customers do. If there's shortage--It's probally Internal?
Hay Chantel--a manager asked if I wanted to have you written up. I figured working there was punishment enough.(bad customer service experience--really bad.)