It seems like the post creates more questions than it answers, but it's great that they are sort of transparent. I guess it's due to ongoing investigation. But it is quite surprising that someone was able to acquire the key for the token generation and they seem to have no explaination for it. And wow, they only started tokenizing credit cards now? And SHA-2 for password hashes? THB, after reading this post my confid…
>completely transparent How so? Either they're 100% clueless or they aren't being transparent.
It feels like they have no clue at all how it happened, but want to fix some issues nevertheless.
I'm not sure if they thought this would bring confidence back. Because if so, they failed hard.