Live data from Hacker News

Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

krebsonsecurity.com

31–40 of 102 posts

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#31

So I'm pretty ignorant to the history of personal identity/credit breaches, but for those who aren't, is this only getting to get worse? More and more companies are holding more and more data, to the point that these breaches seem to affect so many people. I entered the credit card game pretty recently, and almost immediately I'm affected by the Equifax breach. As a young person, this doesn't make the future of priva…

As it says in the article, this should get better once chips become standard. At that point, the chip will be doing something like an encrypted transaction with the bank, so listening in on any stage of the transaction shouldn't matter (not that I have any details on the process).

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#32
post #2

Edit: it is sad that my comment that is relevant and contains nothing but facts is downvoted... What has HN become? Say what you want about Bitcoin, but it does solve credit card theft for good. If I could use my Bitcoin hardware wallet¹ to pay Sonic, I wouldn't be affected by this security breach. ¹ No Bitcoin theft has ever occurred on a hardware wallet thanks to their tamper proof isolation of private keys.

So does using a chip reader. Assuming its up to current standards the card's information is cryptographically locked to Sonic's vendor ID and any stolen stored CC info could only be used at other Sonics. Chip + Pin solves it even better by forcing the attacker to learn the pin for the card. We're not there yet in the US but once everyone has modern chip readers, adding pins will be trivial. Also as a customer I'm not…

The US will not be getting PINs for cards. It would put liability on the bank rather than the merchant. And it only affects cloned card fraud, it doesn't affect online transactions. As far as banks are concerned, the chip itself provides enough protection, and they have no interest in helping reduce merchant losses.

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#33
post #5
post #3

Earlier quoted context omitted.

If someone else uses my cc, I’m not paying it. If someone steals my bitcoins, they’re fucking GONE.

Wrong. In the US you may be liable for the full amount stolen if you fail to notice the theft in 30 days. Even if you report the theft promptly, the law allows your issuer to make you liable for the first $50. Also you completely ignored my point about hardware wallets making theft a non-problem.

> the law allows your issuer to make you liable for the first $50

This has never happened to me, and ive had a CC compromised a few times.

If someone steals your hardware wallet, what do you consider that?

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#34
post #8

Maybe I'm a little ignorant on how/why companies store this sort of info. Someone at work informed me that Target storing CC numbers at least made sense when you needed to make a return. But at a Sonic Drive-In? I'm not returning my burger+shake combo. What is possessing Sonic to keep the number any longer than the period it takes to receive money from the CC company? And why is this period any longer than the 20 or…

It is a good way to track customer's buying habits. eg how many people go weekly, or to different stores, or buy same products etc. eg HomeDepot tracks credit card back to userid https://consumerist.com/2013/01/16/home-depot-sort-of-explai...

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#35
post #5

Earlier quoted context omitted.

Wrong. In the US you may be liable for the full amount stolen if you fail to notice the theft in 30 days. Even if you report the theft promptly, the law allows your issuer to make you liable for the first $50. Also you completely ignored my point about hardware wallets making theft a non-problem.

Can't you steal a hardware wallet ?

They are typically PIN-protected. And you can back them up by writing the 12/24-word seed in a safe/hidden spot.

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#36
post #33
post #5

Earlier quoted context omitted.

Wrong. In the US you may be liable for the full amount stolen if you fail to notice the theft in 30 days. Even if you report the theft promptly, the law allows your issuer to make you liable for the first $50. Also you completely ignored my point about hardware wallets making theft a non-problem.

> the law allows your issuer to make you liable for the first $50 This has never happened to me, and ive had a CC compromised a few times. If someone steals your hardware wallet, what do you consider that?

Physically stealing a hardware wallet is typically not usefull because they are PIN-protected. And you can back them up by writing the 12/24-word seed in a safe/hidden spot.

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#37
post #13

Earlier quoted context omitted.

No they aren't. When did cash get 2 factor auth?

When has 2fa stop a bullet or knife? Very little cash is stolen by pick-pockets or home burglars. People open their wallets because they fear pain, it doesn't matter how many locks are on the wallet. relevant xkcd: https://xkcd.com/538/

Timelock stops bullets and knives.

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#38

So I'm pretty ignorant to the history of personal identity/credit breaches, but for those who aren't, is this only getting to get worse? More and more companies are holding more and more data, to the point that these breaches seem to affect so many people. I entered the credit card game pretty recently, and almost immediately I'm affected by the Equifax breach. As a young person, this doesn't make the future of priva…

The news looks bad, but reality is worse. Remember that huge trove of NSA hacking tools and exploits that dumped last year? And the numerous follow-up dumps? There are LOTS of new weapons in the hands of everyone from everyday script kiddies to organized crime to enemy nations.

It's possible Equifax was the only credit agency with enough information to require public disclosure... if Transunion doesn't have the right logs or monitors, they may never find out they've been breached, and nor will we.

At this point, I assume everything on a computer can become public.

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#39
post #29
post #2

Edit: it is sad that my comment that is relevant and contains nothing but facts is downvoted... What has HN become? Say what you want about Bitcoin, but it does solve credit card theft for good. If I could use my Bitcoin hardware wallet¹ to pay Sonic, I wouldn't be affected by this security breach. ¹ No Bitcoin theft has ever occurred on a hardware wallet thanks to their tamper proof isolation of private keys.

Yeah, if I keep my credit card in a safe and never use it, no fraud is going to happen. If I use it to pay for things multiple times a day, this happens. It's not like if there hasn't been bitcoins stolen in the past.

100% of the bitcoin thefts up to this day could have been avoided if people had used hardware wallets. I'm serious when I said hw wallets make theft a non-problem.

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#40
post #2

Edit: it is sad that my comment that is relevant and contains nothing but facts is downvoted... What has HN become? Say what you want about Bitcoin, but it does solve credit card theft for good. If I could use my Bitcoin hardware wallet¹ to pay Sonic, I wouldn't be affected by this security breach. ¹ No Bitcoin theft has ever occurred on a hardware wallet thanks to their tamper proof isolation of private keys.

So does using a chip reader. Assuming its up to current standards the card's information is cryptographically locked to Sonic's vendor ID and any stolen stored CC info could only be used at other Sonics. Chip + Pin solves it even better by forcing the attacker to learn the pin for the card. We're not there yet in the US but once everyone has modern chip readers, adding pins will be trivial. Also as a customer I'm not…

> cryptographically locked to Sonic's vendor ID and any stolen stored CC info could only be used at other Sonics.

That's not how chip cards work.

Post reply on HN