Live data from Hacker News

Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

krebsonsecurity.com

51–60 of 102 posts

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#51
post #34
post #8

Maybe I'm a little ignorant on how/why companies store this sort of info. Someone at work informed me that Target storing CC numbers at least made sense when you needed to make a return. But at a Sonic Drive-In? I'm not returning my burger+shake combo. What is possessing Sonic to keep the number any longer than the period it takes to receive money from the CC company? And why is this period any longer than the 20 or…

It is a good way to track customer's buying habits. eg how many people go weekly, or to different stores, or buy same products etc. eg HomeDepot tracks credit card back to userid https://consumerist.com/2013/01/16/home-depot-sort-of-explai...

For that it should be good enough to just store the first 6 digits and the last 4 digits of the card number. You might occasionally get two different customers whose first 6/last 4 are the same but it should not happen often enough to be a significant issue.

If even that small risk of conflating two different customers is too high, you could go with a hash of the credit card number.

If you go with the hash, then don't ALSO store first 6/last 4. A typical credit card number is 16 digits, and one of those is a check digit. If someone gets a hold of the hash, and first 6/last 4, then there are only 100 000 possible values for the missing 6 digits (10^5, not 10^6, because for any guess for 5 of the digits there is only one possible 6th digit that will make the checksum work). Unless you use a very very slow hash function, brute forcing 100 000 possibilities will be quick.

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#52
post #2

Edit: it is sad that my comment that is relevant and contains nothing but facts is downvoted... What has HN become? Say what you want about Bitcoin, but it does solve credit card theft for good. If I could use my Bitcoin hardware wallet¹ to pay Sonic, I wouldn't be affected by this security breach. ¹ No Bitcoin theft has ever occurred on a hardware wallet thanks to their tamper proof isolation of private keys.

Your digital wallet gives up consumer protections such as chargebacks which is a regression in consumer benefits. It is also accepted approximately nowhere, with very little incentive for merchants to add support.

Apple Pay and related solutions offer "tamper proof isolation of private keys" while still offering all of the consumer protections of cards, plus broad and growing acceptance via compatibility with standard contactless card terminals and POS systems.

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#53
post #45

I'm surprised Krebs end up plugging chip-and-PIN instead of the current leapfrog technology exemplified by Apple Pay. I feel there is not enough awareness of just how much more secure this is. A huge advantage of Apply Pay is that you get the security of a PIN without the hassle of entering a PIN -- or the risk of it being stolen during PIN entry. You just authenticate with your fingerprint or, soon, your face. (Plea…

> A huge advantage of Apply Pay is ... without the hassle of entering a PIN

You are forgetting that tools like Apple Pay are not hassle free for most people, especially those outside of IT circles. Millions of people struggle to use anything beyond basic technology (American banks have even decided that PIN's are too confusing! A four digit number that has been common in the rest of the world for decades!). Combine that with other factors like fears of being caught with a flat battery or businesses that are reluctant to spend money on new POS devices - it's unlikely that plastic cards are going away anytime soon.

Also, I'm not sure entering a PIN is really any more hassle than using a phone as a payment device (I use Android Pay whenever I can due to the added security features but the POS readers are often incredibly slow).

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#54
post #53
post #45

I'm surprised Krebs end up plugging chip-and-PIN instead of the current leapfrog technology exemplified by Apple Pay. I feel there is not enough awareness of just how much more secure this is. A huge advantage of Apply Pay is that you get the security of a PIN without the hassle of entering a PIN -- or the risk of it being stolen during PIN entry. You just authenticate with your fingerprint or, soon, your face. (Plea…

> A huge advantage of Apply Pay is ... without the hassle of entering a PIN You are forgetting that tools like Apple Pay are not hassle free for most people, especially those outside of IT circles. Millions of people struggle to use anything beyond basic technology (American banks have even decided that PIN's are too confusing! A four digit number that has been common in the rest of the world for decades!). Combine t…

Not sure what you're talking about. Apple Pay is so much easier and more pleasant to use than chip-and-PIN. It is designed to be easier for the average consumer.

And in terms of speed, are we living on the same planet? Chip-and-PIN is notoriously slow in the U.S. Apple Pay takes a second.

Also I'm not saying plastic will go away anytime soon. There will be legacy terminals. I'm saying Apply Pay and its ilk are superior to chip-and-PIN, a two decade old technology.

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#55
post #8

Maybe I'm a little ignorant on how/why companies store this sort of info. Someone at work informed me that Target storing CC numbers at least made sense when you needed to make a return. But at a Sonic Drive-In? I'm not returning my burger+shake combo. What is possessing Sonic to keep the number any longer than the period it takes to receive money from the CC company? And why is this period any longer than the 20 or…

> What is possessing Sonic to keep the number They don't. From the article: "Malicious hackers typically steal credit card data from organizations that accept cards by hacking into point-of-sale systems remotely and seeding those systems with malicious software that can copy account data stored on a card’s magnetic stripe. Thieves can use that data to clone the cards and then use the counterfeits to buy high-priced m…

That's assuming the consumers were informed about the source of the compromise.

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#56
post #45

I'm surprised Krebs end up plugging chip-and-PIN instead of the current leapfrog technology exemplified by Apple Pay. I feel there is not enough awareness of just how much more secure this is. A huge advantage of Apply Pay is that you get the security of a PIN without the hassle of entering a PIN -- or the risk of it being stolen during PIN entry. You just authenticate with your fingerprint or, soon, your face. (Plea…

A huge disadvantage of Apple Pay is that you must have an Apple device.

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#57
post #2

Edit: it is sad that my comment that is relevant and contains nothing but facts is downvoted... What has HN become? Say what you want about Bitcoin, but it does solve credit card theft for good. If I could use my Bitcoin hardware wallet¹ to pay Sonic, I wouldn't be affected by this security breach. ¹ No Bitcoin theft has ever occurred on a hardware wallet thanks to their tamper proof isolation of private keys.

[deleted]

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#58
post #49
post #27

Earlier quoted context omitted.

You will still be liable for $50. And you again ignored my point about hardware wallets making theft a non-problem.

Actually it can still be stolen, but like an impenetrable safe full of money, of no use to the thief. You’d still be screwed though!

Not screwed, because a hw wallet can easily be backed up by writing down the 12/24-word seed in a safe/hidden spot.

Our discussion thread demonstrates that more education is needed around hardware wallets, as most people have no idea how they work or even that they exist.

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#59
post #29
post #2

Edit: it is sad that my comment that is relevant and contains nothing but facts is downvoted... What has HN become? Say what you want about Bitcoin, but it does solve credit card theft for good. If I could use my Bitcoin hardware wallet¹ to pay Sonic, I wouldn't be affected by this security breach. ¹ No Bitcoin theft has ever occurred on a hardware wallet thanks to their tamper proof isolation of private keys.

Yeah, if I keep my credit card in a safe and never use it, no fraud is going to happen. If I use it to pay for things multiple times a day, this happens. It's not like if there hasn't been bitcoins stolen in the past.

It sure can happen: breach at the bank, predictable patterns used, intercepted mail. I'm sure there are more situations I haven't thought of.

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#60
post #54
post #53

Earlier quoted context omitted.

> A huge advantage of Apply Pay is ... without the hassle of entering a PIN You are forgetting that tools like Apple Pay are not hassle free for most people, especially those outside of IT circles. Millions of people struggle to use anything beyond basic technology (American banks have even decided that PIN's are too confusing! A four digit number that has been common in the rest of the world for decades!). Combine t…

Not sure what you're talking about. Apple Pay is so much easier and more pleasant to use than chip-and-PIN. It is designed to be easier for the average consumer. And in terms of speed, are we living on the same planet? Chip-and-PIN is notoriously slow in the U.S. Apple Pay takes a second. Also I'm not saying plastic will go away anytime soon. There will be legacy terminals. I'm saying Apply Pay and its ilk are superi…

> are we living on the same planet?

Are we? I assume you have never experienced the requests for support from tech illiterate relatives since childhood for assistance with VCR's, PC's, basic cell phones, printers, anything USB related in the 90's, scanners, cable boxes, modems, endless websites/web applications, and of course, smartphones. Demographic changes are shifting the definition of "average consumer" but boomers still dominate and many of them struggle with technology.

Chip and PIN is indeed slow in the US (I grew up elsewhere and travel regularly so it drives me insane) but the experience with Android Pay isn't necessarily faster or more convenient. Like I said, I use Android Pay whenever I can but I don't recall ever seeing another person using their smartphone to pay in a store.

A quick search seems to suggest this is more than just anecdotal:

http://fortune.com/2017/08/04/apple-pay-samsung-mobile-payme...

"Despite much publicity upon launch, Apple Pay, Samsung Pay, and Android Pay have struggled to gain traction," the analysts concluded. "Mobile wallet adoption has been underwhelming to date by nearly every objective standard, including initial penetration of smartphone users and repeat usage rate. While up to one-third of U.S. phone owners have enrolled in the payment plans, frequent usage is uncommon, the analysts said. Only 8%, 6%, and 3% of people use Apple Pay, Samsung Pay, and Android Pay at least once per week."

Post reply on HN