Live data from Hacker News

Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

krebsonsecurity.com

81–90 of 102 posts

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#81
post #8

Maybe I'm a little ignorant on how/why companies store this sort of info. Someone at work informed me that Target storing CC numbers at least made sense when you needed to make a return. But at a Sonic Drive-In? I'm not returning my burger+shake combo. What is possessing Sonic to keep the number any longer than the period it takes to receive money from the CC company? And why is this period any longer than the 20 or…

Target wasn't storing credit cards. They installed spyware onto the POS systems, and the CC numbers were not stored in memory on the actual register. So there was a point in time that they could be pulled from system memory. There was an in-depth analysis I'm struggling to find at the moment. But Krebs shines a bit more light on it.

https://krebsonsecurity.com/2014/02/target-hackers-broke-in-...

While Target does store transaction information, they don't store the actual credit card info. That's why you need to provide the physical credit card to do a return, or they give you store credit.

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#82
post #73
post #52

Earlier quoted context omitted.

Your digital wallet gives up consumer protections such as chargebacks which is a regression in consumer benefits. It is also accepted approximately nowhere, with very little incentive for merchants to add support. Apple Pay and related solutions offer "tamper proof isolation of private keys" while still offering all of the consumer protections of cards, plus broad and growing acceptance via compatibility with standar…

« gives up consumer protections such as chargebacks » True. On the flip side, most merchants are honest so chargebacks are rarely needed. It's a different tradeoff: credit cards open you to ID theft, which is a lot more prevalent than the need for a chargeback, so personally I prefer Bitcoin. « accepted approximately nowhere » Any new technology, such as Bitcoin or Apple Pay, has to start from zero. So it is an irrel…

[deleted]

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#83

Earlier quoted context omitted.

> What is possessing Sonic to keep the number They don't. From the article: "Malicious hackers typically steal credit card data from organizations that accept cards by hacking into point-of-sale systems remotely and seeding those systems with malicious software that can copy account data stored on a card’s magnetic stripe. Thieves can use that data to clone the cards and then use the counterfeits to buy high-priced m…

That's assuming the consumers were informed about the source of the compromise.

To this point, my bank replaced my card due to a breach that they refused to disclose to me. I'd like to know the source so I can avoid shopping there, but cannot.

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#84
post #63
post #51

Earlier quoted context omitted.

For that it should be good enough to just store the first 6 digits and the last 4 digits of the card number. You might occasionally get two different customers whose first 6/last 4 are the same but it should not happen often enough to be a significant issue. If even that small risk of conflating two different customers is too high, you could go with a hash of the credit card number. If you go with the hash, then don'…

The first four digits are pretty generic. They tell you who issued the card. Many people will have the same first four digits. Maybe the second set of four and the last set of four would be better? Usually the first four is the issuer and whatever numbers signify the specific type of card. The next set is the bank, I think. The third set is, as I recall, the account number, and the last numbers equate to your routing…

I can’t tell if you are playing, but by storing the most unique part of the credit card with last name you are not reducing the desirability of the target much.

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#85
post #84
post #63

Earlier quoted context omitted.

The first four digits are pretty generic. They tell you who issued the card. Many people will have the same first four digits. Maybe the second set of four and the last set of four would be better? Usually the first four is the issuer and whatever numbers signify the specific type of card. The next set is the bank, I think. The third set is, as I recall, the account number, and the last numbers equate to your routing…

I can’t tell if you are playing, but by storing the most unique part of the credit card with last name you are not reducing the desirability of the target much.

You don't store the name. You use the name to generate the salt and hash the results. You only store the hashes.

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#86

Can we all now move to Bitcoin? We have enough evidence with all the breaches so far. This is not going to stop anytime soon.

Does that actually help all that much? I doubt most people know how to, or want to, keep their keys secure enough, so you'd likely end up with them being managed by central services anyway.

I sense an opportunity here for someone to figure out better UX when it comes to managing keys. A lot of folks do dabble and use 1password or lastpass, etc.

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#87
post #35

Earlier quoted context omitted.

Can't you steal a hardware wallet ?

They are typically PIN-protected. And you can back them up by writing the 12/24-word seed in a safe/hidden spot.

What assurance do I have that the HW wallet vendor doesn't have my seed written down for when they decide to retire?

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#88
post #27
post #14

Earlier quoted context omitted.

Sure, so don’t ignore your finances for a month.

You will still be liable for $50. And you again ignored my point about hardware wallets making theft a non-problem.

There is no major credit card company in the US that doesn't have a $0 liability policy.

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#89
post #58
post #49

Earlier quoted context omitted.

Actually it can still be stolen, but like an impenetrable safe full of money, of no use to the thief. You’d still be screwed though!

Not screwed, because a hw wallet can easily be backed up by writing down the 12/24-word seed in a safe/hidden spot. Our discussion thread demonstrates that more education is needed around hardware wallets, as most people have no idea how they work or even that they exist.

I know how they work and that they exist. However, I use cash as little as possible, and really don't need a cash substitute. The few times I use cash it is for small consumable purchases and things paid with a few quarters. No need for the waiting for a bitcoin transaction to clear.

There are people that prefer cash. Of those people, a large portion of them are old or luddites/anti-tech (I actually don't mean this pejoratively as I sympathize with this view), but these people probably won't be too keen on Bitcoin as a replacement. The other portion are those seemingly like yourself that are all embracing of alternative payment methods or basically e-gold. That's great, but you are a niche bunch and I assume a pretty self-selected group.

The mainstream wants convenient credit with decent consumer protections for the many advantages it brings to their boring, mainstream life. This is not ignorance.

My credit cards give me extended warranties, travel protection. I just got a courtesy credit for a purchase well outside the return window, and I just was reimbursed a few hundred bucks for a computer that failed out of warranty. Meanwhile, I have had to call the credit card company once in 5 years for an unauthorized $200 charge. And no, I was not liable for a penny of it. I don't know where you keep getting off on this $50 stuff, but it's complete nonsense. No one ever pays $50 in practice. And most cards the window is 90 days for a dispute.

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#90
post #35

Earlier quoted context omitted.

They are typically PIN-protected. And you can back them up by writing the 12/24-word seed in a safe/hidden spot.

What assurance do I have that the HW wallet vendor doesn't have my seed written down for when they decide to retire?

If you are paranoid you can choose your own random seed when initializing the wallet.
Post reply on HN