Live data from Hacker News

Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

krebsonsecurity.com

91–100 of 102 posts

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#91

So I'm pretty ignorant to the history of personal identity/credit breaches, but for those who aren't, is this only getting to get worse? More and more companies are holding more and more data, to the point that these breaches seem to affect so many people. I entered the credit card game pretty recently, and almost immediately I'm affected by the Equifax breach. As a young person, this doesn't make the future of priva…

The news looks bad, but reality is worse. Remember that huge trove of NSA hacking tools and exploits that dumped last year? And the numerous follow-up dumps? There are LOTS of new weapons in the hands of everyone from everyday script kiddies to organized crime to enemy nations. It's possible Equifax was the only credit agency with enough information to require public disclosure... if Transunion doesn't have the right…

This talk seems to always be relevant:

https://vimeo.com/135347162

Abstract: In this bleak, relentlessly morbid talk, James Mickens will describe why making computers secure is an intrinsically impossible task. He will explain why no programming language makes it easy to write secure code. He will then discuss why cloud computing is a black hole for privacy, and only useful for people who want to fill your machine with ads, viruses, or viruses that masquerade as ads. At this point in the talk, an audience member may suggest that Bitcoins can make things better. Mickens will laugh at this audience member and then explain why trusting the Bitcoin infrastructure is like asking Dracula to become a vegan. Mickens will conclude by describing why true love is a joke and why we are all destined to die alone and tormented. The first ten attendees will get balloon animals, and/or an unconvincing explanation about why Mickens intended to (but did not) bring balloon animals. Mickens will then flee on horseback while shouting “The Prince of Lies escapes again!”

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#92
post #60

Earlier quoted context omitted.

> are we living on the same planet? Are we? I assume you have never experienced the requests for support from tech illiterate relatives since childhood for assistance with VCR's, PC's, basic cell phones, printers, anything USB related in the 90's, scanners, cable boxes, modems, endless websites/web applications, and of course, smartphones. Demographic changes are shifting the definition of "average consumer" but boom…

I've switched to Android Pay pretty much everywhere because it's nearly instantaneous, whereas chip transactions require 10-20 seconds of awkward waiting around. Before I had a phone with a fingerprint reader it took more effort to wake and unlock the device, but now that part is frictionless.

Android Pay is almost always as slow as chip transactions here in Minnesota. The app seems to work quickly but the POS machine is always slow to complete it's part of the transaction. It seems to vary depending upon the POS machine - for example Trader Joe's is always quick but those in the larger grocery chains or local sandwich shop are painfully slow.

From the downvotes I assume it's a regional thing!

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#93
post #91

Earlier quoted context omitted.

The news looks bad, but reality is worse. Remember that huge trove of NSA hacking tools and exploits that dumped last year? And the numerous follow-up dumps? There are LOTS of new weapons in the hands of everyone from everyday script kiddies to organized crime to enemy nations. It's possible Equifax was the only credit agency with enough information to require public disclosure... if Transunion doesn't have the right…

This talk seems to always be relevant: https://vimeo.com/135347162 Abstract: In this bleak, relentlessly morbid talk, James Mickens will describe why making computers secure is an intrinsically impossible task. He will explain why no programming language makes it easy to write secure code. He will then discuss why cloud computing is a black hole for privacy, and only useful for people who want to fill your machine wi…

That is the most hilarious abstract I have ever read in my life.

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#94
post #73
post #52

Earlier quoted context omitted.

Your digital wallet gives up consumer protections such as chargebacks which is a regression in consumer benefits. It is also accepted approximately nowhere, with very little incentive for merchants to add support. Apple Pay and related solutions offer "tamper proof isolation of private keys" while still offering all of the consumer protections of cards, plus broad and growing acceptance via compatibility with standar…

« gives up consumer protections such as chargebacks » True. On the flip side, most merchants are honest so chargebacks are rarely needed. It's a different tradeoff: credit cards open you to ID theft, which is a lot more prevalent than the need for a chargeback, so personally I prefer Bitcoin. « accepted approximately nowhere » Any new technology, such as Bitcoin or Apple Pay, has to start from zero. So it is an irrel…

This is just poor reasoning. There would be more dishonest merchants if the possibility of chargebacks ceased to exist. Your reasoning is like saying look how safe this town is, guess we don’t need police anymore.

And to say that virtually no merchant acceptance[1] is an “irrelevant argument” is laughable. Merchants have little incentive to spend money and effort to add support for an obscure payment method that virtually no one uses and likely never will, due to its reduction in consumer benefits. Apple Pay piggybacked the rollout of contactless terminals which gave it support at millions of locations out of the gate, and fully supports standard consumer protections and reward programs.

Finally, “person-to-person payments” is completely irrelevant to person-to-business transactions. But even in that corner Apple Pay will very soon be superior to any other method for “paying back lunch money to a coworker”. They are rolling out P2P this fall which supports all debit cards, is free, instantaneous, and you can spend the money right away at any Apple Pay merchant or send it to your bank account.

That cuts your argument down to just avoiding transaction limits and authorization at merchants you trust. Extremely narrow use case, so no way there’s going to be enough consumer interest to drive merchant adoption.

[1] https://www.bloomberg.com/news/articles/2017-07-12/bitcoin-a...

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#95
post #60
post #54

Earlier quoted context omitted.

Not sure what you're talking about. Apple Pay is so much easier and more pleasant to use than chip-and-PIN. It is designed to be easier for the average consumer. And in terms of speed, are we living on the same planet? Chip-and-PIN is notoriously slow in the U.S. Apple Pay takes a second. Also I'm not saying plastic will go away anytime soon. There will be legacy terminals. I'm saying Apply Pay and its ilk are superi…

> are we living on the same planet? Are we? I assume you have never experienced the requests for support from tech illiterate relatives since childhood for assistance with VCR's, PC's, basic cell phones, printers, anything USB related in the 90's, scanners, cable boxes, modems, endless websites/web applications, and of course, smartphones. Demographic changes are shifting the definition of "average consumer" but boom…

Don’t be mislead by the headline. “Up to one-third of U.S. phone owners have enrolled” and a collective 17% of “people” use it regularly. That is not bad! It is still early days; new payment systems take time to roll out. But once you use it you become a fan, as you’ve discovered.

And did you just compare enrolling in Apple Pay to a VCR? All you have to do is point your camera at your card. That’s pretty much it. It is very consumer friendly.

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#96

Earlier quoted context omitted.

A huge disadvantage of Apple Pay is that you must have an Apple device.

Android Pay is accepted everywhere Apple Pay is.

Exactly. Between Apple and Android/Samsung there is broad support for this payment method across consumer devices.

My argument is not "merchant's shouldn't support chip-and-PIN." It's a fine fallback method. I'm just surprised Krebs mentioned that instead of Apple Pay.

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#97
post #91

Earlier quoted context omitted.

This talk seems to always be relevant: https://vimeo.com/135347162 Abstract: In this bleak, relentlessly morbid talk, James Mickens will describe why making computers secure is an intrinsically impossible task. He will explain why no programming language makes it easy to write secure code. He will then discuss why cloud computing is a black hole for privacy, and only useful for people who want to fill your machine wi…

That is the most hilarious abstract I have ever read in my life.

The talk itself is just as funny too, please do watch it fully. It's not chock full of evidence, but it has some good points and some great entertainment.

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#98
post #94
post #73

Earlier quoted context omitted.

« gives up consumer protections such as chargebacks » True. On the flip side, most merchants are honest so chargebacks are rarely needed. It's a different tradeoff: credit cards open you to ID theft, which is a lot more prevalent than the need for a chargeback, so personally I prefer Bitcoin. « accepted approximately nowhere » Any new technology, such as Bitcoin or Apple Pay, has to start from zero. So it is an irrel…

This is just poor reasoning. There would be more dishonest merchants if the possibility of chargebacks ceased to exist. Your reasoning is like saying look how safe this town is, guess we don’t need police anymore. And to say that virtually no merchant acceptance[1] is an “irrelevant argument” is laughable. Merchants have little incentive to spend money and effort to add support for an obscure payment method that virt…

«There would be more dishonest merchants if the possibility of chargebacks ceased to exist»

Yes there will probably be a minor uptick in merchants being dishonest. But I doubt it will be as bad as you make it to be. Many other factors push merchants to stay honest: legal repercussions, damaged reputation, etc.

«And to say that virtually no merchant acceptance[1] is an “irrelevant argument” is laughable»

Irrelevant was the wrong word. I meant illogical. Your argument is like saying in the early days of Blu-ray that "no one will buy Blu-ray discs because no one has Blu-ray players".

«Merchants have little incentive»

Second time you say it, second time you are wrong. I already pointed out their main (largest!) incentive to accept BTC is to avoid chargeback fraud. This fraud is a major problem for merchants. They can go bankrupt (eg. https://www.youtube.com/watch?v=6Chp12sEnWk&t=45m0s) or be drawn into costly suits with no way to recover the money (https://www.reddit.com/r/legaladvice/comments/5r9nqi/credit_...).

Apple Pay P2P will be riddled with roadblocks. For starters most people will not be able to use it as it requires a $500 device (iPhone). I guarantee you there will be transaction limits, delays in access to funds, etc. All things that Bitcoin solves.

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#99
post #98
post #94

Earlier quoted context omitted.

This is just poor reasoning. There would be more dishonest merchants if the possibility of chargebacks ceased to exist. Your reasoning is like saying look how safe this town is, guess we don’t need police anymore. And to say that virtually no merchant acceptance[1] is an “irrelevant argument” is laughable. Merchants have little incentive to spend money and effort to add support for an obscure payment method that virt…

« There would be more dishonest merchants if the possibility of chargebacks ceased to exist » Yes there will probably be a minor uptick in merchants being dishonest. But I doubt it will be as bad as you make it to be. Many other factors push merchants to stay honest: legal repercussions, damaged reputation, etc. « And to say that virtually no merchant acceptance[1] is an “irrelevant argument” is laughable » Irrelevan…

> Yes there will probably be a minor uptick in merchants being dishonest. But I doubt it will be as bad...

Simply wishful thinking. If that were the case consumer protections never would have been a very interesting feature. But they are. Especially for ecommerce.

> Your argument is like saying in the early days of Blu-ray that "no one will buy Blu-ray discs...

No and I clearly stated otherwise. Apple Pay is more like launching a new disc standard that is compatible with millions of existing players already deployed, compared to one that requires brand new hardware and has fewer features. No contest.

You also ignored -- probably because it is in your interest to ignore it -- that the reason merchants have no incentive to adopt is that nobody uses it. Payments are a two-sided market. Advances need to offer benefits to both sides of the market. You've only cited an advantage to one side, the merchant, which comes directly at the cost of a regression in benefits to the other side, the consumer.

Bitcoin as it stands is a major regression in consumer benefits, and you've only managed to cite one extremely narrow case where it offers any advantage whatsoever (no transaction limits or approval step). This is nowhere near enough to offer a compelling value proposition to consumers.

As for P2P, your own use case was sending lunch money. You've offered nothing to suggest that Apple Pay won't dominate this category. You're also incorrect in your "guarantee" about delays in access to funds; they are debit transactions that process instantly.

Re: Breach at Sonic Drive-In May Have Impacted Millions of Credit, Debit Cards

#100
post #91

Earlier quoted context omitted.

The news looks bad, but reality is worse. Remember that huge trove of NSA hacking tools and exploits that dumped last year? And the numerous follow-up dumps? There are LOTS of new weapons in the hands of everyone from everyday script kiddies to organized crime to enemy nations. It's possible Equifax was the only credit agency with enough information to require public disclosure... if Transunion doesn't have the right…

This talk seems to always be relevant: https://vimeo.com/135347162 Abstract: In this bleak, relentlessly morbid talk, James Mickens will describe why making computers secure is an intrinsically impossible task. He will explain why no programming language makes it easy to write secure code. He will then discuss why cloud computing is a black hole for privacy, and only useful for people who want to fill your machine wi…

I don't know who this James Mickens fellow is, but I like the cut of his jib.
Post reply on HN