That proves my point again that there are not enough regulations on electronic security standards that applies to private companies. All you have are white hat security consultant experts that only have their dollars and reputation to work with. The public is highly vulnerable on those things yet I don't see politicians really caring.
Postbank to replace 12M bank cards after employees steal 'master key'
41–50 of 194 posts
Re: Postbank to replace 12M bank cards after employees steal 'master key'
#42Earlier quoted context omitted.
Hardly a private company: PostBank is the banking division of the SA Post Office, and firmly a government-run entity.
And not the first government run entity in SA to have funds stolen from it. Transnet/PRASA (railways) Eskom (electricity) SAA (airline) All have had just totally monumental theft often at the top levels. It all seems to be pretty consequence free. Meanwhile, the hawks open immediate investigations and charge people almost immediately who are trying to expose things - which is kind of funny - 10 years to investigate t…
Re: Postbank to replace 12M bank cards after employees steal 'master key'
#43That proves my point again that there are not enough regulations on electronic security standards that applies to private companies. All you have are white hat security consultant experts that only have their dollars and reputation to work with. The public is highly vulnerable on those things yet I don't see politicians really caring.
Quite the opposite: the free market will deal with this just fine, giving a big penalty to companies that don't care enough. The government, on the other hand, imposes bad businesses, enables regulatory capture and has proven many times that it has no idea how to handle infosec. These white hat consultants aren't perfect but through competition they're still better than lobbied lawmakers.
Re: Postbank to replace 12M bank cards after employees steal 'master key'
#44>The breach resulted from the printing of the bank's encrypted master key in plain, unencrypted digital language at the Postbank's old data centre in the Pretoria city centre I can't read anymore. Is there anymore technical explanation? Was it actually 'printed' ... on paper? Was it even an actual encryption key or just a password or something?
People seem to forget why credit cards came into existence. It was not for security. Ever. Credit Cards were introduced as a less-secure-but-more-convenient-check. The store then would have a stock of "blank checks" with absolutely no security features where they would imprint with carbon paper and a pressure roll the credit card information and pretty much "mint" the client a check on the spot. Over time the raised…
Re: Postbank to replace 12M bank cards after employees steal 'master key'
#45Earlier quoted context omitted.
People seem to forget why credit cards came into existence. It was not for security. Ever. Credit Cards were introduced as a less-secure-but-more-convenient-check. The store then would have a stock of "blank checks" with absolutely no security features where they would imprint with carbon paper and a pressure roll the credit card information and pretty much "mint" the client a check on the spot. Over time the raised…
Even more fun fact: we rely on mag stripes (vs. chip n pin / nfc / etc) because of gas pumps. The cost of refitting gas pumps holds us back. Yay.
When NFC showed up, it was intended for plastic cards. This was pretty widely deployed. Then software companies integrated it with phones. This made the telcos unhappy, because these phones had a "secure element" that they did not control (traditionally the SIM card was the secure element, but these phones ignored that and that upset them; back then, a carrier being upset meant that your phone could not be used on their network). It also made processing networks unhappy, because they saw that they were losing control. (You don't need Mastercard and Visa when the phone can just use the Internet to ask Apple to authorize the transaction, after all.) So they flat-out stopped issuing cards with NFC. Then the final blow is that merchants were tired of paying credit card transaction fees, so they removed NFC readers from their stores, and banded together to make some shitty system to bill your purchase directly to your checking account. No more paying fees or pesky chargebacks.
The retail side blew up -- no consumer wanted it, and it was technologically bad. NFC readers are back in stores. The carrier side blew up -- SIM cards are gone and Apple or Samsung is your secure element provider. I am not sure what happened on the processing card network. I'm guessing they made some private deal with the NFC payment providers (Apple, Google, Garmin, Fitbit, etc.; enough companies in on the game that they can sit back and watch them fight each other while they profit).
I kind of got to watch this from both sides. I worked on Google Wallet when I started at Google in 2012. Used it pretty much every time I went to CVS. Then CVS removed their readers. Then Apple entered the market, and CVS once again accepts NFC cards.
So maybe gas pumps played a role; I don't drive so I don't interact with gas pumps ever. But there were much deeper problems. A lot of entrenched monopolies stood to lose a lot, so they were happy to impede progress wherever possible. There was never a good possible outcome, though -- let the incumbents keep their power, or let the upstart megacorps become the new incumbent. Plenty of VC money available if you think you can fix this problem, or become the new big guy ;)
Re: Postbank to replace 12M bank cards after employees steal 'master key'
#46Earlier quoted context omitted.
Even more fun fact: we rely on mag stripes (vs. chip n pin / nfc / etc) because of gas pumps. The cost of refitting gas pumps holds us back. Yay.
So why not limit the magstripe to gas pumps and give them a time frame of 5-10 years to upgrade existing pumps, and mandate chip capable card readers in new pumps? At the same time fees could be raised 2% for non-chip transactions to incentivize upgrades.
Shops accepting mag stripe payments are liable for counterfeit fraud. If you use EMV (chip cards), then card brands protect you (Visa, MasterCard, etc.
You can Google it as "EMV liability shift" if you're interested in more details.
Re: Postbank to replace 12M bank cards after employees steal 'master key'
#47>The breach resulted from the printing of the bank's encrypted master key in plain, unencrypted digital language at the Postbank's old data centre in the Pretoria city centre I can't read anymore. Is there anymore technical explanation? Was it actually 'printed' ... on paper? Was it even an actual encryption key or just a password or something?
Probably a backup. It makes sense to have an offline backup in cleartext (for DR), as long as you have the appropriate storage and security controls in place to protect it.
This is a huge failure.
Re: Postbank to replace 12M bank cards after employees steal 'master key'
#48In any case it would make sense to have multiple master keys...say use a different master key for each batch of so many cards.. then if one key was compromised it wouldn't affect 12M cards.
Re: Postbank to replace 12M bank cards after employees steal 'master key'
#49and why was there a "master" key?
Re: Postbank to replace 12M bank cards after employees steal 'master key'
#50Earlier quoted context omitted.
It's a general purpose publication. The general public knows what a "master key" is. "Main key" is meaningless.
I'm fairly certain this was a joke about the debate going on regarding git and the broader development community trying to be more inclusive by changing the name of the default branch in git. Which is typically called master.
Painters can be masters, carpenters and all kinds of other artists and craftsmen too. Are they no longer masters of their crafts because the word is somehow "not inclusive"? It's not. And it shouldn't be. It takes word to be a master crafter.
What about BDSM, should subs and doms no longer refer to their counterparts as master/mistress & slave?
Apparently this is a controversial issue in some places, and I don't understand why. Maybe HN isn't the best place to gain that understanding, but then maybe I'll be pleasantly surprised?