Live data from Hacker News

Postbank to replace 12M bank cards after employees steal 'master key'

timeslive.co.za

41–50 of 194 posts

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#41
post #16

That proves my point again that there are not enough regulations on electronic security standards that applies to private companies. All you have are white hat security consultant experts that only have their dollars and reputation to work with. The public is highly vulnerable on those things yet I don't see politicians really caring.

Quite the opposite: the free market will deal with this just fine, giving a big penalty to companies that don't care enough. The government, on the other hand, imposes bad businesses, enables regulatory capture and has proven many times that it has no idea how to handle infosec. These white hat consultants aren't perfect but through competition they're still better than lobbied lawmakers.

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#42

Earlier quoted context omitted.

Hardly a private company: PostBank is the banking division of the SA Post Office, and firmly a government-run entity.

And not the first government run entity in SA to have funds stolen from it. Transnet/PRASA (railways) Eskom (electricity) SAA (airline) All have had just totally monumental theft often at the top levels. It all seems to be pretty consequence free. Meanwhile, the hawks open immediate investigations and charge people almost immediately who are trying to expose things - which is kind of funny - 10 years to investigate t…

South Africa has insane levels of graft and corruption that have been going on for decades. They also have a lot of politically motivated assassinations. Total basket case of a country.

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#43
post #41
post #16

That proves my point again that there are not enough regulations on electronic security standards that applies to private companies. All you have are white hat security consultant experts that only have their dollars and reputation to work with. The public is highly vulnerable on those things yet I don't see politicians really caring.

Quite the opposite: the free market will deal with this just fine, giving a big penalty to companies that don't care enough. The government, on the other hand, imposes bad businesses, enables regulatory capture and has proven many times that it has no idea how to handle infosec. These white hat consultants aren't perfect but through competition they're still better than lobbied lawmakers.

Do you think that the free market worked as desired in the case of Equifax?

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#44
post #17
post #5

>The breach resulted from the printing of the bank's encrypted master key in plain, unencrypted digital language at the Postbank's old data centre in the Pretoria city centre I can't read anymore. Is there anymore technical explanation? Was it actually 'printed' ... on paper? Was it even an actual encryption key or just a password or something?

People seem to forget why credit cards came into existence. It was not for security. Ever. Credit Cards were introduced as a less-secure-but-more-convenient-check. The store then would have a stock of "blank checks" with absolutely no security features where they would imprint with carbon paper and a pressure roll the credit card information and pretty much "mint" the client a check on the spot. Over time the raised…

Maybe 5 years ago or so a store in London pulled out their carbon copy machine from under the counter to accept my American credit card.

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#45
post #17

Earlier quoted context omitted.

People seem to forget why credit cards came into existence. It was not for security. Ever. Credit Cards were introduced as a less-secure-but-more-convenient-check. The store then would have a stock of "blank checks" with absolutely no security features where they would imprint with carbon paper and a pressure roll the credit card information and pretty much "mint" the client a check on the spot. Over time the raised…

Even more fun fact: we rely on mag stripes (vs. chip n pin / nfc / etc) because of gas pumps. The cost of refitting gas pumps holds us back. Yay.

I am not sure that is the problem. Timing was a big problem.

When NFC showed up, it was intended for plastic cards. This was pretty widely deployed. Then software companies integrated it with phones. This made the telcos unhappy, because these phones had a "secure element" that they did not control (traditionally the SIM card was the secure element, but these phones ignored that and that upset them; back then, a carrier being upset meant that your phone could not be used on their network). It also made processing networks unhappy, because they saw that they were losing control. (You don't need Mastercard and Visa when the phone can just use the Internet to ask Apple to authorize the transaction, after all.) So they flat-out stopped issuing cards with NFC. Then the final blow is that merchants were tired of paying credit card transaction fees, so they removed NFC readers from their stores, and banded together to make some shitty system to bill your purchase directly to your checking account. No more paying fees or pesky chargebacks.

The retail side blew up -- no consumer wanted it, and it was technologically bad. NFC readers are back in stores. The carrier side blew up -- SIM cards are gone and Apple or Samsung is your secure element provider. I am not sure what happened on the processing card network. I'm guessing they made some private deal with the NFC payment providers (Apple, Google, Garmin, Fitbit, etc.; enough companies in on the game that they can sit back and watch them fight each other while they profit).

I kind of got to watch this from both sides. I worked on Google Wallet when I started at Google in 2012. Used it pretty much every time I went to CVS. Then CVS removed their readers. Then Apple entered the market, and CVS once again accepts NFC cards.

So maybe gas pumps played a role; I don't drive so I don't interact with gas pumps ever. But there were much deeper problems. A lot of entrenched monopolies stood to lose a lot, so they were happy to impede progress wherever possible. There was never a good possible outcome, though -- let the incumbents keep their power, or let the upstart megacorps become the new incumbent. Plenty of VC money available if you think you can fix this problem, or become the new big guy ;)

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#46

Earlier quoted context omitted.

Even more fun fact: we rely on mag stripes (vs. chip n pin / nfc / etc) because of gas pumps. The cost of refitting gas pumps holds us back. Yay.

So why not limit the magstripe to gas pumps and give them a time frame of 5-10 years to upgrade existing pumps, and mandate chip capable card readers in new pumps? At the same time fees could be raised 2% for non-chip transactions to incentivize upgrades.

We already have incentives in place in the US to stop using mag stripe.

Shops accepting mag stripe payments are liable for counterfeit fraud. If you use EMV (chip cards), then card brands protect you (Visa, MasterCard, etc.

You can Google it as "EMV liability shift" if you're interested in more details.

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#47
post #5

>The breach resulted from the printing of the bank's encrypted master key in plain, unencrypted digital language at the Postbank's old data centre in the Pretoria city centre I can't read anymore. Is there anymore technical explanation? Was it actually 'printed' ... on paper? Was it even an actual encryption key or just a password or something?

Probably a backup. It makes sense to have an offline backup in cleartext (for DR), as long as you have the appropriate storage and security controls in place to protect it.

It makes absolutely no sense. Such highly valuable secrets are usually saved using Shamir's secret sharing with parts of the split secret held by people unlikely to collude. Key ceremonies are done in a way that at no point a human being is in position to single-handedly extract the secret from its HSM.

This is a huge failure.

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#48
How exactly would one use this key nefariously? It seems to do so would require a whole chain of capabilities.

In any case it would make sense to have multiple master keys...say use a different master key for each batch of so many cards.. then if one key was compromised it wouldn't affect 12M cards.

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#50
post #10

Earlier quoted context omitted.

It's a general purpose publication. The general public knows what a "master key" is. "Main key" is meaningless.

I'm fairly certain this was a joke about the debate going on regarding git and the broader development community trying to be more inclusive by changing the name of the default branch in git. Which is typically called master.

I'm a little bit confused by that whole discussion. Keys are not people. Nor are branches. Bank cards. Hard drives. It seems perfectly fine to have a master/slave relationship between components. I don't quite get how that impacts anyone. Intelligent lifeforms obviously shouldn't be treated as slaves, but that doesn't seem to be what this is about; merely a matter of terminology?

Painters can be masters, carpenters and all kinds of other artists and craftsmen too. Are they no longer masters of their crafts because the word is somehow "not inclusive"? It's not. And it shouldn't be. It takes word to be a master crafter.

What about BDSM, should subs and doms no longer refer to their counterparts as master/mistress & slave?

Apparently this is a controversial issue in some places, and I don't understand why. Maybe HN isn't the best place to gain that understanding, but then maybe I'll be pleasantly surprised?

Post reply on HN