Live data from Hacker News

Postbank to replace 12M bank cards after employees steal 'master key'

timeslive.co.za

61–70 of 194 posts

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#61
post #17

Earlier quoted context omitted.

People seem to forget why credit cards came into existence. It was not for security. Ever. Credit Cards were introduced as a less-secure-but-more-convenient-check. The store then would have a stock of "blank checks" with absolutely no security features where they would imprint with carbon paper and a pressure roll the credit card information and pretty much "mint" the client a check on the spot. Over time the raised…

Even more fun fact: we rely on mag stripes (vs. chip n pin / nfc / etc) because of gas pumps. The cost of refitting gas pumps holds us back. Yay.

Liability shift for gas pumps has been pushed back (October 2020 I think) but not eliminated.

Liability shift works like this: Historically the merchant is protected if they had good faith belief that the payment card was authorised via things like a mag stripe. After liability shift that goes away unless you use EMV. You checked the card was "real" with just a mag stripe? Not interested, the chargeback comes out of your money.

Your local gas station can keep using mag stripe readers for another decade if they like. But liability shift means places that see significant fraud will have an obvious economic incentive to go EMV, and that shifts the fraud onto nearby stations that didn't have fraud problems, so they go EMV and so on.

If you're a merchant with very low fraud rates it can make sense to do no Authorization step whatsoever. Any merchant, anywhere in the world, can do Settlement, which is the step that moves money from your account to theirs, based just on the card number. Only if it becomes a question as to whether this payment was authorized does it matter whether they did the Authorization step, a mag stripe read, the old fashioned impression machines, or a chip-and-PIN terminal.

Certain types of companies can find it makes sense to do no Authorization for groups of customers. One Click may be an example of that. You did a bunch of transactions, with a physical delivery address, what are the chances that a new transaction with the same delivery address and card details is fraud while the previous ones were not?

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#62
Ah hah hah haha!

And our (USA) law enforcement agencies promise us that any encryption master keys required by their grandiose plans will only be used in cases with proper legal court warrants (ignore the FISA court warrant abuse based on lies and deceit) and will be super secure and never stolen.

Just like those secret hacking tools stolen from the CIA.

Or these private master keys.

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#63
post #41
post #16

That proves my point again that there are not enough regulations on electronic security standards that applies to private companies. All you have are white hat security consultant experts that only have their dollars and reputation to work with. The public is highly vulnerable on those things yet I don't see politicians really caring.

Quite the opposite: the free market will deal with this just fine, giving a big penalty to companies that don't care enough. The government, on the other hand, imposes bad businesses, enables regulatory capture and has proven many times that it has no idea how to handle infosec. These white hat consultants aren't perfect but through competition they're still better than lobbied lawmakers.

Free markets don't exist outside of textbooks and can't due to the complexities of social relations we have to deal with in the real world. It seems like you're suggesting a solution that can't ever work by merit of it being unable to exist.

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#64
post #58

Earlier quoted context omitted.

The few places is everywhere in the EU at least. Signing card transactions is very last century in more advanced nations. ;) Edit: also the pin is verified each Transaction unlike with receipt signatures, which as you say were rarely checked by anyone.

Also, nearly everywhere in Canada, the interac system really has it together up here.

It helps having one debit card system to support. The US has like 7 and I couldn't begin to name most of them (Interlink is one of them, I think Maestro is another)

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#65
post #50
post #10

Earlier quoted context omitted.

I'm fairly certain this was a joke about the debate going on regarding git and the broader development community trying to be more inclusive by changing the name of the default branch in git. Which is typically called master.

I'm a little bit confused by that whole discussion. Keys are not people. Nor are branches. Bank cards. Hard drives. It seems perfectly fine to have a master/slave relationship between components. I don't quite get how that impacts anyone. Intelligent lifeforms obviously shouldn't be treated as slaves, but that doesn't seem to be what this is about; merely a matter of terminology? Painters can be masters, carpenters a…

It's just a lot of pointless outrage about nothing by a couple of people who need to feel they're accomplishing something. Sadly companies seem to follow them as to avoid being targeted by social media 'shitstorms'.

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#66
post #62

Ah hah hah haha! And our (USA) law enforcement agencies promise us that any encryption master keys required by their grandiose plans will only be used in cases with proper legal court warrants (ignore the FISA court warrant abuse based on lies and deceit) and will be super secure and never stolen. Just like those secret hacking tools stolen from the CIA. Or these private master keys.

Don't forget the TSA travel master keys, which can now be 3-D printed by anyone using this repo: https://github.com/Xyl2k/TSA-Travel-Sentry-master-keys

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#67
post #32
post #8

Earlier quoted context omitted.

I believe the parent is referencing the github "main" vs "master" controversy, where "master" was considered "exclusionary", and should therefore be replaced with "main".

I thought the problem was master/slave terminology, in say replication.

It started that way. Now any use of "master" is considered problematic by a small group. Same with blacklist and whitelist.

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#69
post #31

Earlier quoted context omitted.

I've worked at more than one location where the Cameras in customer areas were conspicuous but the cameras in the employee area were hidden.

> but the cameras in the employee area were hidden. Is this legal? Sounds like a lawsuit waiting to happen.

What law would you think is being broken here? I don't think they are talking about bathrooms, where one might argue there is a "reasonable expectation of privacy." If you are working for an employer on their premises I think they have a right to do monitoring including clandestine. Just like they can monitor anything you do on their computer

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#70

Earlier quoted context omitted.

Even more fun fact: we rely on mag stripes (vs. chip n pin / nfc / etc) because of gas pumps. The cost of refitting gas pumps holds us back. Yay.

I am not sure that is the problem. Timing was a big problem. When NFC showed up, it was intended for plastic cards. This was pretty widely deployed. Then software companies integrated it with phones. This made the telcos unhappy, because these phones had a "secure element" that they did not control (traditionally the SIM card was the secure element, but these phones ignored that and that upset them; back then, a carr…

>The retail side blew up -- no consumer wanted it, and it was technologically bad.

Didn't help that thr superior user experience of NFC built into cards was drowned out by the klaxons of the media continuously warning customers of proximity theft.

Wrong threat model, the cheap mag skimmer or camera or unsecured database models were the real risks. It wasn't that someone will stand butt-to-butt with you to steal a NFC token.

Post reply on HN