Live data from Hacker News

Postbank to replace 12M bank cards after employees steal 'master key'

timeslive.co.za

81–90 of 194 posts

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#81
post #65
post #50

Earlier quoted context omitted.

I'm a little bit confused by that whole discussion. Keys are not people. Nor are branches. Bank cards. Hard drives. It seems perfectly fine to have a master/slave relationship between components. I don't quite get how that impacts anyone. Intelligent lifeforms obviously shouldn't be treated as slaves, but that doesn't seem to be what this is about; merely a matter of terminology? Painters can be masters, carpenters a…

It's just a lot of pointless outrage about nothing by a couple of people who need to feel they're accomplishing something. Sadly companies seem to follow them as to avoid being targeted by social media 'shitstorms'.

I was hoping that as a non-native speaker I might have missed some point of nuance somewhere.

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#82
post #38

Earlier quoted context omitted.

Looks like they have deadline of 10/2020 before visa and mastercard start holding owners liable for fraud if they haven't upgraded to chip readers. https://www.latimes.com/business/technology/story/2020-01-07...

That's stupid. Just issue cards without stripe and the problem will solve itself.

It's a chicken and egg problem. Gas purchases are on the of the most common purchases in the US. Removing the ability to pay using a credit card would a) piss of owners of the new credit cards, b) likely cause people to use their old credit cards for longer and still wouldn't push gas stations to switch over quickly as most have atms and gas stations could insist on cash payments. Keep in mind that at least some of these gas pumps can't be upgraded but have to be replaced in order to support the new chip cards. What should have been done is a combination of good incentives for upgrading early (maybe reduced fees?) and penalties for not upgrading within a time frame (fraud payments are owners responsibility after n amount of time, increased fees for dealing with fraud)

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#83
post #19

It seems ridiculously cheap, relative to payout, to attack financial institutions by joining them as employees. Couple this with the fact that "white collar" crimes are punished with relatively lenient sentences.

When IT leadership talks a big game about security, as a skilled practitioner on the ground I still see plenty of opportunities. When you delve into details, a lot of that “serious business regulated entity with compliance auditing requirements” stuff is brain dead. Like, running vulnerability scanners that don’t even speak the same wire protocols as a the applications under test. Enforcing strict ACLs on UIs while it’s trivial to SSH and curl the backend APIs.

I sometimes wonder whether accounting is like this too. Is financial audit just as much of a fig leaf? Can a skilled accountant also spot dozens of ways to embezzle?

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#84

Earlier quoted context omitted.

Do you think we actually have a free market?

If we don't have a free market, it doesn't do much good to say the free market will solve any of our problems.

Huh? Presumably the suggestion is to make the market freer.

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#85

Earlier quoted context omitted.

Do you think that the free market worked as desired in the case of Equifax?

The idea is not that the free market will always produce perfect results and perfect goods. The idea is that the free market will produce better results at a faster pace with less unintended consequences than government intervention. Government intervention rarely happens proactively, just as major market changes rarely happen proactively. Supplier failure on a large scale makes it apparent that change is necessary,…

[deleted]

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#86
post #42

Earlier quoted context omitted.

South Africa has insane levels of graft and corruption that have been going on for decades. They also have a lot of politically motivated assassinations. Total basket case of a country.

1. Most of the graft and corruption has been going on at least 7 decades. i.e. Long before the ANC government. 2. "politically motivated assasinations"? Citation wanted, please.

http://archive.vn/73yLl

> These prizes seem to be worth killing for. Since 2014 more than 115 Glebelands residents have been murdered. Many were anc members who objected to the ways of Robert Mzobe, an anc councillor accused of corruption, and Bongani Hlope, a local warlord who terrorised residents. “Glebelands is a microcosm,” argues Mary de Haas, a researcher into local violence. Throughout the country violence is regularly meted out by one faction of the anc against another. From 2000 to 2017 nearly 300 political assassinations have been recorded, many of them anc members.

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#87
post #19

It seems ridiculously cheap, relative to payout, to attack financial institutions by joining them as employees. Couple this with the fact that "white collar" crimes are punished with relatively lenient sentences.

When IT leadership talks a big game about security, as a skilled practitioner on the ground I still see plenty of opportunities. When you delve into details, a lot of that “serious business regulated entity with compliance auditing requirements” stuff is brain dead. Like, running vulnerability scanners that don’t even speak the same wire protocols as a the applications under test. Enforcing strict ACLs on UIs while i…

We are truly saved by our better angels. If all people were ruthless economic competitors, and took every efficient financial opportunity available to them, criminal or legal, a cooperative society would be unmaintainable. We should consider ourselves lucky (perhaps blessed) that the anti-social among us are a tail end minority.

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#88
post #62

Ah hah hah haha! And our (USA) law enforcement agencies promise us that any encryption master keys required by their grandiose plans will only be used in cases with proper legal court warrants (ignore the FISA court warrant abuse based on lies and deceit) and will be super secure and never stolen. Just like those secret hacking tools stolen from the CIA. Or these private master keys.

Don't forget the TSA travel master keys, which can now be 3-D printed by anyone using this repo: https://github.com/Xyl2k/TSA-Travel-Sentry-master-keys

Simply put: putting anything you can't replace into checked luggage is foolish.

The TSA is a lot more likely to steal your stuff than some random person with a printed key. Plus, if you use a real lock, they have the right to clip it off, which is trivial. Don't put stuff of value into checked luggage. Keep it on your person or ship it via a carrier who has insurance.

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#89
post #41
post #16

That proves my point again that there are not enough regulations on electronic security standards that applies to private companies. All you have are white hat security consultant experts that only have their dollars and reputation to work with. The public is highly vulnerable on those things yet I don't see politicians really caring.

Quite the opposite: the free market will deal with this just fine, giving a big penalty to companies that don't care enough. The government, on the other hand, imposes bad businesses, enables regulatory capture and has proven many times that it has no idea how to handle infosec. These white hat consultants aren't perfect but through competition they're still better than lobbied lawmakers.

The FDA made it mandatory for food manufacturers to list their ingredients on food they sell. Prior to these laws no food manufacturer was willing to do this freely, for fear of someone else stealing their recipe. But now consumers can make informed decisions and avoid foods that will give them severe, life threatening allergic reactions.

Every citizen who drives a motor vehicle must be issued a driver's licence by the state they reside in. This enables a minimum understanding of how a complex machine (the highway transportation system) works so that other drivers / participants of that system can use it safely. Without regulation, vehicle collisions would be rampant and the system would be far less stable.

Not all government regulation and oversight is bad.

I highly recommend reading the book "Click here to kill everybody" by Bruce Schneier [1]. Bruce has been in the cyber-security world for a long time now and is considered one of the world's foremost experts on cryptography and computer security. In this book he makes projections about the "internet of things (internet+)" and the security problems that will come with it. He strongly advocates for government oversight and legal reform in multiple areas.

[1]: https://www.schneier.com/books/click_here/

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#90
post #31

Earlier quoted context omitted.

> but the cameras in the employee area were hidden. Is this legal? Sounds like a lawsuit waiting to happen.

What law would you think is being broken here? I don't think they are talking about bathrooms, where one might argue there is a "reasonable expectation of privacy." If you are working for an employer on their premises I think they have a right to do monitoring including clandestine. Just like they can monitor anything you do on their computer

Not in the EU.
Post reply on HN