Would you build a castle with a back-door?
Postbank to replace 12M bank cards after employees steal 'master key'
111–120 of 194 posts
Re: Postbank to replace 12M bank cards after employees steal 'master key'
#112Ah hah hah haha! And our (USA) law enforcement agencies promise us that any encryption master keys required by their grandiose plans will only be used in cases with proper legal court warrants (ignore the FISA court warrant abuse based on lies and deceit) and will be super secure and never stolen. Just like those secret hacking tools stolen from the CIA. Or these private master keys.
Don't forget the TSA travel master keys, which can now be 3-D printed by anyone using this repo: https://github.com/Xyl2k/TSA-Travel-Sentry-master-keys
I'm glad we don't need to trust the TSA with following any kind of security protocols. /s
Re: Postbank to replace 12M bank cards after employees steal 'master key'
#113Earlier quoted context omitted.
You can use a ball point pen to pop open the zipper on any luggage. I understand that the illusion of control is very helpful for nervous passengers, but your luggage is leaving your control and it's mostly nylon fabric and plastic.
Yes, but you're missing the forest for the trees. A government entity (TSA) had a thing built specifically for their needs ("secure" locks for luggage) and promised they would be the only ones capable of unlocking it. Then somehow the "secret" they promised to protect (physical keys) got leaked out somehow and now the entire thing is security theater. Also I think they used these locks on handgun / firearm containers…
I am not the one missing the forest for the trees.
It has always been security theater. From day 1. What's most galling is that quite a lot of the people participating here are young enough that they don't remember a time before the theater. If you are under 30 your first plane flight you can remember is probably after this all started.
Locks are mechanical, and a master key can be built by taking apart a lock and measuring the innards. In some cases you can create a master key by filing down the right teeth on a key you already have. Master keys in apartment buildings are an old, known problem to competitive lockpickers.
As other people are pointing out elsewhere in this thread, carrying a firearm requires that you use a lock-lock, not a TSA "lock".
Re: Postbank to replace 12M bank cards after employees steal 'master key'
#114My accounting professor used to say the mirrors and security cameras in stores were to monitor the employees more than the customers.
Employers steal far more than employees: https://upload.wikimedia.org/wikipedia/commons/c/c4/Wage_the... https://www.gq.com/story/wage-theft https://www.epi.org/publication/employers-steal-billions-fro... https://www.epi.org/publication/wage-theft-bigger-problem-th...
Re: Postbank to replace 12M bank cards after employees steal 'master key'
#115Earlier quoted context omitted.
You can use a ball point pen to pop open the zipper on any luggage. I understand that the illusion of control is very helpful for nervous passengers, but your luggage is leaving your control and it's mostly nylon fabric and plastic.
Yes, but you're missing the forest for the trees. A government entity (TSA) had a thing built specifically for their needs ("secure" locks for luggage) and promised they would be the only ones capable of unlocking it. Then somehow the "secret" they promised to protect (physical keys) got leaked out somehow and now the entire thing is security theater. Also I think they used these locks on handgun / firearm containers…
Deviant Ollam gave an (in)famous talk [2] about this at Defcon.
[1]: https://www.tsa.gov/travel/transporting-firearms-and-ammunit...
Re: Postbank to replace 12M bank cards after employees steal 'master key'
#116Earlier quoted context omitted.
Don't forget the TSA travel master keys, which can now be 3-D printed by anyone using this repo: https://github.com/Xyl2k/TSA-Travel-Sentry-master-keys
Simply put: putting anything you can't replace into checked luggage is foolish. The TSA is a lot more likely to steal your stuff than some random person with a printed key. Plus, if you use a real lock, they have the right to clip it off, which is trivial. Don't put stuff of value into checked luggage. Keep it on your person or ship it via a carrier who has insurance.
Re: Postbank to replace 12M bank cards after employees steal 'master key'
#117Earlier quoted context omitted.
I am not sure that is the problem. Timing was a big problem. When NFC showed up, it was intended for plastic cards. This was pretty widely deployed. Then software companies integrated it with phones. This made the telcos unhappy, because these phones had a "secure element" that they did not control (traditionally the SIM card was the secure element, but these phones ignored that and that upset them; back then, a carr…
>The retail side blew up -- no consumer wanted it, and it was technologically bad. Didn't help that thr superior user experience of NFC built into cards was drowned out by the klaxons of the media continuously warning customers of proximity theft. Wrong threat model, the cheap mag skimmer or camera or unsecured database models were the real risks. It wasn't that someone will stand butt-to-butt with you to steal a NFC…
You need to do a relay attack. Here's how that goes:
1. Jenny's payment card is in her jacket pocket.
2. Charlie walks into a store wearing a small NFC-capable computer and a medium distance radio (a cell phone might do) perhaps concealed inside his clothing
3. Charlie's friend Barry walks near Jenny, Barry is also wearing a similar setup to Charlie.
4. As Barry gets close to Jenny, Charlie "checks out" at the store, paying with NFC. The transaction travels from a machine near Charlie, through the radio, to Barry (now creepily close to Jenny) and then back over NFC to Jenny's card. Jenny's card agrees to the purchase - everything seems legit.
Jenny just paid for Charlie's purchases even though they've never met.
This attack isn't economically attractive because transaction sizes are limited. A complicated trick that sometimes allows you to get "free" pizza or coffee in exchange for risking time behind bars seems like a bad idea. If you could get a laptop, or a big TV then it might be more attractive, but you can't because those cost too much to allow mere NFC presence authorization.
Re: Postbank to replace 12M bank cards after employees steal 'master key'
#118Earlier quoted context omitted.
South Africa has insane levels of graft and corruption that have been going on for decades. They also have a lot of politically motivated assassinations. Total basket case of a country.
Replace "south africa" with the USA and your statement is equally verifiable and accurate.
Re: Postbank to replace 12M bank cards after employees steal 'master key'
#119Re: Postbank to replace 12M bank cards after employees steal 'master key'
#120That proves my point again that there are not enough regulations on electronic security standards that applies to private companies. All you have are white hat security consultant experts that only have their dollars and reputation to work with. The public is highly vulnerable on those things yet I don't see politicians really caring.
Quite the opposite: the free market will deal with this just fine, giving a big penalty to companies that don't care enough. The government, on the other hand, imposes bad businesses, enables regulatory capture and has proven many times that it has no idea how to handle infosec. These white hat consultants aren't perfect but through competition they're still better than lobbied lawmakers.