Live data from Hacker News

Postbank to replace 12M bank cards after employees steal 'master key'

timeslive.co.za

121–130 of 194 posts

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#121
post #115

Earlier quoted context omitted.

Yes, but you're missing the forest for the trees. A government entity (TSA) had a thing built specifically for their needs ("secure" locks for luggage) and promised they would be the only ones capable of unlocking it. Then somehow the "secret" they promised to protect (physical keys) got leaked out somehow and now the entire thing is security theater. Also I think they used these locks on handgun / firearm containers…

I don’t think you have to use a TSA lock on luggage with a firearm [1]. If it meets the legal definition of a “firearm” you trigger (get it?) the TSA rules that allow you to use a non-joke lock. Since this includes just the legal firearm you don’t even have to carry an actual gun to prevent the TSA from sniffing your undies. Deviant Ollam gave an (in)famous talk [2] about this at Defcon. [1]: https://www.tsa.gov/trav…

That's a funny hack. However, this looks like conflicting advice:

"Only the passenger should retain the key or combination to the lock unless TSA personnel request the key to open the firearm container to ensure compliance with TSA regulations. You may use any brand or type of lock to secure your firearm case, including TSA-recognized locks."

If you use a TSA lock, that means they have a key to open up the case and access the firearm without you around. That's a big no-no and could result in problems with the law.

You'd also probably want to show up an extra hour early because this could cause long delays. Some airports are notorious for workers who don't know the regulations, don't want to be responsible for any of it, and will refuse to do anything to help you resolve the situation. Also, definitely don't try this if you're flying through New York or New Jersey.

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#122
post #88

Earlier quoted context omitted.

Simply put: putting anything you can't replace into checked luggage is foolish. The TSA is a lot more likely to steal your stuff than some random person with a printed key. Plus, if you use a real lock, they have the right to clip it off, which is trivial. Don't put stuff of value into checked luggage. Keep it on your person or ship it via a carrier who has insurance.

Or check a metal case with a lock the TSA can't open: buy a flare gun (legally a firearm, cheaper than normal guns), declare it, and have your other valuables in the same bag. Legally firearms must be in checked luggage, without ammunition, in hard cases (not soft bags), locked by a mechanism only the owner can open . But unless you travel with valuables quite often it is definitely cheaper to ship it insured.

This sounds like a better idea than flying with AR-15 parts. Less likely to scare people, and less likely to raise flags or get put on some list.

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#123
post #115

Earlier quoted context omitted.

I don’t think you have to use a TSA lock on luggage with a firearm [1]. If it meets the legal definition of a “firearm” you trigger (get it?) the TSA rules that allow you to use a non-joke lock. Since this includes just the legal firearm you don’t even have to carry an actual gun to prevent the TSA from sniffing your undies. Deviant Ollam gave an (in)famous talk [2] about this at Defcon. [1]: https://www.tsa.gov/trav…

That's a funny hack. However, this looks like conflicting advice: "Only the passenger should retain the key or combination to the lock unless TSA personnel request the key to open the firearm container to ensure compliance with TSA regulations. You may use any brand or type of lock to secure your firearm case, including TSA-recognized locks." If you use a TSA lock, that means they have a key to open up the case and a…

I agree that paragraph seems contradictory. I guess I have a slightly lower opinion of the TSA now.

What’s important is that you don’t have to use a TSA lock. You just have to open it for them if they ask.

> Also, definitely don't try this if you're flying through New York or New Jersey.

Why?

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#124
post #9
post #5

>The breach resulted from the printing of the bank's encrypted master key in plain, unencrypted digital language at the Postbank's old data centre in the Pretoria city centre I can't read anymore. Is there anymore technical explanation? Was it actually 'printed' ... on paper? Was it even an actual encryption key or just a password or something?

People print their bitcoin keys all the time. Sometimes physical security is easier than electronic - current situation not withstanding.

No it’s not

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#125

Earlier quoted context omitted.

>The retail side blew up -- no consumer wanted it, and it was technologically bad. Didn't help that thr superior user experience of NFC built into cards was drowned out by the klaxons of the media continuously warning customers of proximity theft. Wrong threat model, the cheap mag skimmer or camera or unsecured database models were the real risks. It wasn't that someone will stand butt-to-butt with you to steal a NFC…

There isn't anything to really "steal", a contactless card is willing to participate in transactions but "I am standing next to you" isn't a transaction on its own. You need to do a relay attack. Here's how that goes: 1. Jenny's payment card is in her jacket pocket. 2. Charlie walks into a store wearing a small NFC-capable computer and a medium distance radio (a cell phone might do) perhaps concealed inside his cloth…

What about mobile payment terminals (where I live, they're very common)? Instead of virtually moving the card to the store through a relay attack, move the store to the card through one of the spare payment terminals (many stores have several as a backup for when the POS or the network is down, or for deliveries) hidden in the clothing. Of course, this changes the threat model a bit, since it now needs collusion from a store employee.

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#127
post #5

>The breach resulted from the printing of the bank's encrypted master key in plain, unencrypted digital language at the Postbank's old data centre in the Pretoria city centre I can't read anymore. Is there anymore technical explanation? Was it actually 'printed' ... on paper? Was it even an actual encryption key or just a password or something?

Isn't paper actually one of the more secure storage mediums? If you asked me the best way to store a secret I'd say put it on paper and lock it in a safe. I'd probably do something like print a QR code with an encrypted secret and store the key on a separate printed QR code.

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#128
post #62

Ah hah hah haha! And our (USA) law enforcement agencies promise us that any encryption master keys required by their grandiose plans will only be used in cases with proper legal court warrants (ignore the FISA court warrant abuse based on lies and deceit) and will be super secure and never stolen. Just like those secret hacking tools stolen from the CIA. Or these private master keys.

Don't forget the TSA travel master keys, which can now be 3-D printed by anyone using this repo: https://github.com/Xyl2k/TSA-Travel-Sentry-master-keys

[deleted]

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#129
post #123

Earlier quoted context omitted.

That's a funny hack. However, this looks like conflicting advice: "Only the passenger should retain the key or combination to the lock unless TSA personnel request the key to open the firearm container to ensure compliance with TSA regulations. You may use any brand or type of lock to secure your firearm case, including TSA-recognized locks." If you use a TSA lock, that means they have a key to open up the case and a…

I agree that paragraph seems contradictory. I guess I have a slightly lower opinion of the TSA now. What’s important is that you don’t have to use a TSA lock. You just have to open it for them if they ask. > Also, definitely don't try this if you're flying through New York or New Jersey. Why?

CPL's are typically granted at the state level, but not all states need to recognize your CPL as valid. So it's perfectly legal for me to fly from Detroit to New York with a firearm, because the TSA staff in Detroit, MI legally recognize my MI CPL.

However, the TSA agents in NY do not recognize my MI CPL. As a result when I fly back from NY to MI, I could get arrested for carrying a firearm.

More on this here: https://www.theblaze.com/news/2018/01/18/colorado-woman-decl...

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#130
post #9

Earlier quoted context omitted.

People print their bitcoin keys all the time. Sometimes physical security is easier than electronic - current situation not withstanding.

No it’s not

An A-Z character string written inside random page a book stored at a relative's house is a super easy way to secure a physical backup of your private key. You could even get clever and encrypt the key using some memorable passage of another book. Since the book passage is unknown to anyone else and be selected from a near infinite pool of paragraphs from the entirety of all published books, it would be impossible for someone to bruteforce even if they found the book where you stored the encrypted key. This would be an easy enough process to generate the ciphertext and store it in the event that you totally lost access to all of your electronics, online accounts, and home.
Post reply on HN