Live data from Hacker News

Postbank to replace 12M bank cards after employees steal 'master key'

timeslive.co.za

131–140 of 194 posts

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#131
post #18

This is quite surprising to me. Some of the banking technology and practices in Germany are extremely tight and their infrastructure seems problematic. Living there for a while as a non-native and being with PostBank, it was insanely difficult to login and understand. Germany is also heavily marred with bank cash groups, meaning you get charged elsewhere. It was great to see N26 come along and change that, and thank…

They really should add "[South Africa]" the title, since my first thought was "Is this Germany or might they mean PostFinance in Switzerland?"...

How do you summmon dang, with @dang?

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#132
post #9

Earlier quoted context omitted.

People print their bitcoin keys all the time. Sometimes physical security is easier than electronic - current situation not withstanding.

No it’s not

Sometimes it is: https://en.bitcoin.it/wiki/Cold_storage

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#133
post #123

Earlier quoted context omitted.

I agree that paragraph seems contradictory. I guess I have a slightly lower opinion of the TSA now. What’s important is that you don’t have to use a TSA lock. You just have to open it for them if they ask. > Also, definitely don't try this if you're flying through New York or New Jersey. Why?

CPL's are typically granted at the state level, but not all states need to recognize your CPL as valid. So it's perfectly legal for me to fly from Detroit to New York with a firearm, because the TSA staff in Detroit, MI legally recognize my MI CPL. However, the TSA agents in NY do not recognize my MI CPL. As a result when I fly back from NY to MI, I could get arrested for carrying a firearm. More on this here: https:…

That has to do with concealed carry. Putting a firearm in your suitcase does not require a CPL, nor does it require concealed or even open carry. I'm sure it's still legal to transport a firearm in New York.

To be clear, this rule can be triggered by a flare gun or starting pistol. Traveling with those seems perfectly reasonable and I don't see why a CPL would be required.

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#134

Earlier quoted context omitted.

Even more fun fact: we rely on mag stripes (vs. chip n pin / nfc / etc) because of gas pumps. The cost of refitting gas pumps holds us back. Yay.

I'm starting to see chip enabled pumps. Unfortunately they aren't obviously labeled so you assume it needs a swipe and have to wait to restart when it complains about not reading the chip.

At the chip gas pumps, I'm seeing paper signs left by the owner that say "Leave card inserted". I'm glad everyone is going the chip route but I still wish that pins would be required for credit cards. Just having a 4 digit pin is loads more secure than expecting some cashier to verify a signature on the back of the card (which never happens). I can still bypass the pin on my debit card in most situations by just entering in nothing unless I'm doing cash back. I'm not really sure how that's supposed to protect me, whats the point of a pin if you don't need to type it in? Card companies are quick to refund you for any fraud but it creates an inconvenience for the user that really just isn't necessary. I've been on vacation abroad when my credit card was used fraudulently which I had to cancel immediately. Luckily I had access to my corporate credit card I could use to pay my hotel bill since that was the only thing I couldn't afford with the cash I had on me but I very well could have been shit out of luck. I paid the charges off myself and wasn't in too much trouble after I explained the situation.

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#135
post #100

Insane. Just think of the risk that this 'master key' exposed to the bank's employees. Having access to something as insanely valuable as a bank 'master key' puts the employees at risk of blackmail, extortion, etc. That's why you have HSMs, key ceremonies, Shamir's secret sharing etc. It's not just for trust, it's also for protection of those involved. Unauthorized wire transfers can be undone, or covered by insuranc…

I appreciate this. I wasn't familiar with Adi Shamir's secret sharing scheme. I found this video quite helpful in clarifying how it works for cases where only a subset of the participants are required to confirm the secret.

https://www.youtube.com/watch?v=iFY5SyY3IMQ

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#136
post #5

>The breach resulted from the printing of the bank's encrypted master key in plain, unencrypted digital language at the Postbank's old data centre in the Pretoria city centre I can't read anymore. Is there anymore technical explanation? Was it actually 'printed' ... on paper? Was it even an actual encryption key or just a password or something?

How else would you store it? Printed is not vulnerable to electronic hacking, and encrypting it would be pointless since you’d also need to store the encryption key to the master encryption key then.

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#137
Note that this is a banking division of South Africa's Post Office. I was confused it was the Deutsche Postbank.

They lost more than $3.2 million from fraudulent transactions and will now have to replace more than 12 million cards for its customers after employees printed and then stole its master key in December 2018. Took them long enough to figure it out.

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#138
post #17

Earlier quoted context omitted.

People seem to forget why credit cards came into existence. It was not for security. Ever. Credit Cards were introduced as a less-secure-but-more-convenient-check. The store then would have a stock of "blank checks" with absolutely no security features where they would imprint with carbon paper and a pressure roll the credit card information and pretty much "mint" the client a check on the spot. Over time the raised…

Maybe 5 years ago or so a store in London pulled out their carbon copy machine from under the counter to accept my American credit card.

Happened to my wife about 10 months ago when there was a power failure in a department store while she was in the middle of a transaction.

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#139
post #76
post #47

Earlier quoted context omitted.

It makes absolutely no sense. Such highly valuable secrets are usually saved using Shamir's secret sharing with parts of the split secret held by people unlikely to collude. Key ceremonies are done in a way that at no point a human being is in position to single-handedly extract the secret from its HSM. This is a huge failure.

Interesting.. What Open source tools do you use for this? I would love to read further how I can not have a printed copy of a master key in a safety deposit box.

For card system master keys, you don't use open source tools, you buy a set of properly hardened hardware modules, and follow the appropriate (documented, tested, verified) 'rituals' on them. IIRC the set we used cost something in the ballpark of $50k-$100k, which is not really much compared to all the other things that are table stakes of doing it properly. You can do it much cheaper if the risks are lower and you need less tamper resistance and auditing because you're less likely to have (for example) one of the trusted authorised employees be malicious and willing to invest nontrivial effort in circumventing the system.

Because losing these keys can be very, very, very expensive.

For an example (somewhat similar to this Postbank case) see India Cosmos Bank 2018 incident (https://www.reuters.com/article/cyber-heist-india-idUSL4N1V5... is one link) where criminals generated fake cards to cash out some $13 million; and replacing 12M bank cards also has an huge cost to replace the cards (perhaps roughly $12M - $1 per card replacement is plausible though possibly on the cheap side) even if we ignore the reputation cost.

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#140

Earlier quoted context omitted.

Even more fun fact: we rely on mag stripes (vs. chip n pin / nfc / etc) because of gas pumps. The cost of refitting gas pumps holds us back. Yay.

I'm starting to see chip enabled pumps. Unfortunately they aren't obviously labeled so you assume it needs a swipe and have to wait to restart when it complains about not reading the chip.

I'm starting to see chip enabled pumps.

Exxon (pre-ExxonMobil) had chip-enabled pumps in the early 90's. Instead of a card, you had a little cylinder-shaped keyfob about the size of a few Tylenols strung together. I'm not sure what happened to that, I ended up moving out of an area served by Exxon.

These days I see gas pumps with the little wireless payment logo, and I have a card with the same logo, but it's never worked for me.

Post reply on HN