Live data from Hacker News

Postbank to replace 12M bank cards after employees steal 'master key'

timeslive.co.za

141–150 of 194 posts

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#141
post #38

Earlier quoted context omitted.

Looks like they have deadline of 10/2020 before visa and mastercard start holding owners liable for fraud if they haven't upgraded to chip readers. https://www.latimes.com/business/technology/story/2020-01-07...

That's stupid. Just issue cards without stripe and the problem will solve itself.

That's stupid. Just issue cards without stripe and the problem will solve itself.

I don't see a bank replacing its customers' forms of payment with a new form that isn't accepted in as many places as the old one.

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#142
post #125

Earlier quoted context omitted.

There isn't anything to really "steal", a contactless card is willing to participate in transactions but "I am standing next to you" isn't a transaction on its own. You need to do a relay attack. Here's how that goes: 1. Jenny's payment card is in her jacket pocket. 2. Charlie walks into a store wearing a small NFC-capable computer and a medium distance radio (a cell phone might do) perhaps concealed inside his cloth…

What about mobile payment terminals (where I live, they're very common)? Instead of virtually moving the card to the store through a relay attack, move the store to the card through one of the spare payment terminals (many stores have several as a backup for when the POS or the network is down, or for deliveries) hidden in the clothing. Of course, this changes the threat model a bit, since it now needs collusion from…

> Of course, this changes the threat model a bit, since it now needs collusion from a store employee.

An employee? Or the store owner?

These terminals don't offer a choice of destination bank account, if you type $16.94 into Walmart terminal and hold it near Jenny's card the card will authorize $16.94 payment... to Walmart.

For an independent merchant (including e.g. franchise operators) in some sense that's their money in the merchant account, so it makes a little bit more sense, but I still don't think it really adds up. It's like opening a bar so you can get cheap booze, the economics don't make sense.

There are opportunities for insider crooks. In the UK for example there were a rash of what are morally skimmers built into chip card terminals. Here's how that worked:

You own one or more stores with shiny new EMV payment terminals. From an instructional video you learn how to prise open a common model of terminal without setting off its tamper detection. Then you use the huge space inside the terminal left for an optional security feature (never implemented because features costs money) to add a board that taps the communication to the card and uses a cell phone connection to upload it. You seal up the tampered terminal and install it at one of your busier stores.

Customer puts their chip card in, the terminal works as expected but unknown to them your modification stores the card details and transmits them to other crooks half way around the world.

The other crooks are making old-fashioned magnetic stripe cards with details that have been uploaded. They send small fry out with these bogus cards to buy stuff in a country that doesn't have EMV yet. The stuff is fenced, and you, back in the country with EMV, get say 10% of the proceeds for your contribution to this international crime.

Some people in the UK got prison time for this. International card fraud is easier to spot (this person bought groceries just outside Luton, then forty minutes later they bought a laptop computer in Hyderabad or Houston?) but until EMV is rolled out everywhere similar tricks will be done.

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#143

Earlier quoted context omitted.

No it’s not

Sometimes it is: https://en.bitcoin.it/wiki/Cold_storage

You could just save it on a flash drive and hide it in safe. How does printing it on a piece of paper make it any safer?

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#144
post #130

Earlier quoted context omitted.

No it’s not

An A-Z character string written inside random page a book stored at a relative's house is a super easy way to secure a physical backup of your private key. You could even get clever and encrypt the key using some memorable passage of another book. Since the book passage is unknown to anyone else and be selected from a near infinite pool of paragraphs from the entirety of all published books, it would be impossible fo…

You are not adding any more security than that if you simply remembering some random key (which isn’t that hard if you put your mind to it).

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#145

Earlier quoted context omitted.

Sometimes it is: https://en.bitcoin.it/wiki/Cold_storage

You could just save it on a flash drive and hide it in safe. How does printing it on a piece of paper make it any safer?

With paper you can be confident that you will still be able to read it in decades. How true is that of a flash drive?

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#146
post #76
post #47

Earlier quoted context omitted.

It makes absolutely no sense. Such highly valuable secrets are usually saved using Shamir's secret sharing with parts of the split secret held by people unlikely to collude. Key ceremonies are done in a way that at no point a human being is in position to single-handedly extract the secret from its HSM. This is a huge failure.

Interesting.. What Open source tools do you use for this? I would love to read further how I can not have a printed copy of a master key in a safety deposit box.

We keep printed keys in a safe. I suppose if we were a bank we'd do it differently. They're in "tamper evident" envelopes, too. These are AWS master keys, Bitlocker encryption keys, etc.

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#147

Earlier quoted context omitted.

Sometimes it is: https://en.bitcoin.it/wiki/Cold_storage

You could just save it on a flash drive and hide it in safe. How does printing it on a piece of paper make it any safer?

Did you even bother viewing the linked page?

> The advantage is that any security issues of USB interfaces or cameras are completely avoided.

There's also the section that enumerates all the downsides for each medium of storage: https://en.bitcoin.it/wiki/Cold_storage#Private_key_backup_s...

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#148
post #115

Earlier quoted context omitted.

I don’t think you have to use a TSA lock on luggage with a firearm [1]. If it meets the legal definition of a “firearm” you trigger (get it?) the TSA rules that allow you to use a non-joke lock. Since this includes just the legal firearm you don’t even have to carry an actual gun to prevent the TSA from sniffing your undies. Deviant Ollam gave an (in)famous talk [2] about this at Defcon. [1]: https://www.tsa.gov/trav…

That's a funny hack. However, this looks like conflicting advice: "Only the passenger should retain the key or combination to the lock unless TSA personnel request the key to open the firearm container to ensure compliance with TSA regulations. You may use any brand or type of lock to secure your firearm case, including TSA-recognized locks." If you use a TSA lock, that means they have a key to open up the case and a…

> If you use a TSA lock, that means they have a key to open up the case and access the firearm without you around. That's a big no-no and could result in problems with the law.

Why? If a TSA person unlocks it in accordance with their procedures, surely that's fine (and is what they would do anyway, just getting the key from you first)? If a TSA person abuses their position to open your luggage with their master key against their procedures, surely that's not your problem - more akin to a criminal breaking open your luggage than anything else.

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#150
post #58

Earlier quoted context omitted.

Also, nearly everywhere in Canada, the interac system really has it together up here.

It helps having one debit card system to support. The US has like 7 and I couldn't begin to name most of them (Interlink is one of them, I think Maestro is another)

I don't really buy that though. The banks may have an easy time talking to other Canadian banks but they also need to talk with American banks and Canadian PoS terminals often support US debit cards. Perhaps Euro PoS terminals just refuse to work with US debit cards but Canada gets a lot of those American tourist dollars and doesn't want to make it hard for you to spend your money up here.
Post reply on HN