Live data from Hacker News

Postbank to replace 12M bank cards after employees steal 'master key'

timeslive.co.za

181–190 of 194 posts

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#181
post #135
post #100

Insane. Just think of the risk that this 'master key' exposed to the bank's employees. Having access to something as insanely valuable as a bank 'master key' puts the employees at risk of blackmail, extortion, etc. That's why you have HSMs, key ceremonies, Shamir's secret sharing etc. It's not just for trust, it's also for protection of those involved. Unauthorized wire transfers can be undone, or covered by insuranc…

I appreciate this. I wasn't familiar with Adi Shamir's secret sharing scheme. I found this video quite helpful in clarifying how it works for cases where only a subset of the participants are required to confirm the secret. https://www.youtube.com/watch?v=iFY5SyY3IMQ

That was an amazing video. I understand some fundamental crypto about secret sharing with Shamir's algo and it only took 7 minutes. Oh, and in the last 30 seconds they basically explain how bittorrent missing chunks work too. Thanks!

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#182
post #165
post #100

Insane. Just think of the risk that this 'master key' exposed to the bank's employees. Having access to something as insanely valuable as a bank 'master key' puts the employees at risk of blackmail, extortion, etc. That's why you have HSMs, key ceremonies, Shamir's secret sharing etc. It's not just for trust, it's also for protection of those involved. Unauthorized wire transfers can be undone, or covered by insuranc…

When I was doing IT support one off the trickiest things was trying to get people to stop giving me their passwords. I am not interested in that sort of liability if something gets stolen!

Related to that: why are US landlords so hot on a copy of the house key? In a genuine emergency you let yourself in with an axe, in all other cases it's just a liability with no upside.

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#183
post #79

Earlier quoted context omitted.

You can use a ball point pen to pop open the zipper on any luggage. I understand that the illusion of control is very helpful for nervous passengers, but your luggage is leaving your control and it's mostly nylon fabric and plastic.

Yes, but you're missing the forest for the trees. A government entity (TSA) had a thing built specifically for their needs ("secure" locks for luggage) and promised they would be the only ones capable of unlocking it. Then somehow the "secret" they promised to protect (physical keys) got leaked out somehow and now the entire thing is security theater. Also I think they used these locks on handgun / firearm containers…

> got leaked out somehow

They let the Washington Post take high-res pictures of the masters while supporting them doing a story about the TSA and those got published which was enough to decode the keys.

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#184
post #165

Earlier quoted context omitted.

When I was doing IT support one off the trickiest things was trying to get people to stop giving me their passwords. I am not interested in that sort of liability if something gets stolen!

Related to that: why are US landlords so hot on a copy of the house key? In a genuine emergency you let yourself in with an axe, in all other cases it's just a liability with no upside.

It's more a convenience thing for the tenant. Landlord can perform maintenance without the tenant being home, and door guards are common otherwise. Plus US laws tend to give landlords more power.

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#185

Earlier quoted context omitted.

Isn't paper actually one of the more secure storage mediums? If you asked me the best way to store a secret I'd say put it on paper and lock it in a safe. I'd probably do something like print a QR code with an encrypted secret and store the key on a separate printed QR code.

Paper in this context is a form of cold storage, you could get very similar results encoding the information on magnetic tape or on a hard drive stored in a safe. Cold storage turns the information security problem into a physical security problem. The catch comes when you need to use this information regularly, say to issue bank cards. Now you need protocols for regularly circumventing that physical security and cor…

A QR code on paper has the benefit that it lasts centuries

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#186
post #135

Earlier quoted context omitted.

I appreciate this. I wasn't familiar with Adi Shamir's secret sharing scheme. I found this video quite helpful in clarifying how it works for cases where only a subset of the participants are required to confirm the secret. https://www.youtube.com/watch?v=iFY5SyY3IMQ

The original paper on this “How to Share a Secret” by Adi Shamir is incredible. You should absolutely read it. - The system is proven to be information theoretically secure (not just computationally) - It uses only high school math - The paper is only TWO PAGES LONG I highly recommend printing this out on a single sheet of paper (double sided) and digging in. https://cs.jhu.edu/~sdoshi/crypto/papers/shamirturing.pdf

Thanks for sharing. This is indeed genius and so simple. Brilliant.

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#187
post #100

Insane. Just think of the risk that this 'master key' exposed to the bank's employees. Having access to something as insanely valuable as a bank 'master key' puts the employees at risk of blackmail, extortion, etc. That's why you have HSMs, key ceremonies, Shamir's secret sharing etc. It's not just for trust, it's also for protection of those involved. Unauthorized wire transfers can be undone, or covered by insuranc…

HSMs make your storage more secure, but don’t really solve the problem of people having to have access to stuff. You can address those issues, but not fully, and it’s much more difficult. I’ve worked in a number of banks where my admin accounts have given me access to things like SWIFT credentials [0]. I’ve always hated having access to stuff like that, but when you start trying to figure out how to fix it you realize that no matter what you do you’re always going to have important assets protected by secrets, and people are always going to have to have some level of interaction with those secrets.

[0]: https://en.m.wikipedia.org/wiki/Bangladesh_Bank_robbery

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#188
post #9
post #5

>The breach resulted from the printing of the bank's encrypted master key in plain, unencrypted digital language at the Postbank's old data centre in the Pretoria city centre I can't read anymore. Is there anymore technical explanation? Was it actually 'printed' ... on paper? Was it even an actual encryption key or just a password or something?

People print their bitcoin keys all the time. Sometimes physical security is easier than electronic - current situation not withstanding.

Even KeePass recommends to write the master secret key on a piece of paper. Sure, it must be in a secure place, but we cannot avoid this step for reliability.

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#189
post #165

Earlier quoted context omitted.

When I was doing IT support one off the trickiest things was trying to get people to stop giving me their passwords. I am not interested in that sort of liability if something gets stolen!

Related to that: why are US landlords so hot on a copy of the house key? In a genuine emergency you let yourself in with an axe, in all other cases it's just a liability with no upside.

As a LL I don't want to break down my door to fix a leaking faucet.

It's also so I can enter for regular maintenance without needing the tenant to be there.

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#190

Would you build a castle with a back-door?

Actually, castles almost always had back doors. https://en.wikipedia.org/wiki/Postern

Almost always? Source for that? Very interesting, I guess during a siege there's a tradeoff there. If your postern is on the other side of a mountain range, then definitely it's not so bad.
Post reply on HN