Live data from Hacker News

Card Breaches at Car Washes

krebsonsecurity.com

11–20 of 45 posts

Re: Card Breaches at Car Washes

#11
post #8

I get the low level carders (or whatever you call them -- the folks buying card data and attempting to steal goods with it). If you're stealing $500 worth of gift cards at a time, it's not like you have many life alternatives. But somewhere there's a series of folks that (1) engineered a symantec breach; (2) someone else either knew #1 or figured out how to get their hands on source; (3) security audited said source;…

That assumes that the people doing all of this are located somewhere where better paying legitimate jobs are easy to come by. They usually aren't.

Re: Card Breaches at Car Washes

#12
post #8

I get the low level carders (or whatever you call them -- the folks buying card data and attempting to steal goods with it). If you're stealing $500 worth of gift cards at a time, it's not like you have many life alternatives. But somewhere there's a series of folks that (1) engineered a symantec breach; (2) someone else either knew #1 or figured out how to get their hands on source; (3) security audited said source;…

That assumes that the people doing all of this are located somewhere where better paying legitimate jobs are easy to come by. They usually aren't.

even if they don't, they seem like they have enough technical chops that said jobs would find them...

Re: Card Breaches at Car Washes

#13
post #10

One of the most striking things to me is this sentence: "Trustwave and other companies that get hired to investigate breaches involving card data is that far too many point-of-sale breaches start when the thieves abuse some kind of remote access tool installed on the point-of-sale device itself." We have an incredibly secure and successful piece of remote access software (ssh) that is used on billions of computers an…

SSH is no better than some random Windows-based remote admin tool if the same default password is used.

Ah yes of course, and the portion that I quoted didn't include this tidbit which I guess is what I was actually thinking about: “What the investigators we’ve worked with so far have been able to gather is that [the thieves] were exploiting not the pcAnywhere credentials, but a flaw in old versions of pcAnywhere,”

Then again old versions of SSH are probably equally vulnerable.

It would seem that there is no substitute for having a real root who has responsibility for the system, though perhaps the comment from nuxi7 is a simple way to engineer around part of the problem. Sane defaults or in this case an explicit lack of defaults could be useful.

Re: Card Breaches at Car Washes

#14
“The clerk told me they would come into the store in pairs, using multiple credit cards until one of them was finally approved, at which point they’d buy $500 each in prepaid gift cards,”

"We have two Family Dollar stores in Everett and a bunch in the surrounding area, and these guys would come in three to four times a week at each location, laundering money from stolen cards"

You would have thought they would report them.

Re: Card Breaches at Car Washes

#15
post #14

“The clerk told me they would come into the store in pairs, using multiple credit cards until one of them was finally approved, at which point they’d buy $500 each in prepaid gift cards,” "We have two Family Dollar stores in Everett and a bunch in the surrounding area, and these guys would come in three to four times a week at each location, laundering money from stolen cards" You would have thought they would report…

You might think, but a few years ago, but when credit was crazy cheap in the UK and they were just throwing credit cards at people, I had friends who would go through this process each time they were picking up a bar tab. The credit card company won't let you go over your limit and don't forget just a few years ago there was no easy way to check your limit other than waiting for the bill or calling the company.

I wouldn't be surprised if many people in the service industries still see this type of multi card roulette daily.

I can imagine if the clerk did report his concerns, he'd likely be told they were good customers so why rock the boat....

Re: Card Breaches at Car Washes

#16
post #8

I get the low level carders (or whatever you call them -- the folks buying card data and attempting to steal goods with it). If you're stealing $500 worth of gift cards at a time, it's not like you have many life alternatives. But somewhere there's a series of folks that (1) engineered a symantec breach; (2) someone else either knew #1 or figured out how to get their hands on source; (3) security audited said source;…

That assumes that the people doing all of this are located somewhere where better paying legitimate jobs are easy to come by. They usually aren't.

they probably don't have a degree and unfortunately in most places across the east coast, a 4 yr degree is a prerequisite

Re: Card Breaches at Car Washes

#17
post #12

Earlier quoted context omitted.

That assumes that the people doing all of this are located somewhere where better paying legitimate jobs are easy to come by. They usually aren't.

even if they don't, they seem like they have enough technical chops that said jobs would find them...

Some people just enjoy being the other side of the fence. Think how many hackers do similar work 'for free' without being able to turn their hacks into cash. I guess many of this people also get a kick out of taking on something so huge and powerful and 'winning'.

Re: Card Breaches at Car Washes

#18
post #15
post #14

“The clerk told me they would come into the store in pairs, using multiple credit cards until one of them was finally approved, at which point they’d buy $500 each in prepaid gift cards,” "We have two Family Dollar stores in Everett and a bunch in the surrounding area, and these guys would come in three to four times a week at each location, laundering money from stolen cards" You would have thought they would report…

You might think, but a few years ago, but when credit was crazy cheap in the UK and they were just throwing credit cards at people, I had friends who would go through this process each time they were picking up a bar tab. The credit card company won't let you go over your limit and don't forget just a few years ago there was no easy way to check your limit other than waiting for the bill or calling the company. I wou…

> I can imagine if the clerk did report his concerns, he'd likely be told they were good customers so why rock the boat....

Isn't the merchant liable for the chargebacks? Or in this case, who was footing the bill for this fraud?

Re: Card Breaches at Car Washes

#19
Credit card numbers aren't particularly secret (if you think of all the retail staff online, on the phone and offline) that have access to them. The thing that manages fraud and keeps the value of card numbers down is the difficulty in converting card numbers to cash or goods safely and anonymously.

I'm slightly surprised that the gift cards scheme works as I don't see why there couldn't be a revocation list for gift cards circulated amongst stores that is added to when a chargeback occurs. Even if it doesn't it still exposes the criminal when buying the gift card.

Re: Card Breaches at Car Washes

#20
post #15

Earlier quoted context omitted.

You might think, but a few years ago, but when credit was crazy cheap in the UK and they were just throwing credit cards at people, I had friends who would go through this process each time they were picking up a bar tab. The credit card company won't let you go over your limit and don't forget just a few years ago there was no easy way to check your limit other than waiting for the bill or calling the company. I wou…

> I can imagine if the clerk did report his concerns, he'd likely be told they were good customers so why rock the boat.... Isn't the merchant liable for the chargebacks? Or in this case, who was footing the bill for this fraud?

The merchant may be liable - but the minimum wage clerk...?
Post reply on HN