Live data from Hacker News

Card Breaches at Car Washes

krebsonsecurity.com

21–30 of 45 posts

Re: Card Breaches at Car Washes

#21
post #8

I get the low level carders (or whatever you call them -- the folks buying card data and attempting to steal goods with it). If you're stealing $500 worth of gift cards at a time, it's not like you have many life alternatives. But somewhere there's a series of folks that (1) engineered a symantec breach; (2) someone else either knew #1 or figured out how to get their hands on source; (3) security audited said source;…

"(3) security audited said source;"

You mean found the default credentials? That doesn't take much.

Re: Card Breaches at Car Washes

#22

Earlier quoted context omitted.

That assumes that the people doing all of this are located somewhere where better paying legitimate jobs are easy to come by. They usually aren't.

they probably don't have a degree and unfortunately in most places across the east coast, a 4 yr degree is a prerequisite

Not so sure about that. I don't have a degree, and (almost) every company I've worked for (includes engineering roles at EDS, Microsoft and Nokia) said in their job specs that they absolutely require degrees. I ignore that requirement and let my resume speak for me. It works.

Re: Card Breaches at Car Washes

#23

Earlier quoted context omitted.

they probably don't have a degree and unfortunately in most places across the east coast, a 4 yr degree is a prerequisite

Not so sure about that. I don't have a degree, and (almost) every company I've worked for (includes engineering roles at EDS, Microsoft and Nokia) said in their job specs that they absolutely require degrees. I ignore that requirement and let my resume speak for me. It works.

The problem is getting the resume in the first place. Not that it excuses the theft, I'm just saying that companies that accept GitHub accounts as a substitute for working experience can be hard to find.

Re: Card Breaches at Car Washes

#24
post #12

Earlier quoted context omitted.

That assumes that the people doing all of this are located somewhere where better paying legitimate jobs are easy to come by. They usually aren't.

even if they don't, they seem like they have enough technical chops that said jobs would find them...

> they seem like they have enough technical chops that said jobs would find them...

In my experience, jobs don't find you. By what mechanism do you think this would happen?

Re: Card Breaches at Car Washes

#25
Given how easy it is to buy stolen cards, encode them onto gift cards and then use those cards to buy goods in big-box stores that can be easily resold for cash, Lavey said he wonders why old-fashioned bank robberies are still a problem.

EMV.

I know it's far from perfect, but it raises the bar considerably. You can't just clone EMV cards that way. The USA really ought to try to catch up with the rest of the world on this front.

Re: Card Breaches at Car Washes

#26
post #9

"Chaves said the store owners told him the devices had remote access via Symantec’s pcAnywhere enabled, access that was granted to anyone knew the same set of default credentials." Maybe its because The Cuckoo's Egg is what got me into this field, but I cringe everytime I hear this. Its 25 years later and we are still getting breaches based upon using default credentials. This isn't even a hard problem to solve, you…

A lot of these default passwords on non-consumer devices aren't user admin accounts but tech support accounts. So #1 and #3 don't work, because the user doesn't get the password.

But there is also a 4th option, the user somehow enables the support account.

Re: Card Breaches at Car Washes

#27
post #8

I get the low level carders (or whatever you call them -- the folks buying card data and attempting to steal goods with it). If you're stealing $500 worth of gift cards at a time, it's not like you have many life alternatives. But somewhere there's a series of folks that (1) engineered a symantec breach; (2) someone else either knew #1 or figured out how to get their hands on source; (3) security audited said source;…

"And the more I read krebs, the more I think I should get a $2k limit credit card and use it for all purchases that aren't on amazon."

Let me repeat my advocacy of the virtues of cash for face to face transactions. I normally carry a bit over $400 in my wallet, and almost always use cash for everything up to, say, $800, and around or above that, a check if I can.

Also rewards the retailer with the 2-3% or so in processing charges they'd otherwise have to pay.

Re: Card Breaches at Car Washes

#28
post #15

Earlier quoted context omitted.

You might think, but a few years ago, but when credit was crazy cheap in the UK and they were just throwing credit cards at people, I had friends who would go through this process each time they were picking up a bar tab. The credit card company won't let you go over your limit and don't forget just a few years ago there was no easy way to check your limit other than waiting for the bill or calling the company. I wou…

> I can imagine if the clerk did report his concerns, he'd likely be told they were good customers so why rock the boat.... Isn't the merchant liable for the chargebacks? Or in this case, who was footing the bill for this fraud?

The bank, most likely, or their insurance provider. Deoending on US law (which protects people less than the UK AFAICT) the customer may have some liability. But basically the bank OK'd the transactions so it's on them.

Of course if it's that frickin' obvious what's going on then the merchant will find themselves under review and saddled with much higher fees after a while.

Re: Card Breaches at Car Washes

#29
post #27
post #8

I get the low level carders (or whatever you call them -- the folks buying card data and attempting to steal goods with it). If you're stealing $500 worth of gift cards at a time, it's not like you have many life alternatives. But somewhere there's a series of folks that (1) engineered a symantec breach; (2) someone else either knew #1 or figured out how to get their hands on source; (3) security audited said source;…

" And the more I read krebs, the more I think I should get a $2k limit credit card and use it for all purchases that aren't on amazon. " Let me repeat my advocacy of the virtues of cash for face to face transactions. I normally carry a bit over $400 in my wallet, and almost always use cash for everything up to, say, $800, and around or above that, a check if I can. Also rewards the retailer with the 2-3% or so in pro…

I generally agree, but if the retailer is large enough they almost certainly pay a percentage of their cash payments to a Brinks-like company to securely handle the transfer of the money.

Re: Card Breaches at Car Washes

#30
post #27

Earlier quoted context omitted.

" And the more I read krebs, the more I think I should get a $2k limit credit card and use it for all purchases that aren't on amazon. " Let me repeat my advocacy of the virtues of cash for face to face transactions. I normally carry a bit over $400 in my wallet, and almost always use cash for everything up to, say, $800, and around or above that, a check if I can. Also rewards the retailer with the 2-3% or so in pro…

I generally agree, but if the retailer is large enough they almost certainly pay a percentage of their cash payments to a Brinks-like company to securely handle the transfer of the money.

And if they aren't large enough, they pay with their time.
Post reply on HN