Live data from Hacker News

Card Breaches at Car Washes

krebsonsecurity.com

31–40 of 45 posts

Re: Card Breaches at Car Washes

#31
post #12

Earlier quoted context omitted.

even if they don't, they seem like they have enough technical chops that said jobs would find them...

> they seem like they have enough technical chops that said jobs would find them... In my experience, jobs don't find you. By what mechanism do you think this would happen?

That depends on your exposure to people interested in you working for them. It's certain that when you are well connected jobs just find you. On the other hand it is imaginable that for many people in computer security most "jobs that find them" are not exactly ethical.

While I would not exactly position myself into computer security, I've got my share of borderline black-hat offers, although in all cases the other party believed that what they are doing is perfectly legal.

Re: Card Breaches at Car Washes

#32

Credit card numbers aren't particularly secret (if you think of all the retail staff online, on the phone and offline) that have access to them. The thing that manages fraud and keeps the value of card numbers down is the difficulty in converting card numbers to cash or goods safely and anonymously. I'm slightly surprised that the gift cards scheme works as I don't see why there couldn't be a revocation list for gift…

Security of credit card industry is built not on hard computer security principles but on auditing and ability to point fingers. This breaks with enough levels of indirection and gift cards add such additional level of indirection.

Also gift cards have secondary (and probably more important) use for thieves. Giftcard is legitimately looking magstripe card that in many cases gets processed in same way as card payment, so you can just write stolen magstripe data onto giftcard and get something that does not raise suspicion (store clerk is not going to verify that card number matches or event that payment method matches).

Re: Card Breaches at Car Washes

#33
post #27
post #8

I get the low level carders (or whatever you call them -- the folks buying card data and attempting to steal goods with it). If you're stealing $500 worth of gift cards at a time, it's not like you have many life alternatives. But somewhere there's a series of folks that (1) engineered a symantec breach; (2) someone else either knew #1 or figured out how to get their hands on source; (3) security audited said source;…

" And the more I read krebs, the more I think I should get a $2k limit credit card and use it for all purchases that aren't on amazon. " Let me repeat my advocacy of the virtues of cash for face to face transactions. I normally carry a bit over $400 in my wallet, and almost always use cash for everything up to, say, $800, and around or above that, a check if I can. Also rewards the retailer with the 2-3% or so in pro…

Cash means having to carry cash, count change, reorganize bills, so on and so forth. Checks mean having to write checks and earning the everlasting (and justified) emnity of everyone behind you in line because you're wasting their time.

Credit cards mean a swipe (debit cards add a PIN, oh noes) and indemnity against the fraud that occasionally blows up.

Cash loses. Checks lose hard.

Re: Card Breaches at Car Washes

#34
post #7
post #4

Considering how expensive point-of-sale systems are, I'm not surprised that these systems are running old, vulnerable software. Heck, there are still ATMs running OS/2 Warp in the United States; the only reason people don't hack those is because it's so obscure. My father still uses a small pre-computer cash register to this day; I've had no luck convincing him to buy a new computerized one so he can accept credit ca…

I'm surprised these PoS systems aren't managed with automatic updates, since the merchant service providers (along with the banks) are usually the ones losing money if they get hit with chargebacks.

In europe typical deployment solves this problem (EMV is quite orthogonal to this) by the fact that card data does not touch the PoS system itself. In fact any other approach is not feasible as PoS systems themselves are invariably horrible mess of accumulated kludges and backward compatibility restrictions. And there are quite powerful economic incentives to keep this state of things. Security-wise this is one of the few situations where semi-air-gapped network makes sense (for the PoS part, with card terminals having their separate network).

Re: Card Breaches at Car Washes

#35
post #33
post #27

Earlier quoted context omitted.

" And the more I read krebs, the more I think I should get a $2k limit credit card and use it for all purchases that aren't on amazon. " Let me repeat my advocacy of the virtues of cash for face to face transactions. I normally carry a bit over $400 in my wallet, and almost always use cash for everything up to, say, $800, and around or above that, a check if I can. Also rewards the retailer with the 2-3% or so in pro…

Cash means having to carry cash, count change, reorganize bills, so on and so forth. Checks mean having to write checks and earning the everlasting (and justified) emnity of everyone behind you in line because you're wasting their time. Credit cards mean a swipe (debit cards add a PIN, oh noes) and indemnity against the fraud that occasionally blows up. Cash loses. Checks lose hard .

Checks are only for big purchases, with vendors who know me well. Last was in 2008, for a washer and dryer bought from a GE dealership who's building was purchased from my family decades ago.

If there's a potential for a line, or a vendor who doesn't know me from Adam, as when I bought a water softener, I do use a credit card.

I personally think the overhead for routine use of cash is roughly equivalent to routinely using a credit or debit card, e.g. I don't have to keep track of all those purchases to reconcile them with my monthly statement. Carrying cash is no problem, counting change ... well, I grew up before credit card usage was routine, so it's second nature, and reorganizing the bills etc. takes very little time. It helps that I have a standard load out that's makes refreshing my wallet easy, as well as making change, at least half the time I provide exact change, or an amount that makes my return change easy. Doing the mental math also has its advantages.

Don't know how I've managed it, but I've never needed to do a charge back in 31 years of using credit cards. Certainly there's not much potential for fraud in my face to face translations.

My youngest bother and his wife used to regularly shop at Target; that turned out be a significant hassle due to the recent breach. Hmmm, and only I can quantify the value of increased peace of mind by limiting my exposure to credit card fraud.

Credit and debit cards also "lose".

Re: Card Breaches at Car Washes

#36
post #20

Earlier quoted context omitted.

> I can imagine if the clerk did report his concerns, he'd likely be told they were good customers so why rock the boat.... Isn't the merchant liable for the chargebacks? Or in this case, who was footing the bill for this fraud?

The merchant may be liable - but the minimum wage clerk...?

Minimum wage clerk is not liable due to many laws that protect employees from wage abuse without a judgement in court[1] but they can surely get fired for negligence in reporting suspicious activity.

[1] http://www.seyfarth.com/dir_docs/publications/NEHT01120810.p...

>As a practical matter, the Court’s decision means that employers can- not safely take deductions for theft or damage to property unless fault and value have been determined by a court of law or government agency.

Re: Card Breaches at Car Washes

#37
post #15
post #14

“The clerk told me they would come into the store in pairs, using multiple credit cards until one of them was finally approved, at which point they’d buy $500 each in prepaid gift cards,” "We have two Family Dollar stores in Everett and a bunch in the surrounding area, and these guys would come in three to four times a week at each location, laundering money from stolen cards" You would have thought they would report…

You might think, but a few years ago, but when credit was crazy cheap in the UK and they were just throwing credit cards at people, I had friends who would go through this process each time they were picking up a bar tab. The credit card company won't let you go over your limit and don't forget just a few years ago there was no easy way to check your limit other than waiting for the bill or calling the company. I wou…

>I wouldn't be surprised if many people in the service industries still see this type of multi card roulette daily.

Worked as a cashier about 10ish years ago. Never once saw multi card roulette.

Of course once in a while some people would say "20 on this card and 10 in cash." Never seen it with more than one card though. I almost never saw people get declined, I think it happened like 5 times total. It would be highly suspicious to me, especially coming from the same person!

Re: Card Breaches at Car Washes

#38
post #30

Earlier quoted context omitted.

I generally agree, but if the retailer is large enough they almost certainly pay a percentage of their cash payments to a Brinks-like company to securely handle the transfer of the money.

And if they aren't large enough, they pay with their time.

But at least in the latter case, not incrementally by much for my cash purchase. Every cash purchase does require a bit more work in counting the bills, but the time to deposit the cash doesn't change if it's to a night depository, and again just a little if face to face with a teller.

Unless the purchase is small, there's also a time cost in getting the signature, although that's small if the company is big enough to collect it with their POS terminal, and there's also back end reconciliation work to be done, manually if the place is small, like a non-chain restaurant.

No payment method is free of overhead and friction.

Re: Card Breaches at Car Washes

#39
post #4

Considering how expensive point-of-sale systems are, I'm not surprised that these systems are running old, vulnerable software. Heck, there are still ATMs running OS/2 Warp in the United States; the only reason people don't hack those is because it's so obscure. My father still uses a small pre-computer cash register to this day; I've had no luck convincing him to buy a new computerized one so he can accept credit ca…

> I've had no luck convincing him to buy a new computerized one so he can accept credit cards

You can still accept credit cards without a new register. It's just a different machine. They don't have to be integrated.

Almost every single doctor's office accepts credit card and exactly NONE of them have a register.

The way it works is you charge the card on a separate machine, type in the total, have them sign and put the slip somewhere and press "paid with credit" on the register if it is computerized or if it isn't then just ignore the register for that transaction.

Re: Card Breaches at Car Washes

#40
post #8

I get the low level carders (or whatever you call them -- the folks buying card data and attempting to steal goods with it). If you're stealing $500 worth of gift cards at a time, it's not like you have many life alternatives. But somewhere there's a series of folks that (1) engineered a symantec breach; (2) someone else either knew #1 or figured out how to get their hands on source; (3) security audited said source;…

How do you know they don't already work in computer security? People are greedy.
Post reply on HN