Live data from Hacker News

The Home Depot confirms payment systems breach

ir.homedepot.com

1–10 of 110 posts

Re: The Home Depot confirms payment systems breach

#2
I wonder if this will be less of an issue here in Canada with our euro-style chip & PIN setup. In theory the attackers wouldn't have long-lived access to any of the payment information. I suppose we'll see.

The attackers probably have my name/email address/mailing information, which kind of sucks.

Re: The Home Depot confirms payment systems breach

#3
encouraging that they are using this as a motivator to "roll out EMV "Chip and PIN" to all U.S. stores by the end of this year" ahead of the prescribed deadline.

edit: "Chip and PIN" is taken directly from the sec filing that is linked.

the described deadline of october 2015 for the liability shift comes from banks[1] and not a US law or similar.

[1] http://en.wikipedia.org/wiki/EMV#United_States

Re: The Home Depot confirms payment systems breach

#4
post #2

I wonder if this will be less of an issue here in Canada with our euro-style chip & PIN setup. In theory the attackers wouldn't have long-lived access to any of the payment information. I suppose we'll see. The attackers probably have my name/email address/mailing information, which kind of sucks.

It is not clear to me why they would have your name, email address, and mailing information? For example, I recently purchased some items from home depot and used my debit card + pin, other than rolling the pin, what else should we be doing?

Do you have a home depot CC?

Re: The Home Depot confirms payment systems breach

#5
post #3

encouraging that they are using this as a motivator to "roll out EMV "Chip and PIN" to all U.S. stores by the end of this year" ahead of the prescribed deadline. edit: "Chip and PIN" is taken directly from the sec filing that is linked. the described deadline of october 2015 for the liability shift comes from banks[1] and not a US law or similar. [1] http://en.wikipedia.org/wiki/EMV#United_States

Is there actually a timetable for "chip and pin" in the US? I'm only aware of banks issuing chip + signature style EMV cards.

Re: The Home Depot confirms payment systems breach

#6
post #3

encouraging that they are using this as a motivator to "roll out EMV "Chip and PIN" to all U.S. stores by the end of this year" ahead of the prescribed deadline. edit: "Chip and PIN" is taken directly from the sec filing that is linked. the described deadline of october 2015 for the liability shift comes from banks[1] and not a US law or similar. [1] http://en.wikipedia.org/wiki/EMV#United_States

Is there actually a timetable for "chip and pin" in the US? I'm only aware of banks issuing chip + signature style EMV cards.

PCI deadline for US retailers to implement chip + pin is October 2015. Mentioned in the Home Depot link above

Re: The Home Depot confirms payment systems breach

#7
post #3

encouraging that they are using this as a motivator to "roll out EMV "Chip and PIN" to all U.S. stores by the end of this year" ahead of the prescribed deadline. edit: "Chip and PIN" is taken directly from the sec filing that is linked. the described deadline of october 2015 for the liability shift comes from banks[1] and not a US law or similar. [1] http://en.wikipedia.org/wiki/EMV#United_States

I got into an argument about that with the guy at the Home Depot paint counter today. I blamed the hack on Home Depot probably running XP on their POS machines and he blamed the banks not doing something that they do in Europe, I'm assuming it's this EMV chip because it sounded like he was repeating something he was told.

Re: The Home Depot confirms payment systems breach

#8
post #6

Earlier quoted context omitted.

Is there actually a timetable for "chip and pin" in the US? I'm only aware of banks issuing chip + signature style EMV cards.

PCI deadline for US retailers to implement chip + pin is October 2015. Mentioned in the Home Depot link above

Many don't read the article and just start commenting.

Re: The Home Depot confirms payment systems breach

#9
post #2

I wonder if this will be less of an issue here in Canada with our euro-style chip & PIN setup. In theory the attackers wouldn't have long-lived access to any of the payment information. I suppose we'll see. The attackers probably have my name/email address/mailing information, which kind of sucks.

It is not clear to me why they would have your name, email address, and mailing information? For example, I recently purchased some items from home depot and used my debit card + pin, other than rolling the pin, what else should we be doing? Do you have a home depot CC?

home depot likes to collect email address for sending receipts (and spam). Along with that older style mag stripes will give out the name. Not sure about mailing info or how they'd get that.

The thing to do is to actually get stores to stop storing CC info at all. they should be able to process the payment and then forget the info at all so it never has to be stored so it can't be stolen. EMV is actually a move to force this as they'll no longer be able to get the number, just verify a transaction in theory.

Re: The Home Depot confirms payment systems breach

#10
post #6

Earlier quoted context omitted.

Is there actually a timetable for "chip and pin" in the US? I'm only aware of banks issuing chip + signature style EMV cards.

PCI deadline for US retailers to implement chip + pin is October 2015. Mentioned in the Home Depot link above

When will banks actually start issuing chip + pin cards in the US? It doesn't help US consumers much if the retailers accept them, but the banks don't issue them. I have credit cards with four banks (probably the biggest 4 in the US, but I don't know exactly how they stack up). One is chip+signature, and the rest don't have chips at all. Including a brand new one I got from a huge bank less than a month ago.
Post reply on HN