Live data from Hacker News

The Home Depot confirms payment systems breach

ir.homedepot.com

11–20 of 110 posts

Re: The Home Depot confirms payment systems breach

#11
post #2

I wonder if this will be less of an issue here in Canada with our euro-style chip & PIN setup. In theory the attackers wouldn't have long-lived access to any of the payment information. I suppose we'll see. The attackers probably have my name/email address/mailing information, which kind of sucks.

It is not clear to me why they would have your name, email address, and mailing information? For example, I recently purchased some items from home depot and used my debit card + pin, other than rolling the pin, what else should we be doing? Do you have a home depot CC?

I don't have a Home Depot CC, but I've used their e-receipts in the last couple of months and I'm reasonably sure that I've ordered online from them in the past.

I certainly hope they didn't compromise the PIN pads in the stores. That could be a Very Bad Thing.

Re: The Home Depot confirms payment systems breach

#12
post #6

Earlier quoted context omitted.

PCI deadline for US retailers to implement chip + pin is October 2015. Mentioned in the Home Depot link above

Many don't read the article and just start commenting.

In all fairness, SEC filings are a rather incomprehensible format to read, even one this short.

Re: The Home Depot confirms payment systems breach

#13

Earlier quoted context omitted.

It is not clear to me why they would have your name, email address, and mailing information? For example, I recently purchased some items from home depot and used my debit card + pin, other than rolling the pin, what else should we be doing? Do you have a home depot CC?

home depot likes to collect email address for sending receipts (and spam). Along with that older style mag stripes will give out the name. Not sure about mailing info or how they'd get that. The thing to do is to actually get stores to stop storing CC info at all. they should be able to process the payment and then forget the info at all so it never has to be stored so it can't be stolen. EMV is actually a move to fo…

I've made a lot of Home Depot purchases in the last month (yay, new credit cards for me!), and I don't recall ever being asked for an email address either by a cashier or the self-check kiosk. Maybe it's just my local stores don't do it, though.

Re: The Home Depot confirms payment systems breach

#14
post #6

Earlier quoted context omitted.

PCI deadline for US retailers to implement chip + pin is October 2015. Mentioned in the Home Depot link above

When will banks actually start issuing chip + pin cards in the US? It doesn't help US consumers much if the retailers accept them, but the banks don't issue them. I have credit cards with four banks (probably the biggest 4 in the US, but I don't know exactly how they stack up). One is chip+signature, and the rest don't have chips at all. Including a brand new one I got from a huge bank less than a month ago.

After the EMV liability shift date (October 2015), the fraud liability for a card-present, non-EMV transaction falls on the party which was noncompliant, the issuer or the merchant. Hopefully this will be a significant driver of EMV adoption by both issuers and merchants.

Re: The Home Depot confirms payment systems breach

#15
post #6

Earlier quoted context omitted.

Is there actually a timetable for "chip and pin" in the US? I'm only aware of banks issuing chip + signature style EMV cards.

PCI deadline for US retailers to implement chip + pin is October 2015. Mentioned in the Home Depot link above

It's not clear if US is going to be Chip+Pin or Chip+Signature. This is going to add some confusion come next year.

Re: The Home Depot confirms payment systems breach

#16
post #12

Earlier quoted context omitted.

Many don't read the article and just start commenting.

In all fairness, SEC filings are a rather incomprehensible format to read, even one this short.

"Responding to the increasing threat of cyber-attacks on the retail industry, The Home Depot previously confirmed it will roll out EMV "Chip and PIN" to all U.S. stores by the end of this year, well in advance of the October 2015 deadline established by the payments industry."

Don't excuse laziness.

Re: The Home Depot confirms payment systems breach

#17
(1) Don't use debit cards. You're much better protected as a consumer when you use a credit card. http://www.bbb.org/blog/2013/11/do-debit-cards-and-credit-ca...

(2) Use BillGuard https://www.billguard.com/

(3) Review your transactions every week or so via a personal finance tool (I use https://www.mint.com/)

I don't particularly care if my payment credentials are compromised as it's highly unlikely a fraudulent charge would go unnoticed by me just using the advice above. It's quick, easy to set up, and stuff you really ought to be tracking anyway.

Re: The Home Depot confirms payment systems breach

#18
post #6

Earlier quoted context omitted.

PCI deadline for US retailers to implement chip + pin is October 2015. Mentioned in the Home Depot link above

When will banks actually start issuing chip + pin cards in the US? It doesn't help US consumers much if the retailers accept them, but the banks don't issue them. I have credit cards with four banks (probably the biggest 4 in the US, but I don't know exactly how they stack up). One is chip+signature, and the rest don't have chips at all. Including a brand new one I got from a huge bank less than a month ago.

Both cards that I recently received have a chip. One of them is a debit card so it already has a pin, and presumably at some point I'll at least have the option to get a pin for my credit card.

Re: The Home Depot confirms payment systems breach

#19
post #17

(1) Don't use debit cards. You're much better protected as a consumer when you use a credit card. http://www.bbb.org/blog/2013/11/do-debit-cards-and-credit-ca... (2) Use BillGuard https://www.billguard.com/ (3) Review your transactions every week or so via a personal finance tool (I use https://www.mint.com/ ) I don't particularly care if my payment credentials are compromised as it's highly unlikely a fraudulent cha…

Agreed on debit cards. Another way to vet charges is to use something that notifies your phone whenever you make a purchase. Simple bank does this, maybe others too.
Post reply on HN