Live data from Hacker News

The Home Depot confirms payment systems breach

ir.homedepot.com

21–30 of 110 posts

Re: The Home Depot confirms payment systems breach

#21
Love the EMV plug, as if it'd actually have helped. EMV transmits the card information in the clear, it only makes physical copying of the cards harder (Which really doesn't matter since credit cards can be used online).

The only thing EMV would achieve is making this data slightly less valuable, but still worth it for the attacker. Replacing the EMV cards would also be more expensive by an order of magnitude.

tl;dr: if you use your EMV card on a compromised POS, you'll be as fucked as you'd be with a magstripe card. Your bank will be ten times as fucked.

Re: The Home Depot confirms payment systems breach

#22
post #17

(1) Don't use debit cards. You're much better protected as a consumer when you use a credit card. http://www.bbb.org/blog/2013/11/do-debit-cards-and-credit-ca... (2) Use BillGuard https://www.billguard.com/ (3) Review your transactions every week or so via a personal finance tool (I use https://www.mint.com/ ) I don't particularly care if my payment credentials are compromised as it's highly unlikely a fraudulent cha…

Agreed on debit cards. Another way to vet charges is to use something that notifies your phone whenever you make a purchase. Simple bank does this, maybe others too.

Bump for Simple. Anytime an auth occurs, I get a push notification on my phone. Its so simple from a UX standpoint, not sure why other financial services firms (Discover, Amex, etc) don't push something like it out.

Re: The Home Depot confirms payment systems breach

#23
post #2

I wonder if this will be less of an issue here in Canada with our euro-style chip & PIN setup. In theory the attackers wouldn't have long-lived access to any of the payment information. I suppose we'll see. The attackers probably have my name/email address/mailing information, which kind of sucks.

Chip&PIN is a red herring here, your data is just as compromised as it'd be with a magstripe card. EMV does not protect your card information.

Re: The Home Depot confirms payment systems breach

#24
post #15
post #6

Earlier quoted context omitted.

PCI deadline for US retailers to implement chip + pin is October 2015. Mentioned in the Home Depot link above

It's not clear if US is going to be Chip+Pin or Chip+Signature. This is going to add some confusion come next year.

When I enquired my bank about my EMV card, they informed it that it preferred Chip+Signature, but that it also supported online (aka "realtime") Chip+Pin authorization. It is not configured to support offline Chip+Pin like many european cards.

Re: The Home Depot confirms payment systems breach

#25
post #6

Earlier quoted context omitted.

PCI deadline for US retailers to implement chip + pin is October 2015. Mentioned in the Home Depot link above

When will banks actually start issuing chip + pin cards in the US? It doesn't help US consumers much if the retailers accept them, but the banks don't issue them. I have credit cards with four banks (probably the biggest 4 in the US, but I don't know exactly how they stack up). One is chip+signature, and the rest don't have chips at all. Including a brand new one I got from a huge bank less than a month ago.

I think I saw an option on the Bank of America website to get chip & pin, though they were advertising it as for use internationally.

Re: The Home Depot confirms payment systems breach

#26

Earlier quoted context omitted.

Agreed on debit cards. Another way to vet charges is to use something that notifies your phone whenever you make a purchase. Simple bank does this, maybe others too.

Bump for Simple. Anytime an auth occurs, I get a push notification on my phone. Its so simple from a UX standpoint, not sure why other financial services firms (Discover, Amex, etc) don't push something like it out.

The Amex app on iPhone sends push notifications for changes.

Re: The Home Depot confirms payment systems breach

#27
post #15
post #6

Earlier quoted context omitted.

PCI deadline for US retailers to implement chip + pin is October 2015. Mentioned in the Home Depot link above

It's not clear if US is going to be Chip+Pin or Chip+Signature. This is going to add some confusion come next year.

Most US banks are going for chip and signature.

I've received two new cards in the last month with a chip in them - both were chip and signature.

Re: The Home Depot confirms payment systems breach

#28
post #3

encouraging that they are using this as a motivator to "roll out EMV "Chip and PIN" to all U.S. stores by the end of this year" ahead of the prescribed deadline. edit: "Chip and PIN" is taken directly from the sec filing that is linked. the described deadline of october 2015 for the liability shift comes from banks[1] and not a US law or similar. [1] http://en.wikipedia.org/wiki/EMV#United_States

Would it actually have helped, though? I was under the impression that the Chip and PIN POS terminals don't do anything differently as far as the part between themselves and the authorizer goes - if somebody hacks one, they can still get everything they need to charge against the card. If so, it's more of an issue of firewalling properly at the individual store and corporate level.

Re: The Home Depot confirms payment systems breach

#29
post #17

(1) Don't use debit cards. You're much better protected as a consumer when you use a credit card. http://www.bbb.org/blog/2013/11/do-debit-cards-and-credit-ca... (2) Use BillGuard https://www.billguard.com/ (3) Review your transactions every week or so via a personal finance tool (I use https://www.mint.com/ ) I don't particularly care if my payment credentials are compromised as it's highly unlikely a fraudulent cha…

Or use cash and forget about all this other stuff ;)

Re: The Home Depot confirms payment systems breach

#30
> The Home Depot is offering free identity protection services, including credit monitoring, to any customer who used a payment card at a Home Depot store in 2014, from April on.

This is absolutely not acceptable, and I deplore how this has become the status quo. I reject these services and want nothing less than a full lawsuit.

Post reply on HN