Live data from Hacker News

The Home Depot confirms payment systems breach

ir.homedepot.com

31–40 of 110 posts

Re: The Home Depot confirms payment systems breach

#31
post #30

> The Home Depot is offering free identity protection services, including credit monitoring, to any customer who used a payment card at a Home Depot store in 2014, from April on. This is absolutely not acceptable, and I deplore how this has become the status quo. I reject these services and want nothing less than a full lawsuit.

A lawsuit which you would lose. Especially considering you most likely suffered no damages.

Re: The Home Depot confirms payment systems breach

#32
post #18

Earlier quoted context omitted.

When will banks actually start issuing chip + pin cards in the US? It doesn't help US consumers much if the retailers accept them, but the banks don't issue them. I have credit cards with four banks (probably the biggest 4 in the US, but I don't know exactly how they stack up). One is chip+signature, and the rest don't have chips at all. Including a brand new one I got from a huge bank less than a month ago.

Both cards that I recently received have a chip. One of them is a debit card so it already has a pin, and presumably at some point I'll at least have the option to get a pin for my credit card.

My understanding (and it's entirely possible I'm mistaken) is that chip+pin and chip+signature cards are not interchangeable. In other words, I don't think you can just take a chip+signature card and "get a pin" for it. And the one card I've received with a chip (from Bank of America) is definitely chip+signature.

I'd love to be told I'm wrong, and that this can be made into a chip+pin card without physically swapping the card.

Re: The Home Depot confirms payment systems breach

#33
post #17

(1) Don't use debit cards. You're much better protected as a consumer when you use a credit card. http://www.bbb.org/blog/2013/11/do-debit-cards-and-credit-ca... (2) Use BillGuard https://www.billguard.com/ (3) Review your transactions every week or so via a personal finance tool (I use https://www.mint.com/ ) I don't particularly care if my payment credentials are compromised as it's highly unlikely a fraudulent cha…

Or use cash and forget about all this other stuff ;)

Oh the irony of how using cash is safer these days. You expose yourself to an internet full of thieves using plastic, but with cash it's only to the handful of people you actually cross paths with.

Re: The Home Depot confirms payment systems breach

#34

Earlier quoted context omitted.

Agreed on debit cards. Another way to vet charges is to use something that notifies your phone whenever you make a purchase. Simple bank does this, maybe others too.

Bump for Simple. Anytime an auth occurs, I get a push notification on my phone. Its so simple from a UX standpoint, not sure why other financial services firms (Discover, Amex, etc) don't push something like it out.

I can confirm that Amex has this. If you login on the website, you can also get emails / text for each transaction, set thresholds, etc. I've been using this feature for a while now. They also send you weekly statements on your transactions and how much your account has changed from the previous week, etc.

Re: The Home Depot confirms payment systems breach

#35
post #3

encouraging that they are using this as a motivator to "roll out EMV "Chip and PIN" to all U.S. stores by the end of this year" ahead of the prescribed deadline. edit: "Chip and PIN" is taken directly from the sec filing that is linked. the described deadline of october 2015 for the liability shift comes from banks[1] and not a US law or similar. [1] http://en.wikipedia.org/wiki/EMV#United_States

I got into an argument about that with the guy at the Home Depot paint counter today. I blamed the hack on Home Depot probably running XP on their POS machines and he blamed the banks not doing something that they do in Europe, I'm assuming it's this EMV chip because it sounded like he was repeating something he was told.

Why on earth would you argue this issue with the guy at the paint counter? He clearly has nothing to do with either the cause or any remedy they might decide to offer.

Re: The Home Depot confirms payment systems breach

#36
post #2

I wonder if this will be less of an issue here in Canada with our euro-style chip & PIN setup. In theory the attackers wouldn't have long-lived access to any of the payment information. I suppose we'll see. The attackers probably have my name/email address/mailing information, which kind of sucks.

It is not clear to me why they would have your name, email address, and mailing information? For example, I recently purchased some items from home depot and used my debit card + pin, other than rolling the pin, what else should we be doing? Do you have a home depot CC?

A lot of people make online purchases and pick up in store. When you make a return, you have to supply them a drivers license and that goes into the system as well. I'm wondering how much of this information was compromised. They use a third party company called Retail Equation for tracking returns. This company basically makes a profile / tracks your return patterns.

Re: The Home Depot confirms payment systems breach

#37
post #30

> The Home Depot is offering free identity protection services, including credit monitoring, to any customer who used a payment card at a Home Depot store in 2014, from April on. This is absolutely not acceptable, and I deplore how this has become the status quo. I reject these services and want nothing less than a full lawsuit.

I wonder if I can add this year of identity protection services on to the year I got from the Target breach not to long ago. At the rate these companies are losing my credit card number I'll have free identity theft protection services for life!

Re: The Home Depot confirms payment systems breach

#38
post #21

Love the EMV plug, as if it'd actually have helped. EMV transmits the card information in the clear, it only makes physical copying of the cards harder (Which really doesn't matter since credit cards can be used online). The only thing EMV would achieve is making this data slightly less valuable, but still worth it for the attacker. Replacing the EMV cards would also be more expensive by an order of magnitude. tl;dr:…

> Which really doesn't matter since credit cards can be used online

Don't you need the printed CVV for that? Which isn't stored on either the magstripe nor the chip.

edit: 3DSecure would also help if banks cared to push it harder (for instance my bank now disallows all online debit card charges that don't use 3DSecure)

Re: The Home Depot confirms payment systems breach

#39
post #18

Earlier quoted context omitted.

Both cards that I recently received have a chip. One of them is a debit card so it already has a pin, and presumably at some point I'll at least have the option to get a pin for my credit card.

My understanding (and it's entirely possible I'm mistaken) is that chip+pin and chip+signature cards are not interchangeable. In other words, I don't think you can just take a chip+signature card and "get a pin" for it. And the one card I've received with a chip (from Bank of America) is definitely chip+signature. I'd love to be told I'm wrong, and that this can be made into a chip+pin card without physically swappin…

I had no idea that it wasn't possible to get a pin, but now having done some research it looks like I was wrong. I wonder if it has something to do with them using the existing pin infrastructure for ATM cash advances.

Re: The Home Depot confirms payment systems breach

#40
post #21

Love the EMV plug, as if it'd actually have helped. EMV transmits the card information in the clear, it only makes physical copying of the cards harder (Which really doesn't matter since credit cards can be used online). The only thing EMV would achieve is making this data slightly less valuable, but still worth it for the attacker. Replacing the EMV cards would also be more expensive by an order of magnitude. tl;dr:…

> Which really doesn't matter since credit cards can be used online Don't you need the printed CVV for that? Which isn't stored on either the magstripe nor the chip. edit: 3DSecure would also help if banks cared to push it harder (for instance my bank now disallows all online debit card charges that don't use 3DSecure)

No, you really don't need the printed CVV for that. And several cards have actually had the CVV on the chip.

Also, in many cases the chips actually contain enough information to replicate the magnetic stripe. (Which is well, bad.)

Post reply on HN