> The Home Depot is offering free identity protection services, including credit monitoring, to any customer who used a payment card at a Home Depot store in 2014, from April on. This is absolutely not acceptable, and I deplore how this has become the status quo. I reject these services and want nothing less than a full lawsuit.
The Home Depot confirms payment systems breach
31–40 of 110 posts
Re: The Home Depot confirms payment systems breach
#32Earlier quoted context omitted.
When will banks actually start issuing chip + pin cards in the US? It doesn't help US consumers much if the retailers accept them, but the banks don't issue them. I have credit cards with four banks (probably the biggest 4 in the US, but I don't know exactly how they stack up). One is chip+signature, and the rest don't have chips at all. Including a brand new one I got from a huge bank less than a month ago.
Both cards that I recently received have a chip. One of them is a debit card so it already has a pin, and presumably at some point I'll at least have the option to get a pin for my credit card.
I'd love to be told I'm wrong, and that this can be made into a chip+pin card without physically swapping the card.
Re: The Home Depot confirms payment systems breach
#33(1) Don't use debit cards. You're much better protected as a consumer when you use a credit card. http://www.bbb.org/blog/2013/11/do-debit-cards-and-credit-ca... (2) Use BillGuard https://www.billguard.com/ (3) Review your transactions every week or so via a personal finance tool (I use https://www.mint.com/ ) I don't particularly care if my payment credentials are compromised as it's highly unlikely a fraudulent cha…
Or use cash and forget about all this other stuff ;)
Re: The Home Depot confirms payment systems breach
#34Earlier quoted context omitted.
Agreed on debit cards. Another way to vet charges is to use something that notifies your phone whenever you make a purchase. Simple bank does this, maybe others too.
Bump for Simple. Anytime an auth occurs, I get a push notification on my phone. Its so simple from a UX standpoint, not sure why other financial services firms (Discover, Amex, etc) don't push something like it out.
Re: The Home Depot confirms payment systems breach
#35encouraging that they are using this as a motivator to "roll out EMV "Chip and PIN" to all U.S. stores by the end of this year" ahead of the prescribed deadline. edit: "Chip and PIN" is taken directly from the sec filing that is linked. the described deadline of october 2015 for the liability shift comes from banks[1] and not a US law or similar. [1] http://en.wikipedia.org/wiki/EMV#United_States
I got into an argument about that with the guy at the Home Depot paint counter today. I blamed the hack on Home Depot probably running XP on their POS machines and he blamed the banks not doing something that they do in Europe, I'm assuming it's this EMV chip because it sounded like he was repeating something he was told.
Re: The Home Depot confirms payment systems breach
#36I wonder if this will be less of an issue here in Canada with our euro-style chip & PIN setup. In theory the attackers wouldn't have long-lived access to any of the payment information. I suppose we'll see. The attackers probably have my name/email address/mailing information, which kind of sucks.
It is not clear to me why they would have your name, email address, and mailing information? For example, I recently purchased some items from home depot and used my debit card + pin, other than rolling the pin, what else should we be doing? Do you have a home depot CC?
Re: The Home Depot confirms payment systems breach
#37> The Home Depot is offering free identity protection services, including credit monitoring, to any customer who used a payment card at a Home Depot store in 2014, from April on. This is absolutely not acceptable, and I deplore how this has become the status quo. I reject these services and want nothing less than a full lawsuit.
Re: The Home Depot confirms payment systems breach
#38Love the EMV plug, as if it'd actually have helped. EMV transmits the card information in the clear, it only makes physical copying of the cards harder (Which really doesn't matter since credit cards can be used online). The only thing EMV would achieve is making this data slightly less valuable, but still worth it for the attacker. Replacing the EMV cards would also be more expensive by an order of magnitude. tl;dr:…
Don't you need the printed CVV for that? Which isn't stored on either the magstripe nor the chip.
edit: 3DSecure would also help if banks cared to push it harder (for instance my bank now disallows all online debit card charges that don't use 3DSecure)
Re: The Home Depot confirms payment systems breach
#39Earlier quoted context omitted.
Both cards that I recently received have a chip. One of them is a debit card so it already has a pin, and presumably at some point I'll at least have the option to get a pin for my credit card.
My understanding (and it's entirely possible I'm mistaken) is that chip+pin and chip+signature cards are not interchangeable. In other words, I don't think you can just take a chip+signature card and "get a pin" for it. And the one card I've received with a chip (from Bank of America) is definitely chip+signature. I'd love to be told I'm wrong, and that this can be made into a chip+pin card without physically swappin…
Re: The Home Depot confirms payment systems breach
#40Love the EMV plug, as if it'd actually have helped. EMV transmits the card information in the clear, it only makes physical copying of the cards harder (Which really doesn't matter since credit cards can be used online). The only thing EMV would achieve is making this data slightly less valuable, but still worth it for the attacker. Replacing the EMV cards would also be more expensive by an order of magnitude. tl;dr:…
> Which really doesn't matter since credit cards can be used online Don't you need the printed CVV for that? Which isn't stored on either the magstripe nor the chip. edit: 3DSecure would also help if banks cared to push it harder (for instance my bank now disallows all online debit card charges that don't use 3DSecure)
Also, in many cases the chips actually contain enough information to replicate the magnetic stripe. (Which is well, bad.)