Love the EMV plug, as if it'd actually have helped. EMV transmits the card information in the clear, it only makes physical copying of the cards harder (Which really doesn't matter since credit cards can be used online). The only thing EMV would achieve is making this data slightly less valuable, but still worth it for the attacker. Replacing the EMV cards would also be more expensive by an order of magnitude. tl;dr:…
The Home Depot confirms payment systems breach
51–60 of 110 posts
Re: The Home Depot confirms payment systems breach
#52Earlier quoted context omitted.
I'm pretty sure the card processors would be on my side of the lawsuit, along with a few million other home depot customers. I don't care about damages to me. I want the problem fixed. This Laissez-faire attitude towards online commerce security needs to end. Standards like PCI and PA-DSS are not enough. Corporations need to be liable for leaking everyone's information. A year of free credit monitoring is a slap in t…
Card processors might have a case, but the customers really mostly wouldn't. The PAN that belongs to your credit card company that was assigned to you by your credit card company was compromised and someone tried to defraud your credit card company using it. Yet it's you complaining, why?
Re: The Home Depot confirms payment systems breach
#53I wonder if this will be less of an issue here in Canada with our euro-style chip & PIN setup. In theory the attackers wouldn't have long-lived access to any of the payment information. I suppose we'll see. The attackers probably have my name/email address/mailing information, which kind of sucks.
Chip&PIN is a red herring here, your data is just as compromised as it'd be with a magstripe card. EMV does not protect your card information.
Banks are switching to the EMV system because they can place the liability on the merchant if a fraudulent transaction is performed through them when they could have required an EMV transaction (thereby preventing the fraud).
Re: The Home Depot confirms payment systems breach
#54Earlier quoted context omitted.
Or use cash and forget about all this other stuff ;)
Except I really like the free trips I get every year from accumulating travel reward points. Not to mention in my experience (personal and through acquaintances) Visa refunds fraudulent transactions immediately and with little to no hassle.
Re: The Home Depot confirms payment systems breach
#55Earlier quoted context omitted.
A lawsuit which you would lose. Especially considering you most likely suffered no damages.
I'm pretty sure the card processors would be on my side of the lawsuit, along with a few million other home depot customers. I don't care about damages to me. I want the problem fixed. This Laissez-faire attitude towards online commerce security needs to end. Standards like PCI and PA-DSS are not enough. Corporations need to be liable for leaking everyone's information. A year of free credit monitoring is a slap in t…
Possibly having your data leaked isn't enough of a harm for the courts to hear the lawsuit. If you can force a company to respond to a lawsuit based on the potential that they lost your data, what stops larger companies from suing smaller competitors constantly forcing them to prove they haven't leaked any data? They always could have leaked data.
Re: The Home Depot confirms payment systems breach
#56Earlier quoted context omitted.
Would it actually have helped, though? I was under the impression that the Chip and PIN POS terminals don't do anything differently as far as the part between themselves and the authorizer goes - if somebody hacks one, they can still get everything they need to charge against the card. If so, it's more of an issue of firewalling properly at the individual store and corporate level.
Your impression is incorrect. Current EMV cards do something called DDA, so charging the card (as a card-present transaction) requires the card to be physically present or you to have cloned the application off the card (which the card is designed to prevent you from doing.) You can still get the magstripe data if you compromise the terminal, but the network will (eventually) reject magstripe transactions made by a c…
Re: The Home Depot confirms payment systems breach
#57Love the EMV plug, as if it'd actually have helped. EMV transmits the card information in the clear, it only makes physical copying of the cards harder (Which really doesn't matter since credit cards can be used online). The only thing EMV would achieve is making this data slightly less valuable, but still worth it for the attacker. Replacing the EMV cards would also be more expensive by an order of magnitude. tl;dr:…
Re: The Home Depot confirms payment systems breach
#58Earlier quoted context omitted.
Chip&PIN is a red herring here, your data is just as compromised as it'd be with a magstripe card. EMV does not protect your card information.
It doesn't protect the information but it does protect a user from the re-use of the information because the physical card is needed to perform an EMV transaction. Banks are switching to the EMV system because they can place the liability on the merchant if a fraudulent transaction is performed through them when they could have required an EMV transaction (thereby preventing the fraud).
Re: The Home Depot confirms payment systems breach
#59Earlier quoted context omitted.
Except I really like the free trips I get every year from accumulating travel reward points. Not to mention in my experience (personal and through acquaintances) Visa refunds fraudulent transactions immediately and with little to no hassle.
Depends on where you shop, but some places will give you cash discounts of 3-5%, which is more than most CC rewards pay. Admittedly it's not as widespread.
Re: The Home Depot confirms payment systems breach
#60Earlier quoted context omitted.
I had no idea that it wasn't possible to get a pin, but now having done some research it looks like I was wrong. I wonder if it has something to do with them using the existing pin infrastructure for ATM cash advances.
Do you have a source for this? I distinctly remember my Canadian credit card starting off as chip and signature and sometime later start asking me for my PIN.