Live data from Hacker News

The Home Depot confirms payment systems breach

ir.homedepot.com

61–70 of 110 posts

Re: The Home Depot confirms payment systems breach

#61
post #21

Love the EMV plug, as if it'd actually have helped. EMV transmits the card information in the clear, it only makes physical copying of the cards harder (Which really doesn't matter since credit cards can be used online). The only thing EMV would achieve is making this data slightly less valuable, but still worth it for the attacker. Replacing the EMV cards would also be more expensive by an order of magnitude. tl;dr:…

I think you are forgetting that EMV cards introduce the concept of digitally signing a transaction. That signature is then checked by the payment card processor and if it matches then the charge goes through. The signatures are performed by the chip on the card using a non-exportable certificate. This provides the "proof of presence" for the card and makes duplicating the EMV portion virtually impossible. This doesn'…

It's a step in the right direction, but the current implementations of EMV cards wouldn't have been of any help here.

Re: The Home Depot confirms payment systems breach

#62
post #52
post #48

Earlier quoted context omitted.

Card processors might have a case, but the customers really mostly wouldn't. The PAN that belongs to your credit card company that was assigned to you by your credit card company was compromised and someone tried to defraud your credit card company using it. Yet it's you complaining, why?

I've been screwed by identity theft before.

Sure, but the only real solution would be not accepting cards. Does that sound like a good solution to you?

Re: The Home Depot confirms payment systems breach

#63
post #60
post #50

Earlier quoted context omitted.

Do you have a source for this? I distinctly remember my Canadian credit card starting off as chip and signature and sometime later start asking me for my PIN.

http://www.cardhub.com/edu/chip-and-pin-vs-chip-and-signatur...

After a quick skim that article doesn't say they can't be remotely upgraded to ask for a PIN which is what happened to me.

Re: The Home Depot confirms payment systems breach

#64
post #17

(1) Don't use debit cards. You're much better protected as a consumer when you use a credit card. http://www.bbb.org/blog/2013/11/do-debit-cards-and-credit-ca... (2) Use BillGuard https://www.billguard.com/ (3) Review your transactions every week or so via a personal finance tool (I use https://www.mint.com/ ) I don't particularly care if my payment credentials are compromised as it's highly unlikely a fraudulent cha…

Or use cash and forget about all this other stuff ;)

But don't forget about it in your pocket and then do the laundry ...

Losing or having a credit card compromised is pretty low on my list of real hassles.

Re: The Home Depot confirms payment systems breach

#65
It seems to me like the breach may still be ongoing/the vulnerability may still exist. In the announcement, they use "have been" as in its actively occurring. Additionally, in the press release (http://ir.homedepot.com/phoenix.zhtml?c=63646&p=irol-newsArt...), they don't indicate that the breach has stopped; they only say they have taken aggressive action.

It seems unlikely that the attack would continue since the attackers have lost their cover, but the wording is a bit strange.

Re: The Home Depot confirms payment systems breach

#66
post #59

Earlier quoted context omitted.

Depends on where you shop, but some places will give you cash discounts of 3-5%, which is more than most CC rewards pay. Admittedly it's not as widespread.

Most merchant agreements forbid this, IIRC. Credit card companies have a vested interest in the goods being the same price whether cash or credit.

Not saying that's untrue, but when you think of it, it's pretty amazing that card companies can legally do this. Testament to the efficacy of K Street I suppose.

Re: The Home Depot confirms payment systems breach

#68
post #6

Earlier quoted context omitted.

PCI deadline for US retailers to implement chip + pin is October 2015. Mentioned in the Home Depot link above

Many don't read the article and just start commenting.

while I don't condone blind commenting like you described, I have encountered threads with titles such that they conveyed the entire article accurately enough to comment on from just the title alone, so I can understand that with certain topics.

Re: The Home Depot confirms payment systems breach

#69
post #35

Earlier quoted context omitted.

I got into an argument about that with the guy at the Home Depot paint counter today. I blamed the hack on Home Depot probably running XP on their POS machines and he blamed the banks not doing something that they do in Europe, I'm assuming it's this EMV chip because it sounded like he was repeating something he was told.

Why on earth would you argue this issue with the guy at the paint counter? He clearly has nothing to do with either the cause or any remedy they might decide to offer.

No kidding. Until now, I'd have been hard-pressed to imagine any sentence that started with "I got into an argument with the guy at the Home Depot paint counter", but didn't end with "because my paint color didn't match".

Re: The Home Depot confirms payment systems breach

#70
post #35

Earlier quoted context omitted.

I got into an argument about that with the guy at the Home Depot paint counter today. I blamed the hack on Home Depot probably running XP on their POS machines and he blamed the banks not doing something that they do in Europe, I'm assuming it's this EMV chip because it sounded like he was repeating something he was told.

Why on earth would you argue this issue with the guy at the paint counter? He clearly has nothing to do with either the cause or any remedy they might decide to offer.

All the computers for the paint mixing machines in every Home Depot were screwed up today, which brought up the topic of the hack and he got excited when I suggested it was probably outdated software on the point of sales machines that was to blame.

The interesting part to me was it sounded like the managers explained to them that it was all the bank's fault. Not that Home Depot was too cheap and lazy to update their software. And ya got to talk about something while the paint's shakin

Post reply on HN