Live data from Hacker News

The Home Depot confirms payment systems breach

ir.homedepot.com

71–80 of 110 posts

Re: The Home Depot confirms payment systems breach

#71

Earlier quoted context omitted.

Bump for Simple. Anytime an auth occurs, I get a push notification on my phone. Its so simple from a UX standpoint, not sure why other financial services firms (Discover, Amex, etc) don't push something like it out.

The Amex app on iPhone sends push notifications for changes.

Chase also supports this via SMS, email, or push notification.

Re: The Home Depot confirms payment systems breach

#72
post #40

Earlier quoted context omitted.

> Which really doesn't matter since credit cards can be used online Don't you need the printed CVV for that? Which isn't stored on either the magstripe nor the chip. edit: 3DSecure would also help if banks cared to push it harder (for instance my bank now disallows all online debit card charges that don't use 3DSecure)

No, you really don't need the printed CVV for that. And several cards have actually had the CVV on the chip. Also, in many cases the chips actually contain enough information to replicate the magnetic stripe. (Which is well, bad.)

EMV tag 57 [1] generally contains the "Track 2 Equivalent Data", and 5A the account number (PAN) [2]

[1] http://www.emvlab.org/emvtags/show/t57/ [2] http://www.emvlab.org/emvtags/show/t5a/

Re: The Home Depot confirms payment systems breach

#73
post #59

Earlier quoted context omitted.

Most merchant agreements forbid this, IIRC. Credit card companies have a vested interest in the goods being the same price whether cash or credit.

Not saying that's untrue, but when you think of it, it's pretty amazing that card companies can legally do this. Testament to the efficacy of K Street I suppose.

From what I remember, you can charge a single flat fee for using a credit card, but no percentages. At the time, I thought that 'sliding scale' flat fees (e.g. $100 is $1.50) were too close to percentages per the agreement.

Re: The Home Depot confirms payment systems breach

#74
post #59

Earlier quoted context omitted.

Depends on where you shop, but some places will give you cash discounts of 3-5%, which is more than most CC rewards pay. Admittedly it's not as widespread.

Most merchant agreements forbid this, IIRC. Credit card companies have a vested interest in the goods being the same price whether cash or credit.

It was more complicated, I believe. The marked and advertised price had to be what credit card users would pay, but they could have a cash discount at the register or checkout.

Starting in early 2013, as a result of a settlement of a class action by merchants, they no longer have to charge credit card users the advertised and marked price. They can advertise and mark the cash price, and charge a credit card surcharge of up 4% or the processing fees for that transaction (whichever is smaller).

Some states have laws that limit surcharging. There is a list in this Visa article about the post settlement rules: http://usa.visa.com/personal/get-help/checkout-fees.jsp

Re: The Home Depot confirms payment systems breach

#75

It seems to me like the breach may still be ongoing/the vulnerability may still exist. In the announcement, they use "have been" as in its actively occurring. Additionally, in the press release ( http://ir.homedepot.com/phoenix.zhtml?c=63646&p=irol-newsArt... ), they don't indicate that the breach has stopped; they only say they have taken aggressive action. It seems unlikely that the attack would continue since the…

I also found it strange how they worded things around the identity protection, "from April on", rather than something like, "From April XX, 2014 until September XX, 2014". Perhaps they just simplified the wording to make it clear that they're providing protection, and I'm reading too far into things :)

Re: The Home Depot confirms payment systems breach

#76
post #17

(1) Don't use debit cards. You're much better protected as a consumer when you use a credit card. http://www.bbb.org/blog/2013/11/do-debit-cards-and-credit-ca... (2) Use BillGuard https://www.billguard.com/ (3) Review your transactions every week or so via a personal finance tool (I use https://www.mint.com/ ) I don't particularly care if my payment credentials are compromised as it's highly unlikely a fraudulent cha…

Or use cash and forget about all this other stuff ;)

Unless your job pays you in cold hard cash, you have to go to the ATM. And you expose yourself to getting mugged, or have a the debit card skimmed. You could physically walk into the bank and get whatever-you-spend-per-month-in-stores in cash. So that might be an approach. But now you have to carry a fat wallet with you and manages lots of pocket change. Also not purchase much online.

Re: The Home Depot confirms payment systems breach

#77

Earlier quoted context omitted.

It is not clear to me why they would have your name, email address, and mailing information? For example, I recently purchased some items from home depot and used my debit card + pin, other than rolling the pin, what else should we be doing? Do you have a home depot CC?

I don't have a Home Depot CC, but I've used their e-receipts in the last couple of months and I'm reasonably sure that I've ordered online from them in the past. I certainly hope they didn't compromise the PIN pads in the stores. That could be a Very Bad Thing.

From what I've read so far, this was another case of memory scraping malware[1], most likely running on each POS. The pinpads typically have tamper protection, though I wouldn't completely discount the possibility that we'll see malware at the pinpad level at some point in the future.

[1] http://krebsonsecurity.com/2014/09/home-depot-hit-by-same-ma...

Re: The Home Depot confirms payment systems breach

#78
post #17

(1) Don't use debit cards. You're much better protected as a consumer when you use a credit card. http://www.bbb.org/blog/2013/11/do-debit-cards-and-credit-ca... (2) Use BillGuard https://www.billguard.com/ (3) Review your transactions every week or so via a personal finance tool (I use https://www.mint.com/ ) I don't particularly care if my payment credentials are compromised as it's highly unlikely a fraudulent cha…

Or use cash and forget about all this other stuff ;)

Or understand that your card most likely has a zero fraud liability policy, meaning that if it gets stolen, the fraudulent charges simply go away.

If you use cash and it gets stolen, your money is just gone.

Re: The Home Depot confirms payment systems breach

#79
post #33

Earlier quoted context omitted.

Or use cash and forget about all this other stuff ;)

Oh the irony of how using cash is safer these days. You expose yourself to an internet full of thieves using plastic, but with cash it's only to the handful of people you actually cross paths with.

It's safer than Bitcoin, but still many times less safe than any sane credit card with a no fraud liability policy.

Re: The Home Depot confirms payment systems breach

#80
post #17

(1) Don't use debit cards. You're much better protected as a consumer when you use a credit card. http://www.bbb.org/blog/2013/11/do-debit-cards-and-credit-ca... (2) Use BillGuard https://www.billguard.com/ (3) Review your transactions every week or so via a personal finance tool (I use https://www.mint.com/ ) I don't particularly care if my payment credentials are compromised as it's highly unlikely a fraudulent cha…

Billguard asks for my online bank username and password, it's a deal breaker for me. Do you really trust them? https://medium.com/@hyphenated/mint-com-and-billguard-are-ly...
Post reply on HN