Live data from Hacker News

The Home Depot confirms payment systems breach

ir.homedepot.com

101–110 of 110 posts

Re: The Home Depot confirms payment systems breach

#101
post #21

Love the EMV plug, as if it'd actually have helped. EMV transmits the card information in the clear, it only makes physical copying of the cards harder (Which really doesn't matter since credit cards can be used online). The only thing EMV would achieve is making this data slightly less valuable, but still worth it for the attacker. Replacing the EMV cards would also be more expensive by an order of magnitude. tl;dr:…

EMV isn't about securing information, it's about customer/card validation - validating that the person using the card is who they say they are. Therefore you are secure from fraud - as you said, cards are hard to reproduce.

You still need the CVV code to use the card number in a card not present transaction. So not to your point, it is rather secure...

EMV would have helped immensely here, especially considering EMV compliant machines are held to PCI standards as well.

Re: The Home Depot confirms payment systems breach

#102
post #61

Earlier quoted context omitted.

I think you are forgetting that EMV cards introduce the concept of digitally signing a transaction. That signature is then checked by the payment card processor and if it matches then the charge goes through. The signatures are performed by the chip on the card using a non-exportable certificate. This provides the "proof of presence" for the card and makes duplicating the EMV portion virtually impossible. This doesn'…

It's a step in the right direction, but the current implementations of EMV cards wouldn't have been of any help here.

EMV terminal certification must meet certain PCI standards for one thing. Not sure it would apply in this scenario, it does mention canadian cards affected, but I'm not sure if that's because it was on american machines.

Secondly, if EMV was adopted in the USA, the stolen information would become useless because they wouldn't be able to use the data to produce fraudulent cards.

Re: The Home Depot confirms payment systems breach

#103
post #40

Earlier quoted context omitted.

> Which really doesn't matter since credit cards can be used online Don't you need the printed CVV for that? Which isn't stored on either the magstripe nor the chip. edit: 3DSecure would also help if banks cared to push it harder (for instance my bank now disallows all online debit card charges that don't use 3DSecure)

No, you really don't need the printed CVV for that. And several cards have actually had the CVV on the chip. Also, in many cases the chips actually contain enough information to replicate the magnetic stripe. (Which is well, bad.)

CVV2/CVC2 (visa/mastercard) generation on the back of the card is COMPLETELY different than the CVV on the chip.

http://en.wikipedia.org/wiki/Card_security_code Skip down to Types of Codes

Re: The Home Depot confirms payment systems breach

#104
post #72
post #40

Earlier quoted context omitted.

No, you really don't need the printed CVV for that. And several cards have actually had the CVV on the chip. Also, in many cases the chips actually contain enough information to replicate the magnetic stripe. (Which is well, bad.)

EMV tag 57 [1] generally contains the "Track 2 Equivalent Data", and 5A the account number (PAN) [2] [1] http://www.emvlab.org/emvtags/show/t57/ [2] http://www.emvlab.org/emvtags/show/t5a/

That's not the same CVV.

Edit: Even having the track 2 data won't do you any good in reproducing an EMV card. The only way reproducing a mag stripe EMV card is useful, is if it is used at a non-EMV terminal and mag stripe is the only option.

I believe Europe has complete banished mag stripe now.

Re: The Home Depot confirms payment systems breach

#105
post #21

Love the EMV plug, as if it'd actually have helped. EMV transmits the card information in the clear, it only makes physical copying of the cards harder (Which really doesn't matter since credit cards can be used online). The only thing EMV would achieve is making this data slightly less valuable, but still worth it for the attacker. Replacing the EMV cards would also be more expensive by an order of magnitude. tl;dr:…

> Which really doesn't matter since credit cards can be used online Don't you need the printed CVV for that? Which isn't stored on either the magstripe nor the chip. edit: 3DSecure would also help if banks cared to push it harder (for instance my bank now disallows all online debit card charges that don't use 3DSecure)

Yes, you need the CVV printed on the back of the credit card to make an online purchase.

And the CVV on the back, is different than the CVV stored on the magstripe/chip.

Re: The Home Depot confirms payment systems breach

#106
post #58

Earlier quoted context omitted.

It doesn't protect the information but it does protect a user from the re-use of the information because the physical card is needed to perform an EMV transaction. Banks are switching to the EMV system because they can place the liability on the merchant if a fraudulent transaction is performed through them when they could have required an EMV transaction (thereby preventing the fraud).

Except that information can be used online...

Except they don't have the CVV, so, no...no it can't.

Re: The Home Depot confirms payment systems breach

#107
post #42
post #28

Earlier quoted context omitted.

Would it actually have helped, though? I was under the impression that the Chip and PIN POS terminals don't do anything differently as far as the part between themselves and the authorizer goes - if somebody hacks one, they can still get everything they need to charge against the card. If so, it's more of an issue of firewalling properly at the individual store and corporate level.

Your impression is incorrect. Current EMV cards do something called DDA, so charging the card (as a card-present transaction) requires the card to be physically present or you to have cloned the application off the card (which the card is designed to prevent you from doing.) You can still get the magstripe data if you compromise the terminal, but the network will (eventually) reject magstripe transactions made by a c…

You're supposed to say CDA now - combined data authentication.

Re: The Home Depot confirms payment systems breach

#108
post #15

Earlier quoted context omitted.

It's not clear if US is going to be Chip+Pin or Chip+Signature. This is going to add some confusion come next year.

When I enquired my bank about my EMV card, they informed it that it preferred Chip+Signature, but that it also supported online (aka "realtime") Chip+Pin authorization. It is not configured to support offline Chip+Pin like many european cards.

PIN verification is performed against the chip first, not online. Although Chip+Signature is possible, it really doesn't make sense.

Edit: Chip cards provide a Cardholder Verification Method List (CVML) to the terminal. The terminal then decides what method it'd like to use. Options are PIN online, PIN offline plain text, PIN offline enciphered, Signature, or No Authentication.

Re: The Home Depot confirms payment systems breach

#109
post #30

> The Home Depot is offering free identity protection services, including credit monitoring, to any customer who used a payment card at a Home Depot store in 2014, from April on. This is absolutely not acceptable, and I deplore how this has become the status quo. I reject these services and want nothing less than a full lawsuit.

Typically the financial institute is responsible for any fraudulent charges on their customers' credit cards. The cardholders of the affected cards would probably have a hard time justifying that they were negatively affected by the breach.

Re: The Home Depot confirms payment systems breach

#110

Earlier quoted context omitted.

Billguard asks for my online bank username and password, it's a deal breaker for me. Do you really trust them? https://medium.com/@hyphenated/mint-com-and-billguard-are-ly...

Billguard uses Yodlee as a backend, so at the very least I do trust that Billguard only has read-only access. I'm less certain how Yodlee functions -- whether they just scrape data and have full access, or whether they get some sort of read-only token from the financial institution.

BillGuard indeed has only access to data in a read-only fashion. Yodlee does have a mix of web scrappers as well as data feeds for certain financial institutions. They power different features for banks such as bill payment and others but companies like BillGuard don't have access to these APIs.

On its end, Yodlee is heavily regulated. Like a bank and sometimes even more: http://www.yodlee.com/yodlee-security/

Post reply on HN