Live data from Hacker News

Postbank to replace 12M bank cards after employees steal 'master key'

timeslive.co.za

151–160 of 194 posts

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#151
post #148

Earlier quoted context omitted.

That's a funny hack. However, this looks like conflicting advice: "Only the passenger should retain the key or combination to the lock unless TSA personnel request the key to open the firearm container to ensure compliance with TSA regulations. You may use any brand or type of lock to secure your firearm case, including TSA-recognized locks." If you use a TSA lock, that means they have a key to open up the case and a…

> If you use a TSA lock, that means they have a key to open up the case and access the firearm without you around. That's a big no-no and could result in problems with the law. Why? If a TSA person unlocks it in accordance with their procedures, surely that's fine (and is what they would do anyway, just getting the key from you first)? If a TSA person abuses their position to open your luggage with their master key a…

The problem is not access to the luggage. The problem is access to the firearm. That is why when you are transporting a firearm TSA does not retain the ability to access the firearm outside of your supervision.

TSA's procedures are as robust as a high school recital of A Midsummer Night’s Dream. The TSA knows this and so when it matters (like when firearms are involved) the rules change.

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#152
post #88

Earlier quoted context omitted.

Simply put: putting anything you can't replace into checked luggage is foolish. The TSA is a lot more likely to steal your stuff than some random person with a printed key. Plus, if you use a real lock, they have the right to clip it off, which is trivial. Don't put stuff of value into checked luggage. Keep it on your person or ship it via a carrier who has insurance.

> Plus, if you use a real lock, they have the right to clip it off, which is trivial. Life hack: you can pack a stripped AR lower, and it's legally a firearm. You must use a non-TSA lock, and the TSA (nominally) is not allowed to open it. Though your core point is valid: your nylon luggage isn't going to keep anyone determined out.

I did not understand, what is a "stripped AR lower"?

And why is TSA not allowed to open it?

Edit: I guess AR is Assault Rifle?

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#153
post #125

Earlier quoted context omitted.

There isn't anything to really "steal", a contactless card is willing to participate in transactions but "I am standing next to you" isn't a transaction on its own. You need to do a relay attack. Here's how that goes: 1. Jenny's payment card is in her jacket pocket. 2. Charlie walks into a store wearing a small NFC-capable computer and a medium distance radio (a cell phone might do) perhaps concealed inside his cloth…

What about mobile payment terminals (where I live, they're very common)? Instead of virtually moving the card to the store through a relay attack, move the store to the card through one of the spare payment terminals (many stores have several as a backup for when the POS or the network is down, or for deliveries) hidden in the clothing. Of course, this changes the threat model a bit, since it now needs collusion from…

Let's suppose that you take a mobile payment terminal, get on the train, and make ten $10 charges (you can't do large transactions contactless) through clothing of some people. What does that mean?

First, it does not mean that you're getting any money. Such a charge is effectively "sending an invoice" to the issuing bank from the store which is supposed to have that terminal, and they will pay your merchant bank, which will give money to the institution who got issued that terminal. There's no way for the store clerk personally or someone else to get to these funds.

Second, the money is not coming today. You get an authorization message, but you'll receive the actual money later.. if ever. If the payment is disputed, you won't get that money. If it's disputed a month later, they'll take that money back from you. If many of your payments are disputed, then all your incoming funds will be frozen until they verify if all of them should be returned. If multiple payments are disputed, then the standard methods of tracing 'common point of purchase' will reveal the particular terminal as the culprit. Also, malicious merchants is a known threat, so the merchant bank will ensure that you can't just spam a day's worth of fraudulent purchases and run - standard terms will expect that some amount of money is frozen (e.g. rolling 15 days worth of transactions) so if you suddenly get a bunch of chargebacks, the customers will be paid back in full. Fake stores and shell companies are a thing, but there are reasonably effective measures to try and prevent that.

So there's no threat through collusion from a store employee - the fraudsters would get identified and would not get any money at all; and there's limited threat from collusion with a whole merchant - the fraudsters would get identified and can't get any meaningful amount of money. Extracting a couple hundred dollars could probably work - but you're "burning" the identities of multiple people and a company; the bank will 'eat' that loss if you succeed, but you can't repeat this trick.

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#154
post #5

>The breach resulted from the printing of the bank's encrypted master key in plain, unencrypted digital language at the Postbank's old data centre in the Pretoria city centre I can't read anymore. Is there anymore technical explanation? Was it actually 'printed' ... on paper? Was it even an actual encryption key or just a password or something?

Isn't paper actually one of the more secure storage mediums? If you asked me the best way to store a secret I'd say put it on paper and lock it in a safe. I'd probably do something like print a QR code with an encrypted secret and store the key on a separate printed QR code.

Paper in this context is a form of cold storage, you could get very similar results encoding the information on magnetic tape or on a hard drive stored in a safe. Cold storage turns the information security problem into a physical security problem. The catch comes when you need to use this information regularly, say to issue bank cards. Now you need protocols for regularly circumventing that physical security and correctly using/distributing the information, making it in essence an information security problem again.

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#155
post #151
post #148

Earlier quoted context omitted.

> If you use a TSA lock, that means they have a key to open up the case and access the firearm without you around. That's a big no-no and could result in problems with the law. Why? If a TSA person unlocks it in accordance with their procedures, surely that's fine (and is what they would do anyway, just getting the key from you first)? If a TSA person abuses their position to open your luggage with their master key a…

The problem is not access to the luggage. The problem is access to the firearm . That is why when you are transporting a firearm TSA does not retain the ability to access the firearm outside of your supervision. TSA's procedures are as robust as a high school recital of A Midsummer Night’s Dream. The TSA knows this and so when it matters (like when firearms are involved) the rules change.

Most locks have master keys and most find their way into the hands of sufficiently motivated criminals, right? Is there any lock you could put on your firearm case for which there wouldn't be authorised people who had the master key to it?

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#156
post #150

Earlier quoted context omitted.

It helps having one debit card system to support. The US has like 7 and I couldn't begin to name most of them (Interlink is one of them, I think Maestro is another)

I don't really buy that though. The banks may have an easy time talking to other Canadian banks but they also need to talk with American banks and Canadian PoS terminals often support US debit cards. Perhaps Euro PoS terminals just refuse to work with US debit cards but Canada gets a lot of those American tourist dollars and doesn't want to make it hard for you to spend your money up here.

> Canadian PoS terminals often support US debit cards.

Unless something changed in the past few years, this is not the case. US debit cards are accepted through Visa or Mastercard's payment network which doesn't require a PIN (this is what it means when you process as credit in the US). Those transactions do not use the debit payment network. https://en.wikipedia.org/wiki/Interlink_(interbank_network).

EDIT: I will add that while POS systems don't have a way to do this up there, ATM's with their notoriously high fees do support cash access through a US debit card.

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#157
post #5

>The breach resulted from the printing of the bank's encrypted master key in plain, unencrypted digital language at the Postbank's old data centre in the Pretoria city centre I can't read anymore. Is there anymore technical explanation? Was it actually 'printed' ... on paper? Was it even an actual encryption key or just a password or something?

Isn't paper actually one of the more secure storage mediums? If you asked me the best way to store a secret I'd say put it on paper and lock it in a safe. I'd probably do something like print a QR code with an encrypted secret and store the key on a separate printed QR code.

It depends on what kinds of attacks you're worried about. One of the challenges with paper is that someone can take a photograph of the data and steal it without the physical secret ever leaving trusted hands.

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#158
Postbank is a subsidiary of South Africa's Post Office.

An entity that is bankrupt and barely functional despite having a state mandated monopoly on an entire country's postal system.

As per article they're also running the SASSA social grant system which is a train wreck in itself and has been buried in legal disputes for years (not random small cases...a challenge to the legitimacy of their core mandate on grants).

Someone walking out the door with printed encryption keys sounds about right.

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#159

Earlier quoted context omitted.

> Plus, if you use a real lock, they have the right to clip it off, which is trivial. Life hack: you can pack a stripped AR lower, and it's legally a firearm. You must use a non-TSA lock, and the TSA (nominally) is not allowed to open it. Though your core point is valid: your nylon luggage isn't going to keep anyone determined out.

I did not understand, what is a "stripped AR lower"? And why is TSA not allowed to open it? Edit: I guess AR is Assault Rifle?

In the US (not sure about your location or the laws in other countries), the part of an AR-15 that qualifies as the "firearm" in the eyes of the law is the lower receiver. It's a machined block of metal and does not do anything on its own.

When transporting a firearm through air travel, it's supposed to be locked such that only the owner can open it. So you can claim you're carrying a firearm with nothing but a small-ish piece of metal in your luggage.

For illustration: https://i.imgur.com/ARZgZV6.png. The non-transparent part is the lower receiver.

As an aside, the "AR" in AR-15 stands for Armalite Rifle (after the company that originally designed it); not "assault rifle".

Re: Postbank to replace 12M bank cards after employees steal 'master key'

#160
post #158

Postbank is a subsidiary of South Africa's Post Office. An entity that is bankrupt and barely functional despite having a state mandated monopoly on an entire country's postal system. As per article they're also running the SASSA social grant system which is a train wreck in itself and has been buried in legal disputes for years (not random small cases...a challenge to the legitimacy of their core mandate on grants).…

> An entity that is bankrupt and barely functional despite having a state mandated monopoly on an entire country's postal system.

To be fair, plenty of state-mandated monopolies of postal systems still aren't profitable, often because they don't significantly control their revenue stream insofar as they don't set the prices of their products.

Post reply on HN