Live data from Hacker News

Chipotle Reports Findings from Investigation of Payment Card Security Incident

chipotle.com

31–40 of 73 posts

Re: Chipotle Reports Findings from Investigation of Payment Card Security Incident

#31
post #5

Hopefully this pushes more and more restaurants towards using separate chip-reader (EMV) pinpad devices. I've noticed several area restaurants switching lately (Arby's, Wendy's), and I hope it continues. These devices use point-to-point encryption, meaning that even if the POS machine is comprimised, no sensitive card data can be stolen. The POS machine never sees raw card data.

Chipreaders are terribly slow, I don't understand how they could not develop a secure payment system without 10-second~ delay times. My local grocery store installed new chip readers and within a week had taped over time in favor of the more-expensive but quicker stripe processing.

Weirdly, I've only really noticed this in the US. Back in Australia where we've been using chips for about a decade, I rarely remember it taking more than a couple of seconds, certainly not 10.

We also have contactless payment on most of our credit cards (as in built into the card, not Android/Apple Pay) and support for it on ~90% of terminals as well though so it's not much used anymore.

Re: Chipotle Reports Findings from Investigation of Payment Card Security Incident

#33
post #31

Earlier quoted context omitted.

Chipreaders are terribly slow, I don't understand how they could not develop a secure payment system without 10-second~ delay times. My local grocery store installed new chip readers and within a week had taped over time in favor of the more-expensive but quicker stripe processing.

Weirdly, I've only really noticed this in the US. Back in Australia where we've been using chips for about a decade, I rarely remember it taking more than a couple of seconds, certainly not 10. We also have contactless payment on most of our credit cards (as in built into the card, not Android/Apple Pay) and support for it on ~90% of terminals as well though so it's not much used anymore.

American card terminals pretty much universally suck compared to everywhere else in the western world so it's not that surprising to me.

According to staff at a few shops in my area when asked why they always ask if tap to pay is ok they said a lot of people still don't allow them to tap and insist on chip+pin still.

Re: Chipotle Reports Findings from Investigation of Payment Card Security Incident

#34
post #27

Earlier quoted context omitted.

Do you know for sure your card data was stolen? If not, this isn't necessarily something you need to be very proactive about.

No, but it has been in the past. I'm speaking theoretically in general when people are wronged by things like this.

Your credit card company should offer a $0 liability policy for fraudulent charges. If not, switch card companies. Then it's their problem not yours.

Re: Chipotle Reports Findings from Investigation of Payment Card Security Incident

#35

Earlier quoted context omitted.

No, but it has been in the past. I'm speaking theoretically in general when people are wronged by things like this.

Your credit card company should offer a $0 liability policy for fraudulent charges. If not, switch card companies. Then it's their problem not yours.

Yes, and if you're with a decent company chances are they'll automatically send you a new card if you've been affected.

Re: Chipotle Reports Findings from Investigation of Payment Card Security Incident

#36

Why is there no legal recourse here outside of spending my own time/resources to cancel cards and deal with all the BS that occurs with that whenever this happens? There should be financial repercussions, each affected individual should be awarded monetary compensation for their time.

I believe that since Chipotle was still using magstripe credit card readers that they are now financially liable for any fraudulent charges on your account.

Re: Chipotle Reports Findings from Investigation of Payment Card Security Incident

#37
post #5

Hopefully this pushes more and more restaurants towards using separate chip-reader (EMV) pinpad devices. I've noticed several area restaurants switching lately (Arby's, Wendy's), and I hope it continues. These devices use point-to-point encryption, meaning that even if the POS machine is comprimised, no sensitive card data can be stolen. The POS machine never sees raw card data.

Chipreaders are terribly slow, I don't understand how they could not develop a secure payment system without 10-second~ delay times. My local grocery store installed new chip readers and within a week had taped over time in favor of the more-expensive but quicker stripe processing.

I've encountered a few that only took a second or two. No idea why most of them are slow as crap given that. The ones at Starbucks (and others by that company) are terribly slow

Re: Chipotle Reports Findings from Investigation of Payment Card Security Incident

#38
post #24

Anyone have the whole list? (I hate enforced drill-down selection for such things.) How many locations?

A quick look at the chrome dev tools will point to a us.json which has what you're looking for.

That's a massive list. 2249 restaurants.

Re: Chipotle Reports Findings from Investigation of Payment Card Security Incident

#39
post #31

Earlier quoted context omitted.

Weirdly, I've only really noticed this in the US. Back in Australia where we've been using chips for about a decade, I rarely remember it taking more than a couple of seconds, certainly not 10. We also have contactless payment on most of our credit cards (as in built into the card, not Android/Apple Pay) and support for it on ~90% of terminals as well though so it's not much used anymore.

American card terminals pretty much universally suck compared to everywhere else in the western world so it's not that surprising to me. According to staff at a few shops in my area when asked why they always ask if tap to pay is ok they said a lot of people still don't allow them to tap and insist on chip+pin still.

You mean in Australia? Yeah, I worked in retail while I lived there and it was pretty common. People seemed to think that using it would somehow make them more vulnerable to thieves for some reason. I even had friends who called the bank to exchange their card for one that didn't do contactless.

Re: Chipotle Reports Findings from Investigation of Payment Card Security Incident

#40
post #28
post #16

My area was hit, and I did get hit with credit card fraud. I suspected a different vector (shady medical vendor and coincidental timing). The card that got hit was indeed used at Chipotle, but a week after the supposed "time range" indicated on the security site. Maybe the time range isn't absolute.

Typically, the hackers that get the data sell it off, versus using it personally. That can take a while.

I just mean that I didn't use my card during the time period, but a week later.
Post reply on HN