Live data from Hacker News

Chipotle Reports Findings from Investigation of Payment Card Security Incident

chipotle.com

41–50 of 73 posts

Re: Chipotle Reports Findings from Investigation of Payment Card Security Incident

#41

Earlier quoted context omitted.

No, but it has been in the past. I'm speaking theoretically in general when people are wronged by things like this.

Your credit card company should offer a $0 liability policy for fraudulent charges. If not, switch card companies. Then it's their problem not yours.

Still requires you to notice a weird spend and file the complaint/whatever process they have.

Re: Chipotle Reports Findings from Investigation of Payment Card Security Incident

#42
post #38
post #24

Earlier quoted context omitted.

A quick look at the chrome dev tools will point to a us.json which has what you're looking for.

That's a massive list. 2249 restaurants.

I am appalled at the attempt by Chipotle to downplay the scope and scale of the incident. The sentence which reads, " Not all locations were involved, and the specific time frames vary by location", is a blatant attempt to deflate the significance of the problem. This public disclosure should have been more direct, and disclose in plain language the number of stores affected. Chipotle should explain the full impact in plain language: "2,249 out of X,XXX Chipotle restaurants were compromised."

Re: Chipotle Reports Findings from Investigation of Payment Card Security Incident

#43

Earlier quoted context omitted.

Chipreaders are terribly slow, I don't understand how they could not develop a secure payment system without 10-second~ delay times. My local grocery store installed new chip readers and within a week had taped over time in favor of the more-expensive but quicker stripe processing.

Hilariously, using contactless EMV payment (i.e. Apple/Android Pay) with the same POS terminals is lightning fast. But this gets filed as "infrastructure is hard". A related example: If you get a chance, try the IC card system used by the train and transit systems in Japan; they're delightful.[1] At peak rush-hour, commuters are darn near running through the (many) pay stations tapping through without breaking stride…

I love Android Pay. If a place accepts it, I 100% use it over a card. It's near instantaneous, it's more secure (the merchant isn't getting my real card data), it's easy for me to audit, and it means I don't need my wallet when I go to the store.

Re: Chipotle Reports Findings from Investigation of Payment Card Security Incident

#44

Earlier quoted context omitted.

No, but it has been in the past. I'm speaking theoretically in general when people are wronged by things like this.

Your credit card company should offer a $0 liability policy for fraudulent charges. If not, switch card companies. Then it's their problem not yours.

Yes, they do. I still have to take time out of my day to audit the cards, challenge the payments, and then cancel the cards and get new ones, and update billpay everywhere else.

How hard is this to understand?

Re: Chipotle Reports Findings from Investigation of Payment Card Security Incident

#45
post #5

Hopefully this pushes more and more restaurants towards using separate chip-reader (EMV) pinpad devices. I've noticed several area restaurants switching lately (Arby's, Wendy's), and I hope it continues. These devices use point-to-point encryption, meaning that even if the POS machine is comprimised, no sensitive card data can be stolen. The POS machine never sees raw card data.

Chipreaders are terribly slow, I don't understand how they could not develop a secure payment system without 10-second~ delay times. My local grocery store installed new chip readers and within a week had taped over time in favor of the more-expensive but quicker stripe processing.

Walgreen's has lightening fast chip readers.

Everyone else, yeah, pretty slow.

I am surprised that apparently only 1 vendor has figured out how to make a good chip reader, and I am sad that apparently other retailers don't care enough to buy from that one vendor.

Re: Chipotle Reports Findings from Investigation of Payment Card Security Incident

#46
post #5

Hopefully this pushes more and more restaurants towards using separate chip-reader (EMV) pinpad devices. I've noticed several area restaurants switching lately (Arby's, Wendy's), and I hope it continues. These devices use point-to-point encryption, meaning that even if the POS machine is comprimised, no sensitive card data can be stolen. The POS machine never sees raw card data.

Not much point until they require chips for credit card charges.

Re: Chipotle Reports Findings from Investigation of Payment Card Security Incident

#47
post #35

Earlier quoted context omitted.

Your credit card company should offer a $0 liability policy for fraudulent charges. If not, switch card companies. Then it's their problem not yours.

Yes, and if you're with a decent company chances are they'll automatically send you a new card if you've been affected.

Leaving you without a card for 7-10 business days.

Re: Chipotle Reports Findings from Investigation of Payment Card Security Incident

#48
post #42
post #38

Earlier quoted context omitted.

That's a massive list. 2249 restaurants.

I am appalled at the attempt by Chipotle to downplay the scope and scale of the incident. The sentence which reads, " Not all locations were involved, and the specific time frames vary by location", is a blatant attempt to deflate the significance of the problem. This public disclosure should have been more direct, and disclose in plain language the number of stores affected. Chipotle should explain the full impact i…

Well, they basically have no idea -- it says in bold letters "Please note that not all locations were identified."

For reference, Wikipedia claims Chipotle has 3,010 restaurants. So at least 75%.

Re: Chipotle Reports Findings from Investigation of Payment Card Security Incident

#49
post #42
post #38

Earlier quoted context omitted.

That's a massive list. 2249 restaurants.

I am appalled at the attempt by Chipotle to downplay the scope and scale of the incident. The sentence which reads, " Not all locations were involved, and the specific time frames vary by location", is a blatant attempt to deflate the significance of the problem. This public disclosure should have been more direct, and disclose in plain language the number of stores affected. Chipotle should explain the full impact i…

They are international now, right? I at least think I have memory of running across them in Canada.

The file name in question (thanks, heywire) is "us.json". I'm left wondering whether and how much of an international scope there might be to this.

While the version of their web site that I'm receiving by default seems to be geo-centric to the U.S. and doesn't mention foreign locations, Wikipedia has:

https://en.wikipedia.org/wiki/Chipotle_Mexican_Grill

Chipotle Mexican Grill, Inc. (/tʃᵻˈpoʊtleɪ/)[6] is an American chain of fast casual restaurants in the United States, United Kingdom,[7] Canada,[8][9] Germany,[10] and France

Re: Chipotle Reports Findings from Investigation of Payment Card Security Incident

#50
post #47
post #35

Earlier quoted context omitted.

Yes, and if you're with a decent company chances are they'll automatically send you a new card if you've been affected.

Leaving you without a card for 7-10 business days.

No, this generally doesn't involve immediately cancelling your existing card, sending you a new card and canceling the old one when it arrives is a much smoother experience.

Who doesn't ship next day anyway?

Post reply on HN