Live data from Hacker News

The Home Depot confirms payment systems breach

ir.homedepot.com

41–50 of 110 posts

Re: The Home Depot confirms payment systems breach

#41
post #17

(1) Don't use debit cards. You're much better protected as a consumer when you use a credit card. http://www.bbb.org/blog/2013/11/do-debit-cards-and-credit-ca... (2) Use BillGuard https://www.billguard.com/ (3) Review your transactions every week or so via a personal finance tool (I use https://www.mint.com/ ) I don't particularly care if my payment credentials are compromised as it's highly unlikely a fraudulent cha…

Or use cash and forget about all this other stuff ;)

Except I really like the free trips I get every year from accumulating travel reward points. Not to mention in my experience (personal and through acquaintances) Visa refunds fraudulent transactions immediately and with little to no hassle.

Re: The Home Depot confirms payment systems breach

#42
post #28
post #3

encouraging that they are using this as a motivator to "roll out EMV "Chip and PIN" to all U.S. stores by the end of this year" ahead of the prescribed deadline. edit: "Chip and PIN" is taken directly from the sec filing that is linked. the described deadline of october 2015 for the liability shift comes from banks[1] and not a US law or similar. [1] http://en.wikipedia.org/wiki/EMV#United_States

Would it actually have helped, though? I was under the impression that the Chip and PIN POS terminals don't do anything differently as far as the part between themselves and the authorizer goes - if somebody hacks one, they can still get everything they need to charge against the card. If so, it's more of an issue of firewalling properly at the individual store and corporate level.

Your impression is incorrect. Current EMV cards do something called DDA, so charging the card (as a card-present transaction) requires the card to be physically present or you to have cloned the application off the card (which the card is designed to prevent you from doing.)

You can still get the magstripe data if you compromise the terminal, but the network will (eventually) reject magstripe transactions made by a chip-capable card in a chip-capable reader. You can get the transaction certificate for one transaction, but that TC is protected from replay attacks.

Re: The Home Depot confirms payment systems breach

#43
post #33

Earlier quoted context omitted.

Or use cash and forget about all this other stuff ;)

Oh the irony of how using cash is safer these days. You expose yourself to an internet full of thieves using plastic, but with cash it's only to the handful of people you actually cross paths with.

Only if you get the cash via bank teller though. Skimmers make using ATMs risky as well.

Re: The Home Depot confirms payment systems breach

#44
post #6

Earlier quoted context omitted.

PCI deadline for US retailers to implement chip + pin is October 2015. Mentioned in the Home Depot link above

Many don't read the article and just start commenting.

I took that straight from the article / filing. and been impressed by the downvotes!

Re: The Home Depot confirms payment systems breach

#45
post #12

Earlier quoted context omitted.

In all fairness, SEC filings are a rather incomprehensible format to read, even one this short.

"Responding to the increasing threat of cyber-attacks on the retail industry, The Home Depot previously confirmed it will roll out EMV "Chip and PIN" to all U.S. stores by the end of this year, well in advance of the October 2015 deadline established by the payments industry." Don't excuse laziness.

Yes, they may say that. However, Home Depot is not the one that is determining what technology the issuers use. Most issuers are using Chip&Signature. Home Depot may support Chip and Pin, but if your bank doesn't use Chip&Pin, the fact that Home Depot supports it is worthless to you.

Re: The Home Depot confirms payment systems breach

#46
post #31
post #30

> The Home Depot is offering free identity protection services, including credit monitoring, to any customer who used a payment card at a Home Depot store in 2014, from April on. This is absolutely not acceptable, and I deplore how this has become the status quo. I reject these services and want nothing less than a full lawsuit.

A lawsuit which you would lose. Especially considering you most likely suffered no damages.

I'm pretty sure the card processors would be on my side of the lawsuit, along with a few million other home depot customers.

I don't care about damages to me. I want the problem fixed. This Laissez-faire attitude towards online commerce security needs to end. Standards like PCI and PA-DSS are not enough. Corporations need to be liable for leaking everyone's information. A year of free credit monitoring is a slap in the face.

Re: The Home Depot confirms payment systems breach

#47
post #31
post #30

> The Home Depot is offering free identity protection services, including credit monitoring, to any customer who used a payment card at a Home Depot store in 2014, from April on. This is absolutely not acceptable, and I deplore how this has become the status quo. I reject these services and want nothing less than a full lawsuit.

A lawsuit which you would lose. Especially considering you most likely suffered no damages.

No damages?

- Go through your entire credit history over a six month period looking for illegitimate charges. (Many people, such as myself, use a single credit card for most of their payments -- that's thousands of transactions.)

- Wait a week for a new credit card to arrive in the mail, and hope none of your automatic payments try to charge the old card while you wait for the new one.

- Update all of your automatic payments. Doing it once would be one thing, but every time one these breaches happens?

None of these are the end of the world, but they're certainly not "no damages".

Re: The Home Depot confirms payment systems breach

#48
post #46
post #31

Earlier quoted context omitted.

A lawsuit which you would lose. Especially considering you most likely suffered no damages.

I'm pretty sure the card processors would be on my side of the lawsuit, along with a few million other home depot customers. I don't care about damages to me. I want the problem fixed. This Laissez-faire attitude towards online commerce security needs to end. Standards like PCI and PA-DSS are not enough. Corporations need to be liable for leaking everyone's information. A year of free credit monitoring is a slap in t…

Card processors might have a case, but the customers really mostly wouldn't.

The PAN that belongs to your credit card company that was assigned to you by your credit card company was compromised and someone tried to defraud your credit card company using it. Yet it's you complaining, why?

Re: The Home Depot confirms payment systems breach

#49
post #31

Earlier quoted context omitted.

A lawsuit which you would lose. Especially considering you most likely suffered no damages.

No damages? - Go through your entire credit history over a six month period looking for illegitimate charges. (Many people, such as myself, use a single credit card for most of their payments -- that's thousands of transactions.) - Wait a week for a new credit card to arrive in the mail, and hope none of your automatic payments try to charge the old card while you wait for the new one. - Update all of your automatic…

You'd have a really hard time arguing those as damages in court. And then you'd have an even harder time arguing that it was in fact Home Depot that was responsible.

Re: The Home Depot confirms payment systems breach

#50
post #39

Earlier quoted context omitted.

My understanding (and it's entirely possible I'm mistaken) is that chip+pin and chip+signature cards are not interchangeable. In other words, I don't think you can just take a chip+signature card and "get a pin" for it. And the one card I've received with a chip (from Bank of America) is definitely chip+signature. I'd love to be told I'm wrong, and that this can be made into a chip+pin card without physically swappin…

I had no idea that it wasn't possible to get a pin, but now having done some research it looks like I was wrong. I wonder if it has something to do with them using the existing pin infrastructure for ATM cash advances.

Do you have a source for this? I distinctly remember my Canadian credit card starting off as chip and signature and sometime later start asking me for my PIN.
Post reply on HN