Live data from Hacker News

Chipotle Reports Findings from Investigation of Payment Card Security Incident

chipotle.com

61–70 of 73 posts

Re: Chipotle Reports Findings from Investigation of Payment Card Security Incident

#61
post #51
post #31

Earlier quoted context omitted.

Weirdly, I've only really noticed this in the US. Back in Australia where we've been using chips for about a decade, I rarely remember it taking more than a couple of seconds, certainly not 10. We also have contactless payment on most of our credit cards (as in built into the card, not Android/Apple Pay) and support for it on ~90% of terminals as well though so it's not much used anymore.

Likewise in New zealand. I've always heard the argument that the US is bigger so it's harder to change (for everything - POS, the metric system, any kind of regulation etc). Even after a decade in the US it amuses me that NASA can run a fleet of vehicles on Mars, that the country produced places like silicon valley, and that American ideology is one of entrepreneurship/innovation but as a country we struggle with cha…

Well, it shouldn't amaze you. The telephone was literally invented in Canada, and we have the worst telco situation in North America; and that's really saying something.

I think the problem is inherent in early adoption. The people who buy the first version of the thing are happy to wait another couple versions before upgrading, because they already have something which is substantially similar to the upgrade. You see this with people comparing the telco situation in Ethiopia (which despite a terrible organizational model, and very little capital, is improving rapidly) to anywhere in the developed world doesn't make sense. If you have landlines and a cable TV infrastructure, 4G over the air will have less demand automatically.

Re: Chipotle Reports Findings from Investigation of Payment Card Security Incident

#62
post #5

Hopefully this pushes more and more restaurants towards using separate chip-reader (EMV) pinpad devices. I've noticed several area restaurants switching lately (Arby's, Wendy's), and I hope it continues. These devices use point-to-point encryption, meaning that even if the POS machine is comprimised, no sensitive card data can be stolen. The POS machine never sees raw card data.

Chipreaders are terribly slow, I don't understand how they could not develop a secure payment system without 10-second~ delay times. My local grocery store installed new chip readers and within a week had taped over time in favor of the more-expensive but quicker stripe processing.

The problem with them is they force another prompt, which takes time to read, comprehend, and respond to.

Prompt #1: Credit/Debit?

Prompt #2: PIN

Prompt #3: Would you like cash back

Prompt #4: The total is $xx.xx, ok?

This is time consuming, particularly for people who aren't as comfortable with electronics and pressing buttons. And on top of that, many times the terminals themselves are slow.

Pay-at-the pumps are even worse

Prompt #5: Are you a fuel perks member?

Prompt #6: Receipt yes/no?

Prompt #7: Would you like a car wash?

and they're often even slower, the buttons are often hard to press, or don't register a beep and have a delay before the machine responds, so you wind up pressing the same one twice. And most lack a 'backspace', the screens suck, man don't get me started....lol

Re: Chipotle Reports Findings from Investigation of Payment Card Security Incident

#63
> The malware searched for track data (which sometimes has cardholder name in addition to card number, expiration date, and internal verification code) ... There is no indication that other customer information was affected.

What other customer information could have been affected? Kudos on the masterful PR spin — I guess by now Chipotle has had a lot of practice at this...

Re: Chipotle Reports Findings from Investigation of Payment Card Security Incident

#64
post #19

Earlier quoted context omitted.

Hilariously, using contactless EMV payment (i.e. Apple/Android Pay) with the same POS terminals is lightning fast. But this gets filed as "infrastructure is hard". A related example: If you get a chance, try the IC card system used by the train and transit systems in Japan; they're delightful.[1] At peak rush-hour, commuters are darn near running through the (many) pay stations tapping through without breaking stride…

Something to keep in mind is that Apple/Android Pay support both MSD (magnetic stripe data) and EMV contactless modes, which can result in different timings. EMV contactless also drops significant portions of the EMV contact requirements. This is why banks generally won't let you get cash back, or make large purchases on contactless, there's a trade off.

I've actually found it to be better; no tradeoffs.

I haven't tried cash back as I use credit cards rather than debit cards. I've used Apple Pay in the US, Canada, NZ, Australia, Germany, Sweden, and Denmark, and it's ALWAYS preferably to using the actual card, particularly for an American.

If you have a US based bank, even with EMV the bank prefers a signature, which means you have to sign the damn receipt. This is more inconvenient than doing so in the US because:

1. The merchants aren't used to it, so it's a surprise/hurdle 2. It's not common, so you have to sign an actual receipt, not an electric display 3. They don't seem to waive the signature requirement for small purchases ($25-$50) as they do in the US. So you're signing for EVERYTHING.

Magically, if you try to use your US-card-with-a-PIN (assuming you set one up) in an unmanned scenario like in a parking garage, SUDDENLY YOUR PIN WORKS! (quelle surprise!)

I also fell in love with the convenience of Apple Pay+Watch when I was skiing in Whistler; no need to take off my gloves, unzip a pocket, reach in, find, card, use card, sign receipt. Just a quick double-tap on the side button without even undoing my glove gauntlet, velcro closure around the wrist of my jacket, or any of my 5 layers of clothes (yes, it was cold).

Paywave was the most-commonly accepted in Australia of everywhere I've been recently, to the extent that they even tap your credit card to the machine first, assuming it will work, and are surprised when it doesn't. Yet they were VERY surprised by the watch, often saying they had never seen anyone use their watch before. I'm not sure if contactless+phone would have been as unexpected or not; I never tried.

Re: Chipotle Reports Findings from Investigation of Payment Card Security Incident

#65
post #42

Earlier quoted context omitted.

I am appalled at the attempt by Chipotle to downplay the scope and scale of the incident. The sentence which reads, " Not all locations were involved, and the specific time frames vary by location", is a blatant attempt to deflate the significance of the problem. This public disclosure should have been more direct, and disclose in plain language the number of stores affected. Chipotle should explain the full impact i…

They are international now, right? I at least think I have memory of running across them in Canada. The file name in question (thanks, heywire) is "us.json". I'm left wondering whether and how much of an international scope there might be to this. While the version of their web site that I'm receiving by default seems to be geo-centric to the U.S. and doesn't mention foreign locations, Wikipedia has: https://en.wikip…

Card processing in Europe is secure and doesn't ever involve magstripe data, so it won't have been a problem.

Re: Chipotle Reports Findings from Investigation of Payment Card Security Incident

#66
post #38
post #24

Earlier quoted context omitted.

A quick look at the chrome dev tools will point to a us.json which has what you're looking for.

That's a massive list. 2249 restaurants.

The only ones not affected are most likely the ones that are part of airports/universities/hospitals that require integration with the building's POS system instead of their own.

Re: Chipotle Reports Findings from Investigation of Payment Card Security Incident

#67
Just because someone is forcing you use the chip DOES NOT MEAN THAT IT'S AN EMV TRANSACTION

There is no way too know if you are actually doing and EMV transaction.

The EMV spec has nothing at all to do with security. PCI controls security. I can read the card data via the chip and it's all in the clear. EMV is about process integrity, and the integrity testing is ridiculous. Chip cards are harder to forge, but that's about it. The new rules about liability puts the liability for processing a forged card on the merchant, if the transaction isn't done with EMV.

Re: Chipotle Reports Findings from Investigation of Payment Card Security Incident

#68
post #39

Earlier quoted context omitted.

American card terminals pretty much universally suck compared to everywhere else in the western world so it's not that surprising to me. According to staff at a few shops in my area when asked why they always ask if tap to pay is ok they said a lot of people still don't allow them to tap and insist on chip+pin still.

You mean in Australia? Yeah, I worked in retail while I lived there and it was pretty common. People seemed to think that using it would somehow make them more vulnerable to thieves for some reason. I even had friends who called the bank to exchange their card for one that didn't do contactless.

The companies did a terrible job of advertising all the new technology.

"Just use it--for convenience. Trust us!"

If I want convince, I use cash.

I stopped using credit cards, but still have a debt card, with a chip. Actually it's a credit card too, but never asked for it. When the bank sent me the new card, they just said it was better. Not how to use it, or why it's better; just here's your new card.

It's gotten to the point where I only use it for online purchases, and then only to specific retailers--basically Amazon, Google, and if I'm in a trusting mood PayPal.

Even though I'm in tech, I don't know how all the other technology works, nor care too know at this point.

My security is checking my bank account, and looking for suspicious transactions.

The days of trying new technology tied to my meager amount of money is gone. The days of trusting retailers with my information is gone. I do sometimes feel bad for the little retailer/website though. I just don't trust them anymore. I don't trust banks, and would go back to completely cash(buried in tin cans), if I lived somewhere remote.

Progress?

Re: Chipotle Reports Findings from Investigation of Payment Card Security Incident

#69
post #40
post #28

Earlier quoted context omitted.

Typically, the hackers that get the data sell it off, versus using it personally. That can take a while.

I just mean that I didn't use my card during the time period, but a week later.

I used my card multiple times at multiple affected locations in four states, and I haven't seen any fraud on the card. Just a datapoint. Perhaps yours really was that shady medical provider.

Re: Chipotle Reports Findings from Investigation of Payment Card Security Incident

#70

Just because someone is forcing you use the chip DOES NOT MEAN THAT IT'S AN EMV TRANSACTION There is no way too know if you are actually doing and EMV transaction. The EMV spec has nothing at all to do with security. PCI controls security. I can read the card data via the chip and it's all in the clear. EMV is about process integrity, and the integrity testing is ridiculous. Chip cards are harder to forge, but that's…

Are you saying that you know of systems which use the tag 57 (track 2 equivalent data) to read an EMV chip and process the transaction manually? I'd be surprised if most banks would even approve those transactions (no CVV/CVV2, etc).
Post reply on HN