Live data from Hacker News

The Home Depot confirms payment systems breach

ir.homedepot.com

81–90 of 110 posts

Re: The Home Depot confirms payment systems breach

#81

Earlier quoted context omitted.

home depot likes to collect email address for sending receipts (and spam). Along with that older style mag stripes will give out the name. Not sure about mailing info or how they'd get that. The thing to do is to actually get stores to stop storing CC info at all. they should be able to process the payment and then forget the info at all so it never has to be stored so it can't be stolen. EMV is actually a move to fo…

I've made a lot of Home Depot purchases in the last month (yay, new credit cards for me!), and I don't recall ever being asked for an email address either by a cashier or the self-check kiosk. Maybe it's just my local stores don't do it, though.

Just for another point of data, all of my purchases during the timeframe in question were on the Self-Checkout units, and I was given the option for eReceipt, which I took advantage of. What I noticed was that upon returning with the same card, my email address was remembered, which tells me that they must store some information to cross reference (hopefully just name + last 4 or similar). Typing this reminds me that I actually did use both of my cards at Home Depot, because I now remember being prompted again when I had used another card. Guess that means two new cards for me...

Re: The Home Depot confirms payment systems breach

#82
post #59

Earlier quoted context omitted.

Depends on where you shop, but some places will give you cash discounts of 3-5%, which is more than most CC rewards pay. Admittedly it's not as widespread.

Most merchant agreements forbid this, IIRC. Credit card companies have a vested interest in the goods being the same price whether cash or credit.

They used to - it used to be enough for a merchant to lose 'rights' to process credit cards - but the federal regulations of a couple years ago put a stop to it.

Re: The Home Depot confirms payment systems breach

#83
post #59

Earlier quoted context omitted.

Most merchant agreements forbid this, IIRC. Credit card companies have a vested interest in the goods being the same price whether cash or credit.

They used to - it used to be enough for a merchant to lose 'rights' to process credit cards - but the federal regulations of a couple years ago put a stop to it.

Some states previously used to also restrict the ability of merchant agreements to do that, though usually only in specific industries. E.g. in Texas, liquor stores (but nobody else) have been able to offer cash discounts for ages. Now anyone can.

Re: The Home Depot confirms payment systems breach

#84

Earlier quoted context omitted.

Agreed on debit cards. Another way to vet charges is to use something that notifies your phone whenever you make a purchase. Simple bank does this, maybe others too.

Bump for Simple. Anytime an auth occurs, I get a push notification on my phone. Its so simple from a UX standpoint, not sure why other financial services firms (Discover, Amex, etc) don't push something like it out.

As others pointed out, AMEX has supported this for a while - I get texted almost instantly with any transactions on my card. I believe their mobile app also supports notifications, but I prefer SMS for this.

I only wish my bank (Wells Fargo) supported SMS alerts for transactions - if there's one thing I don't mind getting frequent notifications about, it would be this.

Re: The Home Depot confirms payment systems breach

#85
post #20

Some home depots let you pay with paypal as well.

It will be interesting to see if any Paypal account compromises can be attributed to this breach. From what I've read, this type of malware typically scrapes the memory of processes on the POS, looking specifically for what appears to be track data, and which passes a Luhn check.

Re: The Home Depot confirms payment systems breach

#86
post #35

Earlier quoted context omitted.

Why on earth would you argue this issue with the guy at the paint counter? He clearly has nothing to do with either the cause or any remedy they might decide to offer.

All the computers for the paint mixing machines in every Home Depot were screwed up today, which brought up the topic of the hack and he got excited when I suggested it was probably outdated software on the point of sales machines that was to blame. The interesting part to me was it sounded like the managers explained to them that it was all the bank's fault. Not that Home Depot was too cheap and lazy to update their…

Do you have reason to believe that Windows 7 instead of Windows XP would have prevented this attack? It sounds like weak credentials and overall lax security are more to blame.

edit: Also, keep in mind that some retailers are running POSReady 2009 / POSReady 7, which may look just like Windows XP at first glance.

Re: The Home Depot confirms payment systems breach

#87
post #17

(1) Don't use debit cards. You're much better protected as a consumer when you use a credit card. http://www.bbb.org/blog/2013/11/do-debit-cards-and-credit-ca... (2) Use BillGuard https://www.billguard.com/ (3) Review your transactions every week or so via a personal finance tool (I use https://www.mint.com/ ) I don't particularly care if my payment credentials are compromised as it's highly unlikely a fraudulent cha…

Billguard asks for my online bank username and password, it's a deal breaker for me. Do you really trust them? https://medium.com/@hyphenated/mint-com-and-billguard-are-ly...

Billguard uses Yodlee as a backend, so at the very least I do trust that Billguard only has read-only access. I'm less certain how Yodlee functions -- whether they just scrape data and have full access, or whether they get some sort of read-only token from the financial institution.

Re: The Home Depot confirms payment systems breach

#88
post #17

(1) Don't use debit cards. You're much better protected as a consumer when you use a credit card. http://www.bbb.org/blog/2013/11/do-debit-cards-and-credit-ca... (2) Use BillGuard https://www.billguard.com/ (3) Review your transactions every week or so via a personal finance tool (I use https://www.mint.com/ ) I don't particularly care if my payment credentials are compromised as it's highly unlikely a fraudulent cha…

Billguard asks for my online bank username and password, it's a deal breaker for me. Do you really trust them? https://medium.com/@hyphenated/mint-com-and-billguard-are-ly...

Stealing the key should be impossible, it should be on an HSM (which performs the cryptographic operations for you instead of giving you a key)

That's only one part of the article though.

Re: The Home Depot confirms payment systems breach

#89

Earlier quoted context omitted.

Bump for Simple. Anytime an auth occurs, I get a push notification on my phone. Its so simple from a UX standpoint, not sure why other financial services firms (Discover, Amex, etc) don't push something like it out.

The Amex app on iPhone sends push notifications for changes.

Thanks! I was unaware of this feature!

Re: The Home Depot confirms payment systems breach

#90
post #15
post #6

Earlier quoted context omitted.

PCI deadline for US retailers to implement chip + pin is October 2015. Mentioned in the Home Depot link above

It's not clear if US is going to be Chip+Pin or Chip+Signature. This is going to add some confusion come next year.

I had an AMEX Blue Business card with an RF chip in it, transaction receipts had a completely different last 4 digits using RF vs magnetic. I called to see if I could get a chip+pin and they said yes except it's chip+signature. So at least U.S. AMEX is chip+signature. However, the card's chip "pin out" area is shaped smaller and differently arranged than the one on my bank issued card. So we apparently have two different "chip" standards and I don't know which one is actually going to get used.
Post reply on HN