Live data from Hacker News

The Home Depot confirms payment systems breach

ir.homedepot.com

91–100 of 110 posts

Re: The Home Depot confirms payment systems breach

#91
post #45

Earlier quoted context omitted.

"Responding to the increasing threat of cyber-attacks on the retail industry, The Home Depot previously confirmed it will roll out EMV "Chip and PIN" to all U.S. stores by the end of this year, well in advance of the October 2015 deadline established by the payments industry." Don't excuse laziness.

Yes, they may say that. However, Home Depot is not the one that is determining what technology the issuers use. Most issuers are using Chip&Signature. Home Depot may support Chip and Pin, but if your bank doesn't use Chip&Pin, the fact that Home Depot supports it is worthless to you.

I'm pretty sure the merchant equipment is going to support either chip&signature or chip&pin, seeing as we already have signatures for credit card, and PINs for debit card transactions. The difference will be up to the card issuers. And I for one hate digital "esignatures" talk about all kinds of fraud waiting to happen with that bullcrap. I want to use either PIN or ink on paper signature. Make me use a screen to sign my name, and I'm signing it mickey mouse.

Re: The Home Depot confirms payment systems breach

#93
post #17

(1) Don't use debit cards. You're much better protected as a consumer when you use a credit card. http://www.bbb.org/blog/2013/11/do-debit-cards-and-credit-ca... (2) Use BillGuard https://www.billguard.com/ (3) Review your transactions every week or so via a personal finance tool (I use https://www.mint.com/ ) I don't particularly care if my payment credentials are compromised as it's highly unlikely a fraudulent cha…

And for those that can't get credit cards...? I mean, I agree with you that that's definitely the safest way, but lets not forget that there are a significant portion of the population that have bad or no credit and are stuck with Debit cards at best. What of them?

Re: The Home Depot confirms payment systems breach

#94

Earlier quoted context omitted.

Billguard asks for my online bank username and password, it's a deal breaker for me. Do you really trust them? https://medium.com/@hyphenated/mint-com-and-billguard-are-ly...

Billguard uses Yodlee as a backend, so at the very least I do trust that Billguard only has read-only access. I'm less certain how Yodlee functions -- whether they just scrape data and have full access, or whether they get some sort of read-only token from the financial institution.

I am not familiar with Yodlee, but I recently discovered that many banks support OFX [1], which is a format for exchanging financial information.

GnuCash has a list of OFX credentials for major banks. [2] In fact, there are tons of OFX open source libraries out there - I had luck with this one recently in Python. [3]

[1] http://en.wikipedia.org/wiki/Open_Financial_Exchange

[2] http://wiki.gnucash.org/wiki/OFX_Direct_Connect_Bank_Setting...

[3] https://github.com/captin411/ofxclient

Re: The Home Depot confirms payment systems breach

#96
post #93
post #17

(1) Don't use debit cards. You're much better protected as a consumer when you use a credit card. http://www.bbb.org/blog/2013/11/do-debit-cards-and-credit-ca... (2) Use BillGuard https://www.billguard.com/ (3) Review your transactions every week or so via a personal finance tool (I use https://www.mint.com/ ) I don't particularly care if my payment credentials are compromised as it's highly unlikely a fraudulent cha…

And for those that can't get credit cards...? I mean, I agree with you that that's definitely the safest way, but lets not forget that there are a significant portion of the population that have bad or no credit and are stuck with Debit cards at best. What of them?

While I don't know as much about it as perhaps I should, the reloadable-prepaid market is very large. American Express offers a popular card in this model.

Re: The Home Depot confirms payment systems breach

#97
post #96
post #93

Earlier quoted context omitted.

And for those that can't get credit cards...? I mean, I agree with you that that's definitely the safest way, but lets not forget that there are a significant portion of the population that have bad or no credit and are stuck with Debit cards at best. What of them?

While I don't know as much about it as perhaps I should, the reloadable-prepaid market is very large. American Express offers a popular card in this model.

I wonder if they have the same fraud protections as a proper credit card. I doubt it, but I'd gladly be proven wrong!

Re: The Home Depot confirms payment systems breach

#98
post #92
post #62

Earlier quoted context omitted.

Sure, but the only real solution would be not accepting cards. Does that sound like a good solution to you?

Not sure you are being productive.

Not sure about that either, but trying to blame Home Depot for fundamental flaws of the system isn't productive either. You should blame the card design for allowing this, not the people that accept cards.

Re: The Home Depot confirms payment systems breach

#99
post #94

Earlier quoted context omitted.

Billguard uses Yodlee as a backend, so at the very least I do trust that Billguard only has read-only access. I'm less certain how Yodlee functions -- whether they just scrape data and have full access, or whether they get some sort of read-only token from the financial institution.

I am not familiar with Yodlee, but I recently discovered that many banks support OFX [1], which is a format for exchanging financial information. GnuCash has a list of OFX credentials for major banks. [2] In fact, there are tons of OFX open source libraries out there - I had luck with this one recently in Python. [3] [1] http://en.wikipedia.org/wiki/Open_Financial_Exchange [2] http://wiki.gnucash.org/wiki/OFX_Direct_…

Thanks for the references. After some research, I decided to go with YNAB http://www.youneedabudget.com/ it has a desktop and mobile apps and uses your dropbox for syncing data.

Re: The Home Depot confirms payment systems breach

#100
post #98
post #92

Earlier quoted context omitted.

Not sure you are being productive.

Not sure about that either, but trying to blame Home Depot for fundamental flaws of the system isn't productive either. You should blame the card design for allowing this, not the people that accept cards.

While the card design could be better, those that accept them have a responsibility. The bigger you are and the more cavalier with card data, the more likely you will get targeted. I have yet to see one of these data breaches where the victim (if we call it that) company was doing a very good OpSec job.

You both have a point, but lean towards more punishment. This isn't something that should just be 'charged' away.

Post reply on HN