Live data from Hacker News

Chipotle Reports Findings from Investigation of Payment Card Security Incident

chipotle.com

1–10 of 73 posts

Re: Chipotle Reports Findings from Investigation of Payment Card Security Incident

#3
post #2

What was that thing? It looks like all the stores in my area were hit.

Agreed. Looks like this a big deal™. Would love to know the method of spreading across all their point of sales, were they running on windows?

Re: Chipotle Reports Findings from Investigation of Payment Card Security Incident

#4
post #2

What was that thing? It looks like all the stores in my area were hit.

Agreed. Looks like this a big deal™. Would love to know the method of spreading across all their point of sales, were they running on windows?

A ton of POS systems run on windows. Most on windows xp embedded

Re: Chipotle Reports Findings from Investigation of Payment Card Security Incident

#5
Hopefully this pushes more and more restaurants towards using separate chip-reader (EMV) pinpad devices. I've noticed several area restaurants switching lately (Arby's, Wendy's), and I hope it continues. These devices use point-to-point encryption, meaning that even if the POS machine is comprimised, no sensitive card data can be stolen. The POS machine never sees raw card data.

Re: Chipotle Reports Findings from Investigation of Payment Card Security Incident

#6
post #2

What was that thing? It looks like all the stores in my area were hit.

I checked my home and all of the places where I know Chipotle is at in 4 different states. Every single one was on there. Would be nice if they said what percentage of stores were hit. The language implies a minority, but this looks like it could be most of them.

Re: Chipotle Reports Findings from Investigation of Payment Card Security Incident

#7
post #4

Earlier quoted context omitted.

Agreed. Looks like this a big deal™. Would love to know the method of spreading across all their point of sales, were they running on windows?

A ton of POS systems run on windows. Most on windows xp embedded

In the industry I am in (mostly grocery, convenience, some specialty retail), most have moved to at least POSReady 7, and some are looking at Windows 10, though there are other concerns with PCI compliance there. Most of the large retailers are pretty good about keeping these things away from the general Internet, but once an attacker is in your network, most bets are off. The most important thing to do is to look for retailers who are using the standalone pinpad devices (i.e., they don't take your card and swipe it in the keyboard or on the display). These standalone devices encrypt card data before that Windows-based point-of-sale ever sees it. You can't steal card data from a POS which never sees card data.

Re: Chipotle Reports Findings from Investigation of Payment Card Security Incident

#8
post #5

Hopefully this pushes more and more restaurants towards using separate chip-reader (EMV) pinpad devices. I've noticed several area restaurants switching lately (Arby's, Wendy's), and I hope it continues. These devices use point-to-point encryption, meaning that even if the POS machine is comprimised, no sensitive card data can be stolen. The POS machine never sees raw card data.

Would you suggest reporting a card lost to get a new number issued if it was used at one of these locations?

Re: Chipotle Reports Findings from Investigation of Payment Card Security Incident

#9
post #2

What was that thing? It looks like all the stores in my area were hit.

In the past there have been a mix of "off-the-shelf" memory scrapers as well as custom written targeted malware. Generally they'll get inside the network and push out an exe/dll to all of the POS machines from some compromised machine. Depending on how locked down the POS machines are, there are various methods for either getting read access to the POS application process memory or having the dll injected into its memory. From there they find a way to extricate the data, either manually or automatic, depending on how locked down the network is. Application whitelisting solutions can really help block this kind of attack, but they're not perfect either. If an attacker can figure out how to get root on the machines, game over. This is why stand alone point-to-point encrypted EMV card readers are the way to go. You can't scrape the process memory for data it doesn't have, and the card readers themselves are pretty tamper resistant (if you don't count external skimmers)

Re: Chipotle Reports Findings from Investigation of Payment Card Security Incident

#10
post #5

Hopefully this pushes more and more restaurants towards using separate chip-reader (EMV) pinpad devices. I've noticed several area restaurants switching lately (Arby's, Wendy's), and I hope it continues. These devices use point-to-point encryption, meaning that even if the POS machine is comprimised, no sensitive card data can be stolen. The POS machine never sees raw card data.

Would you suggest reporting a card lost to get a new number issued if it was used at one of these locations?

Definitely if you used a debit card, since it could take a couple days to get any fraudulent charges reversed. Probably less important if you used a credit card, since you'll not have to pay for those charges and they'll just send you a new card at that point. I guess it just depends on if you want to be inconvenienced now or later :)

I personally used my credit card at one of the affected stores, and I do not plan on calling in to have my card number changed. I'll just keep a close eye on my statements (that, and I have alerts sent to my phone via SMS for any charge over $0.01, so I'd know pretty quickly)

Post reply on HN