Global Payments Breach: Big Authentication Lessons
Weaknesses in knowledge-based authentication and mag-stripe are highlighted in security experts' examination of the breach that affected credit card customers.
Anonymous: 10 Facts About The Hacktivist Group
(click image for larger view and for slideshow)
In spite of a Monday morning media conference call, details about the Global Payments breach that broke late last Friday remain sparse this week, but that hasn't stopped the security community from speculating about the potential lessons we might learn from this latest mega breach. Though the conjecture covers numerous angles, the thematic elements tend to converge on authentication: both at the administrator account level where many of these breaches occur, and at the card-holder level when transactions are processed.
According to a conference call early on Monday, Paul Garcia, Global Payments CEO and chairman, reported that early forensics reports from his company show the breach affected Track 2 data from approximately 1.5 million cardholders. He also claims only a small number of Global Payments servers were affected by the breach.
Beyond these few explanations, though, the details from the call were incredibly light and Global Payments did not field media questions following the call.
"He said none of their merchant systems were compromised. Well, then what was compromised?" asked Avivah Litan, VP and distinguished analyst for Gartner Research, venting her frustrations about the lack of details from Garcia. "Why do you tell us what didn't happen? Tell us what did happen."
According to Litan, her confidential sources tell her "a Central American gang broke into the company's system by answering the application's knowledge-based authentication questions correctly." At the same time, other sources told her that over the past few days that a yet-to-be-disclosed breach at a big New York-area taxi cab company could have had connections to the Global Payments breach. She also pointed to reports from Brian Krebs of KrebsOnSecurity.com, who first broke the story and who today mentioned that the company that hosts Global Payments website recently switched to Amazon EC2 and also that he'd been contacted by a hacker who claimed Global Payments end-to-end encryption was circumvented by an inside source.
As businesses rely increasingly on tablets for the productivity benefits they provide, IT must address the security challenges the devices present. Find out more in our Security Pro's Guide To Tablet PCs report. (Free registration required.)
Published: 2014-07-29 WebAccess in Zarafa before 7.1.10 and WebApp before 1.6 stores credentials in cleartext, which allows local Apache users to obtain sensitive information by reading the PHP session files.
Published: 2014-07-29 Multiple directory traversal vulnerabilities in GNU C Library (aka glibc or libc6) before 2.20 allow context-dependent attackers to bypass ForceCommand restrictions and possibly have other unspecified impact via a .. (dot dot) in a (1) LC_*, (2) LANG, or other locale environment variable.
Published: 2014-07-29 Multiple cross-site scripting (XSS) vulnerabilities in IBM Atlas Suite (aka Atlas Policy Suite), as used in Atlas eDiscovery Process Management through 6.0.3, Disposal and Governance Management for IT through 6.0.3, and Global Retention Policy and Schedule Management through 6.0.3, allow remote atta...
Published: 2014-07-29 Ubiquiti UniFi Controller before 3.2.1 logs the administrative password hash in syslog messages, which allows man-in-the-middle attackers to obtains sensitive information via unspecified vectors.
Published: 2014-07-29 install.sh in the Embedded WebSphere Application Server (eWAS) 7.0 before FP33 in IBM Tivoli Integrated Portal (TIP) 2.1 and 2.2 sets world-writable permissions for the installRoot directory tree, which allows local users to gain privileges via a Trojan horse program.