Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Target Breach: Why Smartcards Wont Stop Hackers
Newest First  |  Oldest First  |  Threaded View
<<   <   Page 2 / 3   >   >>
User Rank: Strategist
1/26/2014 | 8:55:37 AM
Re: Smart cards won't stop hackers - but they remove the incentive
Online fraud typically only includes the primary account number and the CVV code. However, one-time use credit cards can resolve that issue. Moving to EMV for card-present payments and bank-supported disposable one-time use card numbers for online purchases may combine to be the safest solution.
User Rank: Ninja
1/25/2014 | 8:38:14 AM
Re: Exempted from PCI Compliance?
It doesn't, but that was the outcome of a court case with a settlement approved by a judge. Judges are experts in law, but understandably lack the knowledge of many areas they have to decide on. My guess it was the same in this case. Just look at the many tech patent cases, the verdicts often lack any common sense and typically do not take long term impact into account. It is difficult for a court to find the fine line between acting upon law versus making new laws and political policy decisions.
User Rank: Ninja
1/25/2014 | 8:34:07 AM
Re: When can we expect better online use of chipped cards?
As with many things, it is a matter of price but even more so the US typical "not invented here" syndrome. Something that works great in Europe and Asia can by no chance work in the US. For that reason we still endure Never The Same Color TV broadcasts, wall outlets that by design are an electrocution hazard, expensive consumer satellite TV service (no extra charge for Europe on the Astra and Eutelsat systems), slow broadband at twice the price, frequent power outages, new roads that need fixing one year later....the list is long and for every issue there is already an established and proven solution that may cost a bit more upfront, but saves everyone tons of money in the long run. But since it is not invented here or no longer hip with the conservative crowd (e.g. high speed rail and favroing rail freight over trucks) it will never get introduced in the US unless there are constantly high price failures. Another example? Sure, rail cars for oil transport! Since decades much safer rail cars are available and proven to be effective protection in derailments. But I guess for the US it is cheaper to have the few dozen people die and half a town get burned down than spend the money on safety. And in regards to payment security, just look how great TJX is doing. They survived the biggest credit card data breach in history and it was nothing more than a footnote in an annual report. It seems as if one is looking for common sense they need to move away from the US.
User Rank: Ninja
1/25/2014 | 8:24:11 AM
Re: Smart cards won't stop hackers - but they remove the incentive
Actually, the chip data can be counterfeited, but at a tremendously larger effort than coding a 1 cent mag stripe card. That might just be sufficient to make it not worth while the effort at least for in person purchases. Online fraud would be the preferred option as the numbers clearly show. The alternative approval process as some advertise now would be one option, but even that could be compromised as long as hackers accummulate enough intel on a person. And it puts the burden on the consumer who not only has to do more without getting any more protection (with or without the consumer is only liable for 50$ of a fraudulent transaction) and it requires expensive smartphones with as expensive data plans.
User Rank: Ninja
1/25/2014 | 8:16:46 AM
It all comes down to money
As soon as a breach of the Target scale will be generating so many damage claims and fines that it would even put a big retailer out of business the EMV systems are in place within months. Both the card industry and retailers consider it cheaper to pay the damages and some petty fines in these cases, but otherwise not care if it ruined the lives of thousands of families.

The discussion is a bit misguided if the EMV systems are not as secure as they seem. The card industry and retailers should seek cases like Target as the opportunity for a positiive campaign and design and implement the most secure payment system ever. But I guess Target will be flip flopping on that as well, Target just sucks.
User Rank: Apprentice
1/24/2014 | 7:45:35 PM
The cynical perspective
This is America, and as I understand it, everything is driven by money. This technology reduces fraud/theft, and thereby saves money. Sounds to me like this could justify reduced charges to retailers which should be all it takes to convince them to get on board. Of course I'm ignoring one detail, the bannks will consider the better security to be a benefit and therefore charges will be increased since, as banks have demonstrated on many occasions, the only thing that interests them is more profits. No wonder it's not been adopted yet.
User Rank: Apprentice
1/24/2014 | 6:21:52 PM
Target Breach: Smartcards
If the perpetratrors had hacked the Target servers, then of course, EMV cards could not have saved the situation. However, a PCI compliant POS terminal with an EPP, would have helped to avoid PIN compromise for EMV cards even if the card numbers were illegally captured. It seems that the obduracy of the US retailers has been the prime cause for the perpetratrors to succeed in this massive onslaught. No wonder, we keep reading about the impending 'death' of retail
User Rank: Apprentice
1/24/2014 | 1:08:40 PM
Smart cards won't stop hackers - but they remove the incentive
Stopping the hackers is not the purpose of EMV chip cards.  PCI security compliance is supposed to do that, and everyone knows that applying network security only against hackers is an arms race that merchants can't win.  EMV chip card data behind the firewalls erected by merchants to prevent hackers from getting in makes those merchants less of a target.  Remove the magnetic stripe data and replace it with chip data, which can't be counterfeited and lacks all the elements neccesary for online fraud, and you eliminate the incentive to break in.  EMV chip cards is the best defense merchants have to avoid being the next target.
User Rank: Apprentice
1/24/2014 | 12:36:00 PM
When can we expect better online use of chipped cards?
There are many banks in Europe (all the one I deal with) who provide a device which can be used to login to the online banking web site and also to confirm any online transaction on these sites.

So it seems to me that if "the world" adopted such simple technology we could get way better security around online financial transaction (and possibly even for non-financial ones).

The main problem is that there does not seem to be an agreed upon standard for such device and my experience with the banks I refer to above is that each has got its own device and apparently they are not fully compatible.

Another problem is price: someone will have to pay for the device and even if they are not very expensive (I pay a fee of about 50$ to obtain such device and they last 5 years) this cost may be difficult to justify for infrequent use. If "the world" was adopting a standard for such a device, I am sure 3rd party would be building and selling such devices and pricce would drop to a more acceptable 2-5$.
Lorna Garey
Lorna Garey,
User Rank: Ninja
1/24/2014 | 11:19:01 AM
Transactions without the card?
These chipped cards do nothing for online or phone purchases either, right?

In terms of PCI, seems like the carrot part of the carrot/stick duo. PCI audits are costly and of questionable value. So, let retailers spend that money to upgrade their devices.
<<   <   Page 2 / 3   >   >>

I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Current Issue
The 10 Most Impactful Types of Vulnerabilities for Enterprises Today
Managing system vulnerabilities is one of the old est - and most frustrating - security challenges that enterprise defenders face. Every software application and hardware device ships with intrinsic flaws - flaws that, if critical enough, attackers can exploit from anywhere in the world. It's crucial that defenders take stock of what areas of the tech stack have the most emerging, and critical, vulnerabilities they must manage. It's not just zero day vulnerabilities. Consider that CISA's Known Exploited Vulnerabilities (KEV) catalog lists vulnerabilitlies in widely used applications that are "actively exploited," and most of them are flaws that were discovered several years ago and have been fixed. There are also emerging vulnerabilities in 5G networks, cloud infrastructure, Edge applications, and firmwares to consider.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2023-03-17
The Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the full name value in versions up to, and including, 21.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that w...
PUBLISHED: 2023-03-17
The WP Express Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the &acirc;&euro;&tilde;pec_coupon[code]&acirc;&euro;&trade; parameter in versions up to, and including, 2.2.8 due to insufficient input sanitization and output escaping. This makes it possible for authenti...
PUBLISHED: 2023-03-17
A vulnerability was found in SourceCodester Student Study Center Desk Management System 1.0. It has been rated as critical. This issue affects the function view_student of the file admin/?page=students/view_student. The manipulation of the argument id with the input 3' AND (SELECT 2100 FROM (SELECT(...
PUBLISHED: 2023-03-17
A vulnerability classified as critical has been found in SourceCodester Student Study Center Desk Management System 1.0. Affected is an unknown function of the file Master.php?f=delete_img of the component POST Parameter Handler. The manipulation of the argument path with the input C%3A%2Ffoo.txt le...
PUBLISHED: 2023-03-17
A vulnerability classified as critical was found in SourceCodester Student Study Center Desk Management System 1.0. Affected by this vulnerability is an unknown functionality of the file admin/?page=reports&amp;date_from=2023-02-17&amp;date_to=2023-03-17 of the component Report Handler. The manipula...