<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Heartland Breach Hit At Its Unencrypted Point</title>
	<atom:link href="http://storefrontbacktalk.com/securityfraud/heartland-breach-hit-at-its-unencrypted-point/feed/" rel="self" type="application/rss+xml" />
	<link>http://storefrontbacktalk.com/securityfraud/heartland-breach-hit-at-its-unencrypted-point/</link>
	<description>Techniques, Tools and Tirades about Retail Technology and E-Commerce</description>
	<lastBuildDate>Wed, 08 Feb 2012 16:02:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: Jestep</title>
		<link>http://storefrontbacktalk.com/securityfraud/heartland-breach-hit-at-its-unencrypted-point/comment-page-1/#comment-53432</link>
		<dc:creator>Jestep</dc:creator>
		<pubDate>Wed, 28 Jan 2009 02:28:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.storefrontbacktalk.com/?p=1768#comment-53432</guid>
		<description>Looking at this from a network security standpoint, I can&#039;t see how there wasn&#039;t someone on the inside helping. Heartland is a large company, with extremely well protected and complex networks. The precision required to find the only spot on the network where this data is not encrypted and put a piece of software that can extract it without tripping any sort of intrusion detection or other alarm is just too unrealistic for me to buy into. Unless their security was grossly less than what should be required, putting any encryption aside, it&#039;s just not very likely that someone who hacked a random computer on the inside could access this point in one of their networks.

This really leads me to two possible conclusions. First, someone on the inside, most likely in IT or someone with a high level of network access, and a very high knowledge of exactly how their system works, helped plant the software so it couldn&#039;t be found either inherently or by the massive amount of data being extracted. Or second, Heartland had extremely weak security, unacceptably weak, and someone was actually allowed enough time to hack across multiple systems, and had enough time to find a very unique pathway of data, and had enough time to plant some software that was undetected, and extract this huge amount of data without ever being noticed for months.</description>
		<content:encoded><![CDATA[<p>Looking at this from a network security standpoint, I can&#8217;t see how there wasn&#8217;t someone on the inside helping. Heartland is a large company, with extremely well protected and complex networks. The precision required to find the only spot on the network where this data is not encrypted and put a piece of software that can extract it without tripping any sort of intrusion detection or other alarm is just too unrealistic for me to buy into. Unless their security was grossly less than what should be required, putting any encryption aside, it&#8217;s just not very likely that someone who hacked a random computer on the inside could access this point in one of their networks.</p>
<p>This really leads me to two possible conclusions. First, someone on the inside, most likely in IT or someone with a high level of network access, and a very high knowledge of exactly how their system works, helped plant the software so it couldn&#8217;t be found either inherently or by the massive amount of data being extracted. Or second, Heartland had extremely weak security, unacceptably weak, and someone was actually allowed enough time to hack across multiple systems, and had enough time to find a very unique pathway of data, and had enough time to plant some software that was undetected, and extract this huge amount of data without ever being noticed for months.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: A reader</title>
		<link>http://storefrontbacktalk.com/securityfraud/heartland-breach-hit-at-its-unencrypted-point/comment-page-1/#comment-53110</link>
		<dc:creator>A reader</dc:creator>
		<pubDate>Thu, 22 Jan 2009 19:35:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.storefrontbacktalk.com/?p=1768#comment-53110</guid>
		<description>You wrote: The most interesting part of his comments about the point of weakness in Heartlandâ€™s system, comments that should sound very familiar to most retail security folk: â€œWe have industry-leading encryption, but the data has to be unencrypted to request the informationâ€ from the card brands, Baldwin was quoted as saying. â€œThe sniffer was able to grab that authorization data at that point.â€

This statement, coupled with the almost countless retailer breaches, demonstrates the need for an industrywide rearchitecture of the fundamentals of credit/debit authorization.  Just as retailers are trying different schemes to avoid having unencrypted data, the fact that it still has to be cleartext to cross the interfaces between retailer and processor, and processor and bank, demonstrates the flaws in the system.

Data should be protected in the cardholder&#039;s hands and in the issuing bank&#039;s systems.  Nobody in between should ever be trusted with anything other than presenting or carrying encrypted data.  

This technology has existed for over a decade now.  The days of routing paper charge slips are over.  We don&#039;t need the credit industry continuing to expose the rest of us to horrendous risks because they can&#039;t modernize beyond carbonless paper.</description>
		<content:encoded><![CDATA[<p>You wrote: The most interesting part of his comments about the point of weakness in Heartlandâ€™s system, comments that should sound very familiar to most retail security folk: â€œWe have industry-leading encryption, but the data has to be unencrypted to request the informationâ€ from the card brands, Baldwin was quoted as saying. â€œThe sniffer was able to grab that authorization data at that point.â€</p>
<p>This statement, coupled with the almost countless retailer breaches, demonstrates the need for an industrywide rearchitecture of the fundamentals of credit/debit authorization.  Just as retailers are trying different schemes to avoid having unencrypted data, the fact that it still has to be cleartext to cross the interfaces between retailer and processor, and processor and bank, demonstrates the flaws in the system.</p>
<p>Data should be protected in the cardholder&#8217;s hands and in the issuing bank&#8217;s systems.  Nobody in between should ever be trusted with anything other than presenting or carrying encrypted data.  </p>
<p>This technology has existed for over a decade now.  The days of routing paper charge slips are over.  We don&#8217;t need the credit industry continuing to expose the rest of us to horrendous risks because they can&#8217;t modernize beyond carbonless paper.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cy Fenton</title>
		<link>http://storefrontbacktalk.com/securityfraud/heartland-breach-hit-at-its-unencrypted-point/comment-page-1/#comment-53093</link>
		<dc:creator>Cy Fenton</dc:creator>
		<pubDate>Thu, 22 Jan 2009 16:48:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.storefrontbacktalk.com/?p=1768#comment-53093</guid>
		<description>David - Is there any info on the customers of Heartland?  It would be interesting to hear from the retailers and restaurants that use Heartland for processing.</description>
		<content:encoded><![CDATA[<p>David &#8211; Is there any info on the customers of Heartland?  It would be interesting to hear from the retailers and restaurants that use Heartland for processing.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

