AKIBIA'S PRACTICAL GUIDE TO ENTERPRISE TECHNOLOGY

Tuesday, September 20, 2011

Has it really come down to a bag of chips?

POSTED BY Tim Trow AT 7:56 AM 2 COMMENTS
  • Comment

A recent vending machine company had some of its POS systems compromised at waterparks in Wisconsin and Tennessee. This was a major breach…up to 40,000! Go figure. People can’t even buy some snacks or what not from a vending machine without having their credit card information compromised. Has it really come down to this? Unfortunately, this is very timely. With the recent anniversary of 9/11 and the horrific attacks that came that day from the sky, it is clear, or at least should be, that the bad guy is out there and will always try to find weaknesses in areas that are sometimes unusual or even very obscure. Computer hacking is no different. Someone decided to find a way to hack into a vending machine/POS system. It appears that credit card data was not encrypted from point-to-point, which would allow someone to ‘sniff” the network for unencrypted credit card data and then use this information for nefarious reasons. I wonder who signed off on the PCI SAQ or ROC for this company. It is not a good situation any way you look at it. Moral of the story, and only one piece of the pie, companies need to encrypt credit card data from point to point. This means from the physical POS system interface to the server storing credit card data or to the payment processor. This will eliminate someone being able to sniff card holder data over the wire.
 

Tim Trow is a Senior Consultant at Akibia.

LABELS:
Tim Trow,
Security,
PCI

Post a Comment

(never made public)
  • Remember my personal information
  • Notify me of follow-up comments?
Please enter the word you see in the image below:

  • By Bob 09/20/2011

    Thanks for the post!  Scary stuff.  Blog outlines that hackers are out there and always finding new ways to penetrate systems!

  • By Anthony 10/01/2011

    Hi,
    Great writing. Security is a must for such systems. Encryption should be done using smart algorithms and techniques as they are done for the internet when exchanging crucial data like credit card or personal information.

    Thank you for highlighting this point.
    Anthony