Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I wonder if Target stores their customers cardholder PIN numbers still [1].

[1] https://www.theguardian.com/world/2013/dec/27/target-hackers...



According to your own linked article, target does not store the PIN numbers.

What happens is, the PIN pad encrypts the PIN code and other payment info, using a key known only to the card issuer (i.e. VISA). This encrypted data then finds it way to the card issuer (e.g. Visa) for verification via one of a few possible paths, either PSTN dialup, or more common these days, over the internet. In the Target incident, hackers grabbed this data as it was being transferred over the LAN.

(For completeness, there are many more organisations this encrypted data passes through between the merchant and card issuer, but nobody but the card issuer can decrypt it)

Also, it's incredibly off topic for the post. I'll bet that's why your getting all the downvotes.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: