-
Path: news-archive.icm.edu.pl!mat.uni.torun.pl!news.man.torun.pl!newsfeed.pionier.net
.pl!news.glorb.com!border1.nntp.dca.giganews.com!nntp.giganews.com!newscon06.ne
ws.prodigy.com!prodigy.net!newsmst01b.news.prodigy.com!prodigy.com!postmaster.n
ews.prodigy.com!newssvr14.news.prodigy.com.POSTED!56adf23e!not-for-mail
From: AP <c...@e...dyndns.org>
Newsgroups: pl.biznes.banki
Subject: Re: gigantyczny skandal w Citibanku
Message-ID: <M...@n...dallas.sbcglobal.net>
References: <s...@d...darkdomain>
<m...@d...localdomain>
Organization: Ap
X-Newsreader: MicroPlanet Gravity v2.30
Lines: 73
NNTP-Posting-Host: 70.251.79.240
X-Complaints-To: a...@p...net
X-Trace: newssvr14.news.prodigy.com 1142094448 ST000 70.251.79.240 (Sat, 11 Mar 2006
11:27:28 EST)
NNTP-Posting-Date: Sat, 11 Mar 2006 11:27:28 EST
X-UserInfo1: TSU[@I_AOHVSSTXYKRHD]_HBWB]^PCPDLXUNNHXIJYWZUYICD^RAQBKZQTZTX\_I[^G_KGFN
ON[ZOE_AZNVO^\XGGNTCIRPIJH[@RQKBXLRZ@CD^HKANYVW@RLGEZEJN@\_WZJBNZYYKVIOR
]T]MNMG_Z[YVWSCH_Q[GPC_A@CARQVXDSDA^M]@DRVUM@RBM
Date: Sat, 11 Mar 2006 16:27:28 GMT
Xref: news-archive.icm.edu.pl pl.biznes.banki:379883
[ ukryj nagłówki ]In article <m...@d...localdomain>, k...@p...waw.pl says...
> Jacek Popławski <j...@i...pl> writes:
>
> > Podobno problem dotyczy USA, UK i Rosji, czy ma to jakiekolwiek
> > przełożenie na
> > polskie realia? Z którym bankiem w Polsce ma coś wspólnego Citibank?
> >
> > http://www.computerworld.com/databasetopics/data/sto
ry/0,10801,109308,00.html
>
> To jakis nonsens, skimming i PINy? Wyglada na to, ze dane o kartach
> (i PINach) po prostu wyciekly z banku. Moze z niezadowolonym
> pracownikiem? Raczej sie tego nie dowiemy, ale pokazuje to zagrozenie
> w podpisywaniu transakcji PINem lub innym np. kodem jednorazowym.
>
Nie dotyczy sie to tylko Citi ale kilku innych wiekszych bankow w
stanach. Firma przetwarzajaca tranzakcje z urzyciem PIN w
"niweyjasniony" sposob w historii tranzakcji przechowywala takze
informacje o pinach.
More banks in the US are reissuing debit cards following the security
breach at an undisclosed retailer that forced Citibank to block PIN-
based ATM transactions on card accounts in Canada, Russia and the UK
earlier this week.
Regional US banks including PNC Financial, National City and First
National Bank of Pennsylvania, have scrambled to close accounts and
reissue debit cards following the breach. The banking industry has yet
to issue a definitive statement on the incident, but it appears
increasingly likley that the nation's banks have fallen victim to an
industrial-scale hacking and card-skimming fraud.
Earlier this week Citibank imposed transaction blocks on an unspecified
number of US card accounts after a series of fraudulent cash withdrawals
at ATMs in the UK, Russia and Canada. The bank indicated that security
problems stem from a breach at a US retailer, although no company name
was disclosed.
National US banks including Bank of America, Wells Fargo and Washington
Mutual have also blocked and reissued debit cards in recent weeks.
Previously PIN-based debit cards were thought to be safe from hackers,
but Gartner analyst Avivah Litan says the banks' actions show that this
incident is one of "the largest PIN thefts to date", in which the
fraudsters not only collected card numbers, but also encrypted PIN data
and terminal keys for unscrambling the codes.
"Armed with the PIN block and terminal encryption key, the thieves can
determine a cardholder's PIN, then create counterfeit cards that enable
them to withdraw cash at ATM machines," says Litan.
Analysts believe the incident may lead the US banking to reconsider its
resistance to chip-based payment cards and force a nationwide flight
from the less-secure mag-stripe standard.
Although the name of the retailer that suffered the breach hasn't been
disclosed, speculation is mounting that the debit card data was obtained
during an incident at office-supply firm OfficeMax although the company
has denied any involvement in the incident.
The Payment Card Industry Data Security Standard (PCI), which defines
how card and cardholder data should be managed and processed to keep it
secure, expressly forbids retailers from storing PINs online, although
compliance with the standard is believed to be under 20% in the US.
Congressman Barney Frank, the senior Democrat on the house financial
services committee recently called on credit card companies to name and
shame retailers who suffer security breaches.
Frank said he was considering introducing legislation that would force
companies that have suffered security breaches to notify customers of
the incident, or be identified publicly as the party responsible.
Następne wpisy z tego wątku
- 11.03.06 16:30 AP
- 11.03.06 16:45 Jacek Popławski
- 11.03.06 20:14 Seba
- 11.03.06 20:43 Krzysztof Halasa
- 12.03.06 09:56 Seba
- 12.03.06 13:53 witek
- 12.03.06 15:53 AP
- 12.03.06 18:13 Seba
- 12.03.06 20:21 Krzysztof Halasa
- 12.03.06 21:13 witrak\(\)
- 13.03.06 03:17 AP
- 13.03.06 10:10 Krzysztof Halasa
- 18.03.06 06:08 witrak\(\)
- 18.03.06 23:52 Krzysztof Halasa
Najnowsze wątki z tej grupy
- Co nalezy do Cinkciarza, a co do Conotoxia ?
- jak tacy debile
- Konto wspólne w N26.
- Bank z archaicznym uwierzytelnianiem.
- Re: Akumulatorki...
- Usiłuję zapłacić za energetyzację...
- w Polsce jest kryzys
- mBank mKsiegowosc
- gotówkowe zjeby
- Mamy WZROST! O 50% wzrosła ilość kredytów gotówkowych
- Jutro to dziś...
- leć gołombeczku
- PUE ZUS -- administracyjna nuda...
- Prawdziwy/fałszywy bank
- Velo dał mi bezpłatny debet...
Najnowsze wątki
- 2024-12-23 Co nalezy do Cinkciarza, a co do Conotoxia ?
- 2024-12-21 jak tacy debile
- 2024-12-13 Konto wspólne w N26.
- 2024-12-09 Bank z archaicznym uwierzytelnianiem.
- 2024-12-04 Re: Akumulatorki...
- 2024-12-03 Usiłuję zapłacić za energetyzację...
- 2024-11-13 w Polsce jest kryzys
- 2024-11-12 mBank mKsiegowosc
- 2024-11-06 gotówkowe zjeby
- 2024-11-01 Mamy WZROST! O 50% wzrosła ilość kredytów gotówkowych
- 2024-11-01 Jutro to dziś...
- 2024-10-22 leć gołombeczku
- 2024-10-19 PUE ZUS -- administracyjna nuda...
- 2024-10-15 Prawdziwy/fałszywy bank
- 2024-10-13 Velo dał mi bezpłatny debet...