Re: T.J. Maxx data theft worse than first reported



re:
http://www.garlic.com/~lynn/2007g.html#10 Record Credit card heist ...TJM
http://www.garlic.com/~lynn/2007g.html#15 T.J. Maxx data theft worse than first reported
http://www.garlic.com/~lynn/2007g.html#19 T.J. Maxx data theft worse than first reported

and a recent update:

TJX Intruder Had Retailer's Encryption Key
http://www.physorg.com/news94480989.html

from above:

Not that the culprit necessarily needed it. Data was apparently taken during the card-approval process before it was encrypted. These are among the latest details in what is almost certainly the worst retail data breach ever.

.... snip ...

i.e. the attacker was skimming the information as part of the initial transaction
process ... as opposed to waiting for a copy to be moved into some sort of transaction log and then harvesting that log.

for a little drift on the subject
http://www.garlic.com/~lynn/aadsm26.htm#44 Governance of anonymous financial services

all of this has been my periodic comment about "security proportional to risk"
http://www.garlic.com/~lynn/2001h.html#61

and/or that the attacker can possibly afford to outspend the defender by possibly
100:1
http://www.garlic.com/~lynn/2007f.html#75 Securing financial transactions a high priority for 2007

and/or that even if the planet was buried under miles of information hiding encryption,
it still wouldn't stop such leaks
http://www.garlic.com/~lynn/2007b.html#8 Special characters in passwords was Re: RACF - Password rules
http://www.garlic.com/~lynn/2007b.html#20 How many 36-bit Unix ports in the old days?
http://www.garlic.com/~lynn/2007b.html#60 Securing financial transactions a high priority for 2007
http://www.garlic.com/~lynn/2007c.html#10 Securing financial transactions a high priority for 2007
http://www.garlic.com/~lynn/2007c.html#33 Securing financial transactions a high priority for 2007
http://www.garlic.com/~lynn/2007c.html#53 Securing financial transactions a high priority for 2007
http://www.garlic.com/~lynn/2007d.html#34 Mixed Case Password on z/OS 1.7 and ACF 2 Version 8
http://www.garlic.com/~lynn/2007e.html#26 Securing financial transactions a high priority for 2007
http://www.garlic.com/~lynn/2007f.html#75 Securing financial transactions a high priority for 2007

.