Barnes & Nobile Says 63 PIN Pads Hacked Nationwide

Status
Not open for further replies.
Its really nice of them to come clean and not sweep this crap under the rug...

The federal government really needs to come down hard on people that do this kind of stuff, since cash is more or less becoming obsolete, and people are using electronic payments more and more, this stuff really needs to be as secure as it can be.
 
A more important question is if the affected PIN pads are only at Barnes and Noble or if other retailers have compromised PIN pads. This could be much wider than one retailer.

I don't know about anyone else but I use these things all the time for groceries, hardware stores, gas, etc.
 
I'm curious as to how this was pulled off. I know pin pads / credit card terminals include several layers of security, from physical mechanisms such as firmware wipe / chip destruct from case switches to epoxy potted cipher chips and firmware chips with anti-probe mechanisms, to software mechanisms such as run time CRC checks to prevent memory address tampering, memory address randomization, etc. Someone knew their stuff to pull this off.
 
Maybe it was the installation contractor.
Seems to me it would have to be dismantled and modified offsite rather than while the staff are distracted for a few seconds.
 
Status
Not open for further replies.