Ask HN: Why is Target storing PIN numbers?
3 comments
Reports are that it was malware on the Point-of-Sale devices:
http://www.businessinsider.com/target-credit-card-hackers-20...
http://www.businessinsider.com/target-credit-card-hackers-20...
Target did not store the PINs. Storing PINs is forbidden by the PCI (Payment Card Industry) rules. If a merchant stores PINs or CVCs (Card Verification Code), he will lose access to the credit card system, and can't sell nuthin' no more.
The PINs were skimmed by malware in the POS devices.
Changing your PIN periodically is not a bad idea.
The PINs were skimmed by malware in the POS devices.
Changing your PIN periodically is not a bad idea.
The scale of the attack had me thinking the PINs were taken from a server. I feel much better with the answers provided here, but yeah, I'm still going to start changing my PIN periodically. At what frequency I'll have to see...
Thanks for all the answers.
Thanks for all the answers.
I think it was a man-in-the-middle attack, so everything during the transaction was stolen.
I'm seriously wondering why no one else is asking this question in the news, and I'm considering changing my PIN every week now.