Target confirms PIN data was stolen in breach(money.cnn.com)
money.cnn.com
Target confirms PIN data was stolen in breach
http://money.cnn.com/2013/12/27/technology/target-pin/index.html
2 comments
"Target ... said the PINs are 'strongly encrypted'"
Take this with a huge grain of salt. White hat analysis of the hacked Adobe database shows that "strong encryption" is only a very small piece of the puzzle for securely storing sensitive data.
Take this with a huge grain of salt. White hat analysis of the hacked Adobe database shows that "strong encryption" is only a very small piece of the puzzle for securely storing sensitive data.
From what I understand, PCI mandates that at least the terminals all have their own (re-used) encryption keys; but that wouldn't fit with their story that the "key never existed within their systems"; unless that's them being a bunch of weasels due to a technicality (perhaps they themselves do not actually own the terminals?)
Is there a source with more technical details available?