I want to clear some things up on the Target breach front. There are hundreds of bloggers making accusations and assumptions that are unfounded and simply incorrect. I get I’m just going to give you a list here. No fluff, no opinion, just fact.
False Statement #1: Target couldn’t have been PCI compliant because attackers stole CVV numbers and storing of numbers violates PCI.
Facts: Nowhere have I read a factual account from Target or law enforcement that says the CVV was being stored. The CVV is read from the magnetic stripe at the PIN pad and transmitted to the POS. It could have been intercepted during transmission. Now, the data transmission between the PIN pad and POS is typically encrypted so we can assume that the data was probably stored somewhere and stolen. If you are going to make assumptions, state them in your post or article.
False Statement #2: Target couldn’t have been PCI compliant because it took them 18 days to discover the breach. They obviously weren’t doing their daily security monitoring.
Facts: Networks are complex. Applications are complex. Attacks are complex. Obviously there was some security monitoring going on. Sometimes it takes time to recognize an attack, investigate it and address the issues. This isn’t Hollywood. We don’t save the world in a 42 minute episode. Is it likely that Target will need to change their security monitoring procedures? Yep. Can anyone say they weren’t monitoring at all? Nope.
False Statement #3: This breach was timed specifically for the holiday shopping season.
Facts: Did the hackers themselves proclaim this? While it is entirely possible that this was a timed breach, it’s also just as likely that the hackers were simply lucky. Hackers strike while they can. It only takes one patch to foil a well-planned breach attempt. I’m not saying the intent may have been to hack during the holiday season but we don’t know that for certain just because it occurred during the holiday season.
In essence, I’ve been very frustrated with the coverage of all this over the past 10 days. Expert after expert has been on this news program and that claiming all these “facts” when in fact all they have at this point are opinions. Oh…and because it’s sensational news, the journalists are calling them out on it. They let the opinions stand as fact. What has become of journalistic integrity?