Receive new posts as email.
RSS 0.91 | RSS 2.0
RDF | Atom
Podcast only feed (RSS 2.0 format)
Get an RSS reader
Get a Podcast receiver
| Sun | Mon | Tues | Wed | Thurs | Fri | Sat |
|---|---|---|---|---|---|---|
| 1 | 2 | 3 | 4 | 5 | ||
| 6 | 7 | 8 | 9 | 10 | 11 | 12 |
| 13 | 14 | 15 | 16 | 17 | 18 | 19 |
| 20 | 21 | 22 | 23 | 24 | 25 | 26 |
| 27 | 28 | 29 | 30 | 31 |
This site operates as an independent editorial operation. Advertising, sponsorships, and other non-editorial materials represent the opinions and messages of their respective origins, and not of the site operator or JiWire, Inc.
Entire site and all contents except otherwise noted © Copyright 2001-2006 by Glenn Fleishman. Some images ©2006 Jupiterimages Corporation. All rights reserved. Please contact us for reprint rights. Linking is, of course, free and encouraged.
Powered by
Movable Type
« Wee-Fi for May 3: St. Louis Wi-Fi, LA Bus-Fi, European Free-Fi | Main | Times Online Misreads UK Starbucks Evil Twin Attacks »
We all know (or should) that Wired Equivalent Privacy (WEP) isn’t real security: And that’s been known since at least 2001, as cracks become more and more efficient at breaking this first line of defense for a Wi-Fi network. Most recently, researchers showed they could crack WEP in as little as one to two minutes, which would overcome even 802.1X plus WEP, in which keys are unique to each user and changed frequently.
Two years ago, The Wall Street Journal reports, crackers monitored the Wi-Fi traffic outside a St. Paul, Minn., Marshalls, a chain of stores owned by TJX, which also owns TJ Maxx and Home Goods. They used this information to crack TJX’s main database, while the company was unaware of the intrusion for 18 months. From 45.7m to 200m credit card numbers were obtained. TJX says the latter number is too high, but told the Journal that it can’t know for sure. Private information like driver’s license numbers, social security numbers, and military IDs for 451,000 customers were also stolen.
TJX has hired 50 investigators to deal with the problem and will pay for fraud monitoring for those whose private information was taken. It’s unclear to me whether TJX is liable for the fraud committed using those stolen cards, having to repay Visa and MasterCard member banks.
The Journal says that TJX didn’t switch to WPA (Wi-Fi Protected Access) early enough—at least by 2005—and an audit they cite showed a lack of encryption and firewalls. The crackers broke into connections used by handheld devices used for inventory and other purposes, almost certainly equipment made by Symbol, the dominant player in that field. (No knock on Symbol: a safe network is the responsibility of the purchaser, and Symbol supported WPA just like everyone else.)
Remarkably, that’s practically all it took: they were able to grab central access passwords through the Wi-Fi network, which means that no real protection for credentials and replay was in place. With access to the central system, they could install their own software without detection, and then they exchanged messages with one another on the system itself! Good gravy.
TJX transmitted credit card numbers to banks without encryption, the Journal says the company noted in an SEC filing, which should be impossible. My guess is that explanation is slightly inaccurate. More likely, they retained and stored credit card numbers without encryption, because banks won’t accept insecure transactions for their back-end processing. The article notes, “A bill in Minnesota would bar any company from storing any consumer data after a transaction is authorized and completed.”
Posted by Glennf at May 5, 2007 10:10 AM
Categories: Security
TrackBack URL for this entry:
https://db.isbn.nu/mt3/mt-tb.pl/4547
This is one of the first major cases I've seen of WEP cracking actually leading to a major real-world intrusion.
Two things I want to add: 1) Symbol does have a lot of old equipment that has never been upgraded to WPA. TJX may be the main culprit, but I wouldn't absolve Symbol or Intermec completely because my suspicion is that they were too cheap to spend the software development money to get their older handhelds upgraded. 2) TJX security had to be damn weak in other areas. Even if WEP is cracked, there are ways to make sure the LAN is secure so that this scale of attack can't happen.
Posted by: Rusty at May 11, 2007 2:38 PM