Showing posts with label TJX. Show all posts
Showing posts with label TJX. Show all posts

Wednesday, September 26, 2007

Kiosk not found to be cause of TJX security breach

A few weeks ago we speculated (with the help of some other speculation) that the security breach at TJX (the company that owns TJ Maxx, Marshalls and others) could have been caused by hackers who used unattended employment application kiosks to gain access to the firm's corporate network. Both Information Week and StorefrontBacktalk suggested that the kiosks were a reasonable vector into the net, especially since many suggested that it was not firewalled away from other connected devices.

However, this story in the WSJ today suggests that was not the case at all. Instead, the privacy commissioners of Canada and the province of Alberta (who jointly conducted a probe), found that:
"TJX was using a weak encryption protocol to protect its consumer data in July 2005, when hackers first broke into its computer system. The protocol, known as Wired Equivalent Privacy, or WEP, isn't recommended by securities experts even for wireless home networks because it is so vulnerable to hackers.

"TJX decided to upgrade to a more secure Wi-Fi Protected Access encryption protocol at the end of September 2005, Canadian officials said. By then, however, hackers had been able to access the company's internal transaction database. They did so initially from outside two stores in Miami, the probe found."
While this isn't the only investigation going on inside the company, and it's possible that others will find additional ways past the firm's security systems, at least for now it looks like kiosks were not directly at fault for causing the breach and subsequent theft of up to 45.7 million credit card numbers.

Tags: , ,

Saturday, August 11, 2007

No firewall + windows registry entry = BAD!

I can't claim the title as my own, as I pilfered it from a colleague who forwarded me this story from Storefront Backtalk about the now-infamous hacker breakin at TJX that led to the theft of hundreds of thousands of credit card numbers and other personal information. While the company had attributed the theft to rogue hackers who had infiltrated the company's wifi network from a nearby parking lot, it now looks as like the attackers may have instead used an unprotected kiosk as the entry vector. The kiosk in question is normally used for taking employment applications (you've probably seen them at your local department store or supermarket). The current theory is that the attackers opened the back of the kiosk and attached a USB drive to the device that was then able to download software onto the kiosk's hard disk, and ultimately the corporate network (which it was connected to directly, sans firewall). Once inside the network, the attackers made quick work of any other security precautions, and went on to steal the data.

So let's do a quick review of what went wrong:

  1. Access to the employment kiosks' innards (e.g. computer hardware) was not restricted (why on earth weren't these locked?)
  2. The computers' USB ports were not disabled, even though they served no purpose on the kiosk.
  3. The kiosks were running an operating system that could somehow be fooled into loading arbitrary software from a USB key
  4. The kiosks were connected to the corporate network WITHOUT A FIREWALL
And of course that partial list leaves off other burning questions, like how store employees didn't notice somebody messing around with the kiosk's innards right inside the store?

Yet, as bad as each of these problems is, they were all avoidable.

For #1, a simple padlock (key or combination) would have done fine. Padlock holes are standard issue on lots of computer cases, and most kiosks come with locking doors.

As for #2, disabling unused USB ports can often be done from the BIOS (which itself can be password protected), but if that option isn't viable, a little crazy glue works wonders.

While I normally don't flog WireSpring's products in this blog, our FireCast kiosk operating system was designed with #3 in mind. We've gone through VISA's PCI compliance testing and PABP certification process, as should pretty much anybody working inside a retail environment these days.

As for #4... well... I'm just dumbfounded. How anybody can put a device on a network these days that ISN'T behind a firewall is just beyond me. I can only hope that TJX's lesson is being learned by others who will now go and re-examine their current customer-facing applications to make sure they're as locked-down and secure as possible.

Tags: , ,