• On CBSSports.com: Watch March Madness® Games Free Online
January 29, 2008 9:24 AM PST

Researcher: Be wary of going-out-of-business sales

by Robert Vamosi
  • Font size
  • Print
  • Post a comment

You might be tempted by the low, low prices, but going-out-of-business sales might come back to haunt you in the form of identity theft, says researcher Neal Krawetz of Hacker Factor. He posted a blog citing concerns over CompUSA closing all of its 103 stores. Bottom line: there currently is no regulation of or accountability for the sale of point-of-sale hardware that could contain credit card information and/or customer and corporate information.

Krawetz, who last year warned of existing vulnerabilities in how large chain stores regularly collect and store credit card information, says that customers need to be wary of businesses going out of business in general.

Mark Gertenbach, director of Sales and Operations Services at CompUSA, responded to Krawetz's blog, saying in part that "CompUSA isn't owned or run by CompUSA any more...the same company that owns dozens of other companies that are going out of business owns it now." Gertenbach also said "PCI compliance will not allow credit card information to be stored IN the POS."

Not true, says Krawetz.

"Last October a group of merchants formally requested changes to the PCI and card processing system. In particular, the credit card industry currently requires the storage of credit card information for as long as 18 months. The merchants want this requirement removed. Their argument is that thieves cannot steal what does not exist. However, the credit card industry has not yet addressed this request."

So, for the moment, most point-of-sale system hardware retains some transaction data, if not at the point of sale itself, then at branch servers that collect and store individual register sales data. It is the branch servers, Krawetz believes, that were hacked in the case of TJX and other retail stores.

Is this a real problem? Yes. In 2003, Massachusetts Institute of Technology graduate students Simson Garfinkel and Abhi Shelat bought some hard drives on the Web and at swap meets. Of the hardware they acquired, 129 of the 158 drives were still functional with 28 drives showing little or no attempt to erase the information. One drive even contained a year's worth of financial transactions.

Krawetz said on his blog site, "Although not the case of CompUSA, many bankruptcy and foreclosure auctions sell off confiscated property. The auction house rarely has the passcodes to clear PoS devices. In my experience, it is only when companies are upgrading their systems (and not going out of business), that they strive to wipe systems before an auction (and even then, they usually forget about cash registers)."

Should you patronize stores that are going out of business? I think it depends on your instinct--whether you feel the store will do the right thing. The right thing, in my opinion, would be for the store not to sell its point-of-sale hardware, or, at the very least, digitally wipe the data first. But I have no idea how many stores actually do either of these.

As CNET's resident security expert, Robert Vamosi has been interviewed on the BBC, CNN, MSNBC, and other outlets to share his knowledge about the latest online threats and to offer advice on personal and corporate security. Listen to his podcast at securitybites.cnet.com or e-mail Robert with your questions and comments.
Recent posts from Defense in Depth
Window Snyder to leave Mozilla
How to handle ID fraud's youngest victims
Is white listing going mainstream?
How Live OneCare changed the antivirus landscape
Express Scripts clients threatened with extortion
Study: DDoS attacks threaten ISP infrastructure
Security expert talks Russian gangs, botnets
Extortion used in Express Scripts database breach
advertisement
CNET River
  • image
    acedtect: New East Meets West is up Parties, Runaways and health care reform http://www.subbrilliant.com/emw/?p=351
    by Tom Merritt
  • image
    jdolcourt: Google maps nav a winner in the wilds of the Vegas foothills.
    by Jessica Dolcourt
  • image
    acedtect: Getting ready to start East Meets West live on TWiT at http://live.twit.tv/ with @jollyroger. What should we talk about?
    by Tom Merritt
  • image
    acedtect: Try that DRM crap in the 19th century, Ubisoft! http://www.myextralife.com/comic/comic-different-time-just-as-bad/
    by Tom Merritt
  • image
    antgoo: http://tweetphoto.com/15336249 When did they start selling these?
    by Antuan Goodwin
advertisement

Viacom, Google air dirty laundry in court docs

Copyright confrontation gets fierce. Viacom says YouTube founders always intended to build video version of Napster and looked for ways to "to avoid the copyright bastards."
• Google's statement on YouTube-Viacom

Google's fast pipe to Asia almost ready

An undersea cable built by a group including Google and telecom companies is set to start carrying traffic at any point, with Google to get as much as 20 percent of the capacity.

About Defense in Depth

Covering computer viruses and computer crime, Robert Vamosi goes beyond the hype to provide you with expert interviews of the top security researchers, as well as offering the hands-on, nontechnical advice you'll need to stay safe online.

Add this feed to your online news reader

Defense in Depth topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right