I normally don’t write much about what I do. However, there’s an article in today’s USA Today related to my specialty that is worth reading. According to a probe by Canadian Privacy Commissioner Jennifer Stoddart (why can’t we have one of those in the US, oh, right, nevermind), hackers stole millions of credit card numbers from discount retailer TJX by intercepting wireless transfers of customer information at two Miami-area Marshalls stores. How did they do this, you may ask.
(How did that do this?)
Funny you should ask. As background, retail wireless networks collect and transmit data via radio waves so information about purchases and returns can be shared between cash registers and store computers. Wireless transmissions can be intercepted by antennas, and high-power models can sometimes intercept wireless traffic from miles away. I’m sure you knew that.
The problem, according to Canadian officials, is that TJX used an encryption method that was outdated and vulnerable – Wireless Encryption Protocol (WEP). I’m sure you’ve heard of that. Theinvestigators said it took TJX two years to convert from WirelessEncryption Protocol to more sophisticated Wi-Fi Protected Access (WPA) standard,although many retailers had done so. TJX’s systems complied with industry standards when the breach started. In 2005, TJX decided to make the conversion and needed more time than some retailers because its systems weren’t compatible with the WPA standard. It completed the switch in time to remain in good standing with credit card associations like Visa and Mastercard, but no specific date was given.
TJX detected the breach by finding “suspicious software” on its computer systems in December 2006. By March, TJX said at least 45.7 million of its shoppers’ cards had been compromised. It has said about three-quarters of the cards had expired by the time of the theft or the stolen information didn’t include security code data from the cards’ magnetic stripes. Ten people were convicted in Florida this year for their roles in a ring using stolen TJX customer data to buy gift cards.
So, what should you learn from this, boys and girls. The more a system is out there, the more vulnerable it is. Exposure provides opportunity. So, if you are given the option of using a stronger encryption system, use it. And for G-d’s sake, if you must use wireless (I don’t unless I’m forced to), use encryption… and not WEP but WPA, if possible. If you’re going to be giving sensitive data over wireless, use encryption over the protocols (TLS, a VPN). Scan regularly for breaches. Protect your databases.
This public safety message has been brought to you by the number 43, and the letter Theta.

