| Author |
Replies: 28 / Views: 6,681 |
|
Pillar Of The Community
United States
6454 Posts |
|
|
Just received the following email overnight: Quote: Dear StampAuctionNetwork user,
We are very sorry to inform you that our SAN server was hacked on September 26, 2017. The attack did not target StampAuctionNetwork directly, we have SSL security there which protects from external attacks. The breach was made through our main offices and they were able access SAN from there.
For the most part we stopped collecting credit card information for StampAuctionNetwork auction firms and their clients years ago and have never collected or stored any social security numbers. Most of the credit card information that was compromised is 5-10 years old and has expired expiration dates.
If you are getting this email, it is because you had credit card infomation at StampAuctionNetwork with a 2017 or greater expiration date with one of the 4 firms that collected credit card info at SAN.
We have removed all credit card information from SAN and new security protocols to protect this from happening in the future.
Regards, - Tom Droege
|
|
Send note to Staff
|
|
|
|
|
|
Valued Member
44 Posts |
|
|
Surely, they can afford better protection for their very successful business. |
Send note to Staff
|
|
|
Pillar Of The Community
United States
6454 Posts |
|
|
Moderator

United States
12330 Posts |
|
|
Quote: ...we have SSL security there which protects from external attacks. The breach was made through our main offices and they were able access SAN from there... First, saying that SSL security protects from external attacks is a huge stretch. SSL only helps by encrypting the packets being sent to and from remote computers. The standard encryptions are generally cracked within a few months of being released. Additionally, I have already made a number of posts warning people that SSL is only a small fraction of a security picture and that it is far easier to simply go get a job at one of these places and get physical access to the servers and data. This sounds like it is exactly what happened, "breach was made through our main offices and they were able access SAN". I am dumbfounded at how much misinformation there is about IT security. There is some kind of misconception that there are people sitting around 'sniffing' packets off the internet from their bedroom or den. This is a very, very rare type of breach. One of the larger IT breaches occurred when a person poised as a pizza delivery man and was granted access to deliver a pizza to a server room. He had done this before and knew the person would leave him alone to gather cash from other employees to pay for the pies. He brought a USB stick with him. Another large breach occurred when the person was given access to a coffee shop server room where he installed his own wireless router and intercepted months of data from the area. And the number of cases where the breach occurred from employees is huge. Some of these were employees with grudges or simply thieves. In other cases people are hired when their intent all along is to steal personal and credit card data. Physical access is exponentially a bigger issue than someone trying to eavesdrop on the internet. SSL is not much more than a marketing gimmick to make user feel like they can send their personal info to a website with confidence. It is like telling people your house is secure just because you added some security to your phone line but leave you doors unlocked when you leave the house. ANY company that is requesting and getting personal info such as credit card data is at risk. It is going to take some class action suits and large jury awards to get these companies to fix the real physical access issues. IT/server rooms HAVE to be secure, people with physical access have to be bonded. This includes any storage of backups and backup media. If I had given my credit card to SANS, I would be on the phone with them right now demanding to know what their physical security was and how it got breached. I would also demand remuneration for the costs involved in taking the steps now required to lock down the credit card and/or change it. Don |
Send note to Staff
|
|
|
Pillar Of The Community
1515 Posts |
|
|
My message is slightly different. Quote: Your Credit Card Ending in xxxx with Expiration date 0805 may have been compromised. Please read the following. We suggest you cancel this card and request a new one, if this card is still active.
For the most part we stopped collecting credit card information for StampAuctionNetwork auction firms and their clients years ago and have never collected or stored any social security numbers. Most of the credit card information that was compromised is 5-10 years old and has expired expiration dates.
If you are getting this email, it is because you had credit card infomation at StampAuctionNetwork. 90% of the credit card info we had at SAN had expired expiration dates, but we are letting everyone know about any card they had at SAN.
We have removed all credit card information from SAN and placed new security protocols to protect this from happening in the future. |
Send note to Staff
|
|
|
Pillar Of The Community
United States
6454 Posts |
|
|
Yeah, I was on the phone having the card in question reissued within a half hour. At least SAN notified people within 2 days of the event... unlike Equifax who waited 6 WEEKS! to go public.
At my day job we made the conscious decision to configure our ecommerce such that our site/server never sees credit card information; that's all entered into an external 3rd-party payment gateway.
We do take credit card orders via fax, but (1) that fax machine is not connected to a computer network (old school analog phone line),and (2) the credit card information is indelibly blacked out as soon as the credit card terminal transaction is run (that information never gets entered into any computer device), and (3) pending orders do not go more than 4 business hours before being processed. |
Send note to Staff
|
|
|
|
Pillar Of The Community
United States
6454 Posts |
|
|
Quote: My message is slightly different. Yes, they subsequently sent me one like yours with the information about the affected card. The first emails that went out though, did not have that information. I had emailed Tom asking "How do I know which card(s) to cancel?" so they must have realized that people might have more than 1 card and need to know which cards are impacted. |
Send note to Staff
|
|
|
|
Pillar Of The Community
United States
1812 Posts |
|
|
I got both messages. Fortunately, the card in question for me had been canceled long ago (due to a hack elsewhere, as it happens). |
Send note to Staff
|
|
|
Pillar Of The Community
United States
1858 Posts |
|
|
The real problem is that consumers having a single credit card (or a small number of them) does not work in an online society in which card numbers are given to dozens of merchants. The solution is to make card numbers disposable which is what they have done at Final, see https://www.getfinal.com/. Chris |
Send note to Staff
|
|
|
Pillar Of The Community
United States
3503 Posts |
|
|
Quote: 2. For the 1000 out of 25,000 users that had their user id and password compromised. We changed all the affected passwords, and sent an email to each person instructing them to change their password. We also removed the password security question and answer for those users. This bothers the heck out of me. Don - I'd be interested in your take on the password issue. I write operating systems for a living, I don't administer systems, but I always thought that passwords were, or should be stored encrypted. In theory, that would make stealing them off of a server largely impossible. The main way that a password gets stolen is via some SSL hack where it is grabbed while being entered by the user, but prior to encryption at the server. So am I correct in assuming that SAN is probably storing our passwords un-encrypted?? ! |
Send note to Staff
|
|
|
Moderator

United States
12330 Posts |
|
|
Txstamp, Yes, sounds like it but this is not surprising. There are much larger companies than SANS with horrendous security practices. I was project manager for a nice embedded kiosk device; we designed everything from the motherboard on up and also had our own BIOS. It was a great device that supported any standard computer operating system and we sold a lot of them to integrators. One of the integrators developed Windows based software and landed a big deal with one the national phone companies. The kiosks sat in the retail locations and allowed customers to pay their bills, order new services etc.
The integrator also had a maintenance deal with the phone company to fix any field problems; the integrator then in turn returned the embedded computer to us if under warranty. They had the OS pretty well locked down, I only ever found one way to defeat the security on it but it was very difficult and involved physical access to the device and jumping through a lot of hoops. (And of course I also has intimate knowledge of the device.)
But while you certainly could not boot into the device without dealing with their security measures it was rather easy to simply take the drive out and hook it up to another computer as a secondary drive. That is IT 101. This gave you access to the entire file system on the kiosk. Imagine my surprise when I found log files with every transaction sitting in the file system unencrypted! Tens of thousands of credit cards, PIN numbers, names etc all sitting in text files on each kiosk! Needless to say, I don't enter my credit card info into their kiosks to this day.
But I also have worked on other embedded projects which went into gas pumps. These were rock solid including requirements to 'pot' the entire PCB in epoxy to prohibit tampering. The specs also required that it had to take over an hour to break into the device and have code which intentional destroyed any data if tampering was detected. I do use credit cards at gas pumps.
Of course back in the 'old days', few of us thought twice about handing credit cards to strangers at gas stations or restaurants.
But just like the old days, security varies from place to place. It is a crap shoot. Don
|
Send note to Staff
|
|
|
Pillar Of The Community
United States
3503 Posts |
|
|
Don - thanks for the response.
Real security for computers has been more of an illusion, rather than a reality for the last couple decades.
Tech companies are getting smarter about it these days, with things like the 2-stage authentication that a lot of banks, even apple, now require. That is forward progress, but there will always be some weak link. Even the Titanic sank.
The movement of all of our data collectively to "the cloud" is IMHO, the biggest technology security risk of this era. There is a lot of innovation going on now in the industry in this area, for security. In the end, however, you still need guards, maybe even the national guard, around cloud computer data centers. One wonders, are we better off with centralized data, and serious guards .. or decentralized data and often, no guards - probably like SAN. |
Send note to Staff
|
|
|
Moderator

United States
12330 Posts |
|
|
The only truly secure electronic device is one that is powered down, sitting in a lead lined vault, with armed guards surrounding it.
Like you, I do not trust 'cloud' storage. Frankly most companies do not want to discuss or describe security measures since it tips their hand and gives nefarious individuals more information. So when you ask questions you just get the standard canned replies 'our servers are in a salt mine 450 feet below ground level'. But if I cannot, for example, understand how they handle their off-site backup data including how it is stored and who has access, then I do not trust them. 'Gee, we give the backups to a guy who drives them to the other facility' also means he stops at McDonalds and leaves them sitting in his car.
The more smoke that gets blown the more nervous I get. The only really good IT security I have seen comes from companies who readily admit that they are facing an ongoing, daily battle to improve. No matter what security anyone comes up with there are thousands of people ready to spend untold hours in trying to defeat it.
Do not use ever the same password for long. Rotate your credit cards, PINs, and passwords often. Setup distinct bank accounts separate from your household and savings accounts and use only these when traveling and doing online transactions. Don
|
Send note to Staff
|
|
|
Pillar Of The Community
Finland
753 Posts |
|
|
Quote: So am I correct in assuming that SAN is probably storing our passwords un-encrypted?? ! Not necessarily... Many 'old school' systems use weak,self-made, and often times reversible encryption/ciphering functions to protect their precious. Basically it provides a slight speed bumb to hacker, nothing more. What is more interesting that they store credid card details in format that was 'crackable'. I would have thought that a 'big name' as them would have been forced to PCI compliance long since? -k- |
Send note to Staff
|
|
| Edited by scb - 09/28/2017 12:57 pm |
|
|
Bedrock Of The Community
12630 Posts |
|
|
Is it me of is this problem getting much worse lately. Over the past year I have had to replace cards 5 times because a bad actor was using them to purchase phone carss in India or video games. Driving me crazy. |
Send note to Staff
|
|
|
Pillar Of The Community
United States
2830 Posts |
|
|
The AMEX card I was informed about had been updated to a new number.... in May 2017. Bullet dodged, but not by much. It's a bit weird- Tom at SAN is an IT person, so this is a pretty big miss. |
Send note to Staff
|
|
Replies: 28 / Views: 6,681 |
|