Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Depths Of TJX's Incompetence Continues To Astound
Techdirt ^ | 05-04-076 | Carlo Longino

Posted on 05/07/2007 9:23:37 AM PDT by em2vn

The TJX credit-card data breach -- the largest ever -- was sort of amazing, in that it went on for a few years before it was detected and disclosed. It was established at the outset that the company didn't comply with credit-card companies' strict security guidelines, but a story in today's Wall Street Journal spells out the depths of TJX's incompetence when it came to security. Investigators believe that the hackers used directional antennas to intercept signals sent over the WiFi networks at the company's stores, which were encrypted only with the easily cracked WEP standard, since TJX never bothered to update to WPA. You wouldn't think that would be too much of a problem, because apart from the network being encrypted, the company had installed other layers of encryption and security, right? Wrong. Once the hackers had gained access to the TJX network through a single store, they used keyloggers to get access to the company's central database at its headquarters, and they established their own accounts and the major theft began. Again, TJX made this easier on the crooks by transmitting credit-card data to banks without encryption. Banks continue to see claims from fraudulent activities related to the theft, and they're left holding the bag -- so it's little wonder some of them have sued TJX in hopes of recovering damages. This illustrates one of the biggest problems when it comes to identity theft and data protection: companies responsible for leaks and losses aren't typically the ones that have to deal with or pay for the fallout. For instance, in this case, TJX's financial liability has thus far been limited, and any fines it will have to pay will likely be minimal, despite its ridiculously shoddy security. The company has no incentive to enact better security if it feels no repercussions from a breach, so why should it bother? These misaligned incentives exacerbate the problem, and don't help anyone.


TOPICS: Business/Economy
KEYWORDS: tjx; wep; wifi
Gotta love the security used.
1 posted on 05/07/2007 9:23:39 AM PDT by em2vn
[ Post Reply | Private Reply | View Replies]

To: em2vn

ID theft is a very serious crime that is nowhere nearly punished hard enough.


2 posted on 05/07/2007 9:26:24 AM PDT by Hydroshock (Duncan Hunter For President, checkout gohunter08.com.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: em2vn

I was happy they caught the thieves, I think down in Florida.

They should try them alongside TJX management. They’d make very appropriate cellmates.


3 posted on 05/07/2007 9:31:24 AM PDT by SteveMcKing
[ Post Reply | Private Reply | To 1 | View Replies]

To: em2vn

TJ Maxx...my former employer. Not exactly doing the maxx for the minimum here, are they?


4 posted on 05/07/2007 9:40:40 AM PDT by pgkdan (Tolerance is the virtue of the man without convictions - G.K. Chesterton)
[ Post Reply | Private Reply | To 1 | View Replies]

To: em2vn

Cash


5 posted on 05/07/2007 9:54:43 AM PDT by Fudd
[ Post Reply | Private Reply | To 1 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson