<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Angels of security &#187; TJ Maxx</title>
	<atom:link href="http://angelsofsecurity.com/blog/tag/tj-maxx/feed/" rel="self" type="application/rss+xml" />
	<link>http://angelsofsecurity.com/blog</link>
	<description>Musings of an infosec renegade</description>
	<lastBuildDate>Tue, 02 Aug 2011 19:01:53 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>ID theft and credit cards</title>
		<link>http://angelsofsecurity.com/blog/2008/08/11/id-theft-and-credit-cards/</link>
		<comments>http://angelsofsecurity.com/blog/2008/08/11/id-theft-and-credit-cards/#comments</comments>
		<pubDate>Tue, 12 Aug 2008 03:09:20 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[general]]></category>
		<category><![CDATA[credit cards]]></category>
		<category><![CDATA[identity theft]]></category>
		<category><![CDATA[TJ Maxx]]></category>

		<guid isPermaLink="false">http://angelsofsecurity.com/blog/2008/08/11/id-theft-and-credit-cards/</guid>
		<description><![CDATA[Over the last few days there have been a lot of headlines about how the US has cracked the biggest ID theft ring ever. Frankly it&#8217;s a load. Biggest? Perhaps. ID theft? Only by the worst definition. The suspects in question are alleged to have stolen 40 million credit card numbers by breaking into retailer&#8217;s [...]]]></description>
			<content:encoded><![CDATA[<p>Over the last few days there have been a lot of headlines about how the US has cracked the <a href="http://www.independent.co.uk/news/world/americas/us-cracks-biggest-identity-theft-ring-886196.html">biggest ID theft ring ever</a>. Frankly it&#8217;s a load. Biggest? Perhaps. ID theft? Only by the worst definition. The suspects in question are alleged to have stolen <a href="http://money.cnn.com/2008/08/05/news/companies/card_fraud/?postversion=2008080604">40 million credit card numbers</a> by breaking into retailer&#8217;s networks. (Most notably the much maligned <a href="http://www.google.com/search?sa=N&amp;tab=nw&amp;q=tj%20maxx%20hack">TJ Maxx</a>). The problem is that the US government defines stealing a credit card number as identity theft. This is the most inclusive definition but it&#8217;s also the worst. If someone steals your credit card number you simply cancel the card and are not held responsible for the fraudulent charges. No one can wreck your credit score or open a line of credit in your name. (For that they usually need your <a href="http://www.nytimes.com/2008/05/24/business/yourmoney/24money.html?_r=1&amp;oref=slogin">social security number</a>.)  Including credit card numbers in ID theft numbers artificially inflates them and makes for great scare tactics from companies like <a href="http://www.lifelock.com/">lifelock</a>, but doesn&#8217;t actually measure the real risk to your credit score. Some organizations that have no vested interest in scaring you (like the <a href="http://www.privacyrights.org">privacy rights clearinghouse</a>), but most simply use the largest and scariest number possible. It&#8217;s time for this tactic to stop. Stealing someone&#8217;s credit card number is not the same as stealing their identity, and if reliable crime statistics are important, then we need to stop equating the two.</p>
]]></content:encoded>
			<wfw:commentRss>http://angelsofsecurity.com/blog/2008/08/11/id-theft-and-credit-cards/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TJ Maxx fires whistleblower</title>
		<link>http://angelsofsecurity.com/blog/2008/05/29/tj-maxx-fires-whistleblower/</link>
		<comments>http://angelsofsecurity.com/blog/2008/05/29/tj-maxx-fires-whistleblower/#comments</comments>
		<pubDate>Fri, 30 May 2008 02:47:05 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[news]]></category>
		<category><![CDATA[pci]]></category>
		<category><![CDATA[security through obscurity]]></category>
		<category><![CDATA[TJ Maxx]]></category>

		<guid isPermaLink="false">http://angelsofsecurity.com/blog/2008/05/29/tj-maxx-fires-whistleblower/</guid>
		<description><![CDATA[A few other people have been all over this already, but TJ Maxx, victims of a rather large electronic break in a few years ago, has recently fired an employee for revealing many of their lax security policies. The issues he raised were not small ones either: Security was so lax at the TJ Maxx [...]]]></description>
			<content:encoded><![CDATA[<p>A few other people have been all over this already, but TJ Maxx, victims of a rather large electronic break in a few years ago, has recently <a href="http://www.theregister.co.uk/2008/05/23/tjx_fires_whistleblower/print.html">fired an employee</a> for revealing many of their lax security policies. The issues he raised were not small ones either:</p>
<blockquote><p>Security was so lax at the TJ Maxx outlet <a href="http://www.tjx.com/contact/storemap.aspx?sid=08-624" target="_blank">located in Lawrence, Kansas</a>, that employees were able to log onto company servers using blank passwords, the fired employee, Nick Benson, told <em>The Register</em>. This policy was in effect as recently as May 8, more than 18 months after company officials learned a massive network breach had leaked the details of more than 94 million customer credit cards.</p>
<p>Other security issues included a store server that was running in administrator mode, making it far more susceptible to attackers.</p>
<p>My store manager even posted the password and username on a post-it note.</p></blockquote>
<p>Lest anyone think this employee started off on the wrong foot, he did try to tell management first, but to no avail. It was only afterwards that he mentioned these things in public. Now whether he should have done this or not is clearly a matter that could be the subject of much debate. The issue which I feel more strongly about is the way TJ Max responded.</p>
<p>Firing this employee is, in my opinion, the worst form of <a href="http://en.wikipedia.org/wiki/Security_through_obscurity">security-through-obscurity</a>. Rather than realizing that lax policies lead to security problems, they think that it&#8217;s the <em>revelation </em>of lax policies that lead to security problems. A simple root cause analysis should reveal that it&#8217;s the policies, not their revelation, which is the source of security weaknesses, and it&#8217;s time for TJ Maxx to wake up.</p>
]]></content:encoded>
			<wfw:commentRss>http://angelsofsecurity.com/blog/2008/05/29/tj-maxx-fires-whistleblower/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

