BreachExchange mailing list archives

Re: TJX breach shows that encryption can be foiled


From: Chris Walsh <cwalsh () cwalsh org>
Date: Mon, 2 Apr 2007 17:41:40 -0500


On Apr 2, 2007, at 2:44 PM, Casey, Troy # Atlanta wrote:

It should make for a short list of suspects, assuming TJX was doing a
reasonable job of key management...

That (reasonable key management) is a critical assumption.

I'd be interested in learning what algorithm (and implementation  
thereof) they were using, as well.

Not holding my breath on that info :^)

cw
_______________________________________________
Dataloss Mailing List (dataloss () attrition org)
http://attrition.org/dataloss
Tracking more than 203 million compromised records in 609 incidents over 7 years.


Current thread: