Best Buy Learns That Data Protection Can Be A Customer Issue

Written by Evan Schuman
June 15th, 2006

When a Cincinnati man brought his hard-drive to Best Buy to be repaired, he was told that he couldn’t have his old hard-drive back. But fear not, he was told: the drive would be made useless by having holes drilled in it.

A few months later, the fully intact drive is purchased at a flea market in Chicago for $25. This story isn’t apocryphal. The hard-drive owner’s name is Hank Gerbus and the story was first reported by a Cincinnati TV station.

The lesson for retailers is that data security is not merely an internal issue to be dealt with by IT. It needs to be dealt with seriously if customers are going to trust that retailer.

Security issues today are getting more difficult to deal with, as the bad guys get more clever. Almost all of the shredders being used by small businesses and consumers turn out pieces of paper that can easily be re-assembled. Here’s a great lab test from Popular Mechanics where they showed how easily shredder output can be de-Humpty-Dumptied.

But the biggest fear is how to deal with data-intensive CDs, DVDs and hard-disks. Some of the same shredders that fare so poorly with regular paper also slash away at CDs and DVDs. Surely that will prevent them from being read? According to one security expert, it depends on how badly you want that data.

Roger Hutchison is president of Digital Data Destruction Inc. and he argues that few IT execs “realize the ease with which media can be put back together. Very imminently, someone is going to publish the recipe for an electronic data dumpster diver.”

The methods Hutchison says crooks may use sounds a bit complicated, but he argues that as technology improves over the next year or so, the reconstruction efforts will get a lot easier. Today, though, the technique involves photographing the CD or DVD with an optical microscope and “then you calculate the zeros and ones and you look it up. You photograph and then run it through a filter to decode the binary information,” he said.

“It takes about $10,000 for a computer pirate to put together the entire suite of tools,” Hutchison said. “A 14-year-old in Taiwan with the equipment can easily do it.”

The methodology that Hutchison prefers involves grinding the information layer “smaller than the retrievable alphanumeric size, which is about 250 microns.”


One Comment | Read Best Buy Learns That Data Protection Can Be A Customer Issue

  1. Stephen Gerard Says:

    Seems biased, since we work in this field, but we have seen the evidence to support this. Scary stuff. An officer at DHS coined the term Digital Pearl Harbor. While this was in a different context, it seem to be an accurate description of what might occur if an adversary of the US used this technique to attack, say, the US banking system. Who’s in charge of this security matter and how do we get the word out?


StorefrontBacktalk delivers the latest retail technology news & analysis. Join more than 60,000 retail IT leaders who subscribe to our free weekly email. Sign up today!

Most Recent Comments

Why Did Gonzales Hackers Like European Cards So Much Better?

I am still unclear about the core point here-- why higher value of European cards. Supply and demand, yes, makes sense. But the fact that the cards were chip and pin (EMV) should make them less valuable because that demonstrably reduces the ability to use them fraudulently. Did the author mean that the chip and pin cards could be used in a country where EMV is not implemented--the US--and this mis-match make it easier to us them since the issuing banks may not have as robust anti-fraud controls as non-EMV banks because they assumed EMV would do the fraud prevention for them Read more...
Two possible reasons that I can think of and have seen in the past - 1) Cards issued by European banks when used online cross border don't usually support AVS checks. So, when a European card is used with a billing address that's in the US, an ecom merchant wouldn't necessarily know that the shipping zip code doesn't match the billing code. 2) Also, in offline chip countries the card determines whether or not a transaction is approved, not the issuer. In my experience, European issuers haven't developed the same checks on authorization requests as US issuers. So, these cards might be more valuable because they are more likely to get approved. Read more...
A smart card slot in terminals doesn't mean there is a reader or that the reader is activated. Then, activated reader or not, the U.S. processors don't have apps certified or ready to load into those terminals to accept and process smart card transactions just yet. Don't get your card(t) before the terminal (horse). Read more...
The marketplace does speak. More fraud capacity translates to higher value for the stolen data. Because nearly 100% of all US transactions are authorized online in real time, we have less fraud regardless of whether the card is Magstripe only or chip and PIn. Hence, $10 prices for US cards vs $25 for the European counterparts. Read more...
@David True. The European cards have both an EMV chip AND a mag stripe. Europeans may generally use the chip for their transactions, but the insecure stripe remains vulnerable to skimming, whether it be from a false front on an ATM or a dishonest waiter with a handheld skimmer. If their stripe is skimmed, the track data can still be cloned and used fraudulently in the United States. If European banks only detect fraud from 9-5 GMT, that might explain why American criminals prefer them over American bank issued cards, who have fraud detection in place 24x7. Read more...

Our apologies. Due to legal and security copyright issues, we can't facilitate the printing of Premium Content. If you absolutely need a hard copy, please contact customer service.