FlyerTalk Forums - View Single Post - Data Breach
Thread: Data Breach
View Single Post
Old Dec 28, 2015 | 10:19 pm
  #58  
edcho
10 Countries Visited
20 Countries Visited
30 Countries Visited
10 Years on Site
 
Join Date: May 2011
Posts: 5,815
Originally Posted by notquiteaff
That is quite unlikely. The payment server isn't someone's desktop that gets used for surfing the web. Chances are in doesn't even have a browser installed.
Um... but if the malware is where the PMS software is, the credit card is swiped and passed onto the software usually unencrypted unfortunately. It's worse when the PMS software is hosted (like Micros Opera in the cloud which a lot of Hyatts + other chains have... and I manage).

It's funny because even PMS installers will refuse to store CC #s at any property because they know how insecure most systems are from top to bottom.

Chip and Sig/PIN is supposed to change that (with one time auth tokens) but the tech to deploy it isn't easy and very immature to deploy it on any scale (and Oracle is making a mess with Micros which doesn't help things in terms of interfaces).

Still not too happy that Hyatt is not making the investigation any more transparent.
edcho is offline