<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Brad Heap &#187; Hacking</title>
	<atom:link href="http://www.bradheap.id.au/blog/tag/hacking/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.bradheap.id.au/blog</link>
	<description>One kiwi&#039;s news and views on politics, science, computers, god, religion, and other ramblings from Sydney, Australia</description>
	<lastBuildDate>Thu, 02 Feb 2012 08:11:01 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Auckland City Council&#8217;s Carparking Machines were hacked not skimmed</title>
		<link>http://www.bradheap.id.au/blog/2009/11/auckland-city-councils-carparking-machines-we-hacked-not-skimmed/</link>
		<comments>http://www.bradheap.id.au/blog/2009/11/auckland-city-councils-carparking-machines-we-hacked-not-skimmed/#comments</comments>
		<pubDate>Wed, 25 Nov 2009 22:34:09 +0000</pubDate>
		<dc:creator>Brad Heap</dc:creator>
				<category><![CDATA[Computers]]></category>
		<category><![CDATA[News & Current Events]]></category>
		<category><![CDATA[Auckland City Council]]></category>
		<category><![CDATA[Credit Cards]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.brad.net.nz/blog/?p=2139</guid>
		<description><![CDATA[Breaking news seems to be coming form the Twitterverse this morning. It appears that the Auckland City Council&#8217;s parking machines were storing the credit card numbers of all cards entered into the machines and the database storing this data has &#8230; <a href="http://www.bradheap.id.au/blog/2009/11/auckland-city-councils-carparking-machines-we-hacked-not-skimmed/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Breaking news seems to be coming form the Twitterverse this morning.</p>
<p>It appears that the Auckland City Council&#8217;s parking machines were storing the credit card numbers of all cards entered into the machines and the database storing this data has been hacked.</p>
<p>There is a discussion going on here at Public Address: <a href="http://publicaddress.net/system/topic,2226,hard-news-a-bigger-breach.sm" target="_blank">http://publicaddress.net/system/topic,2226,hard-news-a-bigger-breach.sm</a></p>
<p>There is no reason why after the transaction was processed for the council to store the credit card numbers unless they were using them as a form of tracking of people using the carpark, if this is the case they still should have never stored the credit card numbers, at a minimum a hash sum of the number would have worked. There appears to be much more to come on this story.</p>
<p>Update:</p>
<p>This just in from Mr A. Source:</p>
<blockquote><p>Auckland City&#8217;s PCI certification is under serious review which will compromise their ability to carry out any credit card transactions. This will also potentially impact the new Auckland Council. Basically, internal systems at Auckland City have been compromised.</p></blockquote>
<p><a href="http://publicaddress.net/system/topic,2226,hard-news-a-bigger-breach.sm?p=142117#post142117" target="_blank">http://publicaddress.net/system/topic,2226,hard-news-a-bigger-breach.sm?p=142117#post142117</a>
<div class="social4i" style="height:29px;">
<div class="social4in" style="height:29px;float: left;">
<div class="socialicons s4twitter" style="float:left;margin-right: 10px;background:url(&quot;http://goo.gl/zjqd1&quot;) no-repeat;"><a href="http://twitter.com/share" data-url="http://www.bradheap.id.au/blog/2009/11/auckland-city-councils-carparking-machines-we-hacked-not-skimmed/" data-counturl="http://www.bradheap.id.au/blog/2009/11/auckland-city-councils-carparking-machines-we-hacked-not-skimmed/" data-text="Auckland City Council&#8217;s Carparking Machines were hacked not skimmed" class="twitter-share-button" data-count="horizontal" data-via=""></a></div>
<div class="socialicons s4fblike" style="float:left;margin-right: 10px;">
<div id="fb-root"></div>
<p><fb:like href="http%3A%2F%2Fwww.bradheap.id.au%2Fblog%2F2009%2F11%2Fauckland-city-councils-carparking-machines-we-hacked-not-skimmed%2F" send="false" layout="button_count" width="100" height="21" show_faces="false" font=""></fb:like></div>
<div class="socialicons s4plusone" style="float:left;margin-right: 10px;"><g:plusone size="medium" href="http://www.bradheap.id.au/blog/2009/11/auckland-city-councils-carparking-machines-we-hacked-not-skimmed/" count="true"></g:plusone></div>
</div>
<div style="clear:both"></div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.bradheap.id.au/blog/2009/11/auckland-city-councils-carparking-machines-we-hacked-not-skimmed/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

