I heard there was a lot of talent here and there's more than I expected. |
Most disturbing is, since stored-value cards can be cashed out by an employee at the register at any time, an attacker could cash out altered cards obtained at little or no monetary cost. If a card is cashed out, its serial number does not appear to be invalidated in the system. If an attacker were to clone a known good card and cash it out, the clone would still be usable. |
We had a lot of long days at practice to get here. |