back to article Thieves steal 35.5M customers’ data from Vans sneakers maker

VF Corporation, parent company of clothes and footwear brands including Vans and North Face, says 35.5 million customers were impacted in some way when criminals broke into their systems in December. The announcement was made in a Thursday 8-K/A filing with the Securities and Exchange Commission (SEC), and we're only left to …

  1. Colin Miller
    Holmes

    Why do they need customers' SSN?

    What legitimate reason does a webstore need for its customers' SSN number?

    Postal and email address, yes. Credit card numbers ideally should be kept on a different server, and passwords should be salted.

    But I can see no reason for the SSN, nor what they would do with it

    1. Catkin Silver badge

      Re: Why do they need customers' SSN?

      SSN is a good way to uniquely identify US residents without the pitfalls of things like the birthday paradox and culturally common names. The problem is that it's grown legs and become a form of ID verification, which is terrible. Because of said leg growing, it's a bad idea for it to be held by a shop but, in the long term, businesses need to move away from using it as a verification code.

      1. Necrohamster Silver badge

        Re: Why do they need customers' SSN?

        ” SSN is a good way to uniquely identify US residents…”

        If I’m buying a pair of Vans online the seller doesn’t need to be able to identify me. I present a valid payment method and a delivery address (and maybe a billing address, if different from the delivery address). Identity verification should not be required by a seller of shoes under any circumstances.

    2. Mike 137 Silver badge

      Re: Why do they need customers' SSN?

      "Credit card numbers ideally should be kept on a different server"

      Whether on a different server or not, credit card numbers (PANs) should ideally not be stored at all once any given transaction is completed. If they must be stored beyond this, PCI-DSS requires that they be one way hashed or truncated (but not both), strongly encrypted with adequate key management, or tokenised. The aim, of course, is to make the PAN unreadable so it doesn't matter if it's leaked.

    3. Anonymous Coward
      Anonymous Coward

      Re: Why do they need customers' SSN?

      They don't need the SSNs of customers, and they don't collect them.

      That was the premise of their smoke and mirrors, which was to avoid answering the actual question (what was actually stolen) by giving some worthless redirection.

      The laws that mandate reporting these breaches should go further and force the company to be fully transparent.

      However, that wouldn't let Congress "appear" to be working "for the people" while they instead commit treason (by selling out their country) and take bribes (lobbying) as they screw over Americans.

    4. david1024

      Re: Why do they need customers' SSN?

      They don't need individual consumer ssn. And don't collect them. Those are for larger buyers on credit.

  2. abend0c4 Silver badge

    Supreme, Timberland, and Dickies

    Not just a load of cobblers, then.

  3. jseuk56

    3 months to notify customers..

    I have today (in the UK) just received a notification from VF/Vans advising my data was involved in a breach. Only took them 3 months to let me know...utterly awful.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like