Comment Re:3des (Score 1) 213
The PIN information is encrypted within Target’s systems and can only be decrypted when it is received by our external, independent payment processor. What this means is that the “key” necessary to decrypt that data has never existed within Target’s system and could not have been taken during this incident.
Which is dammed misleading. Maybe the information truly is never decrypted on their system, but it is encrypted and it's encrypted with exactly the same key as it would be decrypted with at the external, independent payment processor.