Live data from Hacker News

'Shimmers' are the newest tool for stealing credit card info

cbc.ca

41–50 of 88 posts

Re: 'Shimmers' are the newest tool for stealing credit card info

#41
post #6

Krebs has a post on this as well: https://krebsonsecurity.com/2017/01/atm-shimmers-target-chip... “The only way for this attack to be successful is if a [bank card] issuer neglects to check the CVV when authorizing a transaction,”

I have not had the largest confidence in banks abilities to understand security. I've personally dealt with: 1) 'Two factor auth is on, you have to answer two security questions to access your account!' 2) 'Your password is limited to exactly 8 characters ... for security' 3) 'Oh, we now support SMS two factor auth' -- 4 months in, I've received 1 SMS challenge 4) 'You don't want a chip card, they are more hassle' 5)…

> 'You don't want a chip card, they are more hassle'

I got exactly that line fairly recently. To be fair, it probably is much more of a hassle from what I've heard, so they're not wrong, exactly. It seems like the chip+pin rollout has been bungled pretty terribly.

Re: 'Shimmers' are the newest tool for stealing credit card info

#42

Earlier quoted context omitted.

In a proper EMV solution, hardware like this can not intercept the PIN code even if it can interpret any signal, as the unencrypted PIN is not sent anywhere beyond the keypad - even if you do MITM on the wires between the keypad and POS terminal, you would get only an encrypted version that then gets sent to the bank for online verification or to the chip for offline verification. You can get the PIN code by cameras…

Defcon 24 vid about skimming EMV cards at ATMs and withdrawing cash from the skimmed account at a different remote ATM (cashout): https://m.youtube.com/watch?v=FgIk_oIK2SM

A very nice video and a very interesting attack.

That being said, this doesn't allow to duplicate a card (it relays the fraudulent transaction in real time to the real card while it's stuck into compromised hardware), the PIN is captured from video or the "la-cara"device, and you do need to have the "extracting" device mounted to a real ATM for prolonged periods until you can empty it (you can do it only as fast as the real transactions come in, and they do so at unpredictable intervals), which gives a nice opportunity to capture the involved people. It's a very powerful proof of concept, but harder to scale than the current "cashout crews"/mules - the logistic problems are somewhat comparable to the classic approach of setting up a completely fake ATM.

Re: 'Shimmers' are the newest tool for stealing credit card info

#43
post #6

Krebs has a post on this as well: https://krebsonsecurity.com/2017/01/atm-shimmers-target-chip... “The only way for this attack to be successful is if a [bank card] issuer neglects to check the CVV when authorizing a transaction,”

I have not had the largest confidence in banks abilities to understand security. I've personally dealt with: 1) 'Two factor auth is on, you have to answer two security questions to access your account!' 2) 'Your password is limited to exactly 8 characters ... for security' 3) 'Oh, we now support SMS two factor auth' -- 4 months in, I've received 1 SMS challenge 4) 'You don't want a chip card, they are more hassle' 5)…

May I suggest switching banks? And while you're at it, you may want to look into a credit union rather than a corporate bank.

Re: 'Shimmers' are the newest tool for stealing credit card info

#44

Krebs has a post on this as well: https://krebsonsecurity.com/2017/01/atm-shimmers-target-chip... “The only way for this attack to be successful is if a [bank card] issuer neglects to check the CVV when authorizing a transaction,”

In which case, I hope no-one but the bank is liable for the cost of the fraud.

Re: 'Shimmers' are the newest tool for stealing credit card info

#45
post #40

Can we not make certain parts of the ATM from a transparent material, like clear plastic? I'm thinking it would be more obvious when the keypad or card slot have been tampered with.

Would the majority of people actually notice though?

Re: 'Shimmers' are the newest tool for stealing credit card info

#46

Earlier quoted context omitted.

This sounds like the attack presented at DEFCON 19 (in 2011!): https://www.defcon.org/images/defcon-19/dc-19-presentations/... . Basically, the chip used to contain all the information present on the magstripe, which made it easy to create a copy of the magstripe via the chip interface.

From the issuer side, the solution to remove this risk is simple (and I believe I was told it in an EMV implementation seminar 10 years ago): If the incoming transaction lists that the terminal is chip&pin capable, so you'd simply automatically reject a magstripe transaction with a code that should result in POS showing "please insert card in the chip reader"; If the incoming transaction lists that the terminal is no…

If you try to swipe a chip card then yes, the terminal will reject the swipe and tell you to insert the chip. If your chip fails three successive tries, the terminal will accept a mag swipe instead. I don't know if this is true everywhere but I have seen it in multiple retailers across the US. Point is, if attackers are cloning mag cards from chip data, those cards can still be used in chip terminals.

Re: 'Shimmers' are the newest tool for stealing credit card info

#47
post #32

Earlier quoted context omitted.

A good number of the supermarkets and other retailers around me are still just swiping cards. Gas pumps of course as well. I'm guessing the added cost of the fraud liability for swiped cards is turning out to be lower than the cost to convert to chip readers.

It's not the cost of conversion, it's that the fraud just vanishes in the insane rents American credit card processors extract. In the EU, these fees are limited to 0.3% for CC and 0.2% for debit cards, so there is less margin to just keep paying the fraudsters instead of updating systems.

They have the new readers but they don't use them

Re: 'Shimmers' are the newest tool for stealing credit card info

#48
> "Businesses really need to be checking for these kinds of devices and consumers need to be aware of them."

Disagree. Consumers and businesses (ultimately) pay the interchange fees, and this class of problem is the domain of payment infrastructure providers. I'm not interested in keeping vigilant against the latest exploit, and unless the responsibility for dealing with the problem lies with credit card networks and processing gateways they'll have no reason to stop rolling out crappy easily-owned payment tech.

Re: 'Shimmers' are the newest tool for stealing credit card info

#49

Earlier quoted context omitted.

This sounds like the attack presented at DEFCON 19 (in 2011!): https://www.defcon.org/images/defcon-19/dc-19-presentations/... . Basically, the chip used to contain all the information present on the magstripe, which made it easy to create a copy of the magstripe via the chip interface.

> the chip used to contain all the information present on the magstripe Not all of it - the chip has a dynamic CVV that differs from the one on the magstripe. This only works if the bank isn't checking CVVs.

> This only works if the bank isn't checking CVVs.

Source please? Because if you're right, my bank lied to me when they said they couldn't see whether I paid by chip or by magstripe.

Re: 'Shimmers' are the newest tool for stealing credit card info

#50

Note this is in Canada -- unfortunately there's still a lot of Offline Plaintext PIN cards there. See CreditCall's blog on the subject: https://www.level2kernel.com/blog/2012/02/sda-and-plaintext-...

Thanks for this - I was wondering how they got the PIN considering plain text offline PIN has been deprecated for years. My understanding is that the liability shift is in effect for plaintext PINs, but maybe not in the NA/Canada region.
Post reply on HN