Live data from Hacker News

Hackers Are Emptying ATMs with a Single Drilled Hole and $15 Worth of Gear

wired.com

61–70 of 82 posts

Re: Hackers Are Emptying ATMs with a Single Drilled Hole and $15 Worth of Gear

#61
post #44

Earlier quoted context omitted.

I know what a hole saw is. The thing is you aren't going to be cutting through hardened steel with a normal hole saw, assuming the cash box is metal. They could probably have made the enclosure for the cash 8 inches taller and put the computer inside of that, and routed the cables for the modem, the pin pad and the screen through Making a hole in hardened steel is not easy. If you use a hole saw, it will either need…

It is pretty surprising that the computer board/diagnostic ports are not inside the "armored" part of the machine, if that is indeed the case.

> It is pretty surprising that the computer board/diagnostic ports are not inside the "armored" part of the machine

Well humans have to interact with the machine somehow. You can't exactly prevent physical access to the keypad, and from the nature of this attack, thieves could just hack out the pin pad to connect to the internal bus.

It would be noticed much more quickly, but they'd still be away with the cash.

Re: Hackers Are Emptying ATMs with a Single Drilled Hole and $15 Worth of Gear

#62

I am currently designing food machines, which have security concerns equal to financial machines in some senses (you don't want people to get poisoned through environmental contaminants, malicious reprogramming, etc.). The article claims there is essentially no authentication between disparate modules, only simple XOR encryption. That seems a clear fail. In my experience, ATM control boards (I was literally at a fact…

Where do you draw the line between poisoning people, and vending them unhealthy fatty sugary junk food?

Everything we sell will be made to order from fresh ingredients. Sugar is only traditionally used in a few noodle cuisines (eg. Thai) and customers can opt out of any ingredient they wish. Likewise significant lipids are really only present in meats, oils, cheeses and coconut milk. Again, Thai is a strong contender. Calorie counting is transparently supported for those who want to do the numbers. Launching in Asia, for Asia, nothing we sell will likely come close in calories to an average US serving of anything.

Re: Hackers Are Emptying ATMs with a Single Drilled Hole and $15 Worth of Gear

#63

Earlier quoted context omitted.

Enthusiast safe tech here. You cannot casually drill a safe. Not talking about your hardware store variety of safe, or a 'fireproof safe'. But a legit safe like you'd find in an ATM has a number of countermeasures to ensure that its not possible to drill the safe in a short amount of time. Mixed into the steel is usually a number of drill-bit-breaking things like hardened ceramic/steel ball bearings, odd shaped chunk…

I can understand how it's possible to design quite strong small safes. But what about big bank safes? Are the same design techniques used? If not, why bother going through the front door? Isn't that door mostly for show? Aren't the other five sides mostly concrete and rebar? Isn't that easier to go through? Or do big safes really have thick steel on all six sides?

Depends on design and cost. Your thinking of a vault. Vaults have a solid door (as described above) and essentially its layers of security. The other 5 sides sometimes are the weakest point, but will still take significant amounts of time to penetrate on any properly designed vault.

No point in putting an extremely expensive vault door in a room that's got just concrete and re-bar.

The other thing is to make it harder to access those other walls as opposed to the front where you can walk up to it.

Re: Hackers Are Emptying ATMs with a Single Drilled Hole and $15 Worth of Gear

#65
post #2

I'm not terribly shocked. Most communication happens either at serial, SPI, or i2c busses. If it's cars, CAN. And if you can plug in a wire somewhere, you can damage or pwn it. Most things don't have security, other than software security and physical locks. And even when there is other types of security, like cryptokeys and such, physical wires can usually bypass even those. If they wanted something that was secure,…

I wonder how many older models of ATMs are still in service and what the process for "updating" them would be like, or perhaps that it wouldn't be realistic at all. I see a lot of small family-owned corner stores with very old machines.

I don't think there is a process for updating them, other than in the interest of adding new features or when they break. Recently I saw a green-screen CRT ATM in use by a bank in the UK. Maybe the internals have been updated, but it seems unlikely that they would change that and not the screen.

Re: Hackers Are Emptying ATMs with a Single Drilled Hole and $15 Worth of Gear

#66

Earlier quoted context omitted.

> Why we can find whole ATMs at junkyards is beyond me: there are many easy to spot flaws. If there are many easy to spot flaws, I don't think finding them in a junkyard is the root of the problem here. This is good old security by obscurity. As Bruce Schneier says (at least about safes), you should be able to publish the blueprints and source code for the machines, then maybe they'll be secure. There should be enoug…

It's a false dichotomy. Your private keys are just "obscure" information that requires some effort to find too. And security protocols can be designed so the keys aren't enough. At the end of the day it's an arms race, and you're just trying to slow attackers down.

I agree. At a certain level, all security relies on obscurity.

Re: Hackers Are Emptying ATMs with a Single Drilled Hole and $15 Worth of Gear

#67
post #16

> They found that the machine’s only encryption was a weak XOR cipher they were able to easily break, and that there was no real authentication between the machine’s modules. This reminds me of many many years ago some guy in a bimmer forum figured out BMW's iDriver music file formats (BR3/BR4/BR5) were simply DRM'd via XOR.[1] I was able to verify it via a simple script. Kudos to the reverse engineering masters! [1]…

I found it curious that the very person who mentioned it being XOR had only one single post in that forum.

That info was originated from a German bimmer forum, it seems.

Re: Hackers Are Emptying ATMs with a Single Drilled Hole and $15 Worth of Gear

#68
The Firefighters' Guild has been formed and dissolved repeatedly throughout the history of Ankh-Morpork. Usually formed in response to fires which cause significant damage to large parts of the city, the guild is usually dissolved in response to... er, fires which cause significant damage to large parts of the city. The Guild suffers from the undying capitalist spirit of Ankh-Morpork, as those men who are paid per-fire extinguished eventually begin to guarantee a regular supply of fires to be put out (see also Inn-Sewer-Ants). This has led to the frequent destruction of large portions of the city and ultimately to the Guild's being banned.

Seems we need lots of new ATMs, lots of them. And then prayer, for the fire-fighter-guild to not run out of money.

Re: Hackers Are Emptying ATMs with a Single Drilled Hole and $15 Worth of Gear

#69
post #14

Earlier quoted context omitted.

Bloomington, IN.

Heh, after your second paragraph I thought, "that sounds like here", then got down to this comment and realized it is (also in Bloomington).

Maybe we should do a HN meetup, Bloomington IN style :)

Or you can come on over to our hackerspace, Bloominglabs. We have open houses every Wednesday from 7-10P, no matter what day that falls on :)

Re: Hackers Are Emptying ATMs with a Single Drilled Hole and $15 Worth of Gear

#70

My first job was being a field technician for a bank automation supplier. We had a "test" card that could be insert on the eprom socket. This small card was almost the same size of the original chip but had a few buttons that allowed us to make the mechanism deliver notes in order to fine tune it. In a particular ATM design used by major banks in Brazil, this location were accessible by removing a front panel, althou…

I beg to differ, security by obscurity only gives a false sense of security and hats have all kind of colors.

Serge Humpich[1] worked with decommissioned ATMs, found and expose a vulnerability allow to withdraw cash with a card not linked to a bank account. Of course instead of listening and fixing the issue the banks tricked him and sued and gave rise to the yescard which forced the banks to patch up their security and replace ATMs. But hey, banks can't do the right choice all the time, can they?

[1]: https://www.everything2.com/title/Serge+Humpich

Post reply on HN