‘Jackpotting’ Attacks Hit U.S. ATMs
11–20 of 174 posts
Re: ‘Jackpotting’ Attacks Hit U.S. ATMs
#12Re: ‘Jackpotting’ Attacks Hit U.S. ATMs
#13ATMs need to be more physically secure, like bank safes, if they are to be resistant to such attacks. The software part is mostly immaterial here, IMHO --- it doesn't matter what the software is, if you can get access to the physical money.
Re: ‘Jackpotting’ Attacks Hit U.S. ATMs
#14I'm not sure why this hasn't really been done in practice but it shouldn't be to difficult to figure out how to do correctly.
In most ATM's the computer hardware and interface connectors are also all housed in the top (mostly plastic or low-quality cast metal) shrouds (as opposed to the currency locked in a safe). Traditionally wafer locks were also used to secure this section however they are slowly migrating to higher security locks like Abloys.
ATM manufacturers may want to take a look at slot machine manufacturers for clues on how to harden machines against tampering.
Re: ‘Jackpotting’ Attacks Hit U.S. ATMs
#15According to FireEye, the Ploutus attacks seen so far require thieves to somehow gain physical access to an ATM — either by picking its locks, using a stolen master key or otherwise removing or destroying part of the machine. ATMs need to be more physically secure, like bank safes, if they are to be resistant to such attacks. The software part is mostly immaterial here, IMHO --- it doesn't matter what the software is…
Achieving 100% physical security is going to be hard.
Re: ‘Jackpotting’ Attacks Hit U.S. ATMs
#16I think this applies, mutatis mutandis: https://xkcd.com/463/
Re: ‘Jackpotting’ Attacks Hit U.S. ATMs
#17The Secret Service alert says ATMs still running on Windows XP are particularly vulnerable, and it urged ATM operators to update to a version of Windows 7 to defeat this specific type of attack. I think this applies, mutatis mutandis : https://xkcd.com/463/
Re: ‘Jackpotting’ Attacks Hit U.S. ATMs
#18Re: ‘Jackpotting’ Attacks Hit U.S. ATMs
#19The Secret Service alert says ATMs still running on Windows XP are particularly vulnerable, and it urged ATM operators to update to a version of Windows 7 to defeat this specific type of attack. I think this applies, mutatis mutandis : https://xkcd.com/463/
At least they aren't running OS/2 Warp.