‘Jackpotting’ Attacks Hit U.S. ATMs
21–30 of 174 posts
Re: ‘Jackpotting’ Attacks Hit U.S. ATMs
#22Embedded software is easy to hack. Spend quite a bit of money getting access to the binary running a common ATM platform. Reverse engineer it. Find a vulnerability. Trigger it. Done! The age of (common) embedded system exploitation is finally upon us.
The "hack" in question involves replacing the hard drive. This isn't an embedded issue. This is a physical access to OS issue.
Secure Boot should be able to prevent this even with physical access.
Re: ‘Jackpotting’ Attacks Hit U.S. ATMs
#23I people didn't need cash this problem would go away. I think of this occasionally when I visit our local bagel shop, which like many bagel shops in the area does not take cards and has an atm onsite.
Re: ‘Jackpotting’ Attacks Hit U.S. ATMs
#24I people didn't need cash this problem would go away. I think of this occasionally when I visit our local bagel shop, which like many bagel shops in the area does not take cards and has an atm onsite.
A lot of people are not comfortable with that.
Re: ‘Jackpotting’ Attacks Hit U.S. ATMs
#25Re: ‘Jackpotting’ Attacks Hit U.S. ATMs
#26I people didn't need cash this problem would go away. I think of this occasionally when I visit our local bagel shop, which like many bagel shops in the area does not take cards and has an atm onsite.
We had this in Austria a few months ago where one if the biggest providers for electronic payment terminals stopped working for 1 1/2 days
Re: ‘Jackpotting’ Attacks Hit U.S. ATMs
#27I people didn't need cash this problem would go away. I think of this occasionally when I visit our local bagel shop, which like many bagel shops in the area does not take cards and has an atm onsite.
On the other hand, if you pay by card everywhere, your moments and spending habits will be tracked and catalogued. A lot of people are not comfortable with that.
What we should be agitating for is proper control over the use of this info, not trying to limit ways to collect it.
Re: ‘Jackpotting’ Attacks Hit U.S. ATMs
#28With one of offices of my bank being nearby (to be able to block my card if I couldn't get it back), I tried it two more times, just to check that it wasn't a random occurrence.
While it was probably nothing that could further be escalated into gaining access without additional hardware, it gave me a chuckle (and a bit of fear for my card, initially).
Re: ‘Jackpotting’ Attacks Hit U.S. ATMs
#29According to FireEye, the Ploutus attacks seen so far require thieves to somehow gain physical access to an ATM — either by picking its locks, using a stolen master key or otherwise removing or destroying part of the machine. ATMs need to be more physically secure, like bank safes, if they are to be resistant to such attacks. The software part is mostly immaterial here, IMHO --- it doesn't matter what the software is…
The thing is that ATMs from larger vendors (IBM, NCR, Bull, Siemens, etc.) have layer upon layers of protection features. For example, you can configure a secondary combination for the safe which will open it and also send an emergency alert. This is for the cases when someone is being forced to open the safe at gunpoint. There are batteries for secondary power supply. There are options for physical lock-down in case of a power loss. Tilt and movement sensors. Redundant communication options, including exotics like x.28 radio.
I mean that all of this was readily available even 20 years ago. ATMs are not designed by amateurs. The issue is that all these are _options_. They need to be bought first and then they also need to be properly configured and enabled, which falls on the banks or their IT service providers to do. The smaller the bank, the less willing they are to spend even more money on configuring secondary stuff and setting up an infrastructure for it, so many of these options will remain off even if they are available.
Re: ‘Jackpotting’ Attacks Hit U.S. ATMs
#30I assume this will end with there being fewer ATMs. That they will become more expensive to run in due to costs of hardened physical devices and insurance. If they become too rare it could result in a reduction of cash usage, maybe significantly.