Live data from Hacker News

‘Jackpotting’ Attacks Hit U.S. ATMs

krebsonsecurity.com

21–30 of 174 posts

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#22
post #3
post #2

Embedded software is easy to hack. Spend quite a bit of money getting access to the binary running a common ATM platform. Reverse engineer it. Find a vulnerability. Trigger it. Done! The age of (common) embedded system exploitation is finally upon us.

The "hack" in question involves replacing the hard drive. This isn't an embedded issue. This is a physical access to OS issue.

The "hack" in question involves replacing the hard drive.

Secure Boot should be able to prevent this even with physical access.

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#24
post #21

I people didn't need cash this problem would go away. I think of this occasionally when I visit our local bagel shop, which like many bagel shops in the area does not take cards and has an atm onsite.

On the other hand, if you pay by card everywhere, your moments and spending habits will be tracked and catalogued.

A lot of people are not comfortable with that.

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#26
post #21

I people didn't need cash this problem would go away. I think of this occasionally when I visit our local bagel shop, which like many bagel shops in the area does not take cards and has an atm onsite.

I strongly hope that paper money is not completely replaced by electronic payments because it may be convenient as long as it works but I would like to still be able to buy food even when the service stops working.

We had this in Austria a few months ago where one if the biggest providers for electronic payment terminals stopped working for 1 1/2 days

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#27
post #21

I people didn't need cash this problem would go away. I think of this occasionally when I visit our local bagel shop, which like many bagel shops in the area does not take cards and has an atm onsite.

On the other hand, if you pay by card everywhere, your moments and spending habits will be tracked and catalogued. A lot of people are not comfortable with that.

The vast majority carry an internet connected gps tracker with microphone, Wifi, Bluetooth, sms and email all in one place with them at all times, and bank accounts, sms, emails are already accessible to the state on the server side. Shops are using facial recognition and Bluetooth to advertise and track customers. So I honestly think privacy in what you purchase is a ship that has sailed, this data will be recorded in future.

What we should be agitating for is proper control over the use of this info, not trying to limit ways to collect it.

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#28
Several years ago, I've had an ATM crash and reboot after pressing one of the screen side buttons when the machine was waiting for PIN entry via the numeric pad. It rebooted, and I could see that it was running MSDOS, not even Windows. Luckily, after the reboot completed and the ATM frontend program started, it spit out my card again.

With one of offices of my bank being nearby (to be able to block my card if I couldn't get it back), I tried it two more times, just to check that it wasn't a random occurrence.

While it was probably nothing that could further be escalated into gaining access without additional hardware, it gave me a chuckle (and a bit of fear for my card, initially).

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#29

According to FireEye, the Ploutus attacks seen so far require thieves to somehow gain physical access to an ATM — either by picking its locks, using a stolen master key or otherwise removing or destroying part of the machine. ATMs need to be more physically secure, like bank safes, if they are to be resistant to such attacks. The software part is mostly immaterial here, IMHO --- it doesn't matter what the software is…

I used to work with various ATMs and the cash dispenser _is_ a hardened safe, with a combination lock and all. If you are to steal an ATM, you will still need to open the safe and the simplest option would indeed be to try and persuade it to just dispense the money.

The thing is that ATMs from larger vendors (IBM, NCR, Bull, Siemens, etc.) have layer upon layers of protection features. For example, you can configure a secondary combination for the safe which will open it and also send an emergency alert. This is for the cases when someone is being forced to open the safe at gunpoint. There are batteries for secondary power supply. There are options for physical lock-down in case of a power loss. Tilt and movement sensors. Redundant communication options, including exotics like x.28 radio.

I mean that all of this was readily available even 20 years ago. ATMs are not designed by amateurs. The issue is that all these are _options_. They need to be bought first and then they also need to be properly configured and enabled, which falls on the banks or their IT service providers to do. The smaller the bank, the less willing they are to spend even more money on configuring secondary stuff and setting up an infrastructure for it, so many of these options will remain off even if they are available.

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#30

I assume this will end with there being fewer ATMs. That they will become more expensive to run in due to costs of hardened physical devices and insurance. If they become too rare it could result in a reduction of cash usage, maybe significantly.

Good luck with that, outside of a handful of Nordic oddballs, cash is still king in most of the world (US included). We have a massive unbanked population that isn't going to start using banks or digital payments anytime soon, no matter what politicians or economists may desire.
Post reply on HN