Live data from Hacker News

‘Jackpotting’ Attacks Hit U.S. ATMs

krebsonsecurity.com

51–60 of 174 posts

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#51

According to FireEye, the Ploutus attacks seen so far require thieves to somehow gain physical access to an ATM — either by picking its locks, using a stolen master key or otherwise removing or destroying part of the machine. ATMs need to be more physically secure, like bank safes, if they are to be resistant to such attacks. The software part is mostly immaterial here, IMHO --- it doesn't matter what the software is…

There have been several cases of stolen construction equipment (fork lifts, wheel loader, etc.) being used to steal ATMs. For example: https://www.youtube.com/watch?v=K05LT-WpN5I Achieving 100% physical security is going to be hard.

In the UK at least it's common for ATMs at banks and supermarkets to be built into the wall. You still have freestanding ones too (including in bank branches), but if the solution to this issue is to get rid of the freestanding ones, it's not likely to be a major inconvenience, especially as many stores offer cash back on request (e.g. buy a pack of gum on card, request £30 cash back, get charged for the gum and the cash, resulting in obtaining £30 cash taken from the till).

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#52

>"The Secret Service alert says ATMs still running on Windows XP are particularly vulnerable, and it urged ATM operators to update to a version of Windows 7 to defeat this specific type of attack." I had no idea ATMs ran Windows!

In Poland, few years back, I caught several ATMs rebooting to Windows NT 5.0.

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#53

>"The Secret Service alert says ATMs still running on Windows XP are particularly vulnerable, and it urged ATM operators to update to a version of Windows 7 to defeat this specific type of attack." I had no idea ATMs ran Windows!

To be specific, it’s most likely Windows Embedded.

I am regularly surprised by the contrary. Our lifts at work once displayed a popup from the "Desktop cleanup wizard".

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#54
post #3

Earlier quoted context omitted.

The "hack" in question involves replacing the hard drive. This isn't an embedded issue. This is a physical access to OS issue.

The "hack" in question involves replacing the hard drive. Secure Boot should be able to prevent this even with physical access.

I do not understand. If a legitimate version of windows is installed on the hard drive, how secure boot will stop it ?

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#55

I assume this will end with there being fewer ATMs. That they will become more expensive to run in due to costs of hardened physical devices and insurance. If they become too rare it could result in a reduction of cash usage, maybe significantly.

Nah, you'll just see more of the "charge extra and give you cash" checkout options that were in vogue before ATMs where everywhere.

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#56

>"The Secret Service alert says ATMs still running on Windows XP are particularly vulnerable, and it urged ATM operators to update to a version of Windows 7 to defeat this specific type of attack." I had no idea ATMs ran Windows!

You'd be surprised how many things are running Windows. I always wonder if the manufacturer just hires cheap contractors that haven't seen anything apart from Windows in their entire life, or if there is an actual reason it can't run on linux.

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#57
post #53

Earlier quoted context omitted.

To be specific, it’s most likely Windows Embedded.

I am regularly surprised by the contrary. Our lifts at work once displayed a popup from the "Desktop cleanup wizard".

I was in Munich main train station and saw an advertisement display showing a OS X Desktop and a crash report. Like, why exactly would you use a Mac for this..

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#58
post #54

Earlier quoted context omitted.

The "hack" in question involves replacing the hard drive. Secure Boot should be able to prevent this even with physical access.

I do not understand. If a legitimate version of windows is installed on the hard drive, how secure boot will stop it ?

You're thinking of Secure Boot as it's typically used, where firmware on the motherboard verifies that the kernel is signed by whoever wrote the kernel, e.g. Microsoft. But there's no reason you couldn't have the motherboard OEM load, say, the ATM manufacturer's public key, and have Secure Boot verify that the kernel has been signed by the ATM manufacturer. Then the motherboard will refuse to boot an OS which wasn't signed by the ATM manufacturer, even if it's otherwise "pure".

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#59

Earlier quoted context omitted.

On the other hand, if you pay by card everywhere, your moments and spending habits will be tracked and catalogued. A lot of people are not comfortable with that.

The vast majority carry an internet connected gps tracker with microphone, Wifi, Bluetooth, sms and email all in one place with them at all times, and bank accounts, sms, emails are already accessible to the state on the server side. Shops are using facial recognition and Bluetooth to advertise and track customers. So I honestly think privacy in what you purchase is a ship that has sailed, this data will be recorded…

All of that can be turned off or circumvented, or you could even just leave the phone at home.

But laws are tightening on cash payments, a lot of countries have already made cash transactions over a certain amount illegal. At the moment only for services, you can still exchange cash with your friends, but you may get a lot of scrutiny if you wish to deposit said cash into your bank account.

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#60

If you, like me, were wondering what the Secret Service (widely recognized for their duties as presidential bodyguards) has to do with ATM fraud, there's a comment below the article from the author: > I didn’t mention it in the story, but perhaps I should have: The original mission of the Secret Service when it was created in the 1800s was to safeguard the U.S. currency from counterfeiters. Only after a few president…

How does that relate to ATM fraud? The ATMs are, presumably, issuing legitimate currency?
Post reply on HN