Live data from Hacker News

‘Jackpotting’ Attacks Hit U.S. ATMs

krebsonsecurity.com

61–70 of 174 posts

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#61

If you, like me, were wondering what the Secret Service (widely recognized for their duties as presidential bodyguards) has to do with ATM fraud, there's a comment below the article from the author: > I didn’t mention it in the story, but perhaps I should have: The original mission of the Secret Service when it was created in the 1800s was to safeguard the U.S. currency from counterfeiters. Only after a few president…

How does that relate to ATM fraud? The ATMs are, presumably, issuing legitimate currency?

> How does that relate to ATM fraud?

“In 1984, the US Congress passed the Comprehensive Crime Control Act, which extended the Secret Service's jurisdiction over credit card fraud and computer fraud.”

https://en.m.wikipedia.org/wiki/United_States_Secret_Service...

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#62

I assume this will end with there being fewer ATMs. That they will become more expensive to run in due to costs of hardened physical devices and insurance. If they become too rare it could result in a reduction of cash usage, maybe significantly.

Good luck with that, outside of a handful of Nordic oddballs, cash is still king in most of the world (US included). We have a massive unbanked population that isn't going to start using banks or digital payments anytime soon, no matter what politicians or economists may desire.

The way that Sweden did it was in small steps, some which other nations has already done.

Encourage companies to only pay employees through banks by making it practically impossible to pay through cash. Expand money laundering laws so that banks are liable if they give out or take in physical cash, with short and hard limits to ATM's. Make it acceptable to have police confiscate money if a person carry more than a few hundred dollars. Just to give examples of those, a person was stopped by a routine police stop when they saw $350 and confiscated it on the concept that such huge amount of money was a sign of money laundering. A few further months ago a elderly couple (70+) had sold their car but could not put the 10 grand into the bank since the sale papers (including government signed transfer) was not enough to prove definitively that the money was still not part of any money laundering. Sweden invalidated all bills and coins made before 2015, forcing everyone to have them exchanged or put it in the bank which was why the elderly couple needed to put the money in the bank.

Add to that a heavy joint campaign between banks and government to paint any physical cash transaction as putting employees at stores at risk and that its a moral responsibility that everyone only use banks, and a strong decline in the availability of bank offices that handles cash.

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#63

If you ever open up an ATM you'll realise that the majority of things are controlled by serial interfaces (upto 6 of them) for all the motors and pneumatic hardware. If the operating system becomes hardened enough, you'll eventually have people interface with the serial ports directly to manipulate the cash-drawers directly. I'm not sure why this hasn't really been done in practice but it shouldn't be to difficult to…

Don’t some ATMs spray ink on the bills if they detect tampering?

They do, if they detect tampering to the currency safe. However I'm not sure if they are really equipped to detect tampering to electronics.

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#64

>"The Secret Service alert says ATMs still running on Windows XP are particularly vulnerable, and it urged ATM operators to update to a version of Windows 7 to defeat this specific type of attack." I had no idea ATMs ran Windows!

It's not unknown to see windows crash screens on atms.

I've never seen one like this though: https://www.betaarchive.com/imageupload/1182228936.or.19648....

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#65
post #57
post #53

Earlier quoted context omitted.

I am regularly surprised by the contrary. Our lifts at work once displayed a popup from the "Desktop cleanup wizard".

I was in Munich main train station and saw an advertisement display showing a OS X Desktop and a crash report. Like, why exactly would you use a Mac for this..

To be fair I've seen kernel panics on advertising screens too

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#66
I just read through the comments and was VERY surprised to see noone call this out:

> At this point, the crook(s) installing the malware will contact co-conspirators who can remotely control the ATMs and force the machines to dispense cash.

Realize what this means. The ATMs are connected directly to the internet, with a VPN (hopefully...) sitting over the top of that. The ATM can still call out to the internet directly!!

That is, honestly, shocklingly insecure. I'm stunned.

I read https://news.ycombinator.com/item?id=16250498 and how ATMs have different options for security, but "allow anything except the VPN software access to the NIC default route" doesn't sound like something _anything_ should be able to disable.

I mean... I know nothing about networking, and I was able to configure this exact behavior on FreeBSD - which I'd never used before - in a day. I set it up so a torrent program was physically incapable of doing DNS/anything outside of the VPN tunnel interface.

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#67

I assume this will end with there being fewer ATMs. That they will become more expensive to run in due to costs of hardened physical devices and insurance. If they become too rare it could result in a reduction of cash usage, maybe significantly.

Nah, you'll just see more of the "charge extra and give you cash" checkout options that were in vogue before ATMs where everywhere.

Interestingly you start seeing cash back at big chains in some European countries where the concept used to be completely foreign.

With a combination of new online banks that have no physical presence, credit and debit card fees capped by EU laws, and businesses who are happy to pay those fees to get rid of cash, it makes a lot of sense.

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#68
> The Secret Service alert says ATMs still running on Windows XP are particularly vulnerable, and it urged ATM operators to update to a version of Windows 7 to defeat this specific type of attack.

I would argue that Windows isn‘t at all the right OS for this.

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#69
post #56

>"The Secret Service alert says ATMs still running on Windows XP are particularly vulnerable, and it urged ATM operators to update to a version of Windows 7 to defeat this specific type of attack." I had no idea ATMs ran Windows!

You'd be surprised how many things are running Windows. I always wonder if the manufacturer just hires cheap contractors that haven't seen anything apart from Windows in their entire life, or if there is an actual reason it can't run on linux.

OpenBSD would be perfect for the job, wouldn‘t it?

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#70

> The Secret Service alert says ATMs still running on Windows XP are particularly vulnerable, and it urged ATM operators to update to a version of Windows 7 to defeat this specific type of attack. I would argue that Windows isn‘t at all the right OS for this.

What is? And do you have an OS that you are comfortable calling "secure"? Remember security through obscurity as enjoyed by Mac and Linux doesn't apply here because there is actual money and hence incentive to find vulnerability at stake.
Post reply on HN