Live data from Hacker News

‘Jackpotting’ Attacks Hit U.S. ATMs

krebsonsecurity.com

81–90 of 174 posts

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#81

> The Secret Service alert says ATMs still running on Windows XP are particularly vulnerable, and it urged ATM operators to update to a version of Windows 7 to defeat this specific type of attack. I would argue that Windows isn‘t at all the right OS for this.

What is? And do you have an OS that you are comfortable calling "secure"? Remember security through obscurity as enjoyed by Mac and Linux doesn't apply here because there is actual money and hence incentive to find vulnerability at stake.

[deleted]

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#82
post #66

I just read through the comments and was VERY surprised to see noone call this out: > At this point, the crook(s) installing the malware will contact co-conspirators who can remotely control the ATMs and force the machines to dispense cash. Realize what this means. The ATMs are connected directly to the internet, with a VPN (hopefully...) sitting over the top of that. The ATM can still call out to the internet direct…

When I read that part, I figured that the crooks were using their own mobile Internet connection on the laptop or mobile device that they had connected to the ATM.

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#83
post #71

Earlier quoted context omitted.

I've read (though have no first hand experience) that slot machines have better security and better vetting than electronic voting machines do so I'm not surprised either.

In Nevada the source code for gaming devices is required to be provided to the state gaming commission. (c) In the case of a gaming device, a copy of all executable software, including data and graphic information, and a copy of all source code for programs that cannot be reasonably demonstrated to have any use other than in a gaming device, submitted on electronically readable, unalterable media; http://gaming.nv.go…

But only for "programs that cannot be reasonably demonstrated to have any use other than in a gaming device".

Makes one imagine what kind of political trench wars probably went on behind the scenes about this regulation.

Edit: On second thought, this seems awfully easy to circumvent. What stops me from making a rigged PRNG and then refusing to make the source code available on the grounds that there are lots of non-gambling applications for PRNGs?

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#84

> The Secret Service alert says ATMs still running on Windows XP are particularly vulnerable, and it urged ATM operators to update to a version of Windows 7 to defeat this specific type of attack. I would argue that Windows isn‘t at all the right OS for this.

What is? And do you have an OS that you are comfortable calling "secure"? Remember security through obscurity as enjoyed by Mac and Linux doesn't apply here because there is actual money and hence incentive to find vulnerability at stake.

seL4? Other microkernels optimized for secure use cases?

If you wish, you can put the actual UI in a separate chip, with more modern hardware, handling rendering and input.

But please, do not run the control logic for the ATM on a desktop OS

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#85

>"The Secret Service alert says ATMs still running on Windows XP are particularly vulnerable, and it urged ATM operators to update to a version of Windows 7 to defeat this specific type of attack." I had no idea ATMs ran Windows!

In Poland, few years back, I caught several ATMs rebooting to Windows NT 5.0.

...win2000 pre-release? or did you mean NT 4?

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#86
post #66

I just read through the comments and was VERY surprised to see noone call this out: > At this point, the crook(s) installing the malware will contact co-conspirators who can remotely control the ATMs and force the machines to dispense cash. Realize what this means. The ATMs are connected directly to the internet, with a VPN (hopefully...) sitting over the top of that. The ATM can still call out to the internet direct…

When I read that part, I figured that the crooks were using their own mobile Internet connection on the laptop or mobile device that they had connected to the ATM.

....Ah. That is a very real possibility. Thanks for pointing that out.

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#87
post #62

Earlier quoted context omitted.

Good luck with that, outside of a handful of Nordic oddballs, cash is still king in most of the world (US included). We have a massive unbanked population that isn't going to start using banks or digital payments anytime soon, no matter what politicians or economists may desire.

The way that Sweden did it was in small steps, some which other nations has already done. Encourage companies to only pay employees through banks by making it practically impossible to pay through cash. Expand money laundering laws so that banks are liable if they give out or take in physical cash, with short and hard limits to ATM's. Make it acceptable to have police confiscate money if a person carry more than a fe…

I actually think this is fundamentally an attack on the right to transact anonymously. Trends towards the confiscation of large sums of cash, increasing restrictions on moving money relating to KYC/AML, and the further emphasis on digital forms of payment give governments and, more worryingly, banks the ability to exert incredible influence over the day-to-day lives of individuals.

Here's a good Canadian example - banks now refuse accounts to "high risk" businesses like money services (currency conversion etc.) under the guise that the KYC/AML requirements involved make it too risky for the bank to service them. And yet, our major banks have huge currency conversion businesses - so in essence these laws are being used to stifle competition.

For merchants, credit cards and debit were originally billed as items that would improve their sales - so who cares if interchange fees add up to a whopping 3% on transactions? But now with almost everyone demanding that stores accept credit/debit, merchants are hit with what is essentially a non-government tax on their revenues. Every "cash back" or "rewards" card is basically funded at the expense of merchants.

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#88

Earlier quoted context omitted.

Moving the cash from even a free-standing ATM to the till seems unlikely to be a net improvement in security.

The till probably has under £500 in, probably less. The ATM probably 20 times that. By offering cash back you're reducing the amount of cash kept in store, reducing the chance of being robbed (less worthwhile). By putting an ATM in store you're increasing the cash on premises, and in your tills (as people use the ATM rather than cash back) Cash back is a win-win for stores.

Then either the ATM had 20x too much cash in it, or the store will be unable to satisfy 19/20 requests for cash back?

People withdrawing cash from the ATM (often incurring a non-trivial fee) to pay in the same store, rather than just paying on card, seems to be a marginal case and indeed inferior to card payment.

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#89
post #71
post #47

Earlier quoted context omitted.

Somehow I'm not surprised that hardening is a higher priority for slot machines than for ATMs...

I've read (though have no first hand experience) that slot machines have better security and better vetting than electronic voting machines do so I'm not surprised either.

Voting machines have atrocious security. ATM levels of security would be a huge step up for them.

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#90

>"The Secret Service alert says ATMs still running on Windows XP are particularly vulnerable, and it urged ATM operators to update to a version of Windows 7 to defeat this specific type of attack." I had no idea ATMs ran Windows!

To be specific, it’s most likely Windows Embedded.

The one I saw the other day was wedged at a Windows 7 Professional "Shutting Down..." screen.
Post reply on HN