> The Secret Service alert says ATMs still running on Windows XP are particularly vulnerable, and it urged ATM operators to update to a version of Windows 7 to defeat this specific type of attack. I would argue that Windows isn‘t at all the right OS for this.
What is? And do you have an OS that you are comfortable calling "secure"? Remember security through obscurity as enjoyed by Mac and Linux doesn't apply here because there is actual money and hence incentive to find vulnerability at stake.
‘Jackpotting’ Attacks Hit U.S. ATMs
81–90 of 174 posts
Re: ‘Jackpotting’ Attacks Hit U.S. ATMs
#82I just read through the comments and was VERY surprised to see noone call this out: > At this point, the crook(s) installing the malware will contact co-conspirators who can remotely control the ATMs and force the machines to dispense cash. Realize what this means. The ATMs are connected directly to the internet, with a VPN (hopefully...) sitting over the top of that. The ATM can still call out to the internet direct…
Re: ‘Jackpotting’ Attacks Hit U.S. ATMs
#83Earlier quoted context omitted.
I've read (though have no first hand experience) that slot machines have better security and better vetting than electronic voting machines do so I'm not surprised either.
In Nevada the source code for gaming devices is required to be provided to the state gaming commission. (c) In the case of a gaming device, a copy of all executable software, including data and graphic information, and a copy of all source code for programs that cannot be reasonably demonstrated to have any use other than in a gaming device, submitted on electronically readable, unalterable media; http://gaming.nv.go…
Makes one imagine what kind of political trench wars probably went on behind the scenes about this regulation.
Edit: On second thought, this seems awfully easy to circumvent. What stops me from making a rigged PRNG and then refusing to make the source code available on the grounds that there are lots of non-gambling applications for PRNGs?
Re: ‘Jackpotting’ Attacks Hit U.S. ATMs
#84> The Secret Service alert says ATMs still running on Windows XP are particularly vulnerable, and it urged ATM operators to update to a version of Windows 7 to defeat this specific type of attack. I would argue that Windows isn‘t at all the right OS for this.
What is? And do you have an OS that you are comfortable calling "secure"? Remember security through obscurity as enjoyed by Mac and Linux doesn't apply here because there is actual money and hence incentive to find vulnerability at stake.
If you wish, you can put the actual UI in a separate chip, with more modern hardware, handling rendering and input.
But please, do not run the control logic for the ATM on a desktop OS
Re: ‘Jackpotting’ Attacks Hit U.S. ATMs
#85>"The Secret Service alert says ATMs still running on Windows XP are particularly vulnerable, and it urged ATM operators to update to a version of Windows 7 to defeat this specific type of attack." I had no idea ATMs ran Windows!
In Poland, few years back, I caught several ATMs rebooting to Windows NT 5.0.
Re: ‘Jackpotting’ Attacks Hit U.S. ATMs
#86I just read through the comments and was VERY surprised to see noone call this out: > At this point, the crook(s) installing the malware will contact co-conspirators who can remotely control the ATMs and force the machines to dispense cash. Realize what this means. The ATMs are connected directly to the internet, with a VPN (hopefully...) sitting over the top of that. The ATM can still call out to the internet direct…
When I read that part, I figured that the crooks were using their own mobile Internet connection on the laptop or mobile device that they had connected to the ATM.
Re: ‘Jackpotting’ Attacks Hit U.S. ATMs
#87Earlier quoted context omitted.
Good luck with that, outside of a handful of Nordic oddballs, cash is still king in most of the world (US included). We have a massive unbanked population that isn't going to start using banks or digital payments anytime soon, no matter what politicians or economists may desire.
The way that Sweden did it was in small steps, some which other nations has already done. Encourage companies to only pay employees through banks by making it practically impossible to pay through cash. Expand money laundering laws so that banks are liable if they give out or take in physical cash, with short and hard limits to ATM's. Make it acceptable to have police confiscate money if a person carry more than a fe…
Here's a good Canadian example - banks now refuse accounts to "high risk" businesses like money services (currency conversion etc.) under the guise that the KYC/AML requirements involved make it too risky for the bank to service them. And yet, our major banks have huge currency conversion businesses - so in essence these laws are being used to stifle competition.
For merchants, credit cards and debit were originally billed as items that would improve their sales - so who cares if interchange fees add up to a whopping 3% on transactions? But now with almost everyone demanding that stores accept credit/debit, merchants are hit with what is essentially a non-government tax on their revenues. Every "cash back" or "rewards" card is basically funded at the expense of merchants.
Re: ‘Jackpotting’ Attacks Hit U.S. ATMs
#88Earlier quoted context omitted.
Moving the cash from even a free-standing ATM to the till seems unlikely to be a net improvement in security.
The till probably has under £500 in, probably less. The ATM probably 20 times that. By offering cash back you're reducing the amount of cash kept in store, reducing the chance of being robbed (less worthwhile). By putting an ATM in store you're increasing the cash on premises, and in your tills (as people use the ATM rather than cash back) Cash back is a win-win for stores.
People withdrawing cash from the ATM (often incurring a non-trivial fee) to pay in the same store, rather than just paying on card, seems to be a marginal case and indeed inferior to card payment.
Re: ‘Jackpotting’ Attacks Hit U.S. ATMs
#89Earlier quoted context omitted.
Somehow I'm not surprised that hardening is a higher priority for slot machines than for ATMs...
I've read (though have no first hand experience) that slot machines have better security and better vetting than electronic voting machines do so I'm not surprised either.
Re: ‘Jackpotting’ Attacks Hit U.S. ATMs
#90>"The Secret Service alert says ATMs still running on Windows XP are particularly vulnerable, and it urged ATM operators to update to a version of Windows 7 to defeat this specific type of attack." I had no idea ATMs ran Windows!
To be specific, it’s most likely Windows Embedded.