Live data from Hacker News

‘Jackpotting’ Attacks Hit U.S. ATMs

krebsonsecurity.com

91–100 of 174 posts

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#91

If you, like me, were wondering what the Secret Service (widely recognized for their duties as presidential bodyguards) has to do with ATM fraud, there's a comment below the article from the author: > I didn’t mention it in the story, but perhaps I should have: The original mission of the Secret Service when it was created in the 1800s was to safeguard the U.S. currency from counterfeiters. Only after a few president…

How does that relate to ATM fraud? The ATMs are, presumably, issuing legitimate currency?

The Secret Service is the law enforcement branch of the Treasury Department, like the FBI is the law enforcement branch of the Justice Department and ICE is of the Dept of Homeland Security. The President-protecting stuff is the weird part of their duties, not the other way around :)

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#92

Earlier quoted context omitted.

At least they aren't running OS/2 Warp.

Actually, OS/2 has been used for ATMs ( I've seen them in the EU, long time ago ).

Yup, you'd probably be surprised how much of that is still out there. At this point I'd rather have that than XP which has lots of well known exploits.

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#95

>"The Secret Service alert says ATMs still running on Windows XP are particularly vulnerable, and it urged ATM operators to update to a version of Windows 7 to defeat this specific type of attack." I had no idea ATMs ran Windows!

If you really want a blast from the past, a lot of them (used to?) run OS/2.

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#96

> The Secret Service alert says ATMs still running on Windows XP are particularly vulnerable, and it urged ATM operators to update to a version of Windows 7 to defeat this specific type of attack. I would argue that Windows isn‘t at all the right OS for this.

What is? And do you have an OS that you are comfortable calling "secure"? Remember security through obscurity as enjoyed by Mac and Linux doesn't apply here because there is actual money and hence incentive to find vulnerability at stake.

I would argue that any embedded OS (e.g. FreeRTOS) would probably be more appropriate.

You don't need a fully featured OS, with the massive attack surface that it provides.

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#97

Earlier quoted context omitted.

The till probably has under £500 in, probably less. The ATM probably 20 times that. By offering cash back you're reducing the amount of cash kept in store, reducing the chance of being robbed (less worthwhile). By putting an ATM in store you're increasing the cash on premises, and in your tills (as people use the ATM rather than cash back) Cash back is a win-win for stores.

Then either the ATM had 20x too much cash in it, or the store will be unable to satisfy 19/20 requests for cash back? People withdrawing cash from the ATM (often incurring a non-trivial fee) to pay in the same store, rather than just paying on card, seems to be a marginal case and indeed inferior to card payment.

ATMs are often refilled only every day or two, whereas the store's registers are replenished periodically, often at shift changes or when demand increases. Perhaps more importantly the register also takes _in_ cash as unrelated customers pay with cash.

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#98

Earlier quoted context omitted.

How does that relate to ATM fraud? The ATMs are, presumably, issuing legitimate currency?

The Secret Service is the law enforcement branch of the Treasury Department, like the FBI is the law enforcement branch of the Justice Department and ICE is of the Dept of Homeland Security. The President-protecting stuff is the weird part of their duties, not the other way around :)

The Secret Service was moved to Homeland Security in 2003.

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#99
post #83

Earlier quoted context omitted.

In Nevada the source code for gaming devices is required to be provided to the state gaming commission. (c) In the case of a gaming device, a copy of all executable software, including data and graphic information, and a copy of all source code for programs that cannot be reasonably demonstrated to have any use other than in a gaming device, submitted on electronically readable, unalterable media; http://gaming.nv.go…

But only for "programs that cannot be reasonably demonstrated to have any use other than in a gaming device". Makes one imagine what kind of political trench wars probably went on behind the scenes about this regulation. Edit: On second thought, this seems awfully easy to circumvent. What stops me from making a rigged PRNG and then refusing to make the source code available on the grounds that there are lots of non-g…

What’s a PRNG?

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#100
post #77
post #63

Earlier quoted context omitted.

They do, if they detect tampering to the currency safe. However I'm not sure if they are really equipped to detect tampering to electronics.

There are easily multiple locks that could be put in place internally. Encrypt the signal from the host to cash dispenser, have a debugger process that is connected to the host process that also stores the encryption keys and or talks to an HSM. Mitigates tampering of a live system, makes flashing new firmware problematic. Physically limit the cash dispenser from outputting k bills over n seconds. Have those limits b…

Your comment is coming from a good place but it’s rooted in ignorance. Most ATM machines are made by NCR and not financial institutions. Majority are also quite old (runnning windows XP old).

NCR is focused on profits not security, even though they sell POS (point of sale), ATM machines, and airport kiosks.

From my personal dealings with NCR, I can confirm that they care very little for security, regardless of what their corporate line.

To put this in perspective: if you go to a grocery store, restaurant, or quick service (fast food) establishment and use a credit card then your full account number, name, and exp is recorded in their system. This information is accessible by anyone with store level admin (not windows admin, but think a manager with manager card).

This violates PCI but hey, fuck PCI, hard sending the system takes resources and who wants to do that?

On HN, folks keep talking about security and other such nonsense, however, anyone who has seen the other side isn’t very optimistic. Between ease of use, profit margins, and no pushback on insecure systems, all loses are just write offs.

Post reply on HN