Live data from Hacker News

‘Jackpotting’ Attacks Hit U.S. ATMs

krebsonsecurity.com

101–110 of 174 posts

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#101
post #87
post #62

Earlier quoted context omitted.

The way that Sweden did it was in small steps, some which other nations has already done. Encourage companies to only pay employees through banks by making it practically impossible to pay through cash. Expand money laundering laws so that banks are liable if they give out or take in physical cash, with short and hard limits to ATM's. Make it acceptable to have police confiscate money if a person carry more than a fe…

I actually think this is fundamentally an attack on the right to transact anonymously. Trends towards the confiscation of large sums of cash, increasing restrictions on moving money relating to KYC/AML, and the further emphasis on digital forms of payment give governments and, more worryingly, banks the ability to exert incredible influence over the day-to-day lives of individuals. Here's a good Canadian example - ba…

> banks now refuse accounts to "high risk" businesses

We have/had that in the US too: https://en.wikipedia.org/wiki/Operation_Choke_Point

In this case the federal gov't (FDIC and DOJ) pressured the banks. They even attacked a Constitutionally-protected activity (firearms)

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#102

Earlier quoted context omitted.

Then either the ATM had 20x too much cash in it, or the store will be unable to satisfy 19/20 requests for cash back? People withdrawing cash from the ATM (often incurring a non-trivial fee) to pay in the same store, rather than just paying on card, seems to be a marginal case and indeed inferior to card payment.

ATMs are often refilled only every day or two, whereas the store's registers are replenished periodically, often at shift changes or when demand increases. Perhaps more importantly the register also takes _in_ cash as unrelated customers pay with cash.

Cash in an ATM is orders of magnitude safer than cash in a till, most significantly for the store staff as less cash invites fewer (traumatising, dangerous) robberies.

When I worked in a convenience store 20 years ago, we’d dump cash into a safe through a mail slot every time the cash in the till rose over a certain amount (the register computer would show a red bar with a message to this effect), and we’d routinely have to turn down requests for all but trivial amounts of cash back for this reason.

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#104
post #83

Earlier quoted context omitted.

In Nevada the source code for gaming devices is required to be provided to the state gaming commission. (c) In the case of a gaming device, a copy of all executable software, including data and graphic information, and a copy of all source code for programs that cannot be reasonably demonstrated to have any use other than in a gaming device, submitted on electronically readable, unalterable media; http://gaming.nv.go…

But only for "programs that cannot be reasonably demonstrated to have any use other than in a gaming device". Makes one imagine what kind of political trench wars probably went on behind the scenes about this regulation. Edit: On second thought, this seems awfully easy to circumvent. What stops me from making a rigged PRNG and then refusing to make the source code available on the grounds that there are lots of non-g…

The gaming commission also regulates how much each machine must pay out over a given period with a given take. Any machine not in compliance is removed, and the casino can be fined. Continued non-compliance can result in the termination of the casino gaming license.

This was true even before electronic slot machines.

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#105
post #83

Earlier quoted context omitted.

But only for "programs that cannot be reasonably demonstrated to have any use other than in a gaming device". Makes one imagine what kind of political trench wars probably went on behind the scenes about this regulation. Edit: On second thought, this seems awfully easy to circumvent. What stops me from making a rigged PRNG and then refusing to make the source code available on the grounds that there are lots of non-g…

What’s a PRNG?

Pseudo random number generator.

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#106
post #66

I just read through the comments and was VERY surprised to see noone call this out: > At this point, the crook(s) installing the malware will contact co-conspirators who can remotely control the ATMs and force the machines to dispense cash. Realize what this means. The ATMs are connected directly to the internet, with a VPN (hopefully...) sitting over the top of that. The ATM can still call out to the internet direct…

That configuration only works if the attacker can't re-configure the system, but considering they're suggesting that many ATMs are still running Windows XP, I'm guessing that finding a privilege escalation exploit is not that hard.

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#107

> The Secret Service alert says ATMs still running on Windows XP are particularly vulnerable, and it urged ATM operators to update to a version of Windows 7 to defeat this specific type of attack. I would argue that Windows isn‘t at all the right OS for this.

What is? And do you have an OS that you are comfortable calling "secure"? Remember security through obscurity as enjoyed by Mac and Linux doesn't apply here because there is actual money and hence incentive to find vulnerability at stake.

Linux employs security by obscurity now?

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#108
One of the first unethical “hacker” things I did was to attempt to change the bill output to larger bill. I got so incredibly nervous when I went into the debug screen that I power walked out of the corner store when the clerk noticed I had been at the machine for several minutes and had not inserted a card.

You find a lot of these ATMs that are even more insecure than the larger WinXP machines. Those little kiosks are perfect for skimmers, manipulation, or just fucking around with.

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#109
post #56

Earlier quoted context omitted.

You'd be surprised how many things are running Windows. I always wonder if the manufacturer just hires cheap contractors that haven't seen anything apart from Windows in their entire life, or if there is an actual reason it can't run on linux.

OpenBSD would be perfect for the job, wouldn‘t it?

An OpenBSD machine still running unpatched from the XP era would be every bit as vulnerable.

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#110

> The Secret Service alert says ATMs still running on Windows XP are particularly vulnerable, and it urged ATM operators to update to a version of Windows 7 to defeat this specific type of attack. I would argue that Windows isn‘t at all the right OS for this.

What is? And do you have an OS that you are comfortable calling "secure"? Remember security through obscurity as enjoyed by Mac and Linux doesn't apply here because there is actual money and hence incentive to find vulnerability at stake.

I don't think I've heard anyone make that Linux relies on security through obscurity in at least 15 years or so. Linux pretty much won in the server market, and if you consider the volume of e-commerce transactions by the big players on Linux alone... ATMs seem like the small stuff in comparison.
Post reply on HN