Live data from Hacker News

‘Jackpotting’ Attacks Hit U.S. ATMs

krebsonsecurity.com

141–150 of 174 posts

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#142

I assume this will end with there being fewer ATMs. That they will become more expensive to run in due to costs of hardened physical devices and insurance. If they become too rare it could result in a reduction of cash usage, maybe significantly.

Good luck with that, outside of a handful of Nordic oddballs, cash is still king in most of the world (US included). We have a massive unbanked population that isn't going to start using banks or digital payments anytime soon, no matter what politicians or economists may desire.

The US isn't exactly a leader in banking technology. While I agree that cash is here to stay for the time being, the introduction of contactless payments in the UK has made the conversation around dropping cash seem realistic (with he lower fees almost everywhere now accepts contactless, and unlike chip and pin, transaction times are faster than using cash...)

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#143
post #126
post #77

Earlier quoted context omitted.

There are easily multiple locks that could be put in place internally. Encrypt the signal from the host to cash dispenser, have a debugger process that is connected to the host process that also stores the encryption keys and or talks to an HSM. Mitigates tampering of a live system, makes flashing new firmware problematic. Physically limit the cash dispenser from outputting k bills over n seconds. Have those limits b…

They should probably hire some people from microsoft's xbox department, or sony's playstation department. A lot of money has gone into locking this hardware down, and I think for the xbox 360, which was released in 2005(!) there is still only one hack they couldn't solve with a software update, and that's soldering to the CPU and glitching it on a specific compare instruction. I would bet , this "sophisticated malwar…

Another field where security is taken very seriously is cable TV boxes. You'd be surprised how much work goes into securing them.

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#144
post #121

Earlier quoted context omitted.

It's simply not possible to carry on business without a bank account. For that reason I'd like to see legislation which makes it illegal to refuse customers on the basis of their business model, so long as it is legal.

I'm familiar with a few local restaurants that take cash only. All Chinese food places for whatever reason. If your car ever gets towed away on a private-property parking violation, good luck getting it back paying in anything but cash. My barber takes cash only. It's not as uncommon as you might think.

Are they stuffing that money into a mattress? Buying stuff with it? Or do they deposit it somewhere?

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#145
post #71
post #47

Earlier quoted context omitted.

Somehow I'm not surprised that hardening is a higher priority for slot machines than for ATMs...

I've read (though have no first hand experience) that slot machines have better security and better vetting than electronic voting machines do so I'm not surprised either.

They also tend to exist in the context of massive surveillance and security efforts by casinos.

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#146
post #56

>"The Secret Service alert says ATMs still running on Windows XP are particularly vulnerable, and it urged ATM operators to update to a version of Windows 7 to defeat this specific type of attack." I had no idea ATMs ran Windows!

You'd be surprised how many things are running Windows. I always wonder if the manufacturer just hires cheap contractors that haven't seen anything apart from Windows in their entire life, or if there is an actual reason it can't run on linux.

Could be to do with adding and controlling them from an Active Directory Domain perhaps.

A bank I worked for years ago had ATM domains (in different forests) and had policies applied to the ATM's.

They ran XP at the time.

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#147

Earlier quoted context omitted.

There have been several cases of stolen construction equipment (fork lifts, wheel loader, etc.) being used to steal ATMs. For example: https://www.youtube.com/watch?v=K05LT-WpN5I Achieving 100% physical security is going to be hard.

In the UK at least it's common for ATMs at banks and supermarkets to be built into the wall. You still have freestanding ones too (including in bank branches), but if the solution to this issue is to get rid of the freestanding ones, it's not likely to be a major inconvenience, especially as many stores offer cash back on request (e.g. buy a pack of gum on card, request £30 cash back, get charged for the gum and the…

There are ~20 ATMs within a 5 block radius of my apartment (NYC), all in small shops that have no place for an in-wall ATM, and this is in a relatively low ATM density area of the city; there are thousands more like this across the 5 boroughs.

In aggregate these small freestanding ATMs are a huge business, it's unlikely they will harden their whole fleet by building in-wall installations.

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#148
post #47

If you ever open up an ATM you'll realise that the majority of things are controlled by serial interfaces (upto 6 of them) for all the motors and pneumatic hardware. If the operating system becomes hardened enough, you'll eventually have people interface with the serial ports directly to manipulate the cash-drawers directly. I'm not sure why this hasn't really been done in practice but it shouldn't be to difficult to…

Somehow I'm not surprised that hardening is a higher priority for slot machines than for ATMs...

I remember like 20 years ago on the internet there was a lot of cool video/audio tech always being created and it was funny because it didn't really make sense at the time given bandwidth - but everyone joked it was the porn industry pushing all that money/development (fk, even my dad said that once - ok ok I think I turned out ok). It's funny how we get where we get.

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#149
post #112

I worked for Diebold on their ATM's for a while. I was surprised to learn that they run full Windows. In fact, one of the projects I was on had a requirement that we upgrade the OS from XP to Windows 7 for security reasons. Regardless though, you can make an ATM do whatever you want if you have enough time and access to it. One of our low level debugging tools allowed you to effectively control every aspect of the de…

A full version of Windows or Windows Embedded ("Windows IoT")?

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#150
post #29

According to FireEye, the Ploutus attacks seen so far require thieves to somehow gain physical access to an ATM — either by picking its locks, using a stolen master key or otherwise removing or destroying part of the machine. ATMs need to be more physically secure, like bank safes, if they are to be resistant to such attacks. The software part is mostly immaterial here, IMHO --- it doesn't matter what the software is…

I used to work with various ATMs and the cash dispenser _is_ a hardened safe, with a combination lock and all. If you are to steal an ATM, you will still need to open the safe and the simplest option would indeed be to try and persuade it to just dispense the money. The thing is that ATMs from larger vendors (IBM, NCR, Bull, Siemens, etc.) have layer upon layers of protection features. For example, you can configure…

You explain more about the x.28 radio, and its purpose? Communication between where?
Post reply on HN