Live data from Hacker News

Crazy Thin ‘Deep Insert’ ATM Skimmers

krebsonsecurity.com

441–450 of 484 posts

Re: Crazy Thin ‘Deep Insert’ ATM Skimmers

#441

Earlier quoted context omitted.

Unfortunately "random" is a headache for a certain type of bureaucrat. They can't really do "random" or "unpredictable" and it needs somebody who actually understands what is going on to sit down and walk through how they can check whether to tick this box. For the Web PKI we had this problem extensively. No, if you set the top bit of this 128-bit integer, that's not 128 random bits. That's 127 random bits, the top o…

> as there's a tiny chance a random number fails the test There’s ~4e23 _grains of sand_ on Earth. There are more possible values in 128 bits than grains of sand on Earth. Take it further. There are 10^11 stars in our galaxy. If every star in the Milky Way had a planet identical to Earth orbiting it, there would be ~4e35 grains of sand on all the Earths orbiting all the stars of the Milky Way.[1] If you assigned each…

Sure. As an engineer who knows what they're doing I of course agree with you. I'd argue with management that random is both obviously the correct choice and unlikely to cause compliance problems. But...

Here are some of the "Unpredictable numbers" from a series of EMV transactions reported in a paper in 2014:

F1246E04, F1241354, F1244328, F1247348

That's a 32-bit value, so not enough to count living humans, never mind grains of sand. And it's not very "Unpredictable", indeed the researchers have more data from the logs which allows them to predict with confidence future values from that same terminal, basically the low 15 bits are a clock which repeats every 32768 cycles, with cycles having a fixed duration of several milliseconds. The high bits, if they change, don't change for a prolonged period.

Re: Crazy Thin ‘Deep Insert’ ATM Skimmers

#442

> However, there are a great many smaller businesses in the United States that still rely on being able to swipe the customer’s card. Who are these businesses? Seriously, stop issuing cards without chips and send new card readers to theses businesses. End of story. Is it because US businesses use deeply embedded card readers in custom POS machines that aren't modular? Everywhere I go in South America and Europe, busi…

I just got a replacement card from my bank. It still has no chip in it.

Re: Crazy Thin ‘Deep Insert’ ATM Skimmers

#443
post #346

Earlier quoted context omitted.

So should all parking meters be replaced? Paid for by tax payers? How would you implement something like that?

In many European countries parking is paid with a mobile app these days. Very few use parking meters.

I encountered this in the US a few days ago. It made me angry because it locks out those who don't have a smartphone or aren't willing to install Yet Another App.

I moved on and found a different lot.

Re: Crazy Thin ‘Deep Insert’ ATM Skimmers

#444

> However, there are a great many smaller businesses in the United States that still rely on being able to swipe the customer’s card. Who are these businesses? Seriously, stop issuing cards without chips and send new card readers to theses businesses. End of story. Is it because US businesses use deeply embedded card readers in custom POS machines that aren't modular? Everywhere I go in South America and Europe, busi…

I’m in Australia and an American friend who is visiting was shocked at how nearly everywhere from small cafes to supermarkets all support payments with Apple/Google pay and tap and go.

Pretty much everywhere I go in the US supports these as well. I rarely see anyone use them, though.

Re: Crazy Thin ‘Deep Insert’ ATM Skimmers

#445
post #319

Earlier quoted context omitted.

If your phone breaks or you lost it, if there is no connectivity, if apple decides to cancel your digital existence, then what? And it means everything you buy is associated with you and recorded forever to be sold to endless advertisers (and worse) and the transaction may be blocked by third parties. If you pay cash it works without a depending on anything external (no internet, no electricity), it is not traced, it…

Cash is only optimal for privacy, not convenience or availability or speed or security. If my credit card is stolen, I get my money back (so long as I reported it in time, and didn’t surrender to them my pin). Not so with cash. Cards take a second or two to process payments on average. Not so wish cash. My bank account / credit card limits always have enough to cover my purchases, whereas my physical wallet might be…

> Re internet/electricity outages, this is so rare enough to not be a concern

This is definitely not true in my part of the US. Internet outages are not common, but they're also not rare. I see it happen 3 or 4 times per month.

Re: Crazy Thin ‘Deep Insert’ ATM Skimmers

#446

Earlier quoted context omitted.

> as there's a tiny chance a random number fails the test There’s ~4e23 _grains of sand_ on Earth. There are more possible values in 128 bits than grains of sand on Earth. Take it further. There are 10^11 stars in our galaxy. If every star in the Milky Way had a planet identical to Earth orbiting it, there would be ~4e35 grains of sand on all the Earths orbiting all the stars of the Milky Way.[1] If you assigned each…

Sure. As an engineer who knows what they're doing I of course agree with you. I'd argue with management that random is both obviously the correct choice and unlikely to cause compliance problems. But... Here are some of the "Unpredictable numbers" from a series of EMV transactions reported in a paper in 2014: F1246E04, F1241354, F1244328, F1247348 That's a 32-bit value, so not enough to count living humans, never min…

I'm a bit curious now how compliance with the spec is tested.

It certainly can't be done with "pure" unit tests, and it would be difficult to ensure sufficient entropy even with "impure" tests that examine multiple nonces generated in sequence.

Do you happen to have a link to the paper you mentioned?

Re: Crazy Thin ‘Deep Insert’ ATM Skimmers

#447

Earlier quoted context omitted.

Sure. As an engineer who knows what they're doing I of course agree with you. I'd argue with management that random is both obviously the correct choice and unlikely to cause compliance problems. But... Here are some of the "Unpredictable numbers" from a series of EMV transactions reported in a paper in 2014: F1246E04, F1241354, F1244328, F1247348 That's a 32-bit value, so not enough to count living humans, never min…

I'm a bit curious now how compliance with the spec is tested. It certainly can't be done with "pure" unit tests, and it would be difficult to ensure sufficient entropy even with "impure" tests that examine multiple nonces generated in sequence. Do you happen to have a link to the paper you mentioned?

https://www.lightbluetouchpaper.org/2012/09/10/chip-and-skim...

... mentions these values and links a paper they wrote, I suspect it isn't the 2014 paper I was thinking about but it's on the same topic.

The good news is that in the years after this work, I believe the rules were tightened up, there's a good chance if you buy a brand new EMV terminal the people testing it wouldn't have accepted 1, 2, 3, 4, 5 as a series of "Unpredictable numbers", so crooks today are less likely to be able to exploit this, and more likely to get caught.

The bad news is that courts remain very easily persuaded that banks know what they're doing, and expert witnesses who can make it clear that the bank have no idea what they're doing and shouldn't be trusted more than a typical citizen are expensive. If it ends up being your word against a bank, the court is probably going to believe the bank.

Re: Crazy Thin ‘Deep Insert’ ATM Skimmers

#448

Earlier quoted context omitted.

> What about it is inconvenient? You have to remember not one, not two, not three, but several digits. Not only that. You have to look at a keypad. Oh, and you have to push buttons. Not once, not twice, but several times! Pity the poor fool who accidentally pushes the wrong button. More looking at a keypad and button pushing! Yeah, I don't get it either. My only guess is the customer support calls for forgotten pins…

Don't they have to deal with those forgotten PIN calls anyway? Don't you need a PIN to get cash out of an ATM? My debit card and its PIN are used for a few different things - in-store payments, using the ATM, and authenticating when in-person at a bank. The last one is interesting - each desk at the bank, both the tellers and the offices where you talk to someone, has a terminal and every interaction starts with putt…

Imagine that in this other alien culture, most people were using credit cards for most transactions and rarely ever use their ATM/debit card. They don't have a day to day use for cash so do not frequent ATMs nor do they have much reason to frequent bank branches.

They've been presenting a credit card and making a squiggle with a pen for years and never remembered a PIN at all. Their credit card bill is paid electronically online somehow, either automatically because of a direct debit configuration setup years before or via an interactive banking website. These were authenticated with a web password and perhaps archaic knowledge of a routing number and checking account nunber. No PIN in sight there either...

Re: Crazy Thin ‘Deep Insert’ ATM Skimmers

#449

Earlier quoted context omitted.

it’s because american corporations put profit above all else, and someone probably crunched the numbers and determined that faster transactions make them more money despite higher occurrences of fraud

How could entering a 4 digit PIN be slower than "printing a piece of receipt, handing over a pen and waiting for the customer to sign"?

When still requested, the signature is often just scrawling something into a signature box on a touch screen of the same device with the chip reader or contactless receiver. There might be some stylus dangling on a tether and often a spastic finger tip is sufficient to satisfy the UI.

Re: Crazy Thin ‘Deep Insert’ ATM Skimmers

#450
post #327

Earlier quoted context omitted.

> Cash is only optimal for privacy, not convenience or availability or speed or security. Security == privacy. And cash certainly wins availability by a long shot, it can't be blocked by any kind of outage. Convenience is arguable I suppose. I'd rather hand over cash than deal with anything electronic that can fail. > If my credit card is stolen, I get my money back (so long as I reported it in time, and didn’t surre…

> In many areas electricity outages are a daily occurrence. I’ve lived in 4 continents, never had daily, weekly, or even monthly outages. > Security == privacy. And cash certainly wins availability by a long shot, it can't be blocked by any kind of outage. If you don’t have enough cash in your wallet then you don’t have any availability. If you have a internet outage your debit/credit cards still work offline. Also s…

> If you have a internet outage your debit/credit cards still work offline.

Not when the store is offline.

The convenience store just up the street from here every now and then goes cash-only whenever their connectivity is down.

Post reply on HN