Live data from Hacker News

Crazy Thin ‘Deep Insert’ ATM Skimmers

krebsonsecurity.com

461–470 of 484 posts

Re: Crazy Thin ‘Deep Insert’ ATM Skimmers

#461
post #157

Earlier quoted context omitted.

There are a large number of “smart” tab systems in use in US bars where the system retains your magnetic stripe data for the duration of your visit. You pass off your card, it is swiped and immediately returned. If you don’t settle your tab, it’s automatically settled with a pre-set tip using the stored track data. It’s convenient for bar owners and patrons as the bar doesn’t have leftover cards to deal with and the…

> There are a large number of “smart” tab systems in use in US bars where the system retains your magnetic stripe data for the duration of your visit. What a security nightmare.

More or less a security nightmare than a drawer or tray full of physical credit cards behind a busy bar at night, which is the alternative at US bars? I'd argue that time-shifting card data is actually safer, even if it is often against the merchant agreement.

I really haven't heard of much trouble caused by these systems - of course, they require magnetic stripes in general, which are a massive attack vector, but the bar use case specifically doesn't seem to cause additional issues that I'm aware of. There are so many lower-tech and easy ways to steal magnetic track data, like skimmers, that I don't think compromising bar-back point of sale systems is a particularly high priority for most criminals.

Anyway, this is probably just a small snapshot in time regardless, since once swiped-card transactions finally go away US bars will have to switch to the mobile terminal pay-as-you-go method anyway.

Re: Crazy Thin ‘Deep Insert’ ATM Skimmers

#462
post #461

Earlier quoted context omitted.

> There are a large number of “smart” tab systems in use in US bars where the system retains your magnetic stripe data for the duration of your visit. What a security nightmare.

More or less a security nightmare than a drawer or tray full of physical credit cards behind a busy bar at night, which is the alternative at US bars? I'd argue that time-shifting card data is actually safer, even if it is often against the merchant agreement. I really haven't heard of much trouble caused by these systems - of course, they require magnetic stripes in general, which are a massive attack vector, but th…

>Once swiped-card transactions finally go away US bars will have to switch to the mobile terminal pay-as-you-go method anyway.

Now you get it.

Re: Crazy Thin ‘Deep Insert’ ATM Skimmers

#463

> However, there are a great many smaller businesses in the United States that still rely on being able to swipe the customer’s card. Who are these businesses? Seriously, stop issuing cards without chips and send new card readers to theses businesses. End of story. Is it because US businesses use deeply embedded card readers in custom POS machines that aren't modular? Everywhere I go in South America and Europe, busi…

When Canada moved to Chip and Pin there was no fanfare. Merchants started getting chip terminals as part of the regular replacement cycle, consumers started getting chip cards as part of that regular replacement cycle, and eventually the terminals started telling users to insert their card. Interac was the first mover because most people were already familiar with swipe and pin, so the move to chip and pin was a virt…

I'm curious what actually determines when a pin number or signature is required. I seem to get asked for them pretty randomly, sometimes not at all. It's been this way everywhere I go (currently living in Germany). What does the store actually do with all the signed receipts at the end of the day, anyway?

Re: Crazy Thin ‘Deep Insert’ ATM Skimmers

#464

> crooks can then clone payment cards and use them to siphon money from victim accounts at other ATMs. How? I thought all ATMs ignore the magstripe and just read the chip nowadays.

The US is just so backwards on this. a) You can still run transactions as magstripe-only transactions (without any PIN or even signature required) or b) copy the security code (which on most American cards are also encoded on the magstripe) and use it online (CNP transactions). If you're familiar with 3D secure, most American banks and merchants don't require 3D secure to buy.

I'm aware of that, but this comment alleges that the clone can be used to withdraw money at an ATM, which I am skeptical of.

Re: Crazy Thin ‘Deep Insert’ ATM Skimmers

#465
post #386

Earlier quoted context omitted.

This spring I left a job working with payments in a SaaS for the self storage industry. I don't remember exact numbers but the overwhelming majority of the card present payments we processed were either keyed by hand or swiped with a magtek reader. A great many self storage companies are mom and pop operations that only have one or two locations, often run by retirees to supplement their retirement income. Needless t…

> This spring I left a job working with payments in a SaaS for the self storage industry. I don't remember exact numbers but the overwhelming majority of the card present payments we processed were either keyed by hand or swiped with a magtek reader. A great many self storage companies are mom and pop operations that only have one or two locations, often run by retirees to supplement their retirement income. Needless…

We're talking about people often in their 60s or 70s who quite literally hate technology and don't want to spend any money on it unless someone puts a gun to their head. Seriously, the company I worked for had dropped support for windows XP before I ever started there, but they still had some customers running it when I left (this year).

From the POV of these small business owners that Sumup terminal doesn't do anything to help them and if anything makes their life harder. It won't integrate with their business management software (our product) and most likely will have higher transaction fees than their current payment processor. The company I was with offered EMV terminals that were fully integrated with the management software (I helped write the integration), but there wasn't a lot of interest in them outside of larger companies. The small guys in general don't have a lot of incentive to care about information security. One of the other projects I worked on was migrating the management software from using encrypted CC numbers stored in its database to using tokens. When we took away the ability for users to unmask and view the full CC number some of them started saving saving card numbers in the plain text customer info fields (address, etc.).

Re: Crazy Thin ‘Deep Insert’ ATM Skimmers

#466
post #465

Earlier quoted context omitted.

> This spring I left a job working with payments in a SaaS for the self storage industry. I don't remember exact numbers but the overwhelming majority of the card present payments we processed were either keyed by hand or swiped with a magtek reader. A great many self storage companies are mom and pop operations that only have one or two locations, often run by retirees to supplement their retirement income. Needless…

We're talking about people often in their 60s or 70s who quite literally hate technology and don't want to spend any money on it unless someone puts a gun to their head. Seriously, the company I worked for had dropped support for windows XP before I ever started there, but they still had some customers running it when I left (this year). From the POV of these small business owners that Sumup terminal doesn't do anyth…

>don't want to spend any money on it unless someone puts a gun to their head.

"You won't be able to accept cards for payment unless you use an EMV terminal or tokenized card for recurrent CNP transactions."

Problem solved.

Re: Crazy Thin ‘Deep Insert’ ATM Skimmers

#467
post #86

Earlier quoted context omitted.

It may be worth running a magnet over your cards at this point. I can't think of a time I've used the mag-stripe. The skimmers here have a passthrough hole for the chip which means the mag-stripe only exists to feed the skimmers. So even this use case that gets skimmed isn't even using the mag-stripe itself! Fuck it. Where's my magnet.

I've used the mag stripe tons of times over the last couple of years. Most of the time it's when I get "CHIP MALFUNCTION" errors at a card reader, or sometimes they just tell me to swipe for no good reason. I wouldn't kill the stripe unless you've got a backup with you, at least for a while.

Tap is the standard, chip is the backup in Canada. I don't think my card would work with swipe anymore.

Re: Crazy Thin ‘Deep Insert’ ATM Skimmers

#468
post #465

Earlier quoted context omitted.

We're talking about people often in their 60s or 70s who quite literally hate technology and don't want to spend any money on it unless someone puts a gun to their head. Seriously, the company I worked for had dropped support for windows XP before I ever started there, but they still had some customers running it when I left (this year). From the POV of these small business owners that Sumup terminal doesn't do anyth…

>don't want to spend any money on it unless someone puts a gun to their head. "You won't be able to accept cards for payment unless you use an EMV terminal or tokenized card for recurrent CNP transactions." Problem solved.

Sure, but if the US government was on top of passing legislation to force businesses to stay up to date in order to protect consumers we wouldn't be having this conversation.

Re: Crazy Thin ‘Deep Insert’ ATM Skimmers

#469

Earlier quoted context omitted.

Also, when you use self check in terminals at the airport, if you use your credit card for ID, it only works via swipe.

Credit card for ID? This explains a lot.

It’s easy so people go with it. Otherwise you have to type things.

Re: Crazy Thin ‘Deep Insert’ ATM Skimmers

#470
post #468

Earlier quoted context omitted.

>don't want to spend any money on it unless someone puts a gun to their head. "You won't be able to accept cards for payment unless you use an EMV terminal or tokenized card for recurrent CNP transactions." Problem solved.

Sure, but if the US government was on top of passing legislation to force businesses to stay up to date in order to protect consumers we wouldn't be having this conversation.

It's not the government's place, it's industry's place.
Post reply on HN