Live data from Hacker News

‘Jackpotting’ Attacks Hit U.S. ATMs

krebsonsecurity.com

41–50 of 174 posts

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#42
If you, like me, were wondering what the Secret Service (widely recognized for their duties as presidential bodyguards) has to do with ATM fraud, there's a comment below the article from the author:

> I didn’t mention it in the story, but perhaps I should have: The original mission of the Secret Service when it was created in the 1800s was to safeguard the U.S. currency from counterfeiters. Only after a few presidents were assassinated did their mission grow to include protection of the president and other dignitaries. Both are their dual roles today.

https://www.secretservice.gov/about/history/events/

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#43

Earlier quoted context omitted.

On the other hand, if you pay by card everywhere, your moments and spending habits will be tracked and catalogued. A lot of people are not comfortable with that.

The vast majority carry an internet connected gps tracker with microphone, Wifi, Bluetooth, sms and email all in one place with them at all times, and bank accounts, sms, emails are already accessible to the state on the server side. Shops are using facial recognition and Bluetooth to advertise and track customers. So I honestly think privacy in what you purchase is a ship that has sailed, this data will be recorded…

In Europe, the General Data Protection Regulation supposedly does just this. There is a notable exception for “national security”, but it does at least help move in the right direction.

https://www.csoonline.com/article/3202771/data-protection/ge...

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#44

>"The Secret Service alert says ATMs still running on Windows XP are particularly vulnerable, and it urged ATM operators to update to a version of Windows 7 to defeat this specific type of attack." I had no idea ATMs ran Windows!

To be specific, it’s most likely Windows Embedded.

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#45

It seems the ATM has not evolved very much over the past 20 years. Any ideas why?

If $X million is stolen every year by thieves, but it would cost[0] $2X to upgrade ATMs to prevent it then there might be a rational justification for the status quo. Or at least, one that the person(s) making the decision might use to rationalize it to themselves.

[0]depending whether you do (or even consciously don’t) include indirect costs such as law enforcement and knock-on effects such as funding other areas of crime with the proceeds

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#46

If you ever open up an ATM you'll realise that the majority of things are controlled by serial interfaces (upto 6 of them) for all the motors and pneumatic hardware. If the operating system becomes hardened enough, you'll eventually have people interface with the serial ports directly to manipulate the cash-drawers directly. I'm not sure why this hasn't really been done in practice but it shouldn't be to difficult to…

Don’t some ATMs spray ink on the bills if they detect tampering?

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#47

If you ever open up an ATM you'll realise that the majority of things are controlled by serial interfaces (upto 6 of them) for all the motors and pneumatic hardware. If the operating system becomes hardened enough, you'll eventually have people interface with the serial ports directly to manipulate the cash-drawers directly. I'm not sure why this hasn't really been done in practice but it shouldn't be to difficult to…

Somehow I'm not surprised that hardening is a higher priority for slot machines than for ATMs...

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#48
post #38

Earlier quoted context omitted.

How does it work with posting short scenes from a movie on YT, and possibly monetising? Is it just a case of the Studio not reacting or there's a grey area where you're able to do it?

The studio (content-owner) is who receives the proceeds of monetization, even if they didn't upload the video themselves.

[deleted]

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#49
post #3

Earlier quoted context omitted.

The "hack" in question involves replacing the hard drive. This isn't an embedded issue. This is a physical access to OS issue.

It doesn't help that almost all the fascia locks on each vendor's machines are a standard key. With that standard key, you have full access to the computer or embedded device drive. Nowadays the communication link to the dispenser is encrypted, making swapping the hard drive useless. The real problem is the machines aren't replaced very often so there are quite a few old models out in the field that are susceptible t…

> It doesn't help that almost all the fascia locks on each vendor's machines are a standard key.

Interesting. Is there a source for this?

Re: ‘Jackpotting’ Attacks Hit U.S. ATMs

#50

Earlier quoted context omitted.

Good luck with that, outside of a handful of Nordic oddballs, cash is still king in most of the world (US included). We have a massive unbanked population that isn't going to start using banks or digital payments anytime soon, no matter what politicians or economists may desire.

If they don't have a bank account, presumably they also don't use ATMs.

Right. But the people with bank accounts that need to conduct transactions with them have to.
Post reply on HN