Why not publicly distribute the design? Because skimmer-makers might adapt? It seems trivial to acquire one (getting a job at Target or spoofing a corp email account isn't a high barrier).
That's what the OP is.
> Based on the success we saw with EasySweep, we decided to offer the design, for free, to other retailers.
Since it's only implied how it works and there seems to be some confusion in the comments. It seems like the technique is to simply create a very form-fitting insert which won't fit properly if some device is overlaid onto the machine. The insert is not left in the device, but is just used for a quick in-and-out check.
Why not publicly distribute the design? Because skimmer-makers might adapt? It seems trivial to acquire one (getting a job at Target or spoofing a corp email account isn't a high barrier).
That's what the OP is. > Based on the success we saw with EasySweep, we decided to offer the design, for free, to other retailers.
You still have to request access from Target. GP is asking for it to just be published online somewhere.
How do these skimmers work with chip&pin? I understand how magstripe skimmers work, but my understanding is that chip&pin is an active challenge response protocol. I’d love to hear more.
The US still has a heavy reliance on magstripe, even though we rolled out EMV, and many cards still have it, and you can just take a stripe dump regardless. The actual user of the stolen card dump will cause the terminal to allow a magstripe fallback (typically with a bad chip on a fake card that won't read) -- "aw jeez my stupid chip isn't reading" is still every much a valid excuse to a cashier to go to magstripe.
I think there are also just lots of POS systems in the US that aren't on EMV yet. Major retailers are on EMV but random old rural businesses probably aren't.
Believe it or not, Verifone part KIT177-005-01-A is, in fact, a "Skimming Device Detection Tool". https://www.geminicomputersinc.com/kit177-005-01-a.html
I would imagine there's something wrong with it if Target isn't just buying it Though it could just be cost given that Target could just pay for a plastic injection mold overseas and then pay peanuts yearly to make a 60k batch for their yearly renewal they mention, compared to $20*60k each time
Yeah. $8-24 a unit vs "under $1." Although 60,000 x 8 still isn't a huge amount of money.
it allows any Target team member to easily sweep a store for skimmers I'm unclear on how this is supposed to help - unless the skimmers are being installed by frickin ninjas it seems like they already needed insider cooperation.
I feel like this would be particularly easy at self checkout stations where there's usually like 1 employee handling a dozen or so stations. You can also get someone else to go "accidently" scan a pack of gum twice and hit the help button to have said employee come over and fix it. That would provide more than enough of a distraction to quickly place a skimmer on a different station.
We wouldn't even need to worry about this dumb stuff if we had actual cryptographic PKI for payments. Honestly at some point fraud is 100% the card issuer's fault when the tech to prevent it is here and now. Why I still can't register a public key with my bank and say "do not under any circumstance honor a transaction unless it's signed with my private key" is beyond me.
> Why I still can't register a public key with my bank and say "do not under any circumstance honor a transaction unless it's signed with my private key" is beyond me. What you are describing is Bitcoin.
That's what the OP is. > Based on the success we saw with EasySweep, we decided to offer the design, for free, to other retailers.
You still have to request access from Target. GP is asking for it to just be published online somewhere.
Ah good point. Target's one of the most serious companies in the world about this, with a forensics lab and everything. I'm surprised they're doing this much, even if the skimmers obviously have access to the same measurements.
The US still has a heavy reliance on magstripe, even though we rolled out EMV, and many cards still have it, and you can just take a stripe dump regardless. The actual user of the stolen card dump will cause the terminal to allow a magstripe fallback (typically with a bad chip on a fake card that won't read) -- "aw jeez my stupid chip isn't reading" is still every much a valid excuse to a cashier to go to magstripe.
I think there are also just lots of POS systems in the US that aren't on EMV yet. Major retailers are on EMV but random old rural businesses probably aren't.
Some big chains still haven't switched.
I was in a major home improvement store a few weeks ago, and it was swipe-only. Either Home Depot or Lowe's.
The US still has a heavy reliance on magstripe, even though we rolled out EMV, and many cards still have it, and you can just take a stripe dump regardless. The actual user of the stolen card dump will cause the terminal to allow a magstripe fallback (typically with a bad chip on a fake card that won't read) -- "aw jeez my stupid chip isn't reading" is still every much a valid excuse to a cashier to go to magstripe.
Makes me think about intentionally corrupting the magstripe on my cards. I wonder if that’d cause any issues. I can’t remember having to fall back from the chip to a swipe in ages, and I have a couple of cards, so I could keep one as a backup with a working stripe just in case (long ago I found myself far from home and low on gas, with no cash, a dead cell phone and a “suspicious transaction” blocked credit card, and…
It's only an issue with EMV Fallback, which you'd probably not need if you have a backup card that is good. Basically if the chip or near-field antenna on your card fail, the fallback is to collect a magnetic stripe read. Properly-configured readers don't need the stripe read to complete a transaction.