Can’t Hack a Hacker: Reverse Engineering a Discovered ATM Skimmer
trustfoundry.net
trustfoundry.net
https://www.flickr.com/photos/angusf/4450137156
Then the 'keypad overlay' in the second image is just a photoshop of a keypad.
Fortunately, the rest of the article was interesting enough to outweigh these issues. The best advice contained in the article, for me, was that interfering with ATM skimmers and camera modules can result in direct intervention by the criminals who may be watching nearby. The best strategy is to leave it alone and alert the bank immediately.
If you swipe your card at a machine that supports chip it will be disabled until the next time you use the chip.
However, if the card reader doesn't support chip you can still swipe. Essentially all machines support chip now. Only vending machines / parking meters still use swipe.
Fun fact: They apparently aren't connected to anything, and transactions are processed later, so basically any valid card will go through regardless of funds etc.
The market for shoddy bacon baguette & gin fraud is presumably fairly limited.
I really wish I could find that video again. It was interesting.
Cards however have a special "service code" on the mag stripe/chip. Certain cards like the Monese debit card or debit cards for customers who are not allowed to go into overdraft can only be used for online transactions. So they wouldn't work in this case where the transaction is authorized offline.
Source: My experience with cards in Germany where the train company is processing credit cards the same way.
I assume that first word isn't what you meant, but I can't come up with any substitute. What was it supposed to be?
The clerk asked me what I wanted and I said "5 iPods please". I would be suspicious if anyone asked for that many iDevices. When they realized they only had 3 iPods, I said I'd take those. When I went to check out, I asked them to break up the transactions into < $500 chunks so as to not cause additional oversight, they obliged.
This was the first time I had ever used a chip-enabled card. It was obvious to the cashier, I was fumbling around with the card and had to ask how to operate it. Finally, after I bought three iPods in two transactions with a card I had obviously never used before, with the merchandise in a bag in hand, they ask for the credit card and my ID to verify the name. Busted, I thought! But no, after explaining that I was buying the devices on behalf of my boss (with no proof of this) they let me go on my merry way. I was flabbergasted.
TLDR: If you have a stolen credit card and want to use it to buy expensive electronics to fence, go to the Electronics department at the West Lafayette Walmart. Chip and signature cards offer no improvement in security, even when faced with at least five big red flags that indicate fraud.
Furthermore, it's always been obvious that the chip'd cards provide no improvement for online fraud.
It's a PR move to hide the fact that the banks and creditors rely so heavily on transaction disputing to fend off fraud.
Yet, a company sends someone to buy a set of mainstream phones split on two transactions? Totally believable for a cashier and not as crazy as people's grocery orders have gotten while I was in line. ;)
Don't believe me? Wrap your smartphone in foil and then call it.
Mine rang. Freaked me out when I discovered this.
It didn't ring when I put it in the freezer though.
> A common misconception is that a Faraday cage provides full blockage or attenuation, this is not true. The reception or transmission of radio waves, a form of electromagnetic radiation, to or from an antenna within a Faraday cage is heavily attenuated or blocked by the cage. However, a Faraday cage has varied attenuation depending on wave form, frequency or distance from receiver. Near field High powered frequency transmissions like HF RFID are more likely to penetrate. Solid steel cages provide better attenuation over mesh cages.
https://www.google.com/search?q=lead+bag+for+film&gbv=1&prmd...
I wonder if that would be far better to almost completely kill a signal.
Also it probably just reduces the signal, not kill it completely so maybe how close to the tower you are matters too.
Can you call a cell phone in the microwave?
Physics Girl
I'm surprised that the phone in the video was able to receive a signal.
I wonder how much 2.4 GHz power is leaking from that thing.
A microwave with a bad shield has the potential to leak a ton of power at a frequency that's used by many devices.
I know, that could never catch on — no way to track your data or charge you a commission.
Note: Brian Krebs recommended the same thing as a barrier to ACH fraud where the recipients were whitelisted with maybe in-person, strong-auth registration.
You don't think that'd work?
This immediately jumped out at me. Most likely, you might get scolded or in trouble for screwing up chain of evidence or something. In a rare scenario, they might be watching the place with the skimmer there waiting for the perp to show up. Not sure of the risk there.
There was debate on how to handle it on Krebs. I think one person's suggestion of sending an anonymous tip about a skimmer to number on ATM was a good one. Keeps you out of FBI's microscope, local thugs watching don't get you, no convincing store clerks, and the skimmer gets taken care of somehow. Maybe best idea.
Putting the card in the same pocket with my Android phone with a wallet case that has a magnetic "lock" seems to be enough...
I assumed it had rolled out across most of the US at this point since most of the smaller places had even implemented it.
This is true. It's also weird, since really they should be charging less for chip-and-pin, not more for magstripes. By moving to chip-and-pin they immediately release themselves from the hook for card theft, moving the liability to the card holder. The high transaction costs in card networks have historically been defended as largely stemming from fraud costs. Yet, we're expected to pay the same fees.
It's a good time to be in the card processing business.
FWIW, it may be a bank requirement, not a vendor one.
"Beginning in October 2015, that liability will shift to the merchants in certain cases unless they have replaced or upgraded their card acceptance and processing systems to use chip-enabled devices and applications to process payment transactions."
1. http://www.emv-connection.com/understanding-the-2015-u-s-fra...
EDIT: Grammar
Seems like no one is on the same page
I understand the US is doing a slightly slower rollout so you guys might have to put up with either/or for almost a year, but once it is done you'll get used to using the chip pretty quickly.
The two "big" dates for EMV in the US is Oct 2015 (liability shift: merchants) and October 2017 (liability shift: fuel dispensers and ATMs)[0]. After Oct 2017 there will be no reason for banks to issue cards with a magnetic strip at all (although they CAN for travel).
In Europe some banks no longer issue cards with magnetic strips (chip only).
[0] https://www.aciworldwide.com/-/media/files/other/published%2...
[1]: http://investor.visa.com/news/news-details/2016/Visa-Speeds-...
Now that the chip cards and functioning readers are the norm, you see a lot of terminals with a piece of paper taped onto them that says "NO TAP".
I've tapped my card at some merchants who were unaware that their terminal had been tap-enabled. "We don't have tap yet" "It's approved" "Oh!"
They are vulnerable to a set of physical attacks e.g. etching off the surface of the chip, scanning it with sensitive microscope and attempting to deduce stored data from that (IIRC there were some proof of concept videos posted on HN a few months ago) but it's not a major risk as it (a) requires physical possession of the card, (b) takes time and is destructive, and the result is useless once the owner reports the lost/stolen card, and (c) has significant costs (rare expensive equipment, specialized skills, lots of time) that far exceed the limits on normal credit cards.
If I'm reading this right, it still doesn't compromise the data on chip (i.e., the card cannot be copied, the limits enforced by chip are kept, etc) but allowed to modify the chip so that a physically stolen card can be used without knowing the PIN because the POS erroneously accepts a PIN verification response from another chip. This described hack seems to be impossible in recent chip implementations as well, but I'm not eager to dig through specs to check.
Still, it is still similar to the chip analysis vulnerability in risk as it (a) requires physically stealing the card and modifying it - thus it doesn't enable the far more common scenarios of skimming the card by an ATM device or a person e.g. waiter; and (b) doesn't allow to clone the card, so purchases must be made quickly by people physically close to the thieves and operators doing the chip-modification, so it means a much greater chance of arresting the whole team than in the currently common fate of stolen US card data where you can just sell the data to people anonymously over internet, and they themselves can easily make cloned cards to make the risky part of actually obtaining the money/goods.
A skimmed card will just work on the first try. A card modified like this is still likely to trigger "stolen, call the police" message on the POS terminal.
The keys on ATMs I've used don't actually move much, so you could put several fingers on the keys at once and press only slightly harder with the one you intended. It might confuse any PIN pad overlays too, which by design have to activate with less pressure than the real switches so as not to arouse any more suspicion.
Though not to hard to realize last four are pin.
If the atm has a backspace instead of all clear, numbers, backspace one or two, numbers.
Still, not the usual routine.
Here in Fiji, ATMs have a an opaque plastic guard over the keypad to keep the pin out of view of a camera.
Kinda like this one but bigger: http://thumbs.dreamstime.com/x/atm-keypad-22036137.jpg
they're probably back in the u.s. again. it's unlikely they'll send an assassin overseas.
In comments, it's ok to ask how to read an article and
to help other users do so. But please don't post
complaints about paywalls. Those are off topic.