Researchers find avenues for fraud in Square
news.cnet.com
news.cnet.com
The hacks they mentioned:
- Read data from a card with a square reader. Whoop dee doo... a square reader has to do that to process a transaction. They are just capturing that outside of the app?
- Extract the cash from a gift card - Afaik, there's nothing nefarious about this. I had a gift card for $500... paid the processing fee to square and got the cash in my account. Great hack
- Process a transaction without the physical card - You can do that already in square, it just costs you more.
It doesn't make it easier to commit fraud IN square. You still need a tax id / social security number to set up an account. And you need to have a bank account connected.
Really, what it makes it easier to do is to skim credit card numbers. And this is nothing to do with square and everything to do with credit card security.
But that does not mean frauds exploit it easily.
Any one who has access to the credit card already has the credit card numbers and the security code. One could always use that information and order items online. But there are security mechanisms that protect such usage. The audio recording is identical to storing the credit card number. Square uses other mechanisms (like capturing location of each transaction) to deter fraud behavior.
Even if Square used an encrypted dock-connector the magnetic reader is still the equivalent of a tape-reader head. The trick could still be done albeit with some light soldering.