Why are McDonald’s Self Service Kiosks so hackable?
ghuntley.com
ghuntley.com
- Snarky and talks down about people not "in the know" about potential security issues.
- Supreme confidence that they are super knowledgeable about how it "should" be done.
- Fails to provide any actual demonstrable impact, but doing the old "left to the reader" as to how it's clearly exploitable.
But when you drill into the details, they are just fundamentally wrong about how the product is even working, what is possible with the attack surface, and how components are interacting with each other.
There are plenty of vulnerabilities out there, and companies do make stupid mistakes with regards to security in lots of situations. That doesn't mean that every pie in the sky idea you have (oh look, I did a kiosk escape, dot dot dot, clearly I can credit card skim now) is possible.
Yup.
PoC or GTFO.
> If someone installs malware on here - just insert a usb stick or use the recovery mode - then tada we have the next generation of atm skimming.
Which is just not how these payment devices work- they are entirely separate, they are sent a request to make a transaction, that transaction (and also likely the transaction request itself) occur entirely in a secure connection between someone like Verifone, and the device itself.
The PC has has no way to get those card details, only request a transaction and confirm a payment status as successful or failed.
The most interesting transaction would be a very large refund. I’ve seen organised crime groups target restaurants in the past to issue themselves £1k+ refunds. They pretend to pay for meal, and while they have the EMV terminal in their hand, they cancel the original transaction, put the device into management mode (using default passwords) and issue themselves a nice large refund.
It’s a complete pain in the arse for the banks receiving these refunds to catch and deal with properly. It’s surprisingly hard to return the money to the restaurant.
Of course it is still possible to skim the card number off of magnetic strip and sell it in the darknet. However, the static card number is becoming less and less of a relevant thing now a days as more sites/processors are migrating to dynamic auth such as Apple Pay etc.,
A good overview + detail : https://www.youtube.com/watch?v=Zv1DjtBwADg
And in this case the server can have a large antenna and not require physical contact.
So in essence, orders of magnitude worse than the magnetic strip.
Sniffing the NFC traffic gives the attacker nothing useful, just as skimming an EMV contact transaction gives the attacker nothing useful.
>The contactless EMV chip transaction path leverages the cryptographic functions normally associated with a contact EMV chip transaction and uses the same authorization and settlement fields as a contact chip transaction. [0] [1]
[0]: https://www.emv-connection.com/downloads/2015/12/EMV-and-NFC...
[1]: See EMV specifications, “Book 2 – Security and Key Management,” Version 4.3, November, 2011, http://www.emvco.com/specifications.aspx?id=223.
Just ask for it yourself. That's what I meant with encryption not meaning jack if you are one of the participants.
to my knowledge, nobody has ever successfully demonstrated an exploit of this nature.
It is trivially employed.
That was a bit disconcerting.
A rogue terminal can decide to authorize the transaction with a “signature” (there are legitimate uses for this)
Or even with no PIN at all (there are also legitimate uses for this)
It’s also possible to do either of these 2 things and then report back that the transaction what authorized with a PIN
Most cards aren't like this.
With my UK issued AmEx & Visa cards (both Charge/Credit), at certain places terminal didn't even ask me for a PIN, and the transaction just went through as "Chip & Signature"
Which is kinda pointless since if you are paying and receiving service at the counter - you aren't really receiving a service to tip for.
Its crazy, but kinda reasonable
Checking which corresponds to what card is the hard step because you need access to an acquirer to my knowledge, and you'll lose that access quiet quickly if you attempt too many incorrect combinations.
EMV (the card standard used by all modern chip/contactless cards) supports PINs between 4-12 digits in length.
I’d change mine too except I use the PIN so infrequently (99% contactless now days) I’m worried I’d forget the new one!
Not clear how you would match the pin either without having some personal info on the user which you don't have.
In short, for the kiosk this is a anonymous transaction that was confirmed paid.
The most you could do is ask for more details in the kiosk app which would be clunky and very suspicious.
If you want to get creative with attacks you can, but sometimes comparing a creative attack to a "boring" attack can help frame the conversation.
I've written kiosk apps that landed across the US and while there was a ton of hand wringing about security, and in an informal setting I brought up a simple question:
If you reverse engineer the update process to have it show a penis, or you just carve a penis into the public display with a pocket knife, what's the difference and which is more likely to happen?
Also, vandalism is about the least interesting reason to hack kiosks. It can get you into an otherwise inaccessible network, which often contains all sorts of internal services with loose or no authentication (POS software often uses default creds because "it's on an internal netwok anyways"). Hacked kiosks are also often used as proxy servers for illegal activity and bots in DDoS botnets.
The update process can be backed on the kiosk side, hacking the remote side of the update process is a completely different story.
I mean in some cases that was a simple signed package hosted on an S3 bucket... how are you going to leverage that to vandalize a network of devices?
And the kiosks are never on an interesting network (if they were there's dozens of ethernet ports scattered about the place you can use to get access anyways)
Hacked kiosks being used as proxy servers when you need physical access to hack is also a very uninteresting problem. Why risk tying your physical self to a bot for nefarious usage when there are a million and one other "IoT" devices you can pwn instead?
Almost certainly not on EMV certified card acquirers, unless there is a bug in the firmware. These things are so locked down that, even as an authorised developer for the payment terminal, we had no access to the hardware, no way to view the cards encrypted payload, etc.
You just committed a felony to provide $10.000 in free food.
Might as well get a day job and make that contribution annually and skip federal prison.
If this part is correct, it seems like an attacker could compromise the reader itself.
Even if it was real firmware (I doubt it), it’s likely the firmware for the POS device interface. I don’t believe that firmware has any control over the actual payment processing bits of hardware, just the software intermediary.
Since that intermediary only has access to EMV tags (which anyone in the payment path has) there is no point. The secret encryption stuff that secures passwords is not controlled from any layer an attacker could touch, outside of documented configuration parameters.
Maybe they witnessed it, but that would be a bigger deal than some shitty windows box being popped. Certainly, that would not pass compliance.
Those card readers also typically have photodiodes in them and numerous tamper switches pressed to the case to wipe their internal memory if tampered. Just to be clear I'm not talking about EPROM - they have actual photodiodes inside along with physical switches and a coin battery that will wipe the ROM if tampered.
It's common to have the tamper switches trigger if you drop the terminal. They'll need to be re-flashed from scratch when that happens. eg. https://stackoverflow.com/questions/33872627/how-to-fix-tamp...
Anyway the TLDR is that the Card Reader part of any POS system is reasonably secure.
In that case the risk of accepting malicious updates from insecure touch screen would be much less.
You may be thinking of tokenization, which is a feature of some services such as Apple/Google Pay. This is where a “fake” account number—really a number that is scoped to eg a specific device or a specific merchant—is sent with the transaction. That then gets resolved to the real number somewhere down the processing pipeline closer to the card issuer. The benefit being if someone snoops this tokenized account number they won’t be able to use it thanks to the tight scoping.
The terminals really don't trust the POS systems.
You could reprogram a terminal in a bar in a few seconds on a Friday night. Wait for the weekends takings to clear into your merchant account, and then take off with the money. The way that it falls down though, is that you need a merchant account, and there’s a lot of KYC and due diligence to get through if you want to set one of those up (there are a lot of merchant initiated scams, and your bank doesn’t want to be on the hook for them).
That's the difficult part - since the acquiring bank is fully financially responsible if you do so (they'll compensate everyone else involved for the fraud chargebacks, no matter if they can recover it from you), they generally take quite stringent steps to fight merchant-initiated scams, and the simplest step is simply freezing the money for some time; 30 days is not uncommon but I have even seen 90 days if the merchant's profile is risky or if the incoming payment volume suddenly increases significantly - the bank is effectively treating any payments to the merchant as a line of credit or letter of guarantee until it's clear that those payments won't be fraudulent or charged back. So a merchant can quite realistically do some shenanigans with a reprogrammed terminal, but they won't be permitted to take off with a large amount of money from the merchant account until a sufficient amount of time will have passed for the first chargebacks or complaints of fraud to show up.
I think the main reason this never happens is because there’s a lot of easier and more profitable scams you can operate as a fraud-oriented merchant.
They started accepting signups a couple weeks before school started, and on the second day it was running, after several hundred signups (of ~$200 each iirc), apparently some security people from the bank showed up at the orientation office at the school basically just to confirm it was legit. (I don't remember if they suspended the account first or not)
I had built a few online store sites using merchant accounts by then, but nothing that went from zero to that volume so quickly; it was fascinating to see that check in action.
I wonder what volume it would take to trigger such scrutiny today, and what it would look like..
But in this hypothetical would there be chargebacks? People went to a bar. They consumed, and paid for it. As far as the costumers know it went all good.
The one who is harmed would be the pub. And presumably they would complain and soon.
I don’t doubt that the whole scheme would come to light quick, i’m just questioning the exact mechanism.
During that procedure the terminal unique ID is sent, and depending on your environment, if you have a stable outgoing IP the connection might be filtered on that as well (assuming you do that on site, not at a POS provider). Jumping through a bunch of hoops you might still be able to hook a POS on another merchant account, but once the issue is detected there would be enough info to reverse the transactions (doing that after capture could cost fees, but it’s still better than nothing).
Looking at the delays between the transactions being cleared and the money appearing in your bank account, even with the best timing you might not see a penny of all of that.
To be able to pull this off:
1. You need to register yourself as a merchant at an acquirer bank. Either directly or through intermediaries such as Stripe/Square etc.,
2. Go through reasonably stringent KYB (Know Your Business) process.
3. Do a few legitimate transactions so that everyone in the payment processing chain (acquiring bank, payment gateway etc., issuing bank, network (Visa/MasterCard)) begins to trust you.
4. Reconfigure the kiosk to use the above merchant account.
5. Pull out money from the acquiring bank before enough customers raise a charge-back and your your account is marked as fraudulent by someone/everyone in the payment processing chain.
These fly-by-night merchants are indeed created; especially at marketplaces such as EBay, Amazon. But to do it at a physical kiosk such as McDonalds' seems like a low ROI to me.
They have dedicated servers, so I'd expect McDonald's and other big chains to have them, too, which means that you couldn't send payments no anyone outside the mother company.
Yes they do. In fact, you can read the CC number from the chip without even knowing the PIN.
But yes I think this is more a "hey there is so much insecure tech out there - here is another example" as opposed to "we are all dead and our bank accounts emptied"
In some solutions, the readers are in fact hooked up directly to the POS system. However, the card terminal does not see unencrypted payment data. The POS is acting as a network bridge or switch, while getting limited information over network from the terminal.
In fact, I'm not sure that's even something that's allowed in large scale installations today.
That’s why everyone has/is moving off mag-stripe (depending on country) and to EMV. With EMV and EMV contactless the terminal never gets the full card number, among many other significant security improvements.
The terminal encrypts it before sending it over the wire
The EMV spec doesn’t include encryption of any data sent to the terminal from the card.
The transaction cryptogram is signed, however.
> However, the card terminal does not see unencrypted payment data.
The card terminal does see unencrypted payment data. Hard to see your comment as ambiguous?
Registers placed orders to the main routing Server in the back which passed the information to each individual station for fulfillment. The only time the card reader is involved is when the register makes a request to the cashless processing appliance in the back office then it reaches out to the card reader on the segregated network.
It was kind of impressive, but also kind of funny because the secrets we were protecting are symmetric and printed on the card for anyone to see.
On the magstripe and plastic, yes, but that is very rarely used today in stores. A modern chip card doesn't really expose secrets.
Additionally terminals can be configured to detect dodgy chips and automatically fall back magstripe, or a more basic form of processing. But your bank may block these transactions, because they can’t perform chargebacks on them, they’re considered as “secure/good as” Chip and PIN transactions by the card network for merchants in some parts of the worlds (e.g. the US). So if a fraudulent transaction was performed that way, the bank would have to eat the entire cost themselves.
https://en.m.wikipedia.org/wiki/Payment_Card_Industry_Data_S...
I remember Target stores getting hacked a few years back and having a few million credit card numbers leaked..
https://money.cnn.com/2013/12/18/news/companies/target-credi...
(Former in-training OTP here.)
Now, if they are hackable, and if they’re networked, or if you’re in America, your target is the Ethernet ports strategically hidden around the store. Look under and behind soda machines, inside cabinets in the lobby used to store napkins and stuff, randomly on the walls in the playplace etc
I don’t know about skimming cards from those ethernet ports, but you will have full access to the entire POS system which includes ordering and business data and the backend server.
You couldn’t use anything you harvest to make a new transaction on the cards, or even replay the transactions you saw.
(Mag-stripe is different, don’t use that!)
Even after moving everything to our Verifone vault, we still had those fields in our point of sales database, even if all of the numbers were '4111 1111 1111 1111' and the expiration dates were 2099+. We would pass the "proper" things down for the receipt as text fields (AID/TID/etc) to be printed on the receipt and stored with the transaction log.
While at some point the transaction will get to "a giant mainframe somewhere" to get processed, it may or may not be during the process that a customer sees. It may be a "online" transaction where it's essentially that the terminal prepares a transaction message, the chipcard signs it, and then forwards it to issuing institution for authorization (including but not limited to checking availability of funds); or it may be permitted, within certain limits and depending on configuration, to have the chipcard sign the transaction and then deliver it for processing some time later (e.g. at end of day) so that either you can enable transactions in places which do not have internet access, or simply for processing speed for small amounts, taking on some limited risk for customer convenience.
For EMV the terminal and the card generate a request, and send it to the payment processor/bank.
They say yes/no and send back some stuff needed to complete the transaction. At this point there would be a hold on your card.
The terminal and card verify that and finish things, preparing proof of the final transaction.
That’s sent to the processor again who confirms the transaction took place. This is when the money is taken and the hold disappears.
Final proof from the processor is sent back to the terminal so the system knows everything went through. Now you get your receipt.
It was fun to learn, and to see how they solved some of the problems that would come up that you might not think about.
Of course the side effect is you also learn just how insecure older CC tech was. I think almost everyone sort of notice that at this point, but once you start learning the details… it’s bad. Basically electronically writing down CC numbers like they might have in the ‘60s, assuming people are good and trustworthy.
It's terrible.
I loathe it. I always go to a person if possible, whereas I go to the self-checkout at the grocer's. The technical performance and the menu navigation of those kiosks is unbearable, and I'm a 30s techie.
Watch next time an employee has to "help" you with self checkout: they scan their badge and then can press buttons as quickly as they like.
I've noticed recent iterations of self-checkouts are much easier to use. Feels like they've relaxed the weight-on-tray requirements.
And at self checkouts with the option of a handheld scanner, use it. Often the handheld scanner seems to bypass the place-item-in-bagging-area thing.
So that is why ... it makes sense since I distincly remember the kiosks working fine in the beginning.
They should add a "turbo button".
The kiosks infuriate me by the sluggish UI. Also the 3 or 4 sellup spam ads you get make it even slower.
"Please place item in bagging area. Please place item in bagging area. Please place item in bagging area. Thank y... Please place item in bagging area. Please wait for assistance." Yeah, no thanks. I only use those crappy fail machines when I have no choice because there are no open checkout lanes with people manning them.
For a few small items, CVS and HEB do well.
The registers are hidden behind a counter and there's no obvious place to order, unless you use the kiosk.
If you stand at the empty counter for ~5 minutes, a staff member will eventually appear for something else (e.g. to give out an order) and serve you reluctantly - it's awful.
With few items, I can be in and out in a minute and never have to wait in line because there are so many self checkouts. If I have a lot of items, then I can wait in line for cashier because scanning all of them is more work than I care for.
I rarely have issues using them, at a variety of retailers.
Easily, the best self checkout I’ve ever used.
It's a really quick way of doing checkouts, i.e. you pretty much just walk out, unless you bought alcohol, in which case you'll need to wait for someone to check that you're 18.
My main issue with it is that it makes shopping terribly slow and mentally stressful. The whole process of scanning items as you pick them up is less convenient that you'd think. Some items, like vegetables don't have barcode... now what? I found myself constantly checking that I've scanned everything and focused more on the app than anything else. It's a great way to ensure that people only get what's on their shopping list.
Except for the fast checkout, which is really nice, I can't recommend it.
Sometimes though, when all the checkout lanes are in use, I dream of a licensing scheme for use. So many people take _forever_ to checkout, you would think this technology was introduced in the last month.
When this happens I like to play a game where I race to check myself out before everyone else (that has already started since I am taking the latest emptied spot). I would say I win this game probably 80% of the time.
* Australian: Aussie
* McDonalds: maccas
* Barbeque: barbie
* Ambulance: ambo (often used to refer to the ambulance staff -- I'm not even sure what they're called other than 'ambos'!)
* Breakfast: brekky
* Afternoon: arvo
* Cup of coffee: cuppa
* Registration for car: rego
* Woolworth's (supermarket): Woolies
* Service station: servo
I later discovered that it was the "short form" of "Thank you, goodbye"
Avo: Avocado
(And have done since at least 2013, according to whois.)
Back when McDonalds was still relevant there was a lot of press about the nutritional content, food preparation standards and so on. Food poisoning or undercooked food from mcdonalds was a common theme. My understanding is that they have largely addressed these issues.
* the corporate pulled out of Russia several months ago and the business was sold to the biggest franchisee. The new owner reopened the stores under a different brand name but kept most of everything else.
“Den Gyldne Måge or “The Golden Seagull” is another common, but older, name here.
No credit card issuer would refuse chargebacks for fraud that occurred because of this, nd ultimately when they'd find the source, it'd me McDonalds picking up the tab.
The risk to the average person from this is 0. At most it's an inconvenient call to a bank and sorting out a card replacement. (And an extra inconvenience for people using debit cards).
I have plenty of cards, and I wouldn't care one bit if the details of some got leaked, as I'm getting a push notification for every transaction.
Anything unexpected? Call/fill in an online form, and it's resolved within 2 days, and by then you already have a new card in the mail.
It’s 2022, pretty much all developed nations use chip cards so you wouldn’t have anything to gain from this exercise anyway.
Every card, as part of the mag-stripe, has a little bit of data on it called the Service Code. It’s three characters. Part of that tells the terminal if the card has an EMV chip.
The terminal is required (I believe, by the brands) to force you to use the chip. The chip has to fail a set number of times (I believe usually 3) before it will process a mag-stripe transaction.
Even then, the payment processor is informed this transaction was a failed chip transaction that fell back to msg-stripe. So the processor can determine if they want to take the risk.
(Of course this doesn’t apply to mag-stripe only devices like older gas pumps)
It’s not possible for a compromised payment terminal to do anything interesting with other kinds of cards.
Most(?) store gift cards don’t have chips. I think some smaller banks may not have chips on debit cards. I don’t know about “food stamp” cards or gas station branded cards.
So as a thief you can collect what you can get. Plus you can screw up the EMV slot so people must swipe, making them vulnerable (if they don’t use contactless).
I think that outside of USA most banks would configure their systems to automatically decline any transaction from a chip-capable terminal for a chip-capable card (to prevent cloned cards from being used with just the mag-stripe data), so swiping would be possible only on terminals that never had a EMV slot in the first place, and IIRC even that is limited to certain regions as in many countries it's expected that all terminals must be chip-capable; a damaged EMV slot should result in the bank returning an error code effectively saying 'broken terminal, repair or use another' instead of permitting to swipe.
Alternatively, I think I have seen contracts (for merchants who really wanted to keep swipes longer than the expected transition) that say that any fraudulent swiped transactions are fully paid for by the merchant.
It wouldn’t surprise me if mag-stripe is just turned off in a few years.
They’re touch screen and right next to toilets where the previous customer may …or may not have just washed their hands.
Then customers go right ahead and eat their food with their hands.
It’s like the perfect recipe for worms. Gross.
These days most McDonalds seem to have automatic doors and card payments are contactless via phone or card.
Assuming the kitchen staff keep their hands clean and the trays are washed the touchscreens are the most obvious thing too break the illusion of hygene.
The real problem I guess is eating food with your hands without immediately washing them first.
Historically before contactless payments and automatic doors the world didn't end so it probably is just a percived "yuck factor" on my part, I fully acknowledge that.
It's just... those screens and their suspicious smears... :-###..
What I don't get is that NO though was put in to security. Sure the card reader and the payment processing, I'm honestly sure that someone did a reasonable job at that part, because that comes as part of the payment terminal.
For a management perspective I can't see why you didn't think about the security for just a few minutes extra and came up with a much better product in general. There's certainly a point to being overly focused on security and never shipping, but it's also the case that thinking about security and misuse will help you to build better, more stable products.
These devices fail, and they fail constantly. I was a a Burger King two weeks ago, and again at the same restaurant two days ago. Two out of three kiosk where broken when I arrived two days ago, that all three where broken after I order two weeks ago. At the local McDonald's it often that three or four out of ten kiosks are broken. They aren't broken as in physically damaged, it's the software that's not working or stuck somehow.
As the article points out, they break so frequently that they are left unlocked, which in turn violates the idea that they are physically secured.
Three things I'd change is:
* Don't run as administrator, because hey, it's a quick thing to fix, so might as well.
* Read-only filesystems.
* PXE boot those things, so that they'll get fresh OS + application install on each boot.
If you ever see staff try to fix a kiosk, then you'll notice that they just open them and reboot the device. From what I've seen that frequently fails to fix the device, meaning that the system is in a broken state. Having the whole thing boot a known good image could help.
When the normal recovery plan for thousands of these kiosk is: "Reboot and hope it works. If not, wait for a technician to re-image, or reboot again." then you didn't spend enough time on systems design.
I wouldn't be surprised if there was a camera with video, microphone or at least photographs of customers. Indeed, grocery kiosks have these in the UK, some actually show you the video feed on the monitor in front of you to install fear to deter shoplifting.
Where this data goes and what the company uses the data for, we don't know.
[0] https://www.delish.com/food-news/a27091162/mcdonalds-kiosks-...
If McDonalds ever gets hacked, this should come up for possible criminal liability.
Oh no, the criminals might find out about your disgusting eating habits! The horror!
Seriously though, what kind of damages might you as a customer expect to see from McDonalds kiosks getting hacked?
There are some comments here claiming that their experience with McDonald’s order kiosks in the US makes them feel this is unlikely to be hackable, but “employees regularly leave them unlocked” sure sounds like an invitation for someone to find other hacks.
when the credit card issuer fraudulent credits the charges back to your account, you no longer have any (meaningful) damages.
The "EOL" carping is mostly from the corporate interests; and as the other comments here explain, the actual secret part of the card processing happens on a complete separate machine which is definitely far more secured.
A fully patched copy of XP, with all the group/local policies set to lock it down, is very secure.
In a lot of cases, it may look like XP, but it's actually XP Embedded, which has a lot of stuff stripped out, which reduces the attack surface significantly.
It costs money to upgrade the checkout application for a new OS, and put it through rigorous testing - These things need to work almost 24/7 without crashing or needing admin intervention.
It's the old idiom: If it ain't broke, don't fix it.
> Underpaid staff who used to do ordering have been replaced with.... staff across Australia leaving the Kiosks unlocked to make it easier to replace the paper.
They pay the staff who replace paper less than the staff who served at the counter.
Case closed.
Counter service hasn't completely disappeared, but they seem to spend most of their time now bagging orders for Uber Eats / Doordash & taking drive-through orders. They're also there for customer enquiries, eg "why did the self service decline my card", "I didn't get any sauce with my McNuggets", "I got a medium fries instead of a large"
Regarding paper, 99 times out of 100, there’s no paper in the printer. People are used to having to remember their order number.
No, please. Assuming everyone can and will use apps is a terrible idea. Apps are terrible for accessibility
- People who don't have phones
- People who do have a phone, but it can't install your app
- People who didn't bring their phones
- People who brought their phone, but it's out of batteries
- People who brought their phone, but it can't connect to the internet
- People who are not tech savvy enough to install/use apps
- People who can't use your app for disability related reasons
- People who don't want to use your apps out of some principle
- People who might be able to use your app, but it is just so tedious that the extra friction makes them not want to
None of these are small groups. Relying on app usage is business suicide
Not something I’m willing to do just to grab a cheese burger. It’s not like I go to mcd on such regular basis.
Don’t say it’s possible to make one that doesn’t. First, kids would abuse it to anonymously order 200 Big Macs in another town, and secondly companies are always too greedy to look away from that stream of potential user data.
A) app-less or install-free apps are a thing, on iOS they’re called app clips and work great.
B) the mcd’s app (and all of the other fast food apps I can think of) don’t require a login. You pay for your food when you order it, so the ‘anonymous order’ attack isn’t a thing.
Also they usually take ApplePay, which is an added security benefit.
Ordered a meal yesterday and the receipt came out blank. Person making orders asked for receipt and I showed them and they all laughed.
Ugh lost me on the first sentence