Hacking an ATM
henryschwarz.blogspot.co.uk
henryschwarz.blogspot.co.uk
Jack notified the vendor and (obviously) got his talk accepted and announced at Black Hat. The vendor complained to Juniper, and Juniper had the talk pulled††. Jack left Juniper for IOActive and gave the talk the following year. Last time I checked, I believe he was at McAfee.
† Funny thing about Tranax: they managed to let Google crawl their maintenance manual a couple years ago, and the manual had their default maintenance code in it; a huge number of ATMs were found to be running with that default password, which allowed people to re-denominate the bills in the machine.
†† This was probably a reasonable call, because Juniper has billions of dollars to lose to a negligence suit brought by an ATM company.
[edit: I do get that they became 'friends', which gives some levity to these descriptions, but it still strikes me as casting aspersions not just on the individual but more generally on the way he and others like choose to work]
Sorry, there's no drama to be found here. The guy's just having fun writing this up.
If we weren't sarcastically nasty to our friends we might have to talk about emotions to convey our mutual trust and affection with other blokes.
The story could've been good, but the style of writing is neither witty nor clever and when I arrived at reserved seats in the front row at Black Hat I closed the tab with a quick sigh of relief afterwards. Horrible.
That said: What details did you take away from the article? I'm serious. I just went back and skimmed the rest. It seems this is really a long version of 'someone found an exploit, we fixed it, he presented it in public and we handled the aftermath'. No details at all. The most technical bit was the 'Now we're so much more secure by requiring signed code', and that was it?
Apparently, there is little meaningful verification that an ATM is secure before people start using it.
The target was randomly chosen, and a second company's ATM was breached in a completely separate fashion.
This was simply a publicity stunt for a security research company.
etc.
Thank you for such a detailed follow up.
In this sentence, the author mistakes obscurity for security.
This guy still does not get it...
"Barnaby chose my company's ATM arbitrarily, it was just the most conveniently available to purchase on the web and be delivered to his home. Note to our salespeople: for security purposes, please make it more difficult to purchase our product."