Hackers text ATMs for cash via Windows XP flaws
zdnet.com
zdnet.com
You actually need physical access to a USB port of the ATM which is hidden somewhere inside. So I guess the hack here is that the money inside an ATM is very well hidden and even protected by exploding paint barrels so it cannot normally be stolen even with physical access for a long period of time. But it is possible to get the Windows XP based software to dispense money from the safe by injecting a trojan through USB.
Unfortunately, the article does not make that very clear.
Since the life time end of normal XP (not even the embedded version), those "XP will doom our money" news spawn everywhere for no good reason.
TL;DR: It's primary a hardware design issue.
I've never seen ATMs (at least here in Switzerland) which you could just walk up to and plug in a USB device. Do Mexican ATMs come with USB ports on the front of the device?!
Don't forget:
"Law 3: If a bad guy has unrestricted physical access to your computer, it's not your computer anymore." http://technet.microsoft.com/en-us/magazine/2008.10.security...
EDIT: Found it. https://news.ycombinator.com/item?id=6984821
The most wonderful part is that whoever wrote the software had the insight to add a phone verification step so other crooks couldn't run off with their software.
Popping in one of these can not be that hard. http://www.newegg.com/Product/Product.aspx?Item=N82E16833320...
If that's the case, I imagine that yes, you could just walk up, remove keyboard, connect trojan device + mini usb hub, reconnect and replace keyboard then walk off. If space is an issue then one of those micro usb to bluetooth relay thingies and keep the trojan device out.
Then again, that was 5+ years ago and it could just as easily have been some other type of connector altogether vOv
[✓] Trojan horse in physical, symbolic, form.
[✓] Fluffy cloud to represent network "stuff".
[✓] Shopping cart full o' ca$h.
As much as windows XP probably makes barriers to entry easier (well, that combined with generic locks) is this really much different to what Barnaby Jack was doing back in 2010 at Defcon[1]?
NSA already affected the Web giants and Internet Security. If technical details on those hardware exploits, leak and make their way to a restricted few or the public then financial hardware is at risk and with it the financial industry.
With Russia having Snowden, I think those US bonds are not the only way that could inflict some damage.