All About ATM Skimmers
krebsonsecurity.com
krebsonsecurity.com
Yes it costs a little bit more, but CD-ROM drives have been doing both of these approaches for ages, and it would make the installation of a skimmer reader much, much harder.
A machine that deals with the general public on a scale of tens of millions has to be rock solid. People can behave really strangely (think drunk people) and all kinds of ridiculous outcomes can happen.
I'm not saying this is what will happen to a CD-ROM-style tray approach, I'm just trying to add some context to the idea. Machines exposed to enclosed, semi-public areas have to withstand a lot of deliberate, brutal sabotage, that'll make you scratch your head, and ask why on earth?
With that in mind, protruding parts and orifices generally don't fare well with machines subjected to the abuses of the general public. I think it'd probably cost more that a little bit extra...
Even if there were a skim-proof ATM, they could probably get a retired machine on the cheap, program it to accept cards and pins and then print 'Sorry, this machine is out of operation. Please call 1-800-FAK-ENUM to notify a technician' and place it somewhere reasonable.
It's been done. As has creating an entire fake facade and putting in front of the real ATM.
Personally, I am more interested in improving security via credit card chips or contactless payment (cards or phones). Chips alone would heavily improve security due to the inherent cost (hopefully) of cracking the chip's data.
I wasn't sure of the reasoning for this initially, but my assumption is that it makes it more difficult to skim. The actual 'swipe' in which the mag strip is read seems to occur inside the machine, so a skimmer would need to be mounted with the machine opened up.
The anti-skimmer moves the card very fast in short bursts, so while it may seem just a bit jittery (averaged out), the skimmer will end skipping whole pieces of band or losing sync.
Maybe they could use small rubber rollers to detect velocity and sync appropriately, like in a mouse.
What about a chip-and-pin card prevents a skimmer from either monitoring or emulating the radio conversation between the card and the terminal (and thus capturing the card number) and another keypad skimmer from capturing the PIN?
It seems to me that the problem is that everything required to conduct a transaction is handed to every merchant and/or untrusted machine of the merchant. (Compare to public key cryptography, where I remain in possession of a private key.) What about chip-and-pin changes that situation?
They also require the pin code to start the process, so you would have to skim that as well.
In addition to this, in the online scenario it can interact with the payment provider's servers to provide security.
The combination of these methods make rapid stealing of EMV cards difficult.
More info here: http://www.emvco.com/download_agreement.aspx?id=653
Even if these keys was relevant, the important part is that they are public keys, not private keys. You cannot get card's private key from the chip by normal means (ie. without doing something that is classified as attack, be it side-channel, physical inspection or exploiting some firmware bug/backdoor).
Because of backward compatibility, the transaction signature generated by the card has to fit into 8 BCD digits, which essentially precludes use of any kind of public key cryptography. Actual algorithm for how signatures are generated and verified is issuer defined and only card issuer can actually verify signatures (terminal just blindly trusts whatever was returned by card).
Public key cryptography (ie. RSA) is used in EMV to verify that card was really issued by claimed issuer (card contains data structure that is signed by issuer's key) and to optionally encrypt PIN sent to card for offline verification (PIN is somehow regarded as super-sensitive by banking industry)
One can certainly imagine better design than EMV (eg. without various implicit trust relationships), but in all, it is pretty reasonable mechanism nonetheless.
Apart from that, making a skimmer that sits between the chip of the card and the contacts of the machine would be much harder to make than the current skimmers. So even if the chip would not sign the transaction but just provide static data if given the right PIN, the situation would be significantly improved.
http://www.cl.cam.ac.uk/~sjm217/papers/oakland14chipandskim....
Chip and Skim: cloning EMV cards with the pre-play attack Mike Bond, Omar Choudary, Steven J. Murdoch, Sergei Skorobogatov, Ross Anderson Computer Laboratory, University of Cambridge, UK
Wireless payment by NFC is also a possibility, but at least with my card, no payments bigger than 25€ can be done through NFC.
I do agree that skimming exists over here as well, a friend of mine got his card cloned once. He'd used it with an ATM located in a very central and visible place, famous for night-time entertainment -- thiefs must have thought drunk people don't pay too much attention to this sort of thing, especially when they've been queuing for a while (which they typically have to, at this location).
Same in Italy and France, last I heard; places where banks are extremely fraud/security-conscious and continuously maintain their infrastructure to guard from these threats.
For instance, there are jerks who would simply wreck them. In fact, the skimmers could simply wreck them until the non-asshole proof version was brought back and then happily continue to ply their trade.
It's like designing a vault, only it has to open up to total strangers who happen to have digital keys, and to complicate manners stuff has to go in as well as out and there is a whole bunch of user interface components strapped onto it.
Designing an ATM that satisfies all criteria is very much non-trivial and any 'why don't they 'x'' should be followed by a short period of thinking about what other boundary conditions need to be satisfied.
This presents a non-trivial UI problem. Users are conditioned to only insert cards a certain way. Changing that can be very confusing. I guarantee a large percentage of users will try putting their cards in the "normal" way and get confused when it doesn't work.
[0] http://krebsonsecurity.com/2011/01/atm-skimmers-that-never-t...