Mobile Bank Robbery – Why I Don’t Use ATMs


ATM

I’ve always been told by my parents – don’t use ATMs.  Sure it may be convenient.  But is that convenience worth being the victim of identity theft?  I’ve seen scams where brochure holders were “added” next to a machine which had a camera to grab pin numbers and the such, but the latest attack literally allows a malicious attacker to remotely dispense cash on demand.  According to ZDNet, Barnaby Jack, a security researcher was able to access and load custom software into ATMs made by Triton and Tranax that are powered by Windows CE.  “There are attack vectors in all these standalone or hole-in-the-wall ATMs,” Jack warned, noting that many ATMs are protected by a master key that can be bought for $10.78 on hundreds of web sites.  ”With this master key, I can walk up to a secluded ATM and have access to USB [and] SD/CF slots.  In some cases, opening and inserting my USB key was faster than installing a skimmer,” he said.  Now what makes matters even worse is that If someone inserts a card on that machine, I can capture and save the track data remotely".  Scary thoughts.  He’s even able to “dispense cash from each cassette,” “print stats on remaining bill counts,” and “Exit!”  I’m a firm believer of the use of credit cards as well as debit cards.  But as to ATMs, I’ll stay away from them as who knows what can be done to one of those machines during the times when nobody’s watching in the dead of night.  At least with self-checkouts you still have an employee making sure things are going right.  I’m just happy this is in the hands of a security researcher…but the bad news is that such a vulnerability exists.  From the looks of it, ATM manufacturers need to get on the ball with better security.  I don’t use ATMs…but if I did, now would, in my opinion, be a great time to stop.

Be Sociable, Share!

Related posts:

  1. PhoneFactor – Security Authentication
  2. Gawker Media Compromised Commenting Accounts
  3. Windows Mobile Security and Patch Management
  4. Facebook Info Free for the Taking
  5. Intel Buys McAfee for $7.68 Billion

More in General | 1 Comment

1 Comment

You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.


Ken
Jul 30, 2010

I am in the credit union at work, and we have a office in our building. They don’t do any cash transactions at the desk there, but they have a cash machine. It is inside our building, so the only people that can access it are employees. I think that is an added protection (that I’ve been using and didn’t know I needed).

Leave a Reply

You must be logged in to post a comment.