Re[2]: OT: ATM PIN code theft



On 02.07.2008 VAXman-@xxxxxxxxxxxxxxxx <VAXman-@xxxxxxxxxxxxxxxx> wrote:

In article <op.udn2kmn6hv4qyg@xxxxxxxxxxxxxxxxxxxxxxxxxxx>, "Tom
Linden" <tom@xxxxxxxxxxxxxx> writes:
http://www.cbsnews.com/stories/2008/07/01/national/main4226061.shtml

It occurs to me that one should check what type of systems your bank
uses. I have an account at a bank that runs IIS on their front-end
as a result I never use that ATM card. BoA, last I chewcked was all
IBM.

Look again or in the near future. My bank (BofA) recently replaced
its ATMs with new machines. The machine which was accessible from
outside the bank -- not the lobby machine -- was found in a perpet-
ual Weendoze Reboot cycle one day when I approached it. Scarey...
VERY SCAREY!


It's too late to afraid. All modern ATMs I know about are using
Windows inside them. At least here, in Europe. But the subject story
looks very unclear. All normal ATMs (not sure for Citibank's) don't
passed PIN in clear outside their PIN-pad. PIN is thrown outside this
hardware encrypted with DES (obsolete) or 3DES (modern) and encryption
keys are changed on regular basis. So you could hack ATM or even break
it by parts but it doesn't help you to get clear PINs. The real life
is much more simple - bad guys are using add-on on the card reader
and faked PIN pad over the real one. No need to hack anything.

--
Best regards,
Valentin
valentin.likoum@xxxxxxxxxxxx

.



Relevant Pages

  • Re: COBOL Compiler for Windows
    ... objected to EFTPOS because it was hard enough to remember a pin for ATMs ... There is an easy solution -- I write the PIN on the back of the card in ... I always answer bank email inquiries asking for personal information. ...
    (comp.lang.cobol)
  • Re: COBOL Compiler for Windows
    ... objected to EFTPOS because it was hard enough to remember a pin for ATMs ... There is an easy solution -- I write the PIN on the back of the card in large numbers ... I always answer bank email inquiries asking for personal information. ...
    (comp.lang.cobol)
  • Re: Skimmers again.
    ... Money has been taken from the victims bank accounts by ... to the bank to change her PIN code and guess what? ... them taking money from your account if your card has been skimmed". ...
    (uk.media.tv.misc)
  • Re: HELP, Vulnerability in Debit PIN Encryption security, possibly
    ... While there are numerous reports of academia breaking ... > Show us a link in the REAL WORLD where a PIN number has been stolen by ... > breaking the PIN entry encryption. ... hardware security modules which potentially enables a dishonest bank ...
    (sci.crypt)
  • Re: [Geek] M$ feature
    ... >authentication (challenge-response stuff with a proprietary calculator ... >and a PIN) and ABN-AMRO three-factor authentication ... >Whenever I speak to banking people about Internet Banking, ... I have a bank that does that - Alliance and Leicester. ...
    (uk.misc)