10 ms·
Hackers Are Emptying ATMs with a Single Drilled Hole and $15 Worth of Gear
- kefka 10y agoI'm not terribly shocked. Most communication happens either at serial, SPI, or i2c busses. If it's cars, CAN. And if you can plug in a wire somewhere, you can damage or pwn it. Most things don't have security, other than software security and physical locks. And even when there is other types of security, like cryptokeys and such, physical wires can usually bypass even those. If they wanted something that was secure, they could do that glass mesh thing the ORWL does, and have some sort of black dyepack on the money that explodes everywhere. Go for "we ruin so you cant have". But then again, I could see criminals pissed off and taking a hammer primarily to ruin their money, and cause customer consternation.
- mjevans 10y agoI could see a more effective solution being embedded chassis intrusion meshes. Disrupt the meshes in any way (EG drilling) would result in three actions. 1) Electronic erase MOST programmable memory in the machine. (Brick it) 2) Engage something akin to an EMO (Emergency Machine Off) 3) If an uplink of some sort exists, broadcast repeatedly on it that such an event occurred and the current uptime.
- monocasa 10y agoI mean, there's chips that have that in their top metal layers, and there's still crazy people out there with electron microscopes and tiny pins that subvert them. https://web-beta.archive.org/web/20111124050620/http://www.flylogic.net/blog/?p=86 https://web-beta.archive.org/web/20111124050620/http://www.f... I wouldn't be surprised if increased physical security on ATMS isn't worth the practical difference in losses.
- mjevans 10y agoSure, someone COULD do that, but how long and how fiddly is that process? How big of a risk is there to disrupting internal components. What if you sandwich the sensitive layer as a thin mesh encased in weak resin between two metal plates? The point of security isn't absolute, but to ruin the risk + effort vs reward balance.
- ams6110 10y agoEasier than fitting a mesh would be an internal vibration sensor/microphone tuned to detect drilling/sawing.
- mjevans 10y agoThat's way easier to trigger a false positive on... Not that my mesh idea doesn't need fine tuning as well. The drilling idea I could see someone just walking by with a very loud powertools song... watch the ATM brick in the face of their first amendment freedom of expression.
- ben_jones 10y agoI wonder how many older models of ATMs are still in service and what the process for "updating" them would be like, or perhaps that it wouldn't be realistic at all. I see a lot of small family-owned corner stores with very old machines.
- deleted 10y ago[deleted]
- lucaspiller 10y agoI don't think there is a process for updating them, other than in the interest of adding new features or when they break. Recently I saw a green-screen CRT ATM in use by a bank in the UK. Maybe the internals have been updated, but it seems unlikely that they would change that and not the screen.
- anthonybsd 10y agoTo be fair, drilling a 3 inch hole in a modern ATM is no easy task. We are talking about high-grade steel, a layer of fiberglass, etc. Hence "portable power drill" is a bit misleading.
- kefka 10y agoMaybe some of them are. Ive also found some that are crap. I have a tendency to pull on things like ATM covers, credit card slots, and the like. And that's because we have lots of skimmers that are found at local gas stations and places around here (big college presence). So far, I've found an opened gasoline pump door. I called attendant and went to a different pump (attendands didnt have keys for that....) . Ive also found an ATM that was partially locked and came opened when I gave it a tug. I called our bank's security after that one. I also found a skimmer on a gas pump as well. It had a fishy look to it and gave it a tug. Pop. Was just a simple card reader and cam module in 1. I harvested the parts and put the microsd card through a good format.
- lordvon 10y agoWhere do you live?
- kefka 10y agoBloomington, IN.
- jlgaddis 10y agoHeh, after your second paragraph I thought, "that sounds like here", then got down to this comment and realized it is (also in Bloomington).
- kefka 10y agoMaybe we should do a HN meetup, Bloomington IN style :) Or you can come on over to our hackerspace, Bloominglabs. We have open houses every Wednesday from 7-10P, no matter what day that falls on :)
- Declanomous 10y ago>Computer security experts have long warned that no computer should be considered secure if an attacker takes physical control of it. I think the lack of physical security is more surprising than the lack of electronic security. A three-inch hole is pretty big, all things considered. I have to imagine that ATMs are designed to resist drilling three inch holes through to the money or the dispenser mechanism. Why isn't the computer protected to similar degree?
- wnevets 10y ago>Why isn't the computer protected to similar degree? It was cheaper not to.
- scardine 10y agoI can confirm this. I used to work for a major ATM supplier and this was the answer I got every time I asked bank personal about the lack of physical security. They would compute the average loss from burglarized ATMs against the cost to install and maintain better alarm systems and decide against it.
- flukus 10y agoI'm guessing there may be some cooling issues to solve as well.
- Someone 10y ago"I have to imagine that ATMs are designed to resist drilling three inch holes through to the money or the dispenser mechanism" I would use a hole saw (https://en.wikipedia.org/wiki/Hole_saw https://en.wikipedia.org/wiki/Hole_saw), and would think it fairly hard to protect a large enclosure against that. Locally strengthening the enclosure might be enough, but chances are thieves would start drilling around it to remove a larger patch or start employing an endoscope to connect something to the serial port. Hardware-wise, it probably is easier to glue the connector shut, giving up on using the diagnostic port.
- Declanomous 10y ago
- scardine 10y agoMy first job was being a field technician for a bank automation supplier. We had a "test" card that could be insert on the eprom socket. This small card was almost the same size of the original chip but had a few buttons that allowed us to make the mechanism deliver notes in order to fine tune it. In a particular ATM design used by major banks in Brazil, this location were accessible by removing a front panel, although you would have to be kind of a contortionist in order to plug it. Why we can find whole ATMs at junkyards is beyond me: there are many easy to spot flaws. They should grind everything when decommissioning this kind of equipment.
- andrewwharton 10y ago> Why we can find whole ATMs at junkyards is beyond me: there are many easy to spot flaws. If there are many easy to spot flaws, I don't think finding them in a junkyard is the root of the problem here. This is good old security by obscurity. As Bruce Schneier says (at least about safes), you should be able to publish the blueprints and source code for the machines, then maybe they'll be secure. There should be enough physical security to ensure an attack will take longer to perform than the response time of the authorities. Any components which are vulnerable to physical attack need the same level of physical protection as the cash that's being protected. Until this happens, 'hackers' (thieves) are going to keep finding flaws and exploiting them.
- erikpukinskis 10y agoIt's a false dichotomy. Your private keys are just "obscure" information that requires some effort to find too. And security protocols can be designed so the keys aren't enough. At the end of the day it's an arms race, and you're just trying to slow attackers down.
- kevhito 10y ago> It's a false dichotomy. What part of the parent are you responding to here? > Your private keys are just "obscure" information that requires some effort to find too. I think this is highly misleading. There is nothing "just" or "some" about it. Your private keys are "obscured" information that requires a (mostly) specific and quantifiably very large amount of effort to find, and which if it were to become exposed, can be changed without requiring any new design to restore security. Blueprints and wiring diagrams are "barely if at all obscured" information that requires vague, hard-to-quantify, and often trivially little amount of effort to find, and if exposed, can't be easily changed without requiring entirely new designs, manufacturing, and engineering.
- devy 10y ago> They found that the machine’s only encryption was a weak XOR cipher they were able to easily break, and that there was no real authentication between the machine’s modules. This reminds me of many many years ago some guy in a bimmer forum figured out BMW's iDriver music file formats (BR3/BR4/BR5) were simply DRM'd via XOR.[1] I was able to verify it via a simple script. Kudos to the reverse engineering masters! [1]: http://www.e90post.com/forums/showthread.php?t=279294#5 http://www.e90post.com/forums/showthread.php?t=279294#5
- StavrosK 10y agoXOR is rather easy to spot, you just XOR each byte with the bytes N positions downstream, and at the N for which the distribution of bytes changes dramatically, you've found the key's period. Finding the key is also not hard if you suspect that the file is a known format (and thus will have a known structure at some places).
- giancarlostoro 10y agoI found it curious that the very person who mentioned it being XOR had only one single post in that forum.
- devy 10y agoThat info was originated from a German bimmer forum, it seems.
- bigbugbag 10y agoIn the world of chip cards, it's not uncommon to think xor is a secure encryption scheme for some reason, historical maybe or more probably cost related, I don't know. Though I remember even worse when a chip card encryption was found not cost effective enough to be enable and security on this card was limited encoding[1], too bad it was a government issued healthcare card which lead a minister to argue that using ASCII and binary was efficient in securing the data. While the GIE (Economic Interest Group) in charge of the chip tricked the whistleblower to demonstrate the vulnerability and sued him for having done so. Fun Times ! [1]: http://bigbrotherawards.eu.org/Jerome-Cretaux-et-Patrick-Gueulle http://bigbrotherawards.eu.org/Jerome-Cretaux-et-Patrick-Gue...
- contingencies 10y agoI am currently designing food machines, which have security concerns equal to financial machines in some senses (you don't want people to get poisoned through environmental contaminants, malicious reprogramming, etc.). The article claims there is essentially no authentication between disparate modules, only simple XOR encryption. That seems a clear fail. In my experience, ATM control boards (I was literally at a factory in China for these a few weeks ago) tend to be custom PCBs but there is a move towards genericization. Presumably because their designs tend to date from bygone eras, they do not use software-based approaches in favor of hardware and security through obscurity. Perhaps it is time for a software-oriented modular ATM redesign project with an emphasis on modern internal security? Anyone want to collaborate? Serious question. (I have an existing ATM component factory group potentially on side already.) Second, to 'notice' the independent activity of any given module, power draw should be easy to detect. Again, the lack of such a feature probably harks back to a bygone-era hardware-oriented design psychology.
- DonHopkins 10y agoWhere do you draw the line between poisoning people, and vending them unhealthy fatty sugary junk food?
- contingencies 10y agoEverything we sell will be made to order from fresh ingredients. Sugar is only traditionally used in a few noodle cuisines (eg. Thai) and customers can opt out of any ingredient they wish. Likewise significant lipids are really only present in meats, oils, cheeses and coconut milk. Again, Thai is a strong contender. Calorie counting is transparently supported for those who want to do the numbers. Launching in Asia, for Asia, nothing we sell will likely come close in calories to an average US serving of anything.
- anonymous_iam 10y agoNot as elegant as Barnaby Jack, but just as effective.
- s73ver 10y agoSeems like an implementation of that XKCD comic on encryption security: https://xkcd.com/538/ https://xkcd.com/538/
- nodesocket 10y agoHow much cash is in a fully stocked ATM? 10k, 25k, 50k, 100K?
- pp19dd 10y agoFrom a 2013 reddit AMA: "Each ATM is different. We do 12,500, but have ones with metal cases that reach 26k." From a 2010 time article: "The average size machine can hold as much as $200,000, though few do. In off hours, most machines contain less than $10,000." In the article they cite a Philadelphia theft case where a single stolen machine held $96,000.
- ilikeATMs 10y agoThe ones I've commonly seen in .AU, 20k for the thin service station ones and 40+k for the bigger mounted ones.
- nandemo 10y agoAs others replied, it varies. In Japan, an ATM inside a bank might hold up to 40 million yen (≅ USD 350k) while an external one might have up to 30 million (≅ USD 270k). Japan's a fairly safe country but there have been many cases of ATMs getting stolen too. Power shovel seems to be the method of choice.
- DonHopkins 10y agoIs there a tutorial on Instructables or YouTube about how to do this?
- stinos 10y agoAh brings backs sweet memories to Terminator, for real now! IIRC in the movie Connor used some portable Atari with a cable attached to a creditcard to hack an ATM to spit out money.
- Pica_soO 10y agoThe Firefighters' Guild has been formed and dissolved repeatedly throughout the history of Ankh-Morpork. Usually formed in response to fires which cause significant damage to large parts of the city, the guild is usually dissolved in response to... er, fires which cause significant damage to large parts of the city. The Guild suffers from the undying capitalist spirit of Ankh-Morpork, as those men who are paid per-fire extinguished eventually begin to guarantee a regular supply of fires to be put out (see also Inn-Sewer-Ants). This has led to the frequent destruction of large portions of the city and ultimately to the Guild's being banned. Seems we need lots of new ATMs, lots of them. And then prayer, for the fire-fighter-guild to not run out of money.
- bigbugbag 10y agoI see these kind of stories floating around from time to time, I wonder how much money is lifted each year from banks this way. It seems to not be significant enough for banks to be proactive about the issue.