7 ms·
If you ever open up an ATM you'll realise that the majority of things are controlled by serial interfaces (upto 6 of them) for all the motors and pneumatic hard
by ilikeATMs 9y ago
If you ever open up an ATM you'll realise that the majority of things are controlled by serial interfaces (upto 6 of them) for all the motors and pneumatic hardware.
If the operating system becomes hardened enough, you'll eventually have people interface with the serial ports directly to manipulate the cash-drawers directly.
I'm not sure why this hasn't really been done in practice but it shouldn't be to difficult to figure out how to do correctly.
In most ATM's the computer hardware and interface connectors are also all housed in the top (mostly plastic or low-quality cast metal) shrouds (as opposed to the currency locked in a safe). Traditionally wafer locks were also used to secure this section however they are slowly migrating to higher security locks like Abloys.
ATM manufacturers may want to take a look at slot machine manufacturers for clues on how to harden machines against tampering.
- colejohnson66 9y agoDon’t some ATMs spray ink on the bills if they detect tampering?
- jutaz 9y agoThey do, if they detect tampering to the currency safe. However I'm not sure if they are really equipped to detect tampering to electronics.
- sitkack 9y agoThere are easily multiple locks that could be put in place internally. Encrypt the signal from the host to cash dispenser, have a debugger process that is connected to the host process that also stores the encryption keys and or talks to an HSM. Mitigates tampering of a live system, makes flashing new firmware problematic. Physically limit the cash dispenser from outputting k bills over n seconds. Have those limits be session based, again signaled by main host process. Would require a full login/logout cycle for k bills. Most likely, the systems are left wide open internally to ease development and mask bugs. My ending blanket statement is that finance people know how to be cheap, they can optimize along one axis, replacing a 5$ with a 2$ part, but the really good ones optimize the whole system over a long time horizon.
- bardworx 9y agoYour comment is coming from a good place but it’s rooted in ignorance. Most ATM machines are made by NCR and not financial institutions. Majority are also quite old (runnning windows XP old). NCR is focused on profits not security, even though they sell POS (point of sale), ATM machines, and airport kiosks. From my personal dealings with NCR, I can confirm that they care very little for security, regardless of what their corporate line. To put this in perspective: if you go to a grocery store, restaurant, or quick service (fast food) establishment and use a credit card then your full account number, name, and exp is recorded in their system. This information is accessible by anyone with store level admin (not windows admin, but think a manager with manager card). This violates PCI but hey, fuck PCI, hard sending the system takes resources and who wants to do that? On HN, folks keep talking about security and other such nonsense, however, anyone who has seen the other side isn’t very optimistic. Between ease of use, profit margins, and no pushback on insecure systems, all loses are just write offs.
- imglorp 9y agoOn a less concrete note, my bank switched from Diebold to NCR and the difference is very apparent to the ATM user. The design is overall clean and bright, and it's much faster. The Diebold has long UI pauses for no apparent reason where the NCR seems not.
- ak47-1984 9y agoAs one of the engineers initially responsible for achieving PCI compliance on these ATMs, this isn’t strictly true - of course it needs to know your account info, but it’s sent to your bank - it’s not stored on the machine at all - certain digits of your card number are written to a paper log but it’s never written in full - can’t speak for POS machines, but would imagine it’s the same
- bardworx 9y agoUnfortunately, POS is not the same. I’ve worked with NCR (Aloha) POS for 5 years. Can’t speak for ATM machines. Plain text ... and before two years ago, they also had regional master passwords. As in one password for all systems sold by a particular reseller.
- xg15 9y agoSomehow I'm not surprised that hardening is a higher priority for slot machines than for ATMs...
- mcny 9y agoI've read (though have no first hand experience) that slot machines have better security and better vetting than electronic voting machines do so I'm not surprised either.
- EvanAnderson 9y agoIn Nevada the source code for gaming devices is required to be provided to the state gaming commission. (c) In the case of a gaming device, a copy of all executable software, including data and graphic information, and a copy of all source code for programs that cannot be reasonably demonstrated to have any use other than in a gaming device, submitted on electronically readable, unalterable media; http://gaming.nv.gov/modules/showdocument.aspx?documentid=2921 http://gaming.nv.gov/modules/showdocument.aspx?documentid=29...
- xg15 9y agoBut only for "programs that cannot be reasonably demonstrated to have any use other than in a gaming device". Makes one imagine what kind of political trench wars probably went on behind the scenes about this regulation. Edit: On second thought, this seems awfully easy to circumvent. What stops me from making a rigged PRNG and then refusing to make the source code available on the grounds that there are lots of non-gambling applications for PRNGs?
- matt_the_bass 9y agoWhat’s a PRNG?
- da_chicken 9y agoPseudo random number generator.