4 ms·
I was involved with the card reader upgrades at McDonald’s in the US. Essentially the card readers were stripped out of the main network and all buildings were
by wronglebowski 4y ago
I was involved with the card reader upgrades at McDonald’s in the US. Essentially the card readers were stripped out of the main network and all buildings were rewired With a physically segregated network for cashless transactions.
Registers placed orders to the main routing Server in the back which passed the information to each individual station for fulfillment. The only time the card reader is involved is when the register makes a request to the cashless processing appliance in the back office then it reaches out to the card reader on the segregated network.
- shepherdjerred 4y agoThis is good right? It sounds like a secure design.
- wronglebowski 4y agoI’d say so. Also there was effectively no troubleshooting in the store you could do. Aside from unplugging and replugging the appliance and terminals it was all under a very strict service contract. Too many terminals down or the appliance that processes transaction and a tech had to be out in 8 hours regardless of time of day to service.
- kotaKat 4y agoAnd really, the worst exploit I fathomed you could do would be... changing the IP address on two PEDs to swap what lanes they were on (so register 2's pad would be really being used for register 3 and vice versa). (Former in-training OTP here.)
- wronglebowski 4y agoWhat was your experience like and where did it lead you? For me it was part of the wake up call that showed me to the door. Being OTP for 14 Stores and GM for 1 was what pushed me over the edge.
- __MatrixMan__ 4y agoI worked at a POS vendor who did this kind of thing internal to the device. We had a bunch of robots (they looked like 3d printers with a stylus instead of a print head) testing the payment flows because none of the android test tools could interface with that part of the device. It was kind of impressive, but also kind of funny because the secrets we were protecting are symmetric and printed on the card for anyone to see.
- charles_kaw 4y ago> the secrets we were protecting are symmetric and printed on the card for anyone to see. On the magstripe and plastic, yes, but that is very rarely used today in stores. A modern chip card doesn't really expose secrets.
- Gigachad 4y agoI'm surprised the stripe is still added to cards these days. The chip broke on my mums card around 10 years ago and although the card readers had strip readers, they would often refuse to use it. Seem to remember some requiring a few failed chip uses before allowing magnetic strip.
- lmm 4y agoIt's only a few years ago that we started seeing cards without embossed numbers for taking impressions by rubbing.
- Gigachad 4y agoI think that actually made more sense. In a power outage the bumps were the only backup. I had seen it used once at a petrol station. While there is close to no situation where a chip payment or nfc couldn’t be used.
- jon-wood 4y agoMy UK bank card has a mag stripe on it but I have to explicitly activate it via their mobile app, and it will be disabled again after seven days.
- acomjean 4y agoThis matches something the startup I worked at discover when installing power monitoring equipment in restaurants. We initially weren’t PCI compliant but it didn’t matter because we always installed on the network that didn’t process credit card info. Just one potential customer asked us about this… https://en.m.wikipedia.org/wiki/Payment_Card_Industry_Data_Security_Standard https://en.m.wikipedia.org/wiki/Payment_Card_Industry_Data_S... I remember Target stores getting hacked a few years back and having a few million credit card numbers leaked.. https://money.cnn.com/2013/12/18/news/companies/target-credit-card/index.html https://money.cnn.com/2013/12/18/news/companies/target-credi...