5 ms·
We had a rash of credit/debit card skimming locally as a result of crooks coming into stores in the mall and replacing the store's point-of-sale card reader ter
by ayuvar 15y ago
We had a rash of credit/debit card skimming locally as a result of crooks coming into stores in the mall and replacing the store's point-of-sale card reader terminal with one of their own which was rigged to skim before passing on the information to the register, according to the local news.
Normally, I'd distrust the news when it comes to anything vaguely technical but it got me wondering if the POS terminal does anything to guarantee that its credit card reader is still "authentic" (hopefully, it at least used some kind of good faith challenge-response mechanism, even if it could be easily spoofed by a potential attacker).
Physically swapping them out - both to put the rigged reader in, and to remove it once it's "full" - also seems pretty risky. It was probably something like this story instead where the register itself was targeted remotely.
- simcop2387 15y agoFrom what I know about them when helping install them in a new retail store where i was working a few years ago, there's quite a few of them that act like nothing more than a keyboard. the fancier ones with a display still hook up over usb and i don't think they use a challenge response (I honestly don't know there, i don't know the software for them). Even once I got them in if i was skimming I wouldn't even bother removing them ever. Instead I'd use something like the little XBee modules or some other wireless device to read them and just walk in and act like a regular shopper leaving the retrieval thing in my pocket the whole time.
- bradleyland 15y agoHaving done my time in the independent computer repair trenches with more than one restaurant as a customer, I can tell you that while secure, sophisticated card scanning equipment exists, much of the stuff used at mom & pop stores is rudimentary at best. Basic USB card swipers can be swapped out with zero change required in the software. None of this really matters though. What are the consequences of having your card skimmed? For the card holder, it's a mere inconvenience. The banks don't hold you accountable for the breech, because they know you'd never do business with them again. For the bank, it's only a small loss. They chargeback the transactions amounts to the vendor that took the card. The "victim" in this scenario is the merchant who accepted the stolen card. The risk associated with stolen credit card data is diffused this way. Merchants who don't want to assume the risk of accepting stolen credit cards can opt-in to far more stringent CC security practices like CVV2 codes and AVS (address verification). If you've ever had your CC number stolen, you know that the purchases are made overseas, or with shady merchants that don't opt-in for better security.