8 ms·
Nordstrom Finds Cash Register Skimmers
- cardamomo 13y agoIt occurred to me once upon a time that I could use just such a keylogger to capture my classmates' student ID card swipes when they went to release print jobs at any of the print stations on my university campus. I recognized this as a security flaw that (probably) didn't have many lucrative uses, but I never imagined such a technique might work for credit cards. I wrongly assumed that credit card readers would employ greater physical security.
- artas_bartas 13y agohardware security aside, if credit card readers employ proper encryption, that in itself would probably be an effective deterrent against such leaks, but only IF such encryption is implemented.
- 300bps 13y agoThere is very little true security in retail establishments. This lady simply swapped bar codes on expensive items for bar codes of inexpensive items. Got away with it for over a year and made as much as $30,000 per month in some months: http://miami.cbslocal.com/latest-videos/?autoStart=true&topVideoCatNo=default&clipId=7535659 http://miami.cbslocal.com/latest-videos/?autoStart=true&topV...
- triton 13y agoI'll admit to doing similar at the self checkouts at my local supermarket. Quite happily put pink lady apples through as cheap ones. I started doing this after I watched a whole tray of pink lady apples go in a skip because they brought new produce out. The same is true of a lt of retail establishments. Old stock is destroyed to keep prices up.
- _pmf_ 13y agoIn some countries, this is fraud as opposed to theft, leading to significantly higher penalties.
- triton 13y agoYes I know. So throwing out tonnes of food is ok then to protect the value of it?
- masklinn 13y agoYour parents may have told you two wrongs don't make a right.
- triton 13y agoHow do you explain capitalism and politics then? My parents taught me to be wary of both.
- chad_oliver 13y agoCapitalism is a system which aligns incentives so, if people want to get rich, they will do so in a way which also helps other people. Competition in the free market should drives prices down, which is equivalent to spreading profits among all the customers. (Of course, this only applies when the free market works well, which often requires regulation and pesky things like human rights). Capitalism is a system which works very well, and it takes a distorted view of the world to see this as 'two wrongs make a right'. To be clear: there are many businessmen who are greedy selfish exploiters. However, the purpose of capitalism is to take these natural human tendencies and make them into a force for good. You could say the same thing about democracy. It's a game whereby people can seek power and influence without having to kill each other or their subjects. If you doubt that democracy is an effective solution, just read up about all the Wars of Succession that Europe has witnessed when those countries were monarchies. Elections are practically love-fests in comparison.
- 13y ago
- gojomo 13y agoAn SAP Vice President was doing the same thing to steal Legos for resale: http://www.paloaltoonline.com/news/2012/05/21/sap-palo-alto-vice-president-arrested-for-lego-scam http://www.paloaltoonline.com/news/2012/05/21/sap-palo-alto-...
- ohazi 13y agochip and fucking pin. sigh This problem is solved, yet practically nobody in the US is demanding the established solution. Until we do, this is only going to continue.
- yajoe 13y agoI work in the industry. Chip and pin is not statistically safer (fraud rates in Spain, UK, and US are all the same despite having very different payment landscapes). The fundamental problem is that in traditional chip-and-pin setups you also type the pin into the same machine... so adding a skimmer + video camera OR adding a skimmer that records pin is marginally possible and not that hard. The real security would come with a second factor that the user controls, either by approving on your phone or by using one-time-numbers for each transaction. The reason why these do not exist yet is because they would impede transaction flow, and the basic math with these companies is if fraud rate > rate loss of transaction volume from security feature then use security feature. Otherwise, don't.
- raverbashing 13y ago"fraud rates in Spain, UK," for what? Credit cards? Debit? There's always going to be fraud one way or another. "you also type the pin into the same machine... so adding a skimmer..." There's no copying of SIM Cards. Yes, you can still copy the magnetic stripe that's there for backwards compatibility. So, yes, it's not going to be safer while there's support for old technology. My (European) bank issued me a chip-and-pin card without the mag stripe, good for travels, where I won't risk getting my card skimmed again.
- crazygringo 13y agoNot good for travels to the US! :)
- raverbashing 13y agoYes, I'm not sure about the US, but it worked like a charm in Canadian ATMs
- joenathan 13y agoThese are keyloggers and not skimmers, a skimmer looks something like this http://scams.wikispaces.com/file/view/camera02.jpg/30681221/camera02.jpg http://scams.wikispaces.com/file/view/camera02.jpg/30681221/...
- eps 13y agoLook up the guy whose blog this is. Also, it might help to read the article in full before blurting out trivialities.
- joenathan 13y agoI did read the article in full, also what does it matter who wrote it? A skimmer and a keylogger are two very distinct things. When I read the title I was interested to find out how the skimmers were placed, placing a keylogger takes much less skill and craft, it's a piece you can buy in bulk, whereas placing a skimmer usually requires a different class of criminal, skimmers often have to be fabricated for each location.
- cynwoody 13y agoIt's a matter of semantics. What does "to skim" mean? I read the article to mean that the bad guys were using key loggers to skim mag stripe images out of the keyboard data stream (from mag stripe readers attached via "wedges"). That's one level of threat. Your link, however, calls to mind a higher level threat that happened in Rhode Island a while back. Bank customers were disavowing ATM withdrawals. Bank security noticed that the complaining customers had all used their debit cards at the same all-night Stop & Shop. A review of the store's security video showed a gang of four guys coming in during third shift and installing hacked PIN pads at the registers while keeping the thin staff distracted. They were busted when they returned to harvest their next haul of debit card details. How they compromised the PIN pads I do not know. PIN pads are supposed to be sealed and tamper-proof. Your PIN is supposed to be encrypted before it leaves the keypad and decrypted only when it reaches the payment processor. The encryption key is supposed to be erased if someone tampers with the device. In order for the hack to work, they would need to be recording the mag stripe data along with cleartext PINs. I see it happened to Barnes & Noble more recently and on a larger scale: http://www.esecurityplanet.com/hackers/hackers-compromise-barnes-and-noble-pin-pads.html http://www.esecurityplanet.com/hackers/hackers-compromise-ba...
- eksith 13y agoI once worked for a retailer which was connected via Megapath (they outsourced to whatever local ISP is available at the store location). The internet setup was so abysmal in security, in some cases the stores used wifi to connect to the front registers with the password being (not kidding) [storename:storenumber]. That's it. These fools are getting caught doing elaborate plants. That's not how real criminals key log (btw, this is not a skimmer, but is a 'keylogger' as joenathan points out). Real criminals sit in the comfort of their car or nearby coffee shop and scan for open connections and insecure use of credentials.
- ChuckMcM 13y agoThis is another interesting case because it points out how vulnerable this part of the financial transaction chain is. Of course even after they catch the guys who were installing the skimmers they don't get the 'top' guys who make the fake cards and then withdraw funds in Serbia. I did see a talk where the folks noted (but did not remove) such devices and then began tracking every account that went through the modified device. This was to figure out who the bad guys were. By watching the fraudulent transactions that happened later they were able to roll up a carding group in the Baltics. But it does take a more proactive approach. From a future products prospective the use of cards with embedded processors seems better and better.
- dietrichepp 13y agoAnd the question is... why not just use secure card swipe devices? You load an encryption key onto the hardware, and then key loggers don't work any more. Sure, it won't solve all your problems, but nothing does.
- Sami_Lehtinen 13y agoDoesn't help, like I mentioned above. There's no such thing as 'secure device'. Someone is always able to tamper with those.
- dietrichepp 13y agoThere's a difference between "doesn't help" and "not a perfect solution". Secure readers eliminate the ability for non-savvy criminals to drop a keystroke logger in the terminal.
- callmeed 13y agoMy debit card got skimmed at a gas station this past week. It was used that same day to make purchases in LA (about 3 hours south of me). Now that this is happening in other types of retail stores, maybe it will spur the use of more secure options (chip and pin?).
- Sami_Lehtinen 13y agoNobody is using MSR anymore, Chip & PIN + PCI stuff has been the norm for several payment terminal and card generations already. So like 10+ years.
- chrissnell 13y agoWhat? Where is this? I don't think that you're talking about the gas station card readers in the US.
- paulgb 13y agoChip and pin has been widely used in Canada and Europe for a few years now.
- dangrossman 13y ago> Nobody is using MSR anymore The entire US still is, and that represents more transactions per day than happen in all of Europe.
- rwmj 13y agoThe population of the EU is twice the US.
- dangrossman 13y agoBut they do not use Visa cards at the same rate as the US. I didn't pull that out of thin air. EU only makes up about 40M of the 200M+ daily transactions VisaNet handles.
- Sami_Lehtinen 13y agoFrom technical standpoint very lame attack. There's no hacking involved at all. There has been technically much more sophisticated attacks modifying terminal hardware & firmware , off loading data completely out of band using 3g networks, etc. That's something that could be called hacking and proper (malhardware) engineering.
- zhamilton89 13y agoI think a large factor in the lack of change in payment security (In the US anyway, I can't speak for anywhere else) is the rise of the "protected" card. I have no incentive to protect anything about my Amex. Card got skimmed a few years ago somehow, Amex called, asked if I was in Nicaragua (I wasn't) they apologized, removed the $200 or so in charges and next-day aired me a new card. Almost zero hassle. I'd hate to have my debit card skimmed but as far as a credit card... I'm not too worried. The risk isn't mine.
- rwmj 13y agoErm, how is the end user supposed to protect against keyloggers installed in reputable stores? It's much better for the banks to carry the can here, so they implement more secure devices.
- tazzy531 13y agoVisa/MasterCard is pushing for EMV/Chip & Pin technology. Previously, the liability of fraud is on the payment network. Visa/MasterCard have announced a liability shift from the payment network to the merchant for fraud if the merchant doesn't adopt chip & pin. The rollout date is supposed to be Oct 2013. As an end user, you are not able to protect from this type of fraud. That's why the liability doesn't reside with you.
- dguido 13y agoCompelling argument to switch to iPad cash registers? har har Btw, if anyone wants to buy one, you can here: http://www.keelog.com/wifi_hardware_keylogger.html http://www.keelog.com/wifi_hardware_keylogger.html
- deleted 13y ago[deleted]
- cynwoody 13y agoOn the contrary! People need to be made aware of any and all threats to their security that may exist. They need to make sure such hardware is not deployed against them. And they need to design the vulnerability out of future systems.
- fit2rule 13y agoThere are already scanhacks for iPad cash registers. Mostly consisting of a touchscreen overlay wired to look like its part of the protective case. So, forget that iSense of iSecurity, its not there ..
- Theodores 13y agoThe Cherry PS/2 keyboard with built in card reader is designed for retail and used in places where there is no C+P: http://www.cherrycorp.com/english/keyboards/pos/8000/ http://www.cherrycorp.com/english/keyboards/pos/8000/ This explains the 'attack vector'. Presumably the scammers have USB dongles too.
- PeterisP 13y agoI may be mistaken, but I thought that the PCI/DSS forbids using such devices (unencrypted transmission from the keypad), and if a merchant uses them then they're automatically liable in full for all such fraud; i.e., banks just refund all cardholders for their losses and bill that+card replacements to that merchant. You save some $$ in hardware but take on risk.
- dangrossman 13y agoThere's no such rule. Virtually every internet gateway and mobile payment app lets you key in card numbers to make a charge. There is no encryption in your computer's keyboard. The first versions of the headphone jack swipers for phones (i.e. Square) didn't have any kind of encryption either.
- peterwwillis 13y agoThe main reason I find this interesting is the hacker scene in South Florida is so small. I bet if they caught one of these guys, they could track it down to the mastermind faster than somewhere like NY or SF.