5 ms·
"a cyberattacker must connect the ATM to a mobile phone via USB tethering" I've never seen ATMs (at least here in Switzerland) which you could just walk up to
by emeidi 13y ago
"a cyberattacker must connect the ATM to a mobile phone via USB tethering"
I've never seen ATMs (at least here in Switzerland) which you could just walk up to and plug in a USB device. Do Mexican ATMs come with USB ports on the front of the device?!
Don't forget:
"Law 3: If a bad guy has unrestricted physical access to your computer, it's not your computer anymore."
http://technet.microsoft.com/en-us/magazine/2008.10.securitywatch.aspx http://technet.microsoft.com/en-us/magazine/2008.10.security...
- peteretep 13y agoI came here to quote just that. Next up: "How to hack the NSA's Computers!!! First, gain physical access to their server farm..."
- aidos 13y agoThere was an article on here recently about a technique using this attack. Transpires that the usb port is under the cover at the front of the device, you just need to know where to cut the hole. EDIT: Found it. https://news.ycombinator.com/item?id=6984821 https://news.ycombinator.com/item?id=6984821 The most wonderful part is that whoever wrote the software had the insight to add a phone verification step so other crooks couldn't run off with their software.
- ilovecookies 13y agoWell it's still interesting. That law is true, if you have an insider things are always much easier. Popping in one of these can not be that hard. http://www.newegg.com/Product/Product.aspx?Item=N82E16833320166 http://www.newegg.com/Product/Product.aspx?Item=N82E16833320...
- Nanzikambe 13y agoI remember from seeing a vandalised ATM (La Poste I think?) that the keypad was connected with what looked like that same 5 pin connectors you see on internal USB interfaces. If that's the case, I imagine that yes, you could just walk up, remove keyboard, connect trojan device + mini usb hub, reconnect and replace keyboard then walk off. If space is an issue then one of those micro usb to bluetooth relay thingies and keep the trojan device out. Then again, that was 5+ years ago and it could just as easily have been some other type of connector altogether vOv