Thieves "bug" debit card PIN pads in 63 Barnes & Noble stores(news.yahoo.com)
news.yahoo.com
Thieves "bug" debit card PIN pads in 63 Barnes & Noble stores
http://news.yahoo.com/barnes-noble-reports-breach-u-customer-credit-card-032430509--finance.html
10 comments
EMV has been trivially broken[1], and it unpopularly pushes the risk of fraud onto the customer. Customers in the US don't want that (especially since EMV is broken!). On top of that, there are a hell of a lot more merchants that would all need to purchase entirely new credit card terminals, which is a much larger undertaking in this country than it would be elsewhere.
[1] http://www.cl.cam.ac.uk/research/security/banking/nopin/oakl...
[1] http://www.cl.cam.ac.uk/research/security/banking/nopin/oakl...
The paper you have linked describes an attack that is only possible if the attacker has stolen the victim's physical card. I think the real security of EMV lies in the fact that cards cannot be cloned - this attack does not change that fact.
" In this paper we describe and demonstrate a protocol flaw which allows criminals to use a genuine card to make a payment without knowing the card’s PIN, and to remain undetected even when the merchant has an online connection to the banking network."
I wasn't even aware that the chipped cards _had_ PINs.
I think we can all agree that a chipped card + PIN is more secure than a magnetic strip card with no PIN. But, perhaps the reduction in fraud isn't worth the cost of replacing all the old gear.
I wasn't even aware that the chipped cards _had_ PINs.
I think we can all agree that a chipped card + PIN is more secure than a magnetic strip card with no PIN. But, perhaps the reduction in fraud isn't worth the cost of replacing all the old gear.
That attack is far from trivial. There were other attacks against EMV in the past, but they're fixed as they come.
Magnetic stripes stay vulnerable, and ATMs in the US are not that secure either (seriously, some of them can be stolen and taken home by one man alone).
Securing chips is hard, but a lot of the process has already been figured out. What you should fear is the new RFID cards coming up soon. Those are even more vulnerable than magnetic stripes.
That's not trivial compared to magnetic stripe. I created a credit card reader with £2 of electronics, my laptop, and a freely available open-source program. (And I'm pretty dumb, so it's really easy)
What about the most vulnerable part of credit cards, the fact that the card information is printed right on the front (and back) of the card? Someone in line at the grocery store with a pen camera in their pocket can catch a glimpse of the front and back of a card. That is generally enough information to use the card online.
How will you use that card information, though? The printed information isn't sufficient to create a new magnetic stripe (the CVV1 code in the magstripe isn't printed on the card). Using the card info online requires knowing the cardholder's address. If you can find someone still using an imprinter, then that would work, but so would completely made-up data.
> Using the card info online requires knowing the cardholder's address.
US (and Canada, UK) issued cards are verified against the billing address (AVS), in most cases. In other countries (e.g. Australia), this is not the case.
The card number and CVC are typically sufficient; you can put any other address you would like. My Amazon billing address is my work address, which is not the address my bank has (my home).
US (and Canada, UK) issued cards are verified against the billing address (AVS), in most cases. In other countries (e.g. Australia), this is not the case.
The card number and CVC are typically sufficient; you can put any other address you would like. My Amazon billing address is my work address, which is not the address my bank has (my home).
Interesting. Any idea why they don't verify the billing address there? Seems like it would be no harder than doing it in the US.
About a year ago someone did something similar to this (debit cards though, not credit) at the Wal-Mart in the small Canadian city I was living in. Just about everyone in town had their cards frozen and had to get new ones. I'm not sure how the attacker was capturing card information, but I do wonder if it doesn't have to do with the fact that our Chip & Pin cards also have a magnetic stripe.
Yes, I know, you can always challenge a charge, IF you notice it sneak onto your card
A friend of mine has a system for that, at least at gas stations. Whenever he fills up, he tops it off such that the price ends in a 7. Then he scans his American Express statement for any gas station charges not ending in 7. Over the years, he's done several successful charge-backs.
A friend of mine has a system for that, at least at gas stations. Whenever he fills up, he tops it off such that the price ends in a 7. Then he scans his American Express statement for any gas station charges not ending in 7. Over the years, he's done several successful charge-backs.
I've had credit cards compromised before. Takes a few minutes to resolve. Really not a big deal. Debit fraud is worse, because the money and incentives are all arranged differently, but credit cards are pretty simple.
Credit card fraud should not in any way be lumped in with identity theft, which is a vastly different act that's far more difficult to deal with. Credit card fraud is simply not worth worrying about as a consumer.
Credit card fraud should not in any way be lumped in with identity theft, which is a vastly different act that's far more difficult to deal with. Credit card fraud is simply not worth worrying about as a consumer.
They should both be called fraud (the part where the financial institution inflicts damage on a third party doesn't change the fact that the impersonator is defrauding the financial institution).
I think it is important to make the distinction because calling it fraud directs attention at a party that can actually do something about the overall problem.
I think it is important to make the distinction because calling it fraud directs attention at a party that can actually do something about the overall problem.
I had a friend of mine whose house was broken into, they got his credit card, and it took him close to six months to walk back all the charges they made on his card. He was relentless, and his basic posture was, "Any charge on this card made after the date of the police report is fraudulent."
He had to challenge each separate charge though - he couldn't just do them all in bulk. Needless to say - not a pleasant experience, and probably cost him 10s of hours.
He had to challenge each separate charge though - he couldn't just do them all in bulk. Needless to say - not a pleasant experience, and probably cost him 10s of hours.
Out of curiosity, who was the card vendor?
When my number was stolen my CU directed me to an online form with which I could dispute all fraudulent charges in bulk, and they were reversed two days later.
When my number was stolen my CU directed me to an online form with which I could dispute all fraudulent charges in bulk, and they were reversed two days later.
That's odd, how did they manage to make so many purchases with the card? Did he not realize it had been taken for a while?
"Tampered PIN pads were discovered from stores in the following states: CA, CT, FL, IL, MA, NJ, NY, PA, RI. A complete list of specific stores follows."
http://www.barnesandnobleinc.com/press_releases/10_23_12_Imp...
http://www.barnesandnobleinc.com/press_releases/10_23_12_Imp...
> Bugs were planted in the PIN pads...
Fascinating. I wonder how these "bugs" worked. More information here would be great.
Fascinating. I wonder how these "bugs" worked. More information here would be great.
Lots of juicy pictures here:
http://krebsonsecurity.com/2010/02/atm-skimmers-part-ii/
I guess you can learn from these pictures how they work.
http://krebsonsecurity.com/2010/02/atm-skimmers-part-ii/
I guess you can learn from these pictures how they work.
The krebsonsecurity site is pretty awesome. I was at a talk where they discussed the hard part isn't discovering the skimmers, its catching the crooks when they cash out. So some enterprising folks are noting that the skimmers are installed and then logging all the customers who use the ATM, once they have customer records they then flag transactions on all of those accounts and wait for the crooks to try to cash out. They have caught folks with literally a bag full of cards with pins written on them trying to pull $200 - $500 out of each account.
naw, better link to full gallery of skimmer pics on that site is here:
http://krebsonsecurity.com/all-about-skimmers/
Krebs has a story on POS skimmers w/ pics of pin pad overlay here:
http://krebsonsecurity.com/2011/05/point-of-sale-skimmers-ro...
http://krebsonsecurity.com/all-about-skimmers/
Krebs has a story on POS skimmers w/ pics of pin pad overlay here:
http://krebsonsecurity.com/2011/05/point-of-sale-skimmers-ro...
Most probably the criminals just bought/obtained PIN pads, modified them and replaced the ones in the stores when the cashier was not looking. Not so hard to do as the pads are usually on a cord and connected with a RJ (like a phone jack).
[deleted]
I wonder if it's something like a keylogger... maybe something as simple as pulling the plug out and putting something inline.
Probably not. The PIN never leaves a (unmodified) terminal unencrypted.
However (as mentioned previously) it would be pretty straightforward to obtain an identical terminal, insert a logging circuit inside of it (connected directly to the keypad and card reader), and replace the one at the register with the hacked one.
Then all that's necessary is to recover the modified terminal at a later date and download the logged numbers.
However (as mentioned previously) it would be pretty straightforward to obtain an identical terminal, insert a logging circuit inside of it (connected directly to the keypad and card reader), and replace the one at the register with the hacked one.
Then all that's necessary is to recover the modified terminal at a later date and download the logged numbers.
For the first time since I've had credit cards, I've had my cards cloned and used to make purcahses twice over the past couple of months. It's a major hassle because I have auto pay for reoccurring bills (phone, internet, electric, etc...).
It seems to me that this type of activity is on the uptick.
It seems to me that this type of activity is on the uptick.
Recently I had fraudulent charges made on my Wells Fargo debit card. That card had no history (never used at ATMs or Merchants), and even the lady I talked to from Wells Fargo fraud dept was surprised.
The only place I've used it was at the local Wells Fargo branch office with their pads to take out cash out of my checking account.
I bet they have a similar issue. Those pads are networked to their systems, all running Windows, it wouldn't take much to craft something together to pull those #s out.
The only place I've used it was at the local Wells Fargo branch office with their pads to take out cash out of my checking account.
I bet they have a similar issue. Those pads are networked to their systems, all running Windows, it wouldn't take much to craft something together to pull those #s out.
Did you go into an ATM vestibule? The readers that let you insert your card to get to "safe" ATMs inside the bank lobby after hours are often targets of skimmers too. They look something like this: http://krebsonsecurity.com/wp-content/uploads/2010/01/lmskim...
I wonder how long it will take for people to start thinking that shopping online is actually safer than shopping in person.
I remember how reluctant people were during the "dot com boom" to use their credit cards online. Now I am reluctant to use public ATMs, even my own bank's ATM.
I remember how reluctant people were during the "dot com boom" to use their credit cards online. Now I am reluctant to use public ATMs, even my own bank's ATM.
I had to copy & paste the URL for the B&N press release. Why not make it a link?
I remember there being a really interesting story about a Turkish criminal manufacturing tons of ATM number pad overlays in Kingpin:
http://www.amazon.com/Kingpin-Billion-Dollar-Cybercrime-Unde...
That whole book is full of bizarre and amazing stories about hacking and credit card fraud. It's well written, too; the author was a hacker so the technical descriptions aren't painfully generalized as they too often are. Highly suggested.
http://www.amazon.com/Kingpin-Billion-Dollar-Cybercrime-Unde...
That whole book is full of bizarre and amazing stories about hacking and credit card fraud. It's well written, too; the author was a hacker so the technical descriptions aren't painfully generalized as they too often are. Highly suggested.
Wow I was wondering why Chase randomly sent me a warning and a new debit card a few weeks ago. I had made no unique purchases aside from coffee and books from Barnes and Noble and initially thought the new card from Chase was a fake.
At stores like the one at NY's Union Square, the cashiers never leave their stations from 10am to 10pm. I wonder how this could have been done so quickly as to not cause suspicion. Perhaps there might have been some internal cooperation?
Aren't chip-readers the law in the US now? What's the use of getting a PIN if the only thing you can link it to is impossibly-encrypted chip data?
I have never seen a chip reader in my life (living in Seattle, for reference).
Almost no cards issued in the US have chips. As a result, almost no terminals in the US have a chip reader.
A PIN is used to authenticate swiped (magstripe) transactions from a debit card. That said, swiped transactions from a credit card only require a signature -- though many terminals have been upgraded to also require the billing ZIP (postal) code. Most debit cards can also be run as credit cards, effectively bypassing the PIN check.
NFC-enabled terminals (and the cards to go with them) are slowly starting to appear, but even those don't require a PIN. Just a signature.
A PIN is used to authenticate swiped (magstripe) transactions from a debit card. That said, swiped transactions from a credit card only require a signature -- though many terminals have been upgraded to also require the billing ZIP (postal) code. Most debit cards can also be run as credit cards, effectively bypassing the PIN check.
NFC-enabled terminals (and the cards to go with them) are slowly starting to appear, but even those don't require a PIN. Just a signature.
> Almost no cards issued in the US have chips. As a result, almost no terminals in the US have a chip reader.
I was in New York state a while ago, and most places had PIN pads with chip readers. Not a single store person asked me to use it, and the few times I suggested I could, I got blank stares. I ended up signing for a bunch of stuff.
Long story short: just because no-one is using them doesn't mean there's no chip reader.
I was in New York state a while ago, and most places had PIN pads with chip readers. Not a single store person asked me to use it, and the few times I suggested I could, I got blank stares. I ended up signing for a bunch of stuff.
Long story short: just because no-one is using them doesn't mean there's no chip reader.
These sort of exploits are significantly more difficult in other parts of the world that have switched over - the United States use of the outdated "magnetic stripe" for security is not only putting american consumers at risk (Yes, I know, you can always challenge a charge, IF you notice it sneak onto your card, AND if you got to the effort of getting it revoked. Go talk to someone who's been the victim of identity/credit card theft to see how much FUN that is) - it's also putting all the other countries that have to continue to support legacy card systems.
At the very least, the credit card agencies in the United States could start rolling out the Card Machines to NEW businesses, in preparation for the eventual upgrade of consumers.
My only guess is that they've done a RISK/REWARD assessment, and decided that the cost of upgrading all of these systems is more expensive than what they are losing to fraud.