TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

German security experts find major flaw in credit card terminals

49 pointsby cjfarivaralmost 13 years ago

6 comments

revelationalmost 13 years ago
Apparently, the JTAG debugging interface is exposed to the outside. You know, the one that should be turned off physically in the CPU itself through a blow fuse on production processors. The one critical interface where you don't even populate the headers and connectors on the finished boards.<p>As it stands, the only way to fix this is to exchange or repair all devices in circulation.
评论 #4242607 未加载
评论 #4242920 未加载
dazbradburyalmost 13 years ago
Isn't the fact that Chip and Pin is susceptible to "Man in the Middle" attacks, affecting all terminals, the bigger issue?<p><a href="http://www.cl.cam.ac.uk/~sjm217/papers/oakland10chipbroken.pdf" rel="nofollow">http://www.cl.cam.ac.uk/~sjm217/papers/oakland10chipbroken.p...</a>
评论 #4243440 未加载
farmdawgnationalmost 13 years ago
I find it amusing how the CC execs admit they couldn't reproduce the attack, and he seems somewhat proud of that fact. Maybe my interpretation is just colored with my impression of execs of large companies. -.-
erualmost 13 years ago
&#62; “This is one lab that has reported (unsubstantiated) that they were able to do this,” she wrote. “No credit card users are at risk.”<p>And if they had released the attack, VeriFone would have cried even louder..
kylebrownalmost 13 years ago
So its possible to remotely overwrite the Verifone software to capture PIN numbers. The local attacks aren't as terrifying, since it was already possible to replace them with modified devices to skim PINs. And what about all the HSM PIN-recovery attacks, on which the details are already available? And where are those &#60;1mm thick ATM skimmers they warned us about?<p>Ultimately, stolen credit card numbers just aren't that monetizable (they're sold for pennies on the dollar, $2-$3 per) and not enough people use their pin numbers at POS terminals. It seems more fraudsters steal using Scareware/rogue AV (its less likely to be charged back, since the victim actively entered their details).<p>Well-funded organized crime seems more interested in targeting bank logins, or Medicare (losses in the billions, mixed with bonafide doctor-fraud), or maybe home loans and other forms of ID theft.
评论 #4243923 未加载
Sam_Odioalmost 13 years ago
It's disappointing that these guys didn't work with VeriFone before publicizing the attack.<p>This is FUD, just with different actors.
评论 #4242523 未加载