Banks failing on ATM security

Unencrypted messages open to abuse, claims report

Written by Ian Williams

Most people assume that, because an ATM is provided by a bank, the data must be secure

Mark Webb-Johnson Chief technology officer, Network Box

Banks and financial institutions are leaving customers' personal details vulnerable to hackers by failing properly to secure their ATMs, according to a new report.

Managed security firm Network Box cited three main threats to ATMs: IP worms, disruption of the IP network and denial of service, and the harvesting of transaction data for malicious purposes.

The company said that ATM security risks have increased because of the changing ways in which they operate.

Many ATMs were built on proprietary hardware, software and communications protocols.

But it is estimated that 70 per cent of current ATMs are based on PC/Intel hardware and commodity operating systems using standard IP networking with some additional peripherals housed in a secure vault-like box.

The report attributes the changes to advantages in cost, performance, flexibility, standardisation and functionality, but points out that these advantages bring increased threats.

In these newer systems the ATM is connected to the payment processor using a TCP/IP connection. However, while the Pin is triple-DES encrypted, the messages themselves are not.

This leaves card numbers, expiry dates, transaction amounts and account balances clearly readable.

A hacker needs only to access some part of the IP network between the IP-ATM and the payment processor to gather the details.

"Most people simply assume that because an ATM is invariably provided by a bank, the transactions and the data being transmitted must be secure," said Mark Webb-Johnson, chief technology officer at Network Box.

"We have already seen how the Nachi worm crossed over into 'secure' networks and infected ATMs for two financial institutions, and SQL Slammer indirectly shutdown 13,000 Bank of America ATMs.

"If banks do not use technology that can provide an effective level of protection it is very likely that more high-profile attacks will follow."

Network Box recommends that all traffic to and from ATM machines should be encrypted, and not just the Pin.

ATM networks should also be separated from the rest of the bank's network, thereby allowing it to be closely monitored and controlled.

Further reading

Egg in hot water over cancelled credit cards

Customers scramble to understand as bank fries 161,000 accounts   More...

French trader accused of hacking systems

Société Générale exposes extent of Kerviel affair   More...

NatWest now spammers favourite

Most popular company name used by fraudsters   More...

Barclays chairman has identity stolen

Thief gets away with £10,000   More...

Related articles

Hackers step up website attacks

Security forecast for 2008 makes grim reading   More...

Hackers step up search results attack

Big-name sites compromised in IFrame redirect scam   More...

McAfee paints grim picture for 2008

Huge rise in web 2.0 attacks and smarter botnets   More...

vnunet.com analysis: home PCs still wide open

New targeted attacks also on the rise   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

16 May 2008

2.97 MBXP on OLPC, broken dreams and Yahoo fights back More...

15 May 2008

3.28 MBDark fibre, mobile TV and solar power More...

14 May 2008

2.66 MBOnline inequality, mobile thumbprints and corporate raids More...

Poll

HOME WORKING

HOME WORKING

Do you let any or all of your employees work from home?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

OLPC

OLPC to ship with Windows XP

Microsoft teams up with One Laptop per Child project   More...

The Sims

The Sims goes flat-pack with Ikea

Virtual world gets Swedish wood   More...

Advertisement

Microsoft-Yahoo

Yahoo board fights back at Icahn

Investor accused of 'significant misunderstanding' in Microsoft saga   More...

MySpace

Woman charged over MySpace suicide

Lori Drew indicted on federal charges   More...

Advertisement