July 1, 2008 5:37 PM PDT

PINs stolen from Citibank ATMs

We all worry about keeping our online passwords safe from prying eyes. But now our faith in ATM PIN codes is being shaken.

Three people face charges in federal court in New York for allegedly breaking into Citibank's ATM network inside 7-Eleven stores and stealing PIN codes, according to court filings reported on by The Associated Press on Tuesday.

The alleged thieves made off with about $2 million between October 2007 until March of this year. Officials believe they remotely broke into the back-end computers that approve cash withdrawals and grabbed the PINs as they were being transmitted from the ATMs to the transaction processing computers, which increasingly use Windows, the report says.

Wired News was the first to report on the ATM network breach.

Recent posts from News Blog
iLink to deliver answers to military online communities
Vonage names new CEO
T-Mobile 'Gekko' officially reveals itself as T-Mobile Sidekick
Alcatel-Lucent CEO, chairman stepping down
New York gets Fios TV
Add a Comment (Log in or register) 16 comments (Page 1 of 2)
by zanely July 1, 2008 6:44 PM PDT
When are we going to start to critical of the people in charge of the "back-end computers" for leaving the door unlocked for the thieves? Where is their responsibility? This sort of thing has been going on far too long. If bank vaults were being broken into this often Feds would be looking for terrorists, but since the banks money is not as risk, just access to peoples bank accounts, well that's seems to be ok.
Reply to this comment
by styymy July 1, 2008 7:10 PM PDT
This is absolutely dispicable. So all they did was issue new bank cards?? How about assuring and letting account holders know that should their accounts be compromised, that they (the bank) would provide resources to straighten things out for them with minimal hassle.
Reply to this comment
by amandachuck July 1, 2008 8:45 PM PDT
No back-end for ATMs should be based on Windows. Period. If they don't want to pay for a proprietary system (much more secure) then they should be running a brand of Unix.
Reply to this comment
by epr_epr July 1, 2008 10:03 PM PDT
sadly, MS is again the victim of paid reporters and trolls.

"And despite industry standards that call for protecting PINs with strong encryption -- which means encoding them to cloak them to outsiders -- some ATM operators apparently aren't properly doing that. The PINs seem to be leaking while in transit between the automated teller machines and the computers that process the transactions."

now with this, putting your mother there won't help either, not to mention unix.
Reply to this comment
by ralfthedog July 1, 2008 10:46 PM PDT
epr_epr,


This is why it is nearly criminal to use an operating system like Windows for the back end of a banking system. Every service that an operating system runs is a potential exploit. When you are designing a secure system, the first thing you do is strip out everything you do not need (Edited to say, you don't strip things out, you start with nothing and only add what you need). Use of any GUI on a secured system is not only useless but quite crazy.

.


Windows should not be used, nor shout OS X or Linux if it is running a GUI. While Windows can not be striped to a secure level and OS X is a bit of a challenge, Linux is very easy to run with a very minimalistic build.

.



Check out the NSA version of Linux.

Reply to this comment
by iamarcin July 2, 2008 5:06 AM PDT
Why use an atm at a 7eleven anyway. You have to be a moron to not want to gor the extra mile to a local bank which has to be alot more secure. ATMs at strip clubs and bars and such. I would never use those. This is the reason why.
Reply to this comment
by Surendra-Sambana July 2, 2008 5:23 AM PDT
If citi allows me, I'll give a solution to prevent this. But i am not sure with whom should i discuss. Can some one help me with the contact details.

Regards
Surendra
IT-Solution Architect
Reply to this comment
by atm_vet July 2, 2008 5:24 AM PDT
I've been in the business for a long, long time...from cash to hardware, up to processing...it comes down to what it usually comes down to...money. They save money by using readily available Internet connections in stores. This usually means Windows platforms. Before the internet became popular, sites used secure dedicated (aka: expensive) circuits which sounded alarms with any voltage deviation...but PIN security was weak. Now PIN security is strong and the comm is weak! BTW, 'back end' computers are within the atm kiosk, not the processor. The PIN leaves the keypad encrypted...there are strict banking regulations for that, but these yahoos want to save every penny so...stick a windows pc in the kiosk that apparently decrypts the PIN before sending the packet...the problem is...there is no one to 'come down hard' on these companies with these 'back end solutions'...banks usually don't own these atms, they pay for 'branding'. I feel if they are going to put their name on it, they need to take responsibility for whatever happens...and not just to Citibank customers.
Reply to this comment View reply
by mscatena July 2, 2008 6:23 AM PDT
Windows has nothing to do with it.

Having worked with ATM security in a high-treat environment (Brazil), the lack of physical security of the IT part of ATMs in North America is mind-bogling. The safe with the cash inside is very secure. As to the computer, card reader wires, keyboard wires, network connections?

An ATM in an unattended place such as bars, hotels and convenience stores is an easy target. In Brazil we don?t have those anymore.
Reply to this comment
by richto July 2, 2008 6:52 AM PDT
Why would anyone use Linux when security is the issue. Windows server has far fewer vulnerabilities and those that it does have are fixed much faster than Linux.

Also Windows server comes in a minimal GUI less install out of the box. With linux you have to spend ages turning off all the crap you dont need.
Reply to this comment View all 2 replies
1 | 2 | Next 10 Comments >>
Powered by Jive Software
advertisement
  • About News Blog

  • Recent posts on technology, trends, and more.

Add this feed to your online news reader
Google
Yahoo
MSN

Most popular stories

  1. FCC approval suggests November Android debut

  2. Debate rages over free wireless spectrum

  3. Apple willing to replace any smoking first-gen iPod Nanos

  4. Palm leaks Treo Pro photos and videos

  5. Judge lifts MIT students' card-hacking gag order

Latest tech news headlines

Featured blogs

Beyond Binary by Ina Fried

Coop's Corner by Charles Cooper

Defense in Depth by Robert Vamosi

Geek Gestalt by Daniel Terdiman

Green Tech

One More Thing by Tom Krazit

Outside the Lines by Dan Farber

The Iconoclast by Declan McCullagh

The Social by Caroline McCarthy

Underexposed by Stephen Shankland

Resource center from News.com sponsors
Aligning CIO & CEO visions
What CIOs need to know

It's a simple truth. The closer you and your CEO see things, the greater your chance for success. Our exclusive report can help you get there—and help your business grow. To get the report, featuring the views of 765 CEOs on innovation. click here

Click Here!
What CEOs think: Innovation Insights for CIOs

Learn How CIOs can deliver strategic success for their enterprises

The New CIO: Beyond Technology

Learn how CIOs become heroes

Podcast: Chris Gorog of Napster

Learn about the impact of technology in strategy execution

The future of the Enterprise

Read more about tomorrow's organization

advertisement
On TechRepublic: 19 words you don't want in your resume
Advanced
search
Advanced
search
Visit other CBS Interactive sites