Comments on: PINs stolen from Citibank ATMs
Three people are accused of stealing PINs from the Citibank ATM network in 7-Eleven stores.
Three people are accused of stealing PINs from the Citibank ATM network in 7-Eleven stores.
Web sites launch all the time, but they also shut their doors. We highlight 15 that bit the dust this year.
Let the debate begin: Was the iPhone more important than iTunes? Was anything bigger than Google finding a great business model? CNET offers its list of the 10 most important stories of the '00s.
Recent posts on technology, trends, and more.
Add this feed to your online news reader
"And despite industry standards that call for protecting PINs with strong encryption -- which means encoding them to cloak them to outsiders -- some ATM operators apparently aren't properly doing that. The PINs seem to be leaking while in transit between the automated teller machines and the computers that process the transactions."
now with this, putting your mother there won't help either, not to mention unix.
This is why it is nearly criminal to use an operating system like Windows for the back end of a banking system. Every service that an operating system runs is a potential exploit. When you are designing a secure system, the first thing you do is strip out everything you do not need (Edited to say, you don't strip things out, you start with nothing and only add what you need). Use of any GUI on a secured system is not only useless but quite crazy.
.
Windows should not be used, nor shout OS X or Linux if it is running a GUI. While Windows can not be striped to a secure level and OS X is a bit of a challenge, Linux is very easy to run with a very minimalistic build.
.
Check out the NSA version of Linux.
Regards
Surendra
IT-Solution Architect
Having worked with ATM security in a high-treat environment (Brazil), the lack of physical security of the IT part of ATMs in North America is mind-bogling. The safe with the cash inside is very secure. As to the computer, card reader wires, keyboard wires, network connections?
An ATM in an unattended place such as bars, hotels and convenience stores is an easy target. In Brazil we don?t have those anymore.
Also Windows server comes in a minimal GUI less install out of the box. With linux you have to spend ages turning off all the crap you dont need.
- by stampsman July 2, 2008 7:41 PM PDT
- For the last 30 years credit and debit card fraud has almost always increased . Criminals are much more creative and will always look for the weakest link. Once found they will continue to exploit it until a solution is put in place. Encryption and the security of PIN's is an area that needs far greater security for consumers and that is why companies like Secure Identity Systems are developing new technologies like mconfirm that can protect transactions at the point of sale and alert consumers if their accounts are at risk. New technology is the only way to offer the best protection coupled with proper procedures on how to implement.
- Like this Reply to this comment
-
(16 Comments)Tom
Secure Identity Systems