Free Republic
Browse · Search
News/Activism
Topics · Post Article

To: Southack
Get the picture?!

Physical access to a keypad on an ATM is completely different that physical access to a PC. Last I saw, there was no floppy drive on the outside of an ATM that I can stick a boot floppy into to run a password crack program. If you were to break in through the 3 inch thick steel door in the back of the ATM, you would have full access and be able to have some real fun. You can "secure your network" all you want, but if I can get access to a pc on your network with a floppy drive, I can post your 4 digit password on DEJA before "Luke" could pull the force outta his rear end.

Get the picture?
79 posted on 07/23/2003 7:02:42 AM PDT by cspackler (There are 10 kinds of people in this world, those who understand binary and those who don't.)
[ Post Reply | Private Reply | To 35 | View Replies ]


To: cspackler; general_re; Russian Sage
"If you were to break in through the 3 inch thick steel door in the back of the ATM, you would have full access and be able to have some real fun."

Nonsense. I can physically give you an ATM machine, but that won't enable you to access the accounts of the bank's customers.

Same goes for a POS terminal. You can buy one on eBay right now, but that won't give you access to the data that you want on someone else's network, even though you clearly have full physical access to it.

In short, claiming that physical access defeats security is just baby-talk for admitting that **your** own security is child's play.

Same goes for spouting off about needing big, long, complex passwords. POS terminals (and ATMs for that matter) only require a 4 digit password, yet the posters on this thread clearly can't get through that level of security due to the **architecture** involved.

So here's a tip: if you can't guarantee the physical secuirty of a PC, POS terminal, or ATM, then you simply don't place valuable data onto said "vulnerable" machines.

Store such data somewhere else. Somewhere safe.

That's how banks do it today. Steal an old ATM, drill through its armour, boot up the ancient AT&T 3B2 inside with any startup disk that you want, it still won't give you access to all of the customer accounts of any bank, even though said machine has its physical access compromised and even though said machine only asks for a simple numeric 4 digit password.

It ain't the tactics, people; it's the architecture.

81 posted on 07/23/2003 9:48:17 AM PDT by Southack (Media bias means that Castro won't be punished for Cuban war crimes against Black Angolans in Africa)
[ Post Reply | Private Reply | To 79 | View Replies ]

Free Republic
Browse · Search
News/Activism
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson