日批在线视频_内射毛片内射国产夫妻_亚洲三级小视频_在线观看亚洲大片短视频_女性向h片资源在线观看_亚洲最大网

WORLD> America
Citibank ATM breach reveals PIN security problems
(Agencies)
Updated: 2008-07-02 15:35

SAN JOSE - Hackers broke into Citibank's network of ATMs inside 7-Eleven stores and stole customers' PIN codes, according to recent court filings that revealed a disturbing security hole in the most sensitive part of a banking record.

A Citibank ATM machine is shown at 7-Eleven in Palo Alto, Calif., Tuesday, July 1, 2008. [Agencies] 

The scam netted the alleged identity thieves millions of dollars. But more importantly for consumers, it indicates criminals were able to access PINs - the numeric passwords that theoretically are among the most closely guarded elements of banking transactions - by attacking the back-end computers responsible for approving the cash withdrawals.

The case against three people in US District Court for the Southern District of New York highlights a significant problem.

Hackers are targeting the ATM system's infrastructure, which is increasingly built on Microsoft Corp.'s Windows operating system and allows machines to be remotely diagnosed and repaired over the Internet. And despite industry standards that call for protecting PINs with strong encryption - which means encoding them to cloak them to outsiders - some ATM operators apparently aren't properly doing that. The PINs seem to be leaking while in transit between the automated teller machines and the computers that process the transactions.

"PINs were supposed be sacrosanct - what this shows is that PINs aren't always encrypted like they're supposed to be," said Avivah Litan, a security analyst with the Gartner research firm. "The banks need much better fraud detection systems and much better authentication."

It's unclear how many Citibank customers were affected by the breach, which extended at least from October 2007 to March of this year and was first reported by technology news Web site Wired.com. The bank has nearly 5,700 Citibank-branded ATMs inside 7-Eleven Inc. stores throughout the US, but it doesn't own or operate any of them.

That responsibility falls on two companies: Houston-based Cardtronics Inc., which owns all the machines but only operates some, and Brookfield, Wis.-based Fiserv Inc., which operates the others.

A critical issue in the investigation is how the hackers infiltrated the system, a question that still hasn't been answered publicly.

All that's known is they broke into the ATM network through a server at a third-party processor, which means they probably didn't have to touch the ATMs at all to pull off the heist.

They could have gained administrative access to the machines - which means they had carte blanche to grab information - through a flaw in the network or by figuring out those computers' passwords. Or it's possible they installed a piece of malicious software on a banking server to capture unencrypted PINs as they passed through.

What that means for consumers is that their PINs were stolen from machines that showed no signs of tampering they could detect. In previous PIN thefts, thieves generally took steps that might draw notice - sending "phishing" e-mails, for example, or installing false-front keypads or even tiny cameras on ATMs.

   Previous page 1 2 Next Page  
主站蜘蛛池模板: 99久久久国产 | 亚洲欧美在线综合 | 激情婷婷六月天 | 精品一区二区三区四区五区六区 | 亚洲免费av网站 | 91精品久久香蕉国产线看观看 | 秋霞影院午夜伦 | 国产刺激高潮av | 成人3d动漫一区二区三区91 | 国产精久久一区二区三区 | 天天操天天爽天天干 | 精品国产乱码久久久久 | 国产视频网站在线观看 | 成人国产在线视频 | 亚洲伦理影院 | 国产在线观看网站 | 国产女人18毛片水18精品 | 免费黄色在线网站 | 男插女青青影院 | 在线毛片观看 | 中文字幕在线免费观看 | 久久久久9 | 影音先锋国产资源 | 欧美乱日| 日本高清视频一区二区 | 亚洲骚图 | 国产aaa级片 | 男人的天堂视频网站 | 婷婷视频网 | 久久影院中文字幕 | 精品久久久久久亚洲 | 国产成人精品免高潮在线观看 | 国产专区第一页 | 涩涩资源站 | www.日韩精品| 日韩精品久久久 | 久久久久久麻豆 | 亚洲视频欧洲视频 | 午夜国产在线观看 | 黄色成人18 | 久久久欧洲 |