男女羞羞视频在线观看,国产精品黄色免费,麻豆91在线视频,美女被羞羞免费软件下载,国产的一级片,亚洲熟色妇,天天操夜夜摸,一区二区三区在线电影
WORLD> America
Citibank ATM breach reveals PIN security problems
(Agencies)
Updated: 2008-07-02 15:35

SAN JOSE - Hackers broke into Citibank's network of ATMs inside 7-Eleven stores and stole customers' PIN codes, according to recent court filings that revealed a disturbing security hole in the most sensitive part of a banking record.

A Citibank ATM machine is shown at 7-Eleven in Palo Alto, Calif., Tuesday, July 1, 2008. [Agencies] 

The scam netted the alleged identity thieves millions of dollars. But more importantly for consumers, it indicates criminals were able to access PINs - the numeric passwords that theoretically are among the most closely guarded elements of banking transactions - by attacking the back-end computers responsible for approving the cash withdrawals.

The case against three people in US District Court for the Southern District of New York highlights a significant problem.

Hackers are targeting the ATM system's infrastructure, which is increasingly built on Microsoft Corp.'s Windows operating system and allows machines to be remotely diagnosed and repaired over the Internet. And despite industry standards that call for protecting PINs with strong encryption - which means encoding them to cloak them to outsiders - some ATM operators apparently aren't properly doing that. The PINs seem to be leaking while in transit between the automated teller machines and the computers that process the transactions.

"PINs were supposed be sacrosanct - what this shows is that PINs aren't always encrypted like they're supposed to be," said Avivah Litan, a security analyst with the Gartner research firm. "The banks need much better fraud detection systems and much better authentication."

It's unclear how many Citibank customers were affected by the breach, which extended at least from October 2007 to March of this year and was first reported by technology news Web site Wired.com. The bank has nearly 5,700 Citibank-branded ATMs inside 7-Eleven Inc. stores throughout the US, but it doesn't own or operate any of them.

That responsibility falls on two companies: Houston-based Cardtronics Inc., which owns all the machines but only operates some, and Brookfield, Wis.-based Fiserv Inc., which operates the others.

A critical issue in the investigation is how the hackers infiltrated the system, a question that still hasn't been answered publicly.

All that's known is they broke into the ATM network through a server at a third-party processor, which means they probably didn't have to touch the ATMs at all to pull off the heist.

They could have gained administrative access to the machines - which means they had carte blanche to grab information - through a flaw in the network or by figuring out those computers' passwords. Or it's possible they installed a piece of malicious software on a banking server to capture unencrypted PINs as they passed through.

What that means for consumers is that their PINs were stolen from machines that showed no signs of tampering they could detect. In previous PIN thefts, thieves generally took steps that might draw notice - sending "phishing" e-mails, for example, or installing false-front keypads or even tiny cameras on ATMs.

   Previous page 1 2 Next Page  
主站蜘蛛池模板: 涟水县| 崇明县| 离岛区| 二连浩特市| 务川| 新乡县| 玉屏| 南城县| 五指山市| 姚安县| 乌苏市| 昭通市| 民乐县| 连江县| 嘉黎县| 曲沃县| 兴业县| 长武县| 建德市| 交口县| 论坛| 满城县| 成安县| 紫金县| 施秉县| 驻马店市| 临江市| 盐池县| 石狮市| 尉犁县| 大宁县| 阿巴嘎旗| 宁河县| 伊宁县| 杂多县| 汝南县| 沂源县| 兴宁市| 江达县| 安图县| 河东区| 富顺县| 阳新县| 阿坝| 常州市| 上蔡县| 呈贡县| 临湘市| 南投市| 揭西县| 宜宾县| 盐边县| 广东省| 平潭县| 凤台县| 无极县| 青川县| 溆浦县| 淮南市| 尼勒克县| 重庆市| 县级市| 济宁市| 措美县| 西宁市| 兖州市| 丰顺县| 唐海县| 双峰县| 平舆县| 大英县| 连州市| 新邵县| 兰溪市| 佳木斯市| 新闻| 桐柏县| 台湾省| 天全县| 兴和县| 尚志市| 阳原县|