男女羞羞视频在线观看,国产精品黄色免费,麻豆91在线视频,美女被羞羞免费软件下载,国产的一级片,亚洲熟色妇,天天操夜夜摸,一区二区三区在线电影
WORLD> America
Citibank ATM breach reveals PIN security problems
(Agencies)
Updated: 2008-07-02 15:35

SAN JOSE - Hackers broke into Citibank's network of ATMs inside 7-Eleven stores and stole customers' PIN codes, according to recent court filings that revealed a disturbing security hole in the most sensitive part of a banking record.

A Citibank ATM machine is shown at 7-Eleven in Palo Alto, Calif., Tuesday, July 1, 2008. [Agencies] 

The scam netted the alleged identity thieves millions of dollars. But more importantly for consumers, it indicates criminals were able to access PINs - the numeric passwords that theoretically are among the most closely guarded elements of banking transactions - by attacking the back-end computers responsible for approving the cash withdrawals.

The case against three people in US District Court for the Southern District of New York highlights a significant problem.

Hackers are targeting the ATM system's infrastructure, which is increasingly built on Microsoft Corp.'s Windows operating system and allows machines to be remotely diagnosed and repaired over the Internet. And despite industry standards that call for protecting PINs with strong encryption - which means encoding them to cloak them to outsiders - some ATM operators apparently aren't properly doing that. The PINs seem to be leaking while in transit between the automated teller machines and the computers that process the transactions.

"PINs were supposed be sacrosanct - what this shows is that PINs aren't always encrypted like they're supposed to be," said Avivah Litan, a security analyst with the Gartner research firm. "The banks need much better fraud detection systems and much better authentication."

It's unclear how many Citibank customers were affected by the breach, which extended at least from October 2007 to March of this year and was first reported by technology news Web site Wired.com. The bank has nearly 5,700 Citibank-branded ATMs inside 7-Eleven Inc. stores throughout the US, but it doesn't own or operate any of them.

That responsibility falls on two companies: Houston-based Cardtronics Inc., which owns all the machines but only operates some, and Brookfield, Wis.-based Fiserv Inc., which operates the others.

A critical issue in the investigation is how the hackers infiltrated the system, a question that still hasn't been answered publicly.

All that's known is they broke into the ATM network through a server at a third-party processor, which means they probably didn't have to touch the ATMs at all to pull off the heist.

They could have gained administrative access to the machines - which means they had carte blanche to grab information - through a flaw in the network or by figuring out those computers' passwords. Or it's possible they installed a piece of malicious software on a banking server to capture unencrypted PINs as they passed through.

What that means for consumers is that their PINs were stolen from machines that showed no signs of tampering they could detect. In previous PIN thefts, thieves generally took steps that might draw notice - sending "phishing" e-mails, for example, or installing false-front keypads or even tiny cameras on ATMs.

   Previous page 1 2 Next Page  
主站蜘蛛池模板: 廊坊市| 华坪县| 麻栗坡县| 呼伦贝尔市| 上饶县| 高尔夫| 鄂伦春自治旗| 抚松县| 崇仁县| 密山市| 义乌市| 历史| 安徽省| 道真| 永川市| 开封市| 十堰市| 民勤县| 白城市| 阜阳市| 宿迁市| 桐柏县| 黑龙江省| 内丘县| 汕头市| 班戈县| 中超| 慈溪市| 德钦县| 汉阴县| 湖州市| 大理市| 延边| 大同市| 柳江县| 景德镇市| 鸡泽县| 哈尔滨市| 莎车县| 科技| 德阳市| 肇州县| 西昌市| 大理市| 亳州市| 锦屏县| 措勤县| 土默特右旗| 同江市| 棋牌| 托里县| 象州县| 汉寿县| 万宁市| 安岳县| 上蔡县| 土默特右旗| 临湘市| 漳浦县| 永登县| 金山区| 肇庆市| 福安市| 乃东县| 静乐县| 杨浦区| 敦化市| 临朐县| 安庆市| 满城县| 呼和浩特市| 克山县| 广元市| 辽宁省| 康乐县| 龙井市| 洛浦县| 四会市| 五华县| 城口县| 精河县| 安溪县|