1 post • joined 5 Jun 2009
@Cameron, Fraser, et al.
Bank main-frames which are responsible for the validation of your PIN use tamper-proof hardware security modules (HSMs) such as the IBM 4758 (http://www-03.ibm.com/security/cryptocards/pcicc/overproduct.shtml) and the keypad on any half-decent ATM will be part of a similar device. Furthermore, the network interconnects between an ATM and the bank's mainframe contain similar devices.
Their aim is to ensure that your PIN number, etc cannot be discovered *even if the host machine is infested with malware*. However, this does not prevent the mag-stripe data from being copied since that info is not considered sensitive. It would therefore seem that the goal of this scam is to clone the mag-stripe of cards and use them in "card not present" frauds.
- Pic Mars rover 2020: Oxygen generation and 6 more amazing experiments
- Microsoft's Euro cloud darkens: US FEDS can dig into foreign servers
- Boffins spot weirder quantum capers as neutrons take the high road, spin takes the low
- Plug and PREY: Hackers reprogram USB drives to silently infect PCs
- Review Fiat Panda Cross: 'Interesting-looking' Multipla spawn hits UK