Criminals Use 3D-Printed Skimming Devices On Sydney ATMs 110
AlbanX writes "A gang of suspected Romanian criminals is using 3D printers and computer-aided design (CAD) to manufacture 'sophisticated' ATM skimming devices to fleece Sydney residents. One Romanian national has been charged by NSW Police. The state police found one gang that had allegedly targeted 15 ATMs across metropolitan Sydney, affecting tens of thousands of people and nabbing around $100,000."
Re:ah my countrymen... (Score:5, Funny)
Many criminals are hard working too.
Re: (Score:2)
Re: (Score:3, Interesting)
Nonexistent when compared to Wall Street extortion and foreclosure fraud.
$100,000 PFFT!
Re: (Score:2)
"Hard working" is the opposite of capitalism's philosophy by design.
"Law abiding" is just a risk minimisation strategy.
I know Romania's been dragged from the horror of despotism into the quagmire of neoconservatism, but really, patriotism's never the way forward, nor is pandering to the propaganda of the Protestant work ethic. These guys are just dicks who are taking advantage of the guy on the street.
Re: (Score:1)
hmmmmm (Score:1)
Re: (Score:3)
Re: (Score:3, Informative)
People should not lose any money when their cards get skimmed... However, when you find out, and contact your bank, they will immediately block your card, meaning that your access to cash is a little more difficult. Also, it may take several days until you get your money back. It's not the end of the world, but it surely is inconvenient. And therefore, people are affected too.
Totally the fault of the USA (Score:5, Informative)
It's about time that US banks caught up with the rest of the world and put chips on all their cards, then we can finally get rid of the magstripes.
While chip&pin has it's security flaws it's way better than the 20 year old magnetic stripe system, in Australia and most of Europe the only reason they still put the stripes on cards is because the cards have to work when people travel to the US.
It's been at least a year since I've seen a reader without chip support in Australia and the only time the magstrip is used is when the chip or contactless read fails.
Maybe its a blessing for the consumer (Score:5, Interesting)
As you have pointed out, European 'Chip-and-PIN' Cash-Card Security have already been cracked by criminals [technewsdaily.com].
And fair enough, generally cards with chips are still more secure than their magnetic counterparts.
What I am more disturbed about is, from the point of the consumer, it appears that in Europe at least the supposed security of the chip and pin system have been (ab)used by banks to deny refunds to their defrauded clients.
From the POV of the consumer, I would not favor the use of this newer, more secure system if it shifts the burden of fraud on me with the excuse that "it's unhackable, you must have given them your PIN".
Re: (Score:3)
I actually just realised that I do have a non-chip card; my American Express. Apparently my particular bank has chosen not to migrate those to chip cards yet, although Amex have done so on their directly issued ones.
Of course since it's "American" Express i'm going to stand by my "it's America's fault" title.
Re: (Score:2)
the copier is a bit harder to do for chips than for the magstripes. that is the point.
for the record, I haven't heard of any actual working attacks on the chip/pin method, while the magnetic strip needs actually just the magnetic strip copied(having the pin just makes it easier to find a place to get the cash).
and on to the story: 3d printed skimmers are not a new thing! they've been used before. it largely doesn't matter at all how the skimmer is made.
Re: (Score:2, Informative)
Firstly yes, there are working attacks. We know that the following attacks have been done by actual criminals, real bad guys, who obtained money or goods through fraud with the attack, some of whom are now in jail for it:
- "YES cards". Fake chip clone cards which are programmed to tell the terminal that the PIN matched, then hand back a data block for the bank which says no PIN was used because the terminal authorised a signature instead. The bank gets the data data, says "Huh, you authorised on a signature
Re: (Score:2)
Here is an idea of how to make a chip-and-pin type technology that is secure:
1.When the user inserts their chip enabled card into the card reader, the chip tells the reader to ask for the users PIN (under this system there would be no such thing as a chip-and-sign card, all cards would require the user to enter their PIN if the reader supports the technology)
2.The card reader provides the merchant account number, payment amount and entered PIN to the chip on the card.
3.The chip combines the merchant account
Re: (Score:2)
Don't worry, in the US the banks don't get the blame either, they shifted the blame to the shop owners.
Re: (Score:2)
The thing is fraud is just not making a dent in their finances to bother. Even with mag stripe the PIN is checked in real time with your bank for any non-trivial transaction, you could have any type of one-time-pass device for ATM transactions (or for purchases over let's say $100 or similar): paper, SMS, token, smartphone offline app, etc. You could have two cards, one without mag stripe. But no, that's just not possible. Even getting one card but without the mag stripe is not possible. I've been thinking
Re: (Score:2)
The thing is fraud is just not making a dent in their finances to bother.
Of course, those frauds (only called "Identity Theft" in the US) make dents only in their customers' finances, not the banks' own finances, why should the banks in the US bother?
Re: (Score:1)
Re: (Score:2)
This would be a nice idea, if I manage to do it cleanly. (I still want to pay with the card at the stores, in fact I'll be using the card that way mostly).
I wouldn't be able to do it cleanly probably but I'm sure it is possible.
Re: (Score:2)
Re: (Score:2)
Re: (Score:2)
I don't think that is entirely true. The magnetic strip in my PIN card failed and it stopped working on other bank's ATMs. It continues to work fine with my bank's ATMs and in chip readers at retailers... But thanks for reminding me that I have to replace it before I go to the US : )
Re: (Score:2)
It's about time that US banks caught up with the rest of the world and put chips on all their cards, then we can finally get rid of the magstripes.
While chip&pin has it's security flaws it's way better than the 20 year old magnetic stripe system, in Australia and most of Europe the only reason they still put the stripes on cards is because the cards have to work when people travel to the US.
It's been at least a year since I've seen a reader without chip support in Australia and the only time the magstrip is used is when the chip or contactless read fails.
Part of the fault lies with your country's stores, or bank, or both. My credit card has chip and magstrip, at one time when a newb cashier tried to swipe the card through the magstrip reader (instead of correcting inserting the chip end to another slot to use the chip), the machine told her to use the chip instead, i.e. it refused to accept data from the magstrip for a card with chip.
The only people at risk with a fake card with copied magstrip are people with cards that have no chip, i.e. America tourists
Re: (Score:2)
Re: (Score:1)
In the Netherlands, most banks have disabled ATM transfers from outside the European union by default. Customers have to enable access before going outside EU by using their online bank account. This has reduced skimming with 80% (http://www.rtlnieuws.nl/nieuws/binnenland/skimmen-met-80-procent-gedaald (sorry, Dutch only)).
ATM security (Score:2, Offtopic)
Sometimes it's funny how ATMs I see outside of my country (Spain) don't seem to have the security systems that they were forced to use here for problems like the one described in the article.
I also find foreign paper currency to be unsafe, ID documents too easy to forge and store security to be amazingly weak.
Sometimes I wish I lived in one of those countries where all that security isn't needed.
Re: (Score:2)
Sometimes I wish I lived in one of those countries where all that security isn't needed.
It's needed everywhere, it's just some are in greater denial about it.
Why not a Lathe, Drill Press, or Grinder? (Score:5, Insightful)
I read stories like this that try to diss the use of "3D Printers" as if somehow banning the use of those devices is somehow going to stop criminals from engaging in acts like this. What utter nonsense.
How many other stories about ATM skimmers emphasized any of the tools used to make the devices used to make their devices? Why such a strong emphasis on the 3D printing technology? It sounds like a cool buzz word, but means absolutely nothing other than an attempt to make something new sound frightening because the reporters and police officers involved don't have a clue about how the technology works.... therefore it must be some kind of dark magic that must be brought before the Inquisition and those involved banished to Hell (or some equivalent).
While I don't mind seeing stories like this on Slashdot as it does talk about emerging technologies and their impact upon society as a whole, it still turns my stomach to see such awful reporting overemphasizing the manufacturing technology (it was the lead paragraph) instead of describing what people were doing first. Had the technology being used been mentioned much further into the article, I think it would have been much more appropriate.
Re: (Score:2)
Re: (Score:2)
Then why has no one made a wooden gun or ATM skimmer?
Hint: it's because you're full of shit.
There used to be guns made out of cheap plastic with wooden parts that were sold in toy stores that used to be able to take real bullets and were deadly to potential targets. They had the side effect of sometimes jamming up, being incredibly unreliable, and sometimes blowing up in the hand of the guy firing the gun (aka something not really recommended except when you are extremely desperate), but it was done.
The point is that a wooden gun has been made that could even use gunpowder if you wanted. The ste
Re: (Score:3)
Once you've got that shape though you still have a lot of work to make it look real. A good 3d printer is too expensive for this stuff so they're going to use cheap printers that make things that look awful until you sand them down and paint them. Whereas once you have a silicone mold you can make a lot of copies much more quickly.
And 3D printers are not about democratization, they're being used mostly in companies to reduce costs of making prototypes or making one-off components. Whereas most individua
Re:Why not a Lathe, Drill Press, or Grinder? (Score:5, Insightful)
Yep, same old scare tactics...
"If you electrify homes you will make women and children and vulnerable. Predators will be able to tell if they are home because the light will be on, and you will be able to see them. So electricity is going to make women vulnerable. Oh and children will be visible too and it will be predators, who seem to be lurking everywhere, who will attack."
“Women’s bodies were not designed to go at 50 miles an hour. Our uteruses would fly out of our bodies as they were accelerated to that speed [on trains].”
Automobiles, Telegraphs, Telephones, Recorded Music, Radio, TV, MTV, Video Games, Internet, Cellphones, 3D printers, RFID, NFC, etc... Near any new technology you'll find unfounded fear drummed up around it. There is a primal fear of unknown that the unscrupulous exploit for popularity. Not even old technology is safe from the fear mongering media mavens: "After this break from our sponsors: Find out what's probably lurking under your sink that could kill you."
When faced with what they do not understand the primitive minded are easily frightened, the futurists eagerly excited, and the practical remain predictably skeptical.
It's sad really. Your "greatest" thinkers in science and philosophy alike shun their feelings. Those primal communications your ancestors scream wordlessly within your mind are ridiculously ignored, at great risk. This valuable primitive mode of thought was proved by evolution to be rational in general, yet is deemed "irrational". In so doing they discourage people from thinking with their whole minds, and thus they become more susceptible targets to the biases of the ancient ones.
So, while one ignorant group is too strongly swayed by their emotions, the other group ignores their instincts completely in the name of rationality and is thus just as ignorant, literally. Don't you see that reasoning with only half a head is dangerous?! I cultivate my "irrational" feelings, I use them as a faster but less accurate logic unit. I let my subconscious quickly analyze situations and then converse with my wise but unlearned ancient ancestors about the dangers and desires we have. When reasoning with others I reach back through the millennnia and consider the subtexts as they would appear to language-less apes. I'm thus able to more effectively communicate my meanings at multiple levels.
Do not so quickly discount the power of a message that wields both logical and primitive persuasions. This is a skill infamously used to sway weak minds by politicians and the media for centuries. This is a technique best learned sooner than later at the point of a pitchfork. While "insightful" folks like you scoff at the story and think them fools for pandering to the populous' fear in the name of greed, I credit them for doing so. If you want to scoff, then scoff at those so-called "great" rational minds who can not do the very same in the name of good... disgusting.
To shrug off the subtext and not heed and hone the subconscious murmurs of your mind is to foolishly disrespect every single elder your lineage has ever had.
And you call yourselves evolved?! You're barely even aware. Humans, ugh, how primitive!
Re: (Score:2)
However, there is still the question: is technology really improving our lives?
You might want to read this:
There is, though, one group of Americans that is imperturbably sunny: the Amish. Their depression rates are negligibly low relative to the rest of societys. Their happiness levels are consistently high. The Pennsylvania Amish, when asked how much they agree with the statement: You are satisfied with your life (using a scale of 1 to 10), turn out to be as happy as the members of the Forbes 400. The Amish, though, do without most of what we think of as modern technology. They don’t rely on the automobile, don’t need the Internet, and seem to prefer stability and permanence to the heady growth that propels innovation and the U.S. economy. The comparison is a little facile (the Amish have a lot of other characteristics that make people cheerful, including strong community ties, stable families, and religious faith). But it suggests an interesting question: is it possible that technology, instead of liberating us, is holding us back? Is technological progress merely a treadmill, and if so, would we be happier if we stepped off of it?
Taken from: http://www.technologyreview.com/review/403558/technology-and-happiness/ [technologyreview.com]
Re: (Score:3)
Well, there's a postcard version of the Amish in their button-free clothes, hand-making all their stuff and living bucolic lives.
And then there's the real world version of the Amish, where young people smoke, drink, and drive cars before they become full members of the church, the internecine religious conflicts involving sects, beard cutting, etc.
I'm pretty sure that despite the awesome appearance of tech-free Amish life, there's a lot of psychological stress maintaining such an existence in the face of th
Re: (Score:2)
Re: (Score:2)
3D printers have many legitimate uses, but like all technological advances they will also advance the capabilities of criminals. It just so happens that with zero skill any criminal can produce high quality work, this is unprecedented and is the fundamental reason why 3d printing related crimes are reported as such.
When was the last time an article about a technicology-related criminal act mentioned the soldering technology that made it all possible? Or the electrical engineering controversy? Or the dangerous side of progamming languages?
The point is that 3D printing is a tool. Thats it. It's a way to create a thing in the same way a lathe does. You dont hear about how it might be possible for a thug to lathe his own bat that he will obviously use to pummel someone, so we should be afraid of lathes. There arent wee
Re: (Score:2)
- Internet - see TV, gives people false sense of community
The only True Sense of Community is what I say it is.
Re: (Score:2)
Re: (Score:1)
3d printing and the copyrights of physical items are going to be the next 'war on piracy' type thing.
"You wouldn't pirate your neighbors BMW would you?" That sort of thing. Because soon you will be able to pirate your neighbors plastic trinkets at least to start with...
So we have to start NOW to drum up grass roots hatred for 3d printers and those evil design pirate criminal scum.
Expect these negative type storys that throw 3d printing under the bus to continue for decades. We must stop those evil cr
Re: (Score:2)
As if it really took much in the way of even tools to make stuff like they are describing. A trip to Home Depot or Lowe's will get you a pretty wide variety of things including base building materials, buttons, switches, and the ability to simply get kits to build a great many items.... including items that could be used for "illegal purposes" if you had a clue.
Of course you can even buy these tools at these stores together with taking classes on how to use them and books for sale that can teach you most o
Even more interesting... (Score:4, Interesting)
That they used 3D printing device, is hardly interesting news. That’s just more 3D printing hype. What I find fascinating with this story, is that card skimming at ATM still works, today, in 2013.
It’s clearly a failure to implement the most basic security and authentication features, which are widely available today. How can it be that, today, one can still do any kind of transaction with only a card number and a pin – if a pin is needed at all (eg. For online transactions).
They (the banks and/or credit card companies) try a lot of fancy things like nice holograms on ATM machines or abstruse authentication methods that fail to understand that a simple password is about as safe as the card number itself. This PIN skimming thing is the proof of that.
It’s slowly getting better, with unique number generators for validation or unique numbers sent through SMS. But I hardly believe these solutions are optimal for the users. Perhaps this explains why their implementation is so amazing slow – although I believe it still better to have those as none at all.
Re: (Score:2, Interesting)
Since we have a chip capable of basic crypto operations why are we not simply using a 1-time pad stored on the chip itself to sign the transaction data, just sign the transaction and add on the CardID+SeqNum then you just have to store 10kb of true random on the card to use as the pad (or whatever amount of transaction attempts you expect the card to use during it's validity window). Just kill the card when it exhausts it's one-time pad.
This system of challenge-response would even allow you to online shop w
Re: (Score:2)
Re: (Score:2)
Re: (Score:2)
Many cards have chips. I have yet to see a card reader in actual use that reads anything but the stripe, though....
I suspect this has something to do with the way the equipment is billed - less secure, stripe-only device must be cheaper for business to "rent", for some reason.
Anyway, for a CC user, who cares - don't pay charges that you didn't make. Let the banks take the risk and realize they need better equipement. It's not like a debit card where you have to beg the bank to give you your money back for
Re: (Score:2)
I dont know which country you are from but here in Australia most of the payment machines in stores read chips. Never seen an ATM that reads chips though.
Re: (Score:2)
Country is USA. The attitude seems to be, if it takes even a second more or costs even a dollar more, we don't want it. It's like we've all decided we're too busy to be smart or careful about things.
And I'm talking about the customers, not just the banks. The banks sometimes put in the security features, but they don't stick with any one system for long enough for the infrastructure to roll out anywhere...
I had a credit card with a chip in it in 1999, I think, but the only place that would use the chip w
Re: (Score:2)
Does the number show up on the reader, or on the card itself? If it's the reader, you're still not protected from skimming....
Re: (Score:2)
Re: (Score:2)
Re: (Score:2)
These aren't used to skim the PINs usually, they're used to get the card number, while a camera or someone with binoculars will pick up the PIN. This scheme would work with some types of chip and pin as well, as it's easy to be a man-in-the-middle attack if you can monitor the signals.
Another scam is to make note of someone's PIN from a distance at a gasoline station, then walk to the attendant a few minutes later and claim that you forgot to get a receipt and ask for it. A lot of places will still includ
Chasing after amoebas (Score:1)
in an elephant's world.
Re: (Score:3)
There's a lot of much simpler security measures that work a lot more effectively. Every time you hear someone come up with elaborate digital security, you have to go back to thinking of basics. Security is simple, and overthinking it is the best way to make it even worse.
Put ATM's in secure places. In the UK, they are almost always just out on the street where anyone can shoulder-surf your PIN. Like in Europe/US put them inside a room that is controlled and monitored.
Make ATM's show you what they should
Re: (Score:2)
Blah blah blah...
Store a private key on the card so that it cannot be read from the outside without physically damaging the card. Use the card to cryptographically sign transactions after you enter the correct PIN. Problem solved.
The only problem that remains are rogue payment terminals and ATMs which use your own card to overcharge your account. But if you keep track of where you've used your card and when, you have everything the police needs to know and they can either catch the culprit or at least disable the rogue devi
Re: (Score:2)
Re: (Score:2)
It has been broken with non-rogue terminals. You can take legal terminals and modify them.
Re: (Score:2)
Re: (Score:2)
Once someone else knows your PIN then what happens when you've lost the card? At least with cash you only lose the amount of cash you're carrying on your purpose. With a chip and pin system you may lose a huge amount of money from your account. This is probably why most banks limit the amount of cash you can withdraw in a day.
SMS is pointless if you don't use SMS or have it explicitly disabled (I refuse to pay for it as it is an additional expense and I have to pay even if I receive SMS from complete str
Re: (Score:2)
How long will it take for someone to suggest giving everyone an account linked to their biometric info, and just eliminate cash outright?
NSA/CIA/FBI shill detected.
Given their recent shenanigans, the cashless society has probably been pushed back at least one generation.
OMG! (Score:1)
Newsflash
Criminals use 2D printers to create 'sophisticated' forged documents. Ban evil 2D printers!!!
Criminals Use Press and Lathe Too! (Score:1)
WTFC's? Criminals have used lathes, presses, drills, hammers, laptops, PC's, all sorts of tools in the past! So, they use another tool, in this case the dastardly 3D Printer! OOOHH! Who really cares???
Some authors at /. absolutely cream themselves at the mere mention of a 3D Printer. Get over it already. They've been around awhile. Why the recent interest? Yeah, what I thought, a corporate sales scheme has infiltrated /. once again.
3D Printer! 3D Printer! 3D Printer! 3D Printer! 3D Printer! The
A picture is worth a thousand words. (Score:2)
ATMs ought to display a picture of what they are 'supposed' to look like. Might help fight the assholes with the skimmers.
Wide format printers are getting high tech (Score:1)
Comment removed (Score:5, Informative)
Re: (Score:3)
Re: (Score:2)
We don't have beggars, we already pay them collectively to stay inside and watch tv or drink themselves to dead.
And this is where you fail, because you do not understand that we all live on the same planet. As long as you take care of your citizens and say fuck you to the rest of the world, this will keep happening. If you're so wonderful, why not help your neighbors improve? Otherwise some turtle beneath you will move eventually and you will end up in the mud.
Re: (Score:1)
Education is free in Romania. If the gypsies don't want to change, they will not change. Keeping your younglings in school it's a parent's basic duty. But nobody can enforce that to them. I think that, eventualy, Europe will get used to them. As far as I'm concerned, I don't think they will ever change their stupid ways. Tradition needs to be rethinked when it starts to brake the law. At least the law can be enforced. Crime has no ethnicity.
Re: (Score:2)
If the gypsies don't want to change, they will not change.
Prejudice is ugly no matter who tries it on.
Re: (Score:3)
Romainians are NOT Gypsies. The Roma people are the peoples called Gypsies who originated from India.
Re: (Score:2)
Re: (Score:3)
Wait, the point I was trying to make is that not all Romanians are Gypsies otherwise known as Roma people, a subgroup of the Romani people. I never claimed anything. I merely pointed out Gypsies are Roma peoples. Maybe I needed to spell that out better.
In many parts of the world it is often mistaken that Roma = Romanians, meaning all Romanians are mistaken for Gypsies.
Re: (Score:1)
So, you draw conclusions about an entire nation after analyzing a sample of one? Who's the racist here?