March 22, 2009

I want to be a security futurologist; does anyone have a job to offer me?

In future there will be two different types of illiteracy: Those who are unable to read and those who are unable to use computers.

Do you agree? Well, nowadays the sentence is a cliché but imagine yourself spending your childhood hearing this exact sentence? No I wasn't raised by Arthur Luehrmann, I guess the issue is that my mom quickly realized that despite the modest adoption of computers in South America before the 90s, computing was the future and LOGO was the first step... (oh gosh, better change the subject).

Back in 2000 CFSEC Security Architects I've noticed the ascension of Windows based Automated Teller Machines and speculated about the creation of ATM specific worms would follow. My assumption was that although ATM are usually deployed on separated environments, criminals would be able to bypass segregation by collusion or by attacking fragile elements of the network, such as the communication facilities used by standalone Lobby Cash Dispensers. The idealized concept was a worm able to instruct De La Rue Talaris cash dispensers to "spit money" out of the ATM cash cassettes or dynamically reassign the cassettes denomination of the ATM system.

The first feature was clearly influence of the movies, while the second originated from a Brazilian student tale about an incident where an ATM started dispensing bills incorrectly, and customers formed a long queue to withdraw $20 and instead receive two $50 bills. The ATM was said to be located at the UFRJ's Computer Sciences building.

The concept led to a series of interesting off-record discussions with people from the banking industry but failed to go main stream until... Last week, when The Register reported about the discovery by Sophos of a malware targeting ATMs, another of my bizarre ideas came to reality.

Sadly enough the malware failed to achieve cinematographic status by relying on an effective but still boring strategy:

The malware just recorded the details of cards used on the ATM.

Blah... :-)

0 Comments:

Post a Comment

Links to this post:

Create a Link

<< Home