Educause Security Discussion mailing list archives

Re: POint of Sale Device


From: Clyde Valdez <clyde () BERKELEY EDU>
Date: Fri, 18 May 2007 17:20:51 -0700

A list of VISA approved PIN Entry Devices (PCI and pre-PCI) can be found
online at http://www.visa.com/pin.   The footnotes contain specific
information.  At last count there are 89 vendors, 305 devices on the list.

Visa PIN Security for Merchants
http://partnernetwork.visa.com/dv/pin/pdf/BP_US.pdf


-------- Original Message  --------
Subject: Re:[SECURITY] POint of Sale Device
From: Hull, Dave <dphull () KU EDU>
To: SECURITY () LISTSERV EDUCAUSE EDU
Date: Fri May 18 2007 14:33:15 GMT-0700 (Pacific Daylight Time)

I imagine you'll have to break out your oscilliscope and multimeter. I
suspect that these POS machines are subject to side-channel attacks in
the lab, but I'd guess it would difficult to pull something off in the
real world.

A quick glance through various documentation on these devices indicates
that they have 64K - 128K EPROMs, that is more than enough to store
thousands of credit card numbers. The EPROMs have battery backup so if
the CC data is stored locally, it could persist through a power outage.

I'm guessing that the Payment Card Industry has issued standards for
these devices and that document may layout what data can be stored for
later retrieval. I don't know if these devices have to comply with PCI
DSS.

Here's some possibly useful information:
http://www.merchantexpress.com/terminals.htm
http://www.cdeinc.com/remanufacturerepairs.html
http://www.dunfield.com/dave/readme.txt

There's an interesting blurb in this pdf:
http://www.greensheet.com/pdf/060401.pdf

"In this most recent compromise, most agree that fraudsters
copied card data, cardholder verification value
(CVV) and card value code (CVC), from magnetic stripes
at POS terminals."

I wonder how that worked exactly. I see that a person can purchase these
POS devices on eBay. A well funded attacker could probably manufacture
bogus devices that would pass collected data to the credit card
processor and an attacker.


Current thread: