Mon Nov 20, 2006 5:50PM EST
See Comments (53)
Everyone laughed when the movie Firewall had the crook using an iPod to store bank secrets, but—ha ha ha—it turns out life is imitating art.
This story from the United Kingdom reveals how the scam worked: The crook would attach an MP3 player with recording capabilities to the phone line coming out of the ATM. (The ATMs in question were the freestanding ones like the type you see in convenience stores, not the ones built into walls.) By recording the tones the ATM transmitted to the bank, the crooks could later retrieve the recorder, translate the tones into digits, and reconstruct credit card numbers and expiration dates, which could then easily be turned into phony cards.
Maxwell Parsons managed to abscond with tens of thousands of dollars worth of purchases this way. Meanwhile, banks are careful to note that they have corrected the flaws that made this kind of exploit possible. (The story also notes that this scam nearly ruined the banking system in Malaysia, where it seems to have been pioneered.)
Still, there's a lesson here for the overly cautious: ATM scams are legendary (check out this example of how sophisticated they can be), but stand-alone ATMs are more vulnerable to attack because their connectivity cables are often exposed. If you're the paranoid type, stick with in-wall ATMs, especially if they're located indoors.
Join in the discussion. Here you'll see the comments in the order they were posted.
yeah thanks for the info. now it will happen since the details are in the open. hahah
Bubbles Poptart Monkey Cloud
Thanks for this info
The banks obviously don't care about identity theft, otherwise they'd encrypt the information before it hits the phone line.
Is incredible how the things out there are getting worst. This news, shocked me... But, now I know how to prevent situation with this priceless info. Thanks a lot !!
All this time I thought IPOD's were for playing music.
I like how under the comment board it shows MP3's for sale!
Why do you give the criminals all the information to try this, I don't use a ATM unless it is my banks.
Hahaha....the story above is about how mp3 players can be used to record pin numbers etc. how ironic that the advert just slightly below is talking about selling MP3 players...lol
Yes im shocked but we shouldnt take ipods out of stores. Cause ipods can be used for good to like to listen to music and play games and watch movies. I have one and im not giving it up. I won't do all the bad stuff that some of the crooks would. But just because some people done this doesn't mean we will. So theres no reason to punish the good peoplefor what the bad has done.
I wonder if you can download tunes to your Pod while you're doing the ATM hack? I like to multitask.
If crime didn't pay - there would not be so many people involved in it.
wow awsome.... To make it record simply use a Linux port for the ipod... very easy install.... that you can create a tone box and use the line from the atm... They should have been using random digits or going over a network not through a phone line..They deserve this hack.
wow that's amazing i didn't think you could do that from an ipod..
To those scolding Yahoo news for posting how the scam is perpetrated: have actually read the story? "...Meanwhile, banks are careful to note that they have corrected the flaws that made this kind of exploit possible."
I think that is so stupid........ the ATM is supposed to have cameras attached to it and also the bank has cameras, even if it only took these people a split second to attach this stuff, with the cameras in place it shouldn't have taken the security people that long to unattach it. What are the cameras in place for...
Nice idea, but ipods and most other MP3 "PLAYERS" don't record, they do act like drives and can be written to, but audio recording they do not do.
The article explains how the PIN was discovered but not how the account number was stolen. The PIN without the account is useless.
The article explains how the PIN was discovered but not how the account number was stolen. The PIN without the account is useless.
Please enable your browser's cookies to activate the My Tech column.
| Computers | Home Office | Wi-Fi & Networking | Phones & PDAs | Cameras & Camcorders | TV & Home Theater | Portable Audio |
|---|---|---|---|---|---|---|
6 Posted by wenow49 on Thu Sep 3, 2009 10:43PM EDT Report Abuse
Always believe that if it seems impossible it has probably already been done!