[email protected] (Anne & Lynn Wheeler) writes: > however, by at least the early 90s, there were cases of compromised > end-points recording valid information (done during the process of valid > transactions). these operations tended to be more large scale wholesale > operations ... getting information for tens of thousand (or millions) > ... rather than a few tens.
re: http://www.garlic.com/~lynn/2010.html#97 Korean bank Moves back to Mainframes (...no, not back) skimming news item from today: ATM Skimming Incidents Increase http://www.bankinfosecurity.com/articles.php?art_id=2059 frequently these are external attachments specifically targeting magstripe ... however, there have been lots of cases where collecting technology has been installed inside the end-point (pos terminal or atm cash machine). cases have included modification of machines already installed, replacing machine with modified machine, installing modification at time of manufacturer ... or even criminal front organization manufactuering machines and selling them on open market (or on gray market ... copy of some other vendors machine). criminal front manufactuers have even sold such machines "at cost" (undercutting competition) because they are planning on making up the profit with fraudulent transactions. -- 40+yrs virtualization experience (since Jan68), online at home since Mar1970 ---------------------------------------------------------------------- For IBM-MAIN subscribe / signoff / archive access instructions, send email to [email protected] with the message: GET IBM-MAIN INFO Search the archives at http://bama.ua.edu/archives/ibm-main.html

