. Space Industry and Business News .




.
CYBER WARS
Hack turns Square into criminal tool
by Staff Writers
Las Vegas (AFP) Aug 4, 2011

Hackers showed Thursday how to turn mobile payment service Square into a convenient tool for criminals to pump cash from stolen credit card numbers.

Adam Laurie and Zac Franken of computer security firm Aperture Labs used a homemade software program and an easily bought iPad audio wire to trick Square in a way that could be a bonanza for crooks.

Laurie could type credit card numbers into his laptop, which converts to sound data sent to Square, where the transaction registers as if a real card were swiped in a dongle.

"Traditionally, the way you make money from stolen credit cards is sell the data to someone else or buy goods on it, then resell the goods and get the cash," Laurie said while demonstrating the hack at a Black Hat computer security gathering in Las Vegas.

"This really takes the hassle out of it... I can put the money right in the account and it only costs me 2.75 percent."

The percentage he cited was the fee charged by Square, which was co-founded by Jack Dorsey, a Silicon Valley star who helped create popular micro-blogging service Twitter.

Square markets a pocket-sized credit card reader that can be plugged into a smartphone to allow anyone to accept credit or debit card payments on the spot.

Franken and Laurie, whose hacker name is "Major Malfunction," said that they were waiting for a flight at an airport when then figured out how to convert Square into a handy tool for cashing in on stolen credit cards.

Laurie realized that the Square "dongle" used to swipe credit cards plugged into an iPad audio jack, indicating that the small device essentially converted magnetic stripe data to sound then interpreted by the service's software.

He quickly modified software he wrote five years earlier for reading and replicating magnetic stripe data.

Franken and Laurie strolled to an airport shop and bought a wire to plug his laptop into the iPad jack where the dongle would have gone.

"Credit card data is getting skimmed all the time," Laurie said, holding up a pre-paid credit card he used for the demonstration. "Instead of buying this I could have bought it on the Internet from a criminal gang."

Funds are dumped into an individual's Square account to be removed before anyone catches on, according to the hackers.

"You'd have to set up dodgy accounts that don't trace back to you," Laurie said. "But, that is standard practice."

Laurie and Franken said that they shared their findings with Square in February only to be told that it wasn't seen as a threat and that traffic analysis would expose those kinds of transactions.

The hackers had also heard unconfirmed reports that Square planned to release new dongles that encrypt transaction data.

"Encryption would be a good thing," Franken said. "The way it is at the moment a cable between two devices and you can inject credit card numbers right into the system," he continued.

Since Square promises to have money from transactions in accounts within a day, money milked from stolen credit card data could be made off with quickly provided amounts were extreme enough to be noticed, Franken said.




Related Links
Cyberwar - Internet Security News - Systems and Policy Issues

.
Get Our Free Newsletters Via Email
...
Buy Advertising Editorial Enquiries








. Comment on this article via your Facebook, Yahoo, AOL, Hotmail login.

Share this article via these popular social media networks
del.icio.usdel.icio.us DiggDigg RedditReddit GoogleGoogle



CYBER WARS
China says cyber hacking claims 'irresponsible'
Beijing (AFP) Aug 5, 2011
Chinese state media on Friday condemned as "irresponsible" suggestions the country was behind a massive global cyber spying campaign uncovered this week by a US computer security firm. California-based McAfee described the sophisticated hacking effort as a "five-year targeted operation by one specific actor", without naming a country, but analysts and reports said China was the likely culpri ... read more


CYBER WARS
Japanese parents live with radiation fear

Editions, AOL's entrant in iPad news reader race

Watermark ink device identifies unknown liquids instantly

Time Inc. to put full magazine portfolio on tablets

CYBER WARS
Raytheon Develops Miniature Antenna To Extend Millimeter Wave Friendly ID Technology

China launches another experimental satellite

USAF Approves Production of NGC Deployable Digital Wireless System for Remote Warfighters

Raytheon BBN Technologies Awarded DoD Contract to Develop a Secure, Attributed Military Network System

CYBER WARS
Ariane 5 ready for next heavy-lift flight

Inmarsat Selects ILS Proton For Inmarsat-5

United Launch Alliance Saves Money with First Combined Atlas and Delta Shipments on Mariner

Russia sends observation satellite into space

CYBER WARS
S. Korea to fine Apple over tracking feature

Toucans wearing GPS backpacks help Smithsonian scientists study seed dispersal

China launches navigation satellite: Xinhua

China to launch 9th orbiter for indigenous global navigation network

CYBER WARS
Making airport runways safer

Boeing Delivers Milestone 737 with High-Altitude And High-Temperature Operation Features

Southampton engineers fly first printed aircraft

Rolls-Royce flies into profit

CYBER WARS
Designing diamond circuits for extreme environments

Breakthrough in photonic chip research paves way for ultrafast information sharing

'Bendable' computer developed in Canada

Warmed-up organic memory transistor has larger memory capacity

CYBER WARS
NASA Satellite Tracks Severity of African Drought

Tropical Storm Muifa appears huge on NASA infrared imagery

NASA AIRS Movies Show Evolution of US 2011 Heat Wave

Using Satellites for Human and Environmental Security Needs

CYBER WARS
Pollutants found at US base in S.Korea: officials

Toxicologists Find Weathered Crude Oil Less Toxic to Bird Eggs

New study finds cancer-causing mineral in US road gravel

Environmental Pollutants Lurk Long After They "Disappear"


Memory Foam Mattress Review
Newsletters :: SpaceDaily Express :: SpaceWar Express :: TerraDaily Express :: Energy Daily
XML Feeds :: Space News :: Earth News :: War News :: Solar Energy News
.

The content herein, unless otherwise known to be public domain, are Copyright 1995-2011 - Space Media Network. AFP and UPI Wire Stories are copyright Agence France-Presse and United Press International. ESA Portal Reports are copyright European Space Agency. All NASA sourced material is public domain. Additional copyrights may apply in whole or part to other bona fide parties. Advertising does not imply endorsement,agreement or approval of any opinions, statements or information provided by Space Media Network on any Web page published or hosted by Space Media Network. Privacy Statement