Merchant services and credit card processing for any business size. Prompt, friendly and professional service.
MerchantConnect Login

Tuesday, July 3, 2007



Pin Pad Found Vulnerable to Skimming Attacks


Visa has recently been alerted to another point-of-sale (POS) PIN entry device that is vulnerable to skimming attacks in the US. This most recent compromise involves the eN-Crypt 2400, also known as the C2000 Protégé, manufactured from 1992 to 2002 by Ingenico, Inc.
This POS PED was compromised with tapping mechanisms installed to capture PIN and card data. While the situation is being addressed at the merchant location, Acquirers, merchants and processors are advised to be aware of the circumstances of the attack in case other merchants become affected.
As the criminal sector becomes more familiar with the older implementations of PIN Entry Devices, Acquirers must ensure that merchants have upgraded their POS devices or replaced them with more advanced products that incorporate current security features set out for the transaction industry.
There are two variations of the skimming attack, both of which allow the capture and disclosure of card account data and PINs:

  • Knowledgeable individuals, representing themselves as service technicians at the merchant location, modify active PEDs by inserting tapping devices to capture PINs without removing the PEDs from service. Security weaknesses of these PEDs allow the perpetrators to modify the devices without causing noticeable physical damage, or tamper evidence, to the PED and without disabling the PED by “zeroizing” the cryptographic keys, or tamper response.
  • Criminals us a technique involving two PEDs. They take an active PED and remove the internal operating circuitry from the casing without triggering any tamper response. They then attach a tapping device to the PED circuitry, discard the damaged casing, place the internal circuitry with the tapping device into a new casing, and place the PED back into service. Security weaknesses of these PEDs allow the perpetrators to access and then modify the devices without “zeroizing” the cryptographic keys and disabling the PED.
  • VULNERABLE POS PIN ENTRY DEVICES
    In addition to the Ingenico eN-Crypt 2400/C2000 Protégé device, merchants should not deploy any of the following POS PEDs, which are also known to be vulnerable to compromise:

  • Verifone PIN pad 101 and 201
  • Verifone PIN pad 2000
  • Hypercom S7S and S8

Pin Pads approved are:


  • Verifone PIN pad 1000SE - Triple DES encrypted

  • Hypercom S9 - Triple DES encrypted

The Visa PIN Security Tools and Best Practices for Merchants brochure, is available online at www.visa.com/pin or for information regarding Merchant Services and upgrading a PIN Pad, contact NTC Texas at 877-877-6511.


Labels:

0 Comments:

Post a Comment



<< Home


 

 

Merchant services include FREE Statement AnalysisFREE
Credit Card Processing Statement
Analysis


Send us a copy of
your most recent credit card processing
statement and we will
perform a FREE rate analysis to show how you WILL save money with NTC Texas. Fax your recent credit card processing statement to 972-406-8611, Attn: Finance. Within 24 hours, we will have your comparison ready for review.

Show/Hide Navigation

Merchant Services for...

Retail
Hospitals/Clinics
Physicians
Veterinarians
Dentists
Endodontists
Opticians and Optometrists
Web Developers
Entertainment: restaurants, theater & amusements
Travel: lodging & hospitality
Not-for-profit: education,
associations & churches
Business-to-Business:
manufacturers, wholesalers
& suppliers
Recurring Payments: insurance, health club & subscription
Professional Services for Cities, Towns, Libraries and Utility Companies

NTC Texas makes it easy for you to switch merchant service provider

Already Have a Merchant
Services Provider?

Changing is Easy...

...with zero downtime and zero hassle. And if you have sufficient transaction volume, NTC Texas will cover your
cancellation fee when you switch your credit card processing to us.
Call Toll Free: #877-877-6511
or Email Us.


Questions to Ask Your
Merchant Service Provider

A low quoted “rate” can be hiding a high credit card processing cost. Click for Questions.

 


NTC Texas

12300 Ford Road, Suite 150
Dallas, Texas 75234
Toll Free: 877-877-6511
Phone: 972-406-8111
Fax: 972-406-8611
Info@NTC Texas.com
For Technical Assistance: 877-877-6511

Home | About NTC Texas | Services | Terminals | Software | Business Resources | Contact | MerchantConnect Login | Site Map | Resources