+更多
专家名录
唐朱昌
唐朱昌
教授,博士生导师。复旦大学中国反洗钱研究中心首任主任,复旦大学俄...
严立新
严立新
复旦大学国际金融学院教授,中国反洗钱研究中心执行主任,陆家嘴金...
陈浩然
陈浩然
复旦大学法学院教授、博士生导师;复旦大学国际刑法研究中心主任。...
何 萍
何 萍
华东政法大学刑法学教授,复旦大学中国反洗钱研究中心特聘研究员,荷...
李小杰
李小杰
安永金融服务风险管理、咨询总监,曾任蚂蚁金服反洗钱总监,复旦大学...
周锦贤
周锦贤
周锦贤先生,香港人,广州暨南大学法律学士,复旦大学中国反洗钱研究中...
童文俊
童文俊
高级经济师,复旦大学金融学博士,复旦大学经济学博士后。现供职于中...
汤 俊
汤 俊
武汉中南财经政法大学信息安全学院教授。长期专注于反洗钱/反恐...
李 刚
李 刚
生辰:1977.7.26 籍贯:辽宁抚顺 民族:汉 党派:九三学社 职称:教授 研究...
祝亚雄
祝亚雄
祝亚雄,1974年生,浙江衢州人。浙江师范大学经济与管理学院副教授,博...
顾卿华
顾卿华
复旦大学中国反洗钱研究中心特聘研究员;现任安永管理咨询服务合伙...
张平
张平
工作履历:曾在国家审计署从事审计工作,是国家第一批政府审计师;曾在...
转发
上传时间: 2011-08-06      浏览次数:1343次
Square Mobile Credit Card Reader App Makes a Great Simple Money Launderer
关键字:money laundering

08.05.2011 at 5:19 pm

http://www.popsci.com/gadgets/article/2011-08/simple-hack-turns-mobile-credit-card-reader-money-launderer

 

A simple tool that can turn any iPhone into a credit card machine can also be a simple way for crooks to steal cash, hackers demonstrated this week. Square can eliminate the hassle of money laundering.

 

Instead of stealing credit card numbers, buying items and then selling those items for cash, Square can deposit money directly into a user’s account. Computer security experts from a firm called Aperture Labs described the process at the Black Hat security conference in Las Vegas.

 

Square enables mobile credit card payments by inserting a small dongle into the headphone jack of an iPhone or iPad. A user swipes the credit card’s magnetic stripe through a slit on the dongle, and credit card information is sent to the seller’s Square account.

 

Hacker Adam Laurie realized using the headphone jack meant the device was converting the magnetic strip information into sound waves that were interpreted by the app, according to a writeup by AFP. He realized he could trick the system into falsely reading audio data, so it would enter a transaction using a stolen credit card number.

 

He inserted a different wire into the iPad’s headphone jack, so the software thought a dongle was plugged in. Then he modified some software he had already written for translating magnetic stripe data (we mentioned he’s a hacker, right?) and then typed in a credit card number. The data was converted to sound, and the app read the information as if a real card had been swiped. Then he could deposit funds into his Square account, which are delivered within a day.

 

Laurie and co-hacker Zac Franken said they notified Square of the threat, but were told credit card traffic analysis would spot such malfeasance. Meanwhile, they have since learned the company is planning to release new dongles that encrypt data — which they currently do not. Looks like further motivation to keep your personal data secure.