Rice University logo
 
Top blue bar image
A graduate seminar: current topics in computer security
 

Where should I get my cash?

I remember when I travel abroad to Taiwan, credit card wasn’t as prevalent as it is here in the States especially outside of the metropolitan area like Taipei; thus I always need to get cash from some sketchy ATM machines in some sketchy convenience stores. I know it is not safe but I don’t always have an option. Therefore when I see articles like this, I just worry more.

From the article, the common ATM skimmer attack is replaced with a more aggressive attack that direct draws money from the ATM. The ATM being attacked had a security camera connecting via USB and the attacker somehow removed that and replaced it with a folding keyboard. He was then able to take control of the machine since the ATM is believed to use some sort of Microsoft Windows system. After rebooting the system, the attacker could then draw money from the ATM directly. Sounds like movie scene to me but the scary part is that it sounds so easy to do! It is crazy that by plugging in some USB device, the whole ATM can be taken control. Fortunately the police caught him on the spot.

Later in the article, the author talked about other skimmer devices in ATMs in hospital where people are assuming the safety of the cash machines. Apparently the hospital doesn’t hold responsibility but the machine vendor. Those skimmer devices could stay there for weeks before it would be discovered. Here is an article about the details of how a skimmer device work. It really didn’t seem too complicated.

In the end the article suggested people to withdraw money at bank branches, which is what I mostly do if I have to get some quick cash. Even then I am very aware of those machines outside of the bank. It is still possible to have skimmer devices installed there. I feel more comfortable if the machines are in a closed lobby with many security cameras. Where can people really comfortably get cash? That is a tough question.

Leave a Reply

You must be logged in to post a comment.