ATM Skimmers- a conversation
I normally use an ATM located in the reception area of the headquarters of the state police. It's just across the skyway from where I work, and most importantly, it's owned by a credit union that doesn't charge me for withdrawals. Free ATM's are a good thing.
A couple months ago, as I was about to slide my card, I looked up at the ceiling, scanned the nearby walls, grabbed the card reader and wiggled it up and down a bit, and bent down and looked at the bottom of the reader.
The receptionist look at me, 'um - can I help you?'
Me: "I was just thinking about the probability of finding a card skimmer on an ATM in the lobby of the state police headquarters. Do you supposed it's possible?"
Her: (laugh) "I heard about those - how do they work?"
Me: [short explanation]
Her: "I don't know if I could tell the difference."
Me: "I'm not sure I can either..."
We both agreed that it was unlikely that someone would be able to skim this particular ATM. The receptionist is always behind the desk, facing the ATM; the lobby is only open business hours, and that because of heavy use by law enforcement officers, odds are it would be detected.
I like that ATM.
There's a new dance that's popular now, called the 'Skimmer Squint'. It's when the patron bends over & looks up at the bottom of the card reader, peers into the slot, steps back, glances left, right, up & down, grabs the reader and jiggles it...
Q2KU59J6YRVP
O Broadband, Broadband, Wherefore Art Thou Broadband?
Payroll Processor Hacked, Bank Accounts Exposed
F
rom the Minneapolis Star Tribune:
“A hacker attack at payroll processing firm Ceridian Corp. of Bloomington has potentially revealed the names, Social Security numbers, and, in some cases, the birth dates and bank accounts of 27,000 employees working at 1,900 companies nationwide”
A corporation gets hacked, ordinary citizens get screwed. It happens so often that it’s hardly news.
This is interesting to me because Ceridian is a local company and the local media picked up the story. That’s a good thing. I’m glad our local media is still able to hire professional journalists. The executives of a company that fail like that need to read about themselves in their local paper and watch themselves on the evening news. They might learn something. If we’re lucky, the hack might even get mentioned at the local country club and the exec’s might get a second glance from the other suits.
We aren’t that lucky.
In a follow up story, the Star Tribune interviewed a man who claims that he has not had a relationship with Ceridian for 10 years, yet Ceridian notified him that his data was also stolen. The Star Tribune reports that Ceridian told the victim that the compromise of 10 year inactive customer data was due to a ‘computer glitch’:
“a Ceridian software glitch kept it in the company's database long after it should have been deleted.”
Sorry to disappoint the local media, but computer glitches are not the reason that 10 year old data is exposed to hackers.
Brain dead management is the cause.
But even brain dead management occasionally shows sings of life. According to the customer whose 10 year old data was breached:
"The woman from Ceridian said they're working on removing my information from the database now,”
Gee thanks. What’s that horse-barn-door saying again?
Given corporate America’s aversion to ‘DELETE FROM…WHERE…’ queries, my identity and financial information is presumably vulnerable to exposure by any company that I’ve had a relationship with at any time since computers were invented.
That’s comforting.
-
Cargo Cult: …imitate the superficial exterior of a process or system without having any understanding of the underlying substance --Wikipe...
-
Structured system management is a concept that covers the fundamentals of building, securing, deploying, monitoring, logging, alerting, and...
-
In The Cloud - Outsourcing Moved up the Stack [1] I compared the outsourcing that we do routinely (wide area networks) with the outsourcing ...