Re: [FD] [Full-disclosure] Bank of the West security contact?

2014-04-03 Thread Jeffrey Walton
On Wed, Apr 2, 2014 at 4:42 PM, Eric Rand wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > BoA has no incentive to switch, as the customers have not demanded > more secure ATMs, and it's cheaper to have 'hacking insurance' to > cover any losses than it would be to replace all their ATM

Re: [FD] [Full-disclosure] Bank of the West security contact?

2014-04-02 Thread Stefan Weimar
Hi, Am 02. April schrieb Sholes, Joshua: > And how fast would those ATM manufacturers switch to a Linux or other > offering if, say, Bank of America said "We won't buy an ATM with an easily > skimmable reader or with an insecure OS on it?" I agree. But it's not _one_ bank that has to say, it's mo

Re: [FD] [Full-disclosure] Bank of the West security contact?

2014-04-02 Thread raccoon
On Wed, Apr 02, 2014 at 08:30:25PM +, Sholes, Joshua wrote: >> On 4/2/14, 4:01 PM, "Stefan Weimar" wrote: >> >Hi, >> > >> >Am 02. April schrieb raccoon: >> > >> >> This goes for all banks and is probably one of the reasons most ATMs >> >> still run windows and are skimmable time after time by

Re: [FD] [Full-disclosure] Bank of the West security contact?

2014-04-02 Thread Eric Rand
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 BoA has no incentive to switch, as the customers have not demanded more secure ATMs, and it's cheaper to have 'hacking insurance' to cover any losses than it would be to replace all their ATMs. On 04/02/2014 01:30 PM, Sholes, Joshua wrote: > And how f

Re: [FD] [Full-disclosure] Bank of the West security contact?

2014-04-02 Thread Sholes, Joshua
And how fast would those ATM manufacturers switch to a Linux or other offering if, say, Bank of America said "We won't buy an ATM with an easily skimmable reader or with an insecure OS on it?" Diebold, for example, has a market cap of less than $3B. BoA is sitting around $182B. With that much le

Re: [FD] [Full-disclosure] Bank of the West security contact?

2014-04-02 Thread Stefan Weimar
Hi, Am 02. April schrieb raccoon: > This goes for all banks and is probably one of the reasons most ATMs > still run windows and are skimmable time after time by the simplest > exploits. That's not quite right. The manufacturer of the ATM chooses the OS. When you -- as a bank -- buy an ATM yo

Re: [FD] [Full-disclosure] Bank of the West security contact?

2014-04-02 Thread raccoon
On Mon, Mar 17, 2014 at 09:15:50AM -0700, Kristian Erik Hermansen wrote: > * Bank of the West does not seem to take security and privacy > seriously enough, as far as I can tell This goes for all banks and is probably one of the reasons most ATMs still run windows and are skimmable time after time