Vulnerable Some European PoS Payment Systems

Security experts claim that most of the payment terminals, also known as PoS Payment Systems, used in Germany, contain old vulnerable protocols, but also use bad practices when it comes to encrypting data.

pos pay

According to the researchers, the problem exists in both communication processes, ie που tai to contact the PoS Payment a cashier device with the store station, and the protocol that sends the data from the payment terminal to the bank for processing the data.

Vulnerable inside…
On the local communication side, the researchers found that a high percentage of German payment processors use the ZVT protocol, which is known to be susceptible to simple eavesdropping attacks and which allows a hacker to intercept credit card information. .

What makes things worse is that this protocol is also responsible for reading the PIN of the card via PoS and sending it back to the central station to allow the transaction.

Although this communication is encrypted, researchers found that PoS (Point of Sale) manufacturers store the encryption key on the device, and often use the same key.

pay1

… Vulnerable abroad
Between the PoS terminal and the bank, things are not so rosy. The protocol used to exchange data between these two, a variant of the ISO 8583 standard known as Poseidon, has a flaw identity.

By repeating the same error, PoS manufacturers also store the encryption key used to exchange encrypted data with third parties. This key is stored on the device itself and rarely changes, most of the time is the same for whole lots of PoS terminals.

Researchers are scheduled to make an extensive presentation on this topic on Sunday at 27 December in Hamburg at the 32 Chaos Communications Conference (32C3).

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by Dimitris

Dimitris hates on Mondays .....

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).