Feeds

The Hack in the Box ATM talk that never was...

No vendor threats, 'cos no talk, says researcher

SANS - Survey on application security programs

A banking security researcher has stepped forward to deny reports that vendor threats forced him to cancel a presentation on ATM security at the Hack in the Box conference in Amsterdam earlier this month.

Many outlets, including El Reg, reported that a presentation on the vulnerabilities and security shortcomings that cyber criminals were using to break into ATMs was cancelled at the last minute due to legal threats against ethical hacker Raoul Chiesa.

Chiesa issued a statement on Monday explaining that the much-trailed talk on Third Generation ATM Frauds didn't happen because he and his firm Mediaservice.net decided 18 months ago to only disclose vulnerabilities that have emerged to "closed sector-specific" associations and not at public events. Secondly, Chiesa had other commitments at home in Rome on July 2, the date he was due to appear at Hack in the Box.

"No manufacturer or systems integrator of ATM, nor banking or financial institution, have ever threatened Chiesa or the company Mediaservice.net," the statement explained.

Chiesa's research team has already presented part of this research in European Union security agency ENISA's report ATM Crime: Overview of the European situation and golden rules on how to avoid it last September, and in greater depth at a closed-door conference of ABI, an Italian banking trade group, around the same time.

The Mediaservice.net team remains committed to responsible disclosure despite what it describes as "insufficient measures" in mitigating vulnerabilities by the banking industry. Without going into details, the team cited the tampering of software in Ukrainian bank ATMs by organised crime as among the new generation of threat the industry faces.

"Everything has been a big misunderstanding with HITB [Hack in the Box] staff," Chiesa told El Reg.

"My original presentation, planned to be given at HITB EU on July 2nd 2010, was on the "Underground Economy". It is a presentation I've already given (CONfidence 2010, Troopers 2009, nullcon India 2010) and does not have anything to do with ATMs.

"A couple of weeks before HITB EU, I was speaking internally at my company, if going for Full Disclosure or not, given the critical topic we were working on. I told to Dhillon from HITB EU - we're discussing this internally, I'd love to go for Full Disclosure. If we ever decided this, I'd love to give the talk at HITB, since the delegates are serious and the speaker's level is quite high."

Although the supposed legal threats against Chiesa have been denied, other security researchers have not been so lucky. For example, a presentation on ATM security by Barnaby Jack was pulled from last year's Black Hat, only to be reinstated for this month's show.

Jack has moved from Juniper Networks to IOActive Labs over the last 12 months, a job change that has allowed him to explain how ATM machines might be fooled into dispensing more cash than recorded during a transaction at this year's Black Hat USA.

The "Jackpotting" presentation, which Jack himself compares to the cash machines hack run by John Connor in Terminator 2, is likely to be one of the highlights of this year's conference. ®

High performance access to file storage

More from The Register

next story
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Samsung Galaxy S5 fingerprint scanner hacked in just 4 DAYS
Sammy's newbie cooked slower than iPhone, also costs more to build
Putin tells Snowden: Russia conducts no US-style mass surveillance
Gov't is too broke for that, Russian prez says
Snowden-inspired crypto-email service Lavaboom launches
German service pays tribute to Lavabit
Mounties always get their man: Heartbleed 'hacker', 19, CUFFED
Canadian teen accused of raiding tax computers using OpenSSL bug
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Call of Duty 'fragged using OpenSSL's Heartbleed exploit'
So it begins ... or maybe not, says one analyst
prev story

Whitepapers

Top three mobile application threats
Learn about three of the top mobile application security threats facing businesses today and recommendations on how to mitigate the risk.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
SANS - Survey on application security programs
In this whitepaper learn about the state of application security programs and practices of 488 surveyed respondents, and discover how mature and effective these programs are.