Hack turns Square into criminal tool

August 5, 2011 by Glenn Chapman

Mobile payment service Square markets a pocket-sized credit card reader to allow on the spot credit card payments

Hackers have shown how to turn the mobile payment service Square into a convenient tool for criminals to pump cash from stolen credit card numbers.

Hackers have shown how to turn mobile payment service Square into a convenient tool for criminals to pump cash from stolen credit card numbers.

Adam Laurie and Zac Franken of computer security firm Aperture Labs used a homemade software program and an easily bought iPad audio wire to trick Square in a way that could be a bonanza for crooks.

Laurie could type into his laptop, which converts to sound data sent to Square, where the transaction registers as if a real card were swiped in a dongle.

"Traditionally, the way you make money from stolen credit cards is sell the data to someone else or buy goods on it, then resell the goods and get the cash," Laurie said while demonstrating the hack at a Black Hat computer security gathering in Las Vegas.

"This really takes the hassle out of it... I can put the money right in the account and it only costs me 2.75 percent."

The percentage he cited was the fee charged by Square, which was co-founded by Jack Dorsey, a Silicon Valley star who helped create popular micro-blogging service Twitter.

Square markets a pocket-sized that can be plugged into a smartphone to allow anyone to accept credit or debit card payments on the spot.

Franken and Laurie, whose hacker name is "Major Malfunction," said that they were waiting for a flight at an airport when then figured out how to convert Square into a handy tool for cashing in on stolen credit cards.

Laurie realized that the Square "dongle" used to swipe credit cards plugged into an iPad audio jack, indicating that the small device essentially converted magnetic stripe data to sound then interpreted by the service's software.

He quickly modified software he wrote five years earlier for reading and replicating magnetic stripe data.

Franken and Laurie strolled to an airport shop and bought a wire to plug his laptop into the jack where the dongle would have gone.

"Credit card data is getting skimmed all the time," Laurie said, holding up a pre-paid credit card he used for the demonstration. "Instead of buying this I could have bought it on the Internet from a criminal gang."

Funds are dumped into an individual's Square account to be removed before anyone catches on, according to the hackers.

"You'd have to set up dodgy accounts that don't trace back to you," Laurie said. "But, that is standard practice."

Laurie and Franken said that they shared their findings with Square in February only to be told that it wasn't seen as a threat and that traffic analysis would expose those kinds of transactions.

The hackers had also heard unconfirmed reports that Square planned to release new dongles that encrypt transaction data.

"Encryption would be a good thing," Franken said. "The way it is at the moment a cable between two devices and you can inject credit card numbers right into the system," he continued.

Since promises to have money from transactions in accounts within a day, money milked from stolen data could be made off with quickly provided amounts were extreme enough to be noticed, Franken said.

(c) 2011 AFP

4.3 /5 (4 votes)  

Filter


Move the slider to adjust rank threshold, so that you can hide some of the comments.


Display comments: newest first

AnneOminous
Aug 06, 2011

Rank: 1 / 5 (1)
Pleeeeease don't write "software program". It's redundant. It's like saying "automobile car". And it makes those of us in the industry cringe.

There are many different definitions for "program". But if it's software, it's a program. So there is no need to write both. If you want to get technical, not all software runs on what we normally think of as computers, so if you really feel the need to be specific, "computer software" or "home computer software" is perhaps overly descriptive in most circumstances, but at least it's not -- quite -- redundant.
anonperson
Oct 03, 2011

Rank: not rated yet
typo:
when then figured out how to convert Square into a handy tool for cashing in on stolen credit cards.

when THEY
Rank 4.3 /5 (4 votes)
Relevant PhysicsForums posts

More news stories

Browser wars flare in mobile space

The browser wars are heating up again, but this time the fight is for dominance of the mobile Internet.

Technology / Software

created 6 hours ago | popularity 5 / 5 (1) | comments 2

Probability of contamination from severe nuclear reactor accidents is higher than expected: study

Catastrophic nuclear accidents such as the core meltdowns in Chernobyl and Fukushima are more likely to happen than previously assumed. Based on the operating hours of all civil nuclear reactors and the number ...

Technology / Energy & Green Tech

created May 22, 2012 | popularity 3.6 / 5 (22) | comments 56 | with audio podcast

SpotterRF debuts Radar Backpack Kit (w/ Video)

(Phys.org) -- SpotterRF has announced a special radar backpack kit designed to enhance situational awareness for soldiers on the ground. The company says its special radar is designed for warfighters as part ...

Technology / Hi Tech & Innovation

created May 26, 2012 | popularity 5 / 5 (5) | comments 13 | with audio podcast report

HyperSolar shows dirty water no barrier to power world

(Phys.org) -- The Santa Barbara, California, company, HyperSolar, is set to transparently share the ups and downs of its research experiences toward the company’s ultimate vision, successfully producing ...

Technology / Energy & Green Tech

created May 24, 2012 | popularity 4.8 / 5 (16) | comments 17 | with audio podcast report

Tesla to launch electric sedan in US on June 22

Tesla Motors said Tuesday it would begin deliveries of "the world's first premium electric sedan" on June 22, slightly ahead of schedule.

Technology / Energy & Green Tech

created May 22, 2012 | popularity 4.5 / 5 (11) | comments 18


Nvidia trumpets Tegra 3 phone design wins for 2012

(Phys.org) -- Nvidia’s competitive war paint has a name, Tegra 3. On the heels of Nvidia announcements about lowering costs of its Tegra 3 processors and Nvidia-enabled tablets running Android Ice Cream ...

Scientist: Evolution debate will soon be history

(AP) -- Richard Leakey predicts skepticism over evolution will soon be history. Not that the avowed atheist has any doubts himself.

Dell tablet leak: 10.1-inch display, two-battery choice

(Phys.org) -- Headline after headline talks about vendors’ tablets in the wings as likely number-one contenders for the iPad. Such claims have justifiably been taken with a grain of salt, considering ...

Keep food safety in mind this memorial day weekend

(HealthDay) -- Picnics, parades and cookouts are as much a part of Memorial Day weekend as tributes to the United States' war veterans.

Social welfare cuts ultimately come with heavy price, researchers say

(Phys.org) -- Slashing government funding for Medicaid, food stamps and other programs that serve the poor – while politically popular with some lawmakers and many conservatives – may do more harm ...

Is a classical electrodynamics law incompatible with special relativity?

(Phys.org) -- The laws of classical electromagnetism that were developed in the 19th century are the same laws that scientists use today. They include Maxwell’s four equations along with the Lorentz la ...