[00:05.340 --> 00:09.460] So... I want to open this presentation with these words. [00:10.100 --> 00:15.000] The trick might look impossible, but the method is usually simple. [00:17.800 --> 00:20.180] A few words about myself. [00:21.600 --> 00:23.160] My name is Roman Pushkin. [00:23.380 --> 00:24.700] I live in San Francisco. [00:25.940 --> 00:30.840] Before that, I used to live in Germany, Spain, three years in India. [00:32.280 --> 00:36.480] Sometime in Southeast Asia, Ukraine, and I was born in Soviet Union. [00:36.820 --> 00:41.420] I spent my teens in Soviet Union and Russia. [00:42.620 --> 00:50.680] So, I've contributed to 2600 a couple of times under my own name and anonymously. [00:51.020 --> 00:52.740] I'm an open-source contributor. [00:53.460 --> 00:56.160] There is my GitHub account. [00:56.920 --> 01:00.060] I wrote a book about Ruby programming language. [01:00.780 --> 01:01.880] Ruby is for fun. [01:02.140 --> 01:03.320] The link is on the left. [01:04.720 --> 01:07.400] I don't know if you can see it from this side. [01:09.520 --> 01:11.200] So, the book is free. [01:11.500 --> 01:12.320] It is human-written. [01:12.620 --> 01:13.180] Zero AI. [01:13.720 --> 01:14.680] 400 pages. [01:15.720 --> 01:26.120] Today, I work where security and software meet payments in a company that moves from one to three billion dollars a day. [01:26.280 --> 01:28.600] So, I probably moved your money as well. [01:29.880 --> 01:34.860] And I've been in this space for quite a while now, 20 years. [01:35.660 --> 01:51.540] But it all started when I was 10 years old, back in 1992, when the very first publicly accessible ATM was installed by Visa in Moscow. [01:52.680 --> 01:54.840] And I lived 60 months from Moscow. [01:55.860 --> 02:06.400] When I was 12 to 14, I would travel there with a friend of mine to buy programming books and just to touch these magical machines. [02:06.400 --> 02:11.580] We even collected ATM receipts that people left behind. [02:11.800 --> 02:17.060] And that's where my curiosity about ATMs and ATM security really began. [02:17.800 --> 02:24.760] Later, I worked in banks, payment systems, payments terminals, departments. [02:24.760 --> 02:29.780] And most of the time I was working on either security or writing code. [02:30.180 --> 02:34.960] And I consider myself as ethical hacker and cache systems security expert. [02:35.460 --> 02:41.120] And it all started with the first ATM in Moscow, which you are about to see on the next slide. [02:43.520 --> 02:48.020] So, speaking of magic, hacking ATMs is a lot like magic. [02:49.180 --> 02:53.620] Over the years, people have found many different ways to hack ATMs. [02:53.620 --> 02:57.540] Of course, in this talk, we won't cover all of them. [02:57.840 --> 03:04.580] But main methods, famous methods, I'll talk about this a little bit. [03:04.840 --> 03:07.800] And I'll show you a lot, but I can't show you everything. [03:08.320 --> 03:25.940] And I already did many presentations to my clients about payment security to show how variable payment systems and payment terminals can be and how things are often much simpler than people think. [03:26.400 --> 03:30.620] And to prove that point, let's do a small experiment. [03:31.560 --> 03:40.220] This one is not about ATMs at all, but for some people in this room, it is going to feel like magic. [03:41.540 --> 03:46.960] So, it is really up to you if you want to participate or not. [03:47.060 --> 03:49.140] It only takes a minute, I promise. [03:49.580 --> 03:51.500] And I encourage everyone to join in. [03:52.140 --> 03:57.460] What I want is, do not overthink what I'm about to say. [03:58.200 --> 04:00.540] There's no need for second thoughts. [04:03.280 --> 04:04.780] It is that simple. [04:04.780 --> 04:06.200] In a moment, not right now. [04:06.200 --> 04:07.900] I will ask you to close your eyes. [04:11.610 --> 04:12.890] In just a few seconds. [04:13.730 --> 04:15.230] Hopefully, that won't be too hard. [04:15.230 --> 04:19.050] And I will also ask you not to say anything out loud. [04:19.250 --> 04:19.750] Nothing at all. [04:19.750 --> 04:21.310] So, we can keep this a clean experiment. [04:21.670 --> 04:25.790] If you already know this magic trick, just observe quietly. [04:26.330 --> 04:28.690] And do not overthink that. [04:28.870 --> 04:30.230] And please remain silent. [04:33.250 --> 04:38.430] So, think of two random numbers from 0 to 9. [04:38.750 --> 04:40.210] But there are important rules. [04:40.370 --> 04:41.790] Each number must be odd. [04:41.790 --> 04:44.830] And the two numbers must be different. [04:45.210 --> 04:48.470] For example, 11 would not work, but 15 would. [04:48.930 --> 04:49.690] Remain silent. [04:50.590 --> 04:51.010] Got them? [04:51.230 --> 04:52.250] Do not say anything. [04:53.430 --> 04:53.830] Good. [04:54.070 --> 04:57.830] So, now picture these numbers in your mind. [04:58.210 --> 04:59.250] Close your eyes. [04:59.810 --> 05:00.890] Stay silent. [05:01.330 --> 05:04.070] Do not open your eyes yet. [05:04.490 --> 05:09.750] But raise your hand if your number is 37. [05:11.210 --> 05:12.610] 3 and 7. [05:13.150 --> 05:14.310] Raise your hand. [05:16.010 --> 05:16.610] Okay. [05:17.130 --> 05:20.250] So, now you can open your eyes and look around. [05:20.390 --> 05:21.270] Raise your hand, everyone. [05:22.110 --> 05:23.450] Number 3 and 7. [05:23.970 --> 05:24.330] Okay. [05:24.350 --> 05:26.150] We have quite a few people, right? [05:29.270 --> 05:34.950] So, that's what I mean when I say magic. [05:41.890 --> 05:46.050] So, the trick might look impossible, but the explanation is really simple. [05:46.190 --> 05:48.830] If you're curious how it works, we can chat after that. [05:48.990 --> 05:51.410] But, it's a fun little mind exercise. [05:53.570 --> 05:57.430] And, probably we do not have too much time to go into history. [05:57.730 --> 05:59.850] I will just briefly cover that. [06:00.890 --> 06:05.410] Back in the time, in 60's, credit cards were embossed. [06:05.710 --> 06:11.270] And, the holder's name, expiration date were physically raised on the surface of the card. [06:11.270 --> 06:15.230] There was a zip-zap machine or click-clack. [06:16.030 --> 06:19.830] And then, the process was completely mechanical. [06:20.130 --> 06:29.050] The merchant would take the card, put a set of carbon copy forms over it and slide a heavy bar back and forth. [06:29.050 --> 06:37.690] And, you're getting a physical imprint and one copy stays with the merchant and another copy with the customer. [06:39.150 --> 06:42.350] So, there was no real-time authorization. [06:42.590 --> 06:50.050] Merchants would check the card numbers against the bad cards list, which were updated and mailed once a month. [06:50.050 --> 06:57.410] And, these devices were used from 50's and 60's all the way to 80's and even 90's. [06:57.910 --> 07:02.410] This picture is from Wikipedia and I think there is 96. [07:02.950 --> 07:12.570] Yeah, so, they even survived to 2000's in places with no network like taxis, airplanes or as a backup. [07:13.750 --> 07:15.450] Today, they're basically instinct. [07:16.790 --> 07:22.690] And, this guy here, Forrest Perry, invented magnetic stripe. [07:23.450 --> 07:29.950] The story goes that he was trying to figure out how to attach magnetic tape to a plastic card. [07:30.130 --> 07:33.290] And, his wife suggested using an iron to melt the tape into it. [07:33.430 --> 07:34.290] And, it worked. [07:35.350 --> 07:39.070] And, magnetic stripe cards exploded in popularity. [07:39.070 --> 07:45.590] They completely dominated the payment card world for more than three decades. [07:46.170 --> 07:52.310] And, up until 2010's or so, they were still the main standard. [07:53.810 --> 08:01.370] And, I can tell you from my own experience, I played with magnetic stripes a lot. [08:01.550 --> 08:03.770] And, they are surprisingly reliable. [08:04.830 --> 08:06.870] A floppy disk can give you bad sectors. [08:07.170 --> 08:08.890] But, magnetic cards just work. [08:09.570 --> 08:16.230] And, one important thing that you have to know about magnetic stripes is that, on some cards, there are three tracks. [08:16.510 --> 08:18.230] On some cards, there are two tracks. [08:18.950 --> 08:21.810] We call them track one, track two, etc. [08:21.810 --> 08:29.410] And, you actually can see the data on the magnetic card at home with a simple experiment. [08:29.670 --> 08:36.910] All you need is an old credit card and something fine and magnetic, like iron powder. [08:37.150 --> 08:39.590] You can buy iron powder online. [08:39.590 --> 08:49.650] Just sprinkle it gently and you will see with a magnifying glass or even without it. [08:49.850 --> 08:52.070] And, it is a super simple trick. [08:52.670 --> 09:00.910] But, if you look at the next slide, it is an example of the card with just two tracks. [09:00.910 --> 09:04.850] And, you can see how the data is encoded, actually, on the card. [09:05.250 --> 09:07.530] And, you can see it with the ORIs. [09:09.090 --> 09:11.790] And, the second track is lower density. [09:12.230 --> 09:17.550] And, that is the one ATMs usually use for transactions. [09:18.210 --> 09:25.270] It usually stores the card number and expiration date in a format, the ATM on the fence. [09:28.050 --> 09:32.130] And, I know the slide might look a little bit complicated. [09:32.490 --> 09:38.870] But, what we need to know is just that it is track two and it has its own format. [09:40.550 --> 09:44.770] And, time to move on to the hardware overview real quick. [09:45.010 --> 09:51.250] So, it is the magnetic card reader designed to read both track one and track two. [09:51.250 --> 09:53.230] There are two chips. [09:53.710 --> 09:58.350] One chip is responsible for frequency, double frequency decoding. [09:58.570 --> 10:02.510] It is the magnetic stripe data encoding method. [10:02.690 --> 10:09.250] And, the other chip processes data and sends it over to USB. [10:10.090 --> 10:11.810] And, USB is an important word today. [10:12.970 --> 10:15.810] There are also jumpers to configure the behavior. [10:15.810 --> 10:23.070] For example, you can turn on and off specific tracks or choose to display the start and end markers for each track. [10:25.730 --> 10:28.250] And, here is the actual reading module. [10:28.930 --> 10:32.530] The magnetic head is mounted in a plastic frame. [10:33.330 --> 10:37.070] With a small board carrying the operational amplifiers. [10:40.390 --> 10:46.910] So, this photo shows a magnetic head from Ingenico terminal. [10:46.930 --> 10:50.510] You can clearly see all three tracks. [10:51.950 --> 10:57.610] And, before we jump into full-on ATM hacking, let's talk about schemers. [10:57.730 --> 10:59.690] But, personally, I do not like schemers. [11:00.710 --> 11:06.350] Raise your hand if you heard about schemers and you know what it is. [11:06.970 --> 11:07.830] Okay, good. [11:08.050 --> 11:10.170] So, we do not have to talk much about that. [11:10.290 --> 11:13.650] But, because I do not like them. [11:13.890 --> 11:16.750] They are boring copy and paste technology. [11:16.750 --> 11:18.670] They are installed on ATMs. [11:18.910 --> 11:20.830] They copy your track, too. [11:20.830 --> 11:29.410] And, somehow, they record PIN, whether it is a keypad, fake keypad, or it's a camera. [11:30.450 --> 11:36.090] And, they were, like, relatively simple. [11:36.090 --> 11:46.790] But, a card reader over an ATM slot plus a tiny camera or fake keypad can capture your PIN. [11:47.030 --> 11:50.150] And, this data is stored locally. [11:50.150 --> 11:54.930] And, the thief had to come to ATM to collect it. [11:54.930 --> 11:59.490] And, one 2003 case in New York showed the damage. [11:59.610 --> 12:05.810] In a single day, 200k was stolen from customers of just one ATM. [12:08.950 --> 12:09.590] Yeah. [12:09.830 --> 12:14.010] And, on dark web forums, they used to call Track 2 a dump. [12:14.410 --> 12:21.010] For a very long time, some people were selling dumps with PINs for very good money. [12:21.010 --> 12:28.550] Because, if you have dump and PIN, just right off the bat, you can write the dump on the card. [12:28.850 --> 12:35.490] Go to the nearest ATM and get cash with a PIN number and a bonus jail time. [12:38.730 --> 12:44.750] So, 2010, skimmers went global. [12:45.730 --> 12:47.430] 3D printing changed the game. [12:47.610 --> 12:51.130] So, they printed the whole parts that look like ATM. [12:51.510 --> 12:54.650] And, they put those parts like... [12:55.410 --> 12:58.610] So, they look like real ATM, but they not. [13:01.070 --> 13:05.190] And, here you can see how thin the skimmers can be. [13:05.470 --> 13:10.590] They can be placed inside of the card slot. [13:10.850 --> 13:13.270] And, you won't be able to see that. [13:13.270 --> 13:20.710] So, they operate inside the ATM and they send data over the air. [13:21.030 --> 13:25.270] So, it's a kind of slightly sophisticated method. [13:26.130 --> 13:28.650] Here's how they look like. [13:29.670 --> 13:35.050] So, and I said earlier that we would come back to Track 2. [13:35.050 --> 13:36.550] And now it is time. [13:36.910 --> 13:39.810] This is where things get interesting. [13:40.070 --> 13:43.530] And I'm about to show you one trick. [13:43.830 --> 13:47.930] It made organized crime groups millions and millions of dollars. [13:47.930 --> 13:57.330] We're going to see if it is actually possible to recreate the dump, that 40-byte Track 2 sequence. [13:57.590 --> 14:02.070] And pair it with a pin to pull cash from an ATM. [14:02.470 --> 14:10.930] Because, in the end, all ATM really needs is the right Track 2 data and the correct pin to hand out the money. [14:13.070 --> 14:18.870] If we look at the line above, you can see every field in... [14:20.270 --> 14:23.370] Every field is already broken down there. [14:23.650 --> 14:25.370] So, there's no point in going deep. [14:26.590 --> 14:34.610] But, if you want, there is a table below showing exactly what each part means. [14:35.550 --> 14:39.870] And at the top, we have the Dump or Track 2 below. [14:40.010 --> 14:41.090] You can see the fields. [14:41.930 --> 14:44.830] Card number, expiration date, service code. [14:45.130 --> 14:48.350] So, now I'm going to say something important. [14:48.530 --> 14:49.970] There is discretionary data. [14:51.110 --> 14:59.950] And to recreate a dump from just the card number, meaning something you could type with a keyboard. [14:59.950 --> 15:02.650] You must know the discretionary data. [15:03.090 --> 15:07.230] And everything else you can just type by hand. [15:07.370 --> 15:13.410] But discretionary data is the data that is only present on your card and nowhere else. [15:14.590 --> 15:17.910] And it is not visible if you look at your card. [15:18.130 --> 15:25.570] I mean, these numbers, you only have a card number, your name, expiration date, but not discretionary data. [15:27.250 --> 15:31.190] In other words, we know service code. [15:31.630 --> 15:33.770] In our case, it is 121. [15:34.010 --> 15:36.170] This is just a fixed value from a short list. [15:36.610 --> 15:38.090] There aren't many of them. [15:38.090 --> 15:42.530] We can type everything before the service code on the keyboard. [15:42.770 --> 15:47.530] And we can even type the service code itself, of course, into a text file. [15:47.790 --> 15:52.650] So, at this point, we've already recreated about half of the Track 2 dump. [15:52.830 --> 15:56.170] But there is still one more important piece left. [15:59.170 --> 15:59.810] Yeah. [16:00.250 --> 16:03.850] But what exactly is discretionary data? [16:03.850 --> 16:03.910] Yeah. [16:04.190 --> 16:11.150] So, I promise you, many cybercriminals who knew this trick either became millionaires or ended up serving time. [16:12.570 --> 16:17.910] The information I'm about to mention isn't widely known, but it is old news now. [16:18.370 --> 16:21.070] We're talking about 10-15 years ago. [16:21.470 --> 16:24.270] The trick could still work in some places today. [16:25.010 --> 16:27.890] But now, we have chips on the magnetic stripe. [16:29.970 --> 16:30.570] And... [16:30.570 --> 16:31.450] Yeah. [16:31.650 --> 16:34.470] I mean, magnetic stripe is mostly there for backwards compatibility. [16:35.250 --> 16:41.470] And if we knew what was stored in the discretionary data, we could fully recreate Track 2. [16:41.710 --> 16:42.770] But there is a catch. [16:42.850 --> 16:45.650] In real life, this data doesn't appear anywhere else. [16:45.790 --> 16:46.650] Anywhere else. [16:46.770 --> 16:51.190] And it exists only on the second track of the card. [16:51.190 --> 16:56.170] However, remember what I said at the very beginning of this presentation. [16:56.330 --> 17:00.170] The trick might look impossible, but the method is usually simple. [17:01.130 --> 17:07.050] A quick clarification for anyone who's already lost in the details. [17:07.170 --> 17:12.430] Just a reminder of how cybercriminals cared about this in the first place. [17:12.430 --> 17:16.930] To illegally get money from ATM, you don't necessarily need a skimmer. [17:17.130 --> 17:21.050] You don't even need physical access to the card. [17:21.350 --> 17:28.910] Imagine if a skimmer could just call the victim and ask their card number and then the PIN. [17:29.690 --> 17:33.690] Or maybe trick them into a phishing site that asks for PIN. [17:33.870 --> 17:36.190] And it would be much easier for the criminals. [17:36.390 --> 17:42.550] They would not have to order anything from online stores using stolen card numbers. [17:42.590 --> 17:44.970] They could just simply go to ATM and get cash. [17:45.150 --> 17:47.250] Because recreating Track 2 is easy. [17:47.350 --> 17:49.710] It is just 40 bytes of data. [17:49.930 --> 17:51.030] But here's the thing. [17:51.170 --> 17:54.590] The discretionary data is what actually prevents that. [17:54.590 --> 17:56.670] And there is a twist. [17:57.130 --> 17:59.610] Give me a couple of minutes and you'll see what I mean. [18:00.170 --> 18:04.190] First, let's take a look at what discretionary data really is. [18:04.710 --> 18:07.830] What you see here is bad news for cybercriminals. [18:08.730 --> 18:12.130] Some of these fields are not friendly to them at all. [18:12.570 --> 18:24.450] Inside this discretionary data, there are values like PVKI and PVV cryptographic parameters stored by the bank's hardware and security modules and post terminals. [18:25.030 --> 18:30.490] And they are protected by strong encryption and strict key management. [18:30.870 --> 18:36.370] There are some called HSAMs that do this dance. [18:36.690 --> 18:46.890] And in short, this is what actually protects your PIN and prevents someone from cloning your card just by knowing the card number and expiration date. [18:46.890 --> 18:57.490] In other words, discretionary data is the last line of defense stopping someone from grabbing card numbers, cloning them and walking up to the ATM for cash. [18:57.670 --> 19:09.210] It is generated using cryptographic mechanisms linked to your PIN and its verification, all documented, all part of the industry standard. [19:09.210 --> 19:09.430] standard. [19:10.730 --> 19:13.050] But there is a catch. [19:13.810 --> 19:20.670] In banking, standard doesn't always mean one standard. [19:21.330 --> 19:25.850] There are variations, exceptions, easier, specific tweaks. [19:26.230 --> 19:27.370] And think about that. [19:27.590 --> 19:35.510] How can something on the card protect your PIN when you can change the PIN anytime today? [19:35.510 --> 19:40.470] It's a convenient, customer-oriented feature now. [19:40.670 --> 19:42.450] Changing your card PIN number. [19:43.550 --> 19:47.330] So, I promised we would come back to the phrase. [19:47.810 --> 19:51.310] The trick might look impossible, but the method is usually simple. [19:51.310 --> 20:02.630] What if I told you there is a way to bypass discretionary data and build a valid track to dump? [20:02.990 --> 20:03.670] Right? [20:04.130 --> 20:05.210] In a text editor. [20:05.570 --> 20:14.610] This was once the kind of secret that could get you in a serious trouble in certain cybercrime circles in Eastern Europe. [20:14.610 --> 20:17.190] Yes, the method is really that simple. [20:17.730 --> 20:21.870] There is a trick to sidestep the encryption. [20:22.570 --> 20:29.810] It doesn't work for every bank, but some issuers block it, others don't. [20:30.270 --> 20:36.930] Back then, criminals even kept BIN lists, card number, prefixes for which this worked. [20:36.930 --> 20:44.130] So, turns out you can replace the discretionary data with... [20:44.130 --> 20:45.750] Any guesses? [20:49.620 --> 20:50.580] Zeros. [20:53.680 --> 21:02.280] Whether it was for user convenience, for PIN changes, or who knows what reason it was possible. [21:04.600 --> 21:09.800] Not everyone knew this, but the method was kept in the shadows. [21:10.080 --> 21:14.040] But for certain BINs, this ridiculously simple trick worked. [21:14.300 --> 21:21.780] Just replace the discretionary data with zeros, and you've got yourself working track two, jail time, wherever you want. [21:21.960 --> 21:27.440] So, from there, it was easy phishing attack, spare phishing attack, or other schemes. [21:27.440 --> 21:35.440] And roughly 5% of all cards at the time, maybe today, are vulnerable. [21:35.980 --> 21:42.340] Criminals grab the card numbers, rebuild the dumps, and hit ATMs for the max cash out. [21:42.920 --> 21:50.300] Compared to skimmers, you didn't even need to touch ATMs for data capture. [21:50.300 --> 21:53.420] You only approach it to get money from ATMs. [21:53.520 --> 21:58.380] And the track two data itself came entirely online. [21:59.280 --> 22:05.440] Everyone who knew this trick back then is either a millionaire serving time. [22:05.660 --> 22:15.780] Maybe it still works somewhere, but now we have EMV chips, and this loophole is not applicable there. [22:15.780 --> 22:20.920] But if the trick looks impossible... [22:22.460 --> 22:23.140] Okay. [22:23.820 --> 22:28.880] Now, we've already dipped our toes into card hacking, so let's talk about ATMs now. [22:29.460 --> 22:37.280] Around 2012, on a dark web forum, a thread popped up with the title, Working on ATMs. [22:37.280 --> 22:40.640] This was something new at the time, not about cards. [22:40.640 --> 22:48.300] In short, it was about getting cash from ATMs by taking advantage of USB. [22:49.100 --> 22:56.720] Every ATM has USB ports, and in wrong hands, that's basically a shortcut to the cash. [22:56.980 --> 23:04.780] And also, if we talk about gas stations, kiosks, and all these modern machines. [23:06.020 --> 23:23.300] So, on some ATM models, on some of them, the USB ports are located in poorly protected spots, like the top panel where the cards, where the ads are, and that panel is just held by simple clips. [23:23.540 --> 23:30.460] So, you pop it off, and you've got access to the USB ports, like we see on the next slide. [23:32.000 --> 23:32.580] Right. [23:32.580 --> 23:41.600] If the panel is hard to remove, on some models, you just reel a hole in the right spot, and that's your shortcut to USB ports. [23:42.320 --> 23:44.980] Let's see if we have a picture here. [23:46.460 --> 23:48.440] Yeah, something like this. [23:49.160 --> 23:52.240] Then they plug USB hub into those ports. [23:52.760 --> 24:04.340] Of course, with some KVS, because there are some sensors, we can talk about this forever, that prevent or inform about drilling, shaking, tilt, and so on. [24:05.060 --> 24:14.860] But what they do, they plug USB hub into those ports with a wireless keyboard adapter and flash drive, with one program. [24:15.340 --> 24:16.240] One program. [24:16.640 --> 24:18.520] We'll talk about this program shortly. [24:19.220 --> 24:25.080] You connect this USB hub, open up my computer, run the program, and that's it. [24:25.440 --> 24:28.840] The ATM starts speeding up its cache. [24:30.300 --> 24:35.820] There are variations of this method, which we'll see on the next slide. [24:38.700 --> 25:00.010] So, by saying variations, I mean, one can combine different tools, flipper, or just a $5-$10 USB device, that can be used to escape to operating system. [25:00.330 --> 25:08.090] If you think it cannot be that simple, you're both right and wrong, because we haven't gotten to the software yet. [25:08.090 --> 25:12.330] We've been talking about ATM hardware hacking. [25:12.530 --> 25:18.890] And simply put, hardware ATM hacking is about getting control of USB. [25:19.310 --> 25:26.010] There are many methods and many caveats, yeah, like I said before. [25:26.270 --> 25:32.250] There are sensors like temperature and impact sensors. [25:32.870 --> 25:36.770] But the security measures do not come for free. [25:36.770 --> 25:41.710] It is not about the cost of the sensor, which is cheap. [25:41.710 --> 25:53.130] It is about the entire system, who is going to support the system, who is going to monitor people, who is going to be watching these video streams. [25:53.950 --> 26:00.390] And when things sometimes break, banks need to do something about that. [26:00.570 --> 26:02.210] So, it can become really expensive. [26:02.430 --> 26:03.770] Yeah, some banks do that. [26:03.950 --> 26:11.010] But a lot of them try to save money and such decisions are often economy driven, not risk driven. [26:11.010 --> 26:13.030] And there is also insurance factor. [26:13.740 --> 26:20.120] Sometimes it is easier to pay for insurance rather than looking for technological and software protection. [26:22.460 --> 26:33.520] And you can even find YouTube shorts showing a flipper and USB cable like I have here. [26:33.520 --> 26:37.440] And there is a QR code on the left. [26:40.400 --> 26:42.700] And on the right is GitHub link. [26:42.860 --> 26:46.040] So, you can look at how easy this USB script is. [26:46.160 --> 26:52.600] The script is to escape from UI shell to operating system. [26:53.320 --> 27:01.860] In the YouTube video, the flipper is running a kiosk version script on a publicly accessible kiosk with open USB port. [27:02.280 --> 27:03.720] And it works. [27:03.900 --> 27:06.000] The demo is just 30 seconds. [27:06.000 --> 27:14.680] And exactly this mechanism can be used to escape to operating system into operating system in ATMs. [27:14.680 --> 27:22.560] So, it is surprisingly easy for developers to overlook these details when creating software for kiosk or ATMs. [27:22.720 --> 27:25.520] Especially since many ATMs run on Windows. [27:25.760 --> 27:28.120] And those computers are often pretty outdated. [27:29.600 --> 27:31.500] This one is real. [27:33.500 --> 27:36.980] Also, a little bit on the mechanical side of ATMs. [27:37.020 --> 27:39.300] It really depends on the country. [27:39.540 --> 27:41.860] Some countries are under sanctions. [27:41.860 --> 27:44.260] Some have unstable economies. [27:44.760 --> 27:49.980] And that often is reflected on their ATM infrastructure. [27:50.420 --> 27:56.560] In some countries, it is common to see ATMs running Windows 7 or even XP. [27:56.560 --> 27:58.640] Usually a pirated copy. [27:59.000 --> 28:02.460] I've worked in more than 10 countries and traveled even more. [28:02.780 --> 28:10.360] And all over the world, I've never seen a login screen on these systems when you boot them up. [28:10.360 --> 28:14.140] And banks save money on software development and updates. [28:14.340 --> 28:18.840] And they want the system to boot straight into ATM software after a restart. [28:19.460 --> 28:23.600] And I personally developed software improvements for the systems. [28:23.620 --> 28:26.680] And I know that security wasn't always the top priority. [28:27.120 --> 28:30.760] Until I do presentations like this one. [28:30.940 --> 28:39.280] And honestly, you can often tell just by looking at the ATM what operating system it is running and what security it has. [28:39.280 --> 28:46.100] And as for the cameras, 99% record only to local storage. [28:46.380 --> 28:48.360] No live video stream. [28:48.620 --> 28:56.200] And from my experience, in some countries, about 70% of all cameras are completely off. [29:00.350 --> 29:00.830] Hmm. [29:02.690 --> 29:03.170] Hmm. [29:03.170 --> 29:03.190] Hmm. [29:03.610 --> 29:05.610] So, but what about the software? [29:05.970 --> 29:12.990] When I said, if you think it cannot be that easy to hack an ATM, you are right and wrong at the same time. [29:12.990 --> 29:23.170] I was talking about certain types of programs criminals use and criminals run on ATMs to empty the cash dispenser. [29:23.490 --> 29:31.970] Yes, you can buy the software, but it is often for rent on dark web forums. [29:31.970 --> 29:36.610] The thing is, getting access to USB port isn't enough. [29:37.130 --> 29:42.790] Sure, you can run bad USB script and break into operating system, but then what? [29:43.130 --> 29:47.190] How do you actually make the machine to spit out the money? [29:47.450 --> 29:49.810] The cash is still inside ATM. [29:50.930 --> 29:54.290] That's the next level of skill in the criminal world. [29:54.570 --> 29:56.890] And today I'm going to give you a short demo. [29:57.590 --> 30:08.790] But first, let me, let me explain how it works in real life and the shadow economy behind it. [30:13.010 --> 30:17.630] So, the shadow economy of ATM hacking is pretty fascinating. [30:17.710 --> 30:26.810] If a criminal has physical access, the next step is forcing the cash dispenser to spit out all the money. [30:27.210 --> 30:29.870] And how is that done? [30:30.290 --> 30:31.810] There are two main ways. [30:32.610 --> 30:37.170] One is running a program directly on the ATM's main computer. [30:37.170 --> 30:51.310] If that's not possible, the cash dispenser is connected directly to a device like this one here. [30:51.530 --> 30:54.190] We'll talk about this real quick. [30:55.150 --> 31:03.250] So, creating software like this takes a high level of skill and access to ATM hardware. [31:03.250 --> 31:07.310] Either the full machines or dispensers. [31:08.230 --> 31:13.250] And that access can come from insiders who work on ATM software. [31:13.510 --> 31:16.450] But it is not only the way. [31:16.870 --> 31:24.490] Many different cash dispensers and even ATMs are sold openly on eBay. [31:24.490 --> 31:30.730] The price of ATM is around $3,000 cash dispenser from $100. [31:32.050 --> 31:41.970] And this kind of software to control dispensing machine is usually available for a percentage of the cash out. [31:42.310 --> 31:43.470] Here is how it works. [31:43.650 --> 31:52.310] Before flashing the ATM, the program generates 12-digit code containing the amount of cash in the dispenser. [31:52.310 --> 31:56.190] The criminals send that code to Telegram bot. [31:56.610 --> 32:04.070] And in return, they get an unlock code for the one single ATM flash. [32:04.470 --> 32:10.990] In other words, licensing agreements also exist in the dark web between criminal groups. [32:10.990 --> 32:14.390] But the bottom line, yes, this kind of software exists. [32:14.670 --> 32:15.510] It is complex. [32:15.890 --> 32:20.290] And at the first glance, it looks impossible to develop. [32:20.550 --> 32:22.990] But I'm going to show you otherwise. [32:23.470 --> 32:32.170] I'll walk you through how I build similar software from scratch and give you a live demo of how it works. [32:33.450 --> 32:36.130] So, let's recap real quick. [32:36.750 --> 32:43.170] First, ATM is just computer in a metal case with plastic parts. [32:43.670 --> 32:55.170] If that case isn't secure enough and you can get to the USB ports, you can break out of the UI shell into operating system. [32:55.170 --> 33:06.530] If you can get into operating system, the ATM can still be vulnerable if the cash dispenser is connected to computer with USB. [33:06.810 --> 33:23.350] In that case, the dispenser can be unplugged or the cable can be cut and fitted with USB plug to connect it to a so-called small computer acting as the USB host. [33:24.910 --> 33:29.810] To empty cash dispenser, you need special software. [33:30.150 --> 33:43.310] The software can be found on dark web forums or developed by certain criminal groups for private use, or made by enthusiasts like us who research the topic, right? [33:45.530 --> 33:54.630] In short, physical access to the USB ports or cable means you can make the ATM spit out all the cash, as long as you have the right software. [33:54.990 --> 33:57.790] And that software is the real key. [33:58.050 --> 34:05.070] So, let's see how hard it is to recreate the software and I'll show you what I came up with. [34:09.350 --> 34:12.710] So, I was not planning to show you how to hack the real ATM, [34:18.530 --> 34:24.670] but United said they do not accept ATMs as a hand luggage. [34:25.610 --> 34:30.650] And I'm sponsoring the device delivery out of my pocket. [34:31.790 --> 34:35.110] If anyone is willing to sponsor next time, please let me know. [34:35.750 --> 34:45.310] So, purely for convenience, I'll walk you through how I hacked a dispenser and we'll see the demo. [34:45.310 --> 34:50.990] However, it is not going to be ATM or cash dispenser. [34:51.130 --> 34:52.750] Yes, it is going to be the real one. [34:53.210 --> 34:55.990] The real coin dispenser. [35:09.030 --> 35:09.650] Okay. [35:11.610 --> 35:17.650] And today I'm showing you just how easy or hard it is to write software for coin dispenser. [35:17.650 --> 35:19.590] You can buy anywhere. [35:19.590 --> 35:19.950] You can buy anywhere. [35:19.950 --> 35:29.990] We have exactly the same device on eBay and on the right image. [35:31.670 --> 35:33.870] We have exactly the same device here. [35:34.030 --> 35:40.690] And on the right image, you can see it installed in a grocery store fully loaded with coins. [35:41.030 --> 35:44.770] I took this picture before coming to the conference. [35:44.770 --> 35:52.790] So, I hacked this device for you today and I bought it on eBay with no software at all. [35:53.630 --> 36:04.290] So, I was in the same position as any researcher who has nothing but just a piece of electronic waste. [36:05.710 --> 36:13.830] And trust me, I started working with coin and cash dispensers back in 2005 and on several popular models. [36:15.650 --> 36:21.730] And if we are talking about the mass market today, the protocols and communication are more or less the same. [36:21.950 --> 36:26.570] And this kind of coin dispensary is available to anyone for around 100 bucks. [36:26.990 --> 36:28.610] Relatively easy to carry. [36:29.410 --> 36:29.970] Relatively. [36:30.170 --> 36:34.730] But the most important thing, they are everywhere. [36:34.730 --> 36:38.830] Anyway, this is a picture from the grocery store five minutes from my home. [36:41.430 --> 36:50.410] So, and I've noticed more and more of these things once I started going to HOPE. [36:50.590 --> 36:55.190] So, I hope this will be the next thing you'll notice after HOPE. [36:55.890 --> 37:02.570] These units are made for the entire world with versions supporting coins from outside the United States. [37:03.190 --> 37:05.410] Same story with cash dispensers. [37:05.990 --> 37:09.610] The brands are well known across the industry. [37:09.610 --> 37:18.190] If you're curious, each one of these holds about 66 bucks in quarters alone. [37:18.390 --> 37:23.490] And there are like six or seven of them in one grocery store. [37:24.450 --> 37:28.490] There are three grocery stores around the place where I live. [37:30.050 --> 37:32.930] And of course, the dispenser has a lock. [37:33.110 --> 37:36.190] So, you cannot just reach and grab coins. [37:36.450 --> 37:37.550] And it is heavy duty. [37:37.870 --> 37:40.950] And it is also bolted down to the surface. [37:40.950 --> 37:44.630] So, you cannot just take the whole thing and get away with it. [37:45.110 --> 37:53.210] And from the next picture, it looks like nobody can get a single coin from it. [37:53.210 --> 37:55.150] And I'll prove you that's not true. [37:55.290 --> 38:01.750] The most important vector after the lock mechanism here is the open USB port. [38:01.910 --> 38:07.050] It is currently connected with a serial port, which is even easier to hack. [38:07.230 --> 38:11.730] And as you can see from the image, that USB is open. [38:12.350 --> 38:19.250] Companies usually think, oh, open ports are too sophisticated to be a real threat. [38:19.250 --> 38:20.630] But guess what? [38:21.110 --> 38:23.150] For us, it is a challenge. [38:23.150 --> 38:28.910] So, let's see if we can hack it and create our own flusher device. [38:29.630 --> 38:32.390] So, we have around 20 minutes left. [38:33.390 --> 38:34.510] I think we're good. [38:35.910 --> 38:38.250] Finding software can be tricky. [38:38.490 --> 38:42.030] It took me a couple of days to track down software on a Russian website. [38:43.630 --> 38:45.310] Dedicated to vending machines. [38:45.310 --> 38:46.910] There was no SDK. [38:47.450 --> 38:49.710] There was a simple test program. [38:50.050 --> 38:51.250] And it worked. [38:51.610 --> 38:53.910] That alone made the job much easier. [38:54.090 --> 38:59.710] So, for any beginner hackers, I would recommend starting with something popular. [39:00.530 --> 39:03.250] This dispenser is a perfect example. [39:03.250 --> 39:07.150] If we have a program, we're already halfway there. [39:09.170 --> 39:11.650] We know dispenser works. [39:11.650 --> 39:16.530] But even with a program, it is not a real hack yet. [39:16.530 --> 39:24.870] It is still software with no API and nearly impossible to use for our own purposes. [39:25.310 --> 39:27.370] We need full control. [39:27.370 --> 39:31.070] But let's not ahead of ourselves. [39:31.490 --> 39:32.710] I tried running this program. [39:32.710 --> 39:36.170] And it had test interface for the coin dispenser. [39:38.570 --> 39:39.850] Beautiful dialogue. [39:40.170 --> 39:42.730] The kind every hacker would be happy to see. [39:43.310 --> 39:45.450] Looks pretty sophisticated, probably. [39:45.810 --> 39:52.710] But we don't need a copy of all its features to create our own flusher device. [39:52.710 --> 39:56.670] So, at the bottom, we see eight hyper columns. [39:56.910 --> 39:59.950] These represent stacks of coins. [40:00.350 --> 40:08.470] And there is functionality to read the data and check whether the coin status is low or not. [40:08.670 --> 40:10.630] All squares are green, which means everything is fine. [40:10.910 --> 40:14.470] And from the interface, we can actually dispense a coin. [40:14.470 --> 40:23.770] In the top left, there is a section labeled dispense test with a dropdown that shows the options we have. [40:26.330 --> 40:29.030] From this interface, we can dispense a coin. [40:29.150 --> 40:32.170] In the top left, there is a section dispense test. [40:33.730 --> 40:35.710] And there is dispense remaining. [40:39.630 --> 40:44.450] When hacking ATMs, dispense remaining is usually the one. [40:45.710 --> 40:51.770] And independent security researcher would, like, be the most curious about, right? [40:52.350 --> 40:55.570] And, spoiler, in this app, that option didn't work. [40:56.370 --> 40:59.750] The dispenser simply refused to process in. [40:59.750 --> 41:03.110] But it could dispense single coins just fine. [41:03.290 --> 41:06.910] In other words, the software I found online wasn't even fully compatible. [41:08.550 --> 41:11.670] So, how do we reverse engineer this? [41:11.810 --> 41:13.810] There are plenty of free tools for Windows Linux. [41:14.270 --> 41:19.850] Just type USB sniffer Windows, for example, and I found one. [41:20.710 --> 41:25.310] Then, in this tool, I select a so-called URB view. [41:25.570 --> 41:28.650] URB stands for USB request block. [41:28.650 --> 41:31.770] So, it shows request response blocks. [41:32.030 --> 41:35.790] Then, I opened the coin dispenser application and switched to the main view. [41:36.390 --> 41:43.010] And even without dispensing a coin, I could see request response blocks. [41:43.270 --> 41:48.690] And then, just hit the button in the software I found online. [41:48.690 --> 41:52.450] And we are getting our USB packets recorded. [41:53.850 --> 41:57.550] Slightly more sophisticated than that, but you get the point. [41:58.030 --> 42:02.550] Most importantly, this data can be exported in HTML. [42:02.570 --> 42:10.370] And if we can export that, we can feed it into LLM and ask for help. [42:10.730 --> 42:12.470] Here's what it looks like. [42:14.890 --> 42:19.230] So, we are basically asking LLM to do the heavy lifting for us. [42:19.770 --> 42:22.510] And on the next step... [42:23.350 --> 42:27.370] So, everything you see was done by LLM. [42:27.530 --> 42:32.150] We didn't do the heavy lifting or manually reverse engineer the protocol. [42:32.150 --> 42:39.470] All we did was capture the data, explain the context, and let the LLM tell us what it was. [42:39.630 --> 42:44.330] From there, we could recreate our own proof-of-concept application. [42:44.330 --> 42:51.370] And that POC looks something like you're about to see on the next slide. [42:54.350 --> 42:58.890] When you start developing your own flusher device or program. [42:59.210 --> 43:01.390] Here are my quick recommendations. [43:02.010 --> 43:08.730] We used Windows for USB sniffing because the vendor software was Windows only. [43:08.730 --> 43:13.070] But for development, I highly recommend switching to Linux. [43:13.450 --> 43:17.570] Because USB development work is usually easier there. [43:18.110 --> 43:21.610] Pick a simple language like Ruby or Python. [43:21.610 --> 43:23.530] I use Ruby because... [43:23.530 --> 43:25.450] Well, I wrote a book about it. [43:26.910 --> 43:29.330] And you'll see it on the next slide. [43:30.870 --> 43:33.790] And you can even download it for free. [43:34.590 --> 43:36.990] Start with simple POC first. [43:37.710 --> 43:44.130] Don't jump straight into programming on the embedded hardware. [43:44.670 --> 43:47.930] Let Linux handle the USB complexity for you. [43:49.850 --> 43:54.490] Use your USB request block logs and LLM replies together. [43:54.750 --> 43:55.430] Keep them organized. [43:55.430 --> 44:00.670] And you can quickly get working code even if you never hacked USB device before. [44:00.670 --> 44:06.650] Once you have even one or two commands working, you'll figure out the rest. [44:07.730 --> 44:11.210] Don't try to cover the whole protocol at once. [44:11.410 --> 44:13.530] Small wins will get you there. [44:14.550 --> 44:15.950] So here's my book. [44:16.030 --> 44:17.110] It is free, but... [44:17.730 --> 44:21.530] But you'll need to register on LeanPub. [44:22.210 --> 44:23.850] It's a publishing platform. [44:24.450 --> 44:26.330] It is about syntax for beginners. [44:27.110 --> 44:28.370] It is easy to find. [44:28.530 --> 44:30.030] Just type in Google or a piece of fun. [44:31.130 --> 44:32.070] When we have... [44:33.930 --> 44:41.290] When we have POC, we can essentially write our own program implementing as researchers. [44:42.210 --> 44:45.910] The same thing criminals have already done. [44:46.070 --> 44:51.750] However, unlike criminals, we simply drop software on USB stick and run it on a computer. [44:51.750 --> 44:54.430] We, as researchers, can push it further. [44:54.790 --> 45:02.850] Yeah, if you have POC, you could create similar software to run from a USB. [45:02.850 --> 45:11.030] However, from a research standpoint, it is more interesting to replicate an even more sophisticated attack. [45:11.030 --> 45:13.670] For example, creating a black box device. [45:14.130 --> 45:17.130] So that would be a standalone unit. [45:18.150 --> 45:19.910] A standalone unit. [45:20.130 --> 45:22.590] That doesn't require a computer at all. [45:22.810 --> 45:25.030] The device is the computer. [45:25.970 --> 45:30.410] And it is running in USB host mode. [45:30.410 --> 45:34.670] So you can plug it directly into the dispenser. [45:34.670 --> 45:41.950] And it will work even if the original computer is offline or not accessible. [45:43.210 --> 45:46.490] So why do criminals like black boxes? [45:46.490 --> 45:53.030] Because the operating system on the ATM might have protecting mechanisms. [45:53.030 --> 46:01.010] Even if you succeed with bad USB escape attack to the operating system, you might not be able to run anything. [46:01.310 --> 46:04.550] A black box bypasses all of that. [46:04.810 --> 46:07.050] It is completely independent tool. [46:07.290 --> 46:10.710] And besides, it is just more fun. [46:10.870 --> 46:14.890] Hacker culture has always been about building your own box, right? [46:15.170 --> 46:19.770] So, for example, Steve was doing build a blue box back in the day and wrote about it. [46:19.770 --> 46:25.370] We are just doing the modern twist, making a black box. [46:26.870 --> 46:32.350] So, for the black box, I will be using a computer. [46:34.130 --> 46:36.830] So, for the following reasons. [46:37.050 --> 46:37.870] USB host. [46:38.710 --> 46:41.790] Not all of the chips support USB. [46:42.070 --> 46:45.170] So, for example, Flipper Zero doesn't support USB. [46:45.370 --> 46:46.770] The price, it is only $35. [46:47.450 --> 46:49.330] The screen, it has screen. [46:49.330 --> 46:51.670] So, it is easy to debug. [46:51.910 --> 46:53.850] It has a keyboard. [46:55.330 --> 46:58.530] So, I can map multiple dispense commands. [46:58.750 --> 46:59.470] It has battery. [46:59.790 --> 47:01.450] And it is universal. [47:01.730 --> 47:09.610] I can work with multiple coin dispensers, implement multiple protocols, and so on and so forth. [47:09.610 --> 47:23.710] So, when it comes to programming this device and your own blank box, I would recommend skip premade firmware. [47:24.270 --> 47:27.190] There is a lot of stuff available. [47:27.190 --> 47:35.750] You can download ready to use firmware with lots of features like EVO MV5 for these devices. [47:36.050 --> 47:37.090] But it won't help. [47:37.250 --> 47:37.650] It would... [47:38.180 --> 47:45.370] I wouldn't recommend wasting your time trying to run out like script kitty kind of stuff. [47:45.370 --> 47:47.210] So, think small to big. [47:47.590 --> 47:51.750] Start with POC written in Python or Ruby. [47:52.030 --> 47:55.190] If you have POC ready, then it is easier. [47:55.190 --> 48:00.490] Then use ESPIDF, USB host examples. [48:00.670 --> 48:04.550] IDF stands for IoT development framework. [48:05.270 --> 48:09.510] So, the chip maker has USB host examples. [48:09.510 --> 48:12.830] It is not M5 brand that makes these computers. [48:12.830 --> 48:19.710] So, consider PI zero, Raspberry Pi zero as a fallback. [48:19.950 --> 48:23.050] It is Linux-based, easier, USB handling. [48:23.370 --> 48:27.070] I haven't tried that because I do not like easy things. [48:28.430 --> 48:29.950] So, log everything. [48:30.910 --> 48:38.750] Once this device is in host mode, you lose USB access and you cannot see the logs. [48:38.750 --> 48:43.390] So, I've started with building a logging system that writes to a file. [48:44.330 --> 48:45.150] Okay. [48:45.430 --> 48:47.470] So, two minutes left. [48:48.190 --> 48:50.370] We reached the demo. [48:50.830 --> 48:54.170] So, I'm connecting the dispenser. [48:55.110 --> 48:56.570] Here is the back. [48:57.030 --> 48:58.890] Here is the black box. [49:00.770 --> 49:02.650] Here is the dispenser. [49:03.110 --> 49:08.470] One USB cable connected to the slot. [49:10.630 --> 49:11.510] Okay. [49:12.350 --> 49:13.650] Turning on. [49:15.830 --> 49:17.290] Connecting to USB. [49:17.630 --> 49:20.230] It says USB host in five seconds. [49:21.270 --> 49:29.810] And once we are in USB host, it says connected USB device, found coin dispenser. [49:29.810 --> 49:33.050] And I'm clicking one button here. [49:34.110 --> 49:36.430] It dispense one coin. [49:37.230 --> 49:40.310] I can dispense multiple coins. [49:44.410 --> 49:47.370] Or I can dispense all of them. [49:47.550 --> 49:48.190] Just like that. [49:56.510 --> 49:56.970] All right. [49:57.110 --> 49:57.410] Thank you. [49:58.330 --> 49:58.640] Okay. [49:58.950 --> 49:59.970] It will keep on dispenser. [50:14.140 --> 50:14.760] Okay. [50:26.730 --> 50:27.350] Okay. [50:28.190 --> 50:28.950] Something like that. [50:32.730 --> 50:33.670] Is that it? [50:33.970 --> 50:34.170] Yeah. [50:35.290 --> 50:35.890] Something like that. [50:35.990 --> 50:40.010] So, I actually have multiple modes here. [50:40.010 --> 50:44.250] There is a quick dispense or a normal dispense. [50:44.670 --> 50:47.070] It depends on the type of packet. [50:47.290 --> 50:49.810] So, I'm curious if anyone has any questions. [50:50.730 --> 50:55.410] It's not a remote thing with Wi-Fi or empty ether. [50:56.910 --> 50:57.190] Okay. [50:57.490 --> 50:57.590] Yeah. [50:57.950 --> 51:00.710] So, the question is if it can be done remotely. [51:00.910 --> 51:01.330] So, yes. [51:01.530 --> 51:02.550] It can be done remotely. [51:02.890 --> 51:06.050] This device can be connected and then you'll just go away. [51:06.050 --> 51:08.250] And this has Wi-Fi. [51:08.670 --> 51:13.470] So, you can connect and go away like a thousand miles away. [51:13.730 --> 51:15.630] And dispense the cache. [51:16.790 --> 51:17.390] Yeah. [51:17.650 --> 51:17.750] Okay. [51:17.930 --> 51:18.490] Next question. [51:19.070 --> 51:21.510] Would you follow Barbie Jacks? [51:25.720 --> 51:26.640] No. [51:27.180 --> 51:27.220] Actually. [51:27.700 --> 51:28.480] Okay. [51:29.720 --> 51:29.960] Cool. [51:30.720 --> 51:38.320] Could you theoretically access the OS of ATM through the contactless system? [51:40.540 --> 51:45.700] Through contactless system, you mean by network? [51:46.580 --> 51:47.420] The tap. [51:48.400 --> 51:49.160] The tap. [51:49.160 --> 51:49.380] The tap. [51:49.620 --> 51:51.880] So, I don't think so. [51:53.600 --> 51:54.180] Yeah. [51:54.440 --> 51:56.940] So, last time I checked, I haven't gotten too far. [51:59.860 --> 52:08.140] So, a year ago, some Chinese researchers clarified that they use the quantum computer to break a 22-bit RSA encryption. [52:08.720 --> 52:14.360] I had a lot of friends in the banking industry that were very nervous because that somehow I can relate it to ATMs. [52:14.520 --> 52:18.280] There are any 22-bit ones in encryption used at ATM. [52:18.620 --> 52:21.040] I've never heard of 22-bit RSA encryption. [52:22.100 --> 52:34.920] So, when it comes to quantum computing, the problem is that quantum computers do errors and we do not have reliable quantum chips. [52:35.120 --> 52:37.080] We have quantum chips, but they are not reliable. [52:37.320 --> 52:43.300] So, I doubt that one day can be reliable enough, to be honest. [52:43.300 --> 52:46.760] So, that's my personal opinion. [52:50.630 --> 52:57.210] Question about the service code on the magnetic stripe of a credit card. [52:57.410 --> 53:03.030] If you change that to not check for the PIN, would that work? [53:03.330 --> 53:05.490] Would it disable the secondary verification? [53:08.690 --> 53:24.570] Second track, if you change the service code, I think it won't change anything because service code is just the data that you can change it and you can try it out, actually. [53:24.570 --> 53:29.250] If you read your own credit card, then replace the service code. [53:29.250 --> 53:31.530] The card should work, actually. [53:31.990 --> 53:39.230] Yeah, because service code is not a very important piece. [53:39.470 --> 53:49.410] And even if you change it to do not check PIN, I doubt that it is going to work because there are standards and there are substandards. [53:52.110 --> 53:54.330] Probably, it is not going to work. [53:55.050 --> 53:56.250] Okay, last question. [53:56.250 --> 53:56.290] Question. [53:56.910 --> 54:00.210] Is the magspite hacking, is that still relevant? [54:00.690 --> 54:03.530] With modern click cards that have chip and PIN? [54:04.310 --> 54:07.670] We have magnetic stripe for backwards compatibility. [54:09.290 --> 54:14.870] In the United States, probably we won't be able to do that now. [54:15.270 --> 54:19.830] But in some countries, I think it is still relevant. [54:21.410 --> 54:23.790] Okay, last question, because we don't know how to... [54:23.790 --> 54:28.250] I believe the chip, if you try it to ring fires, then it allows you to... [54:28.930 --> 54:30.030] Oh, okay. [54:30.890 --> 54:32.150] It's your time. [54:33.770 --> 54:34.290] Yeah. [54:36.010 --> 54:37.450] There's actually now... [54:37.450 --> 54:38.630] Okay, thank you everyone. [54:39.110 --> 54:39.550] Thank you. [54:40.170 --> 54:40.430] Thank you. [54:40.430 --> 54:40.450] Thank you. [54:41.110 --> 54:42.790] Thank you.