Follow Us

ATM vendor threatens security firm over flaw

Researcher stopped from revealing all at security conference.

A security researcher has been barred from making a presentation on security flaws in bank cash machines after an ATM vendore threatened legal action.

Juniper's staff security researcher Barnaby Jack had been set to deliver a talk later this monthmentitled Jackpotting Automated Teller Machines at the Black Hat security conference in Las Vegas. But Jack abruptly asked conference organizers to pull the talk, according to Black Hat Director Jeff Moss. The talk has also been pulled from Black Hat's sister conference, Defcon, he added.

News of the cancellation was first reported by security news site Risky.Biz.

Juniper said that it made Jack withdraw the talk after an ATM vendor expressed concern that Jack's research could be misused. "Considering the scope and possible exposure of this issue on other vendors, Juniper decided to postpone Jack's presentation until all affected vendors have sufficiently addressed the issues found in his research," Juniper said.

Neither Juniper nor Moss would name the ATM maker that Jack had been studying, but Juniper says it is reaching out to other vendors as well to share information.

According to Jack's description of the talk on the Defcon site, he had found a vulnerability in the underlying software used to run "a line of popular new model ATMs."

"I've always liked the scene in Terminator 2 where John Connor walks up to an ATM, interfaces his Atari to the card reader and retrieves cash from the machine," the Juniper researcher wrote. "I think I've got that kid beat."

The presentation was supposed to "explore both local and remote attack vectors, and finish with a live demonstration of an attack on an unmodified, stock ATM."

According to a source familiar with the situation, Jack had been working with the vendor for the past nine months, but the ATM maker grew concerned that Jack's talk would lead to some bad publicity.

Black Hat talks have been pulled in the past because of legal threats. In 2005 researcher Michael Lynn was told by his employer, Internet Security Systems, to pull a Black Hat talk on router vulnerabilities after Cisco Systems threatened to sue him. Lynn quit and gave the talk anyway -ithin months, he was hired by Juniper.






Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Business continuity and disaster recovery for SMBs

Business continuity (BC) and disaster recovery (DR) are major issues for all businesses, with...

Download Whitepaper

How to get your business ready for the 2012 Olympics

IT Manager: "I'm working on contingency plans to ensure that we can keep the business running...

Download Whitepaper

10 things you have to do today to protect your business in 2012

The next twelve months will be like a fair ground ride: rotation, uncertainty and mild...

Download Whitepaper

Data protection strategies in the age of the iPad

In today’s target-rich environment, CISOs must focus on defending the content of files and...

Download Whitepaper

Techworld UK - Technology - Business

Techworld Awards

Techworld Awards Winners 2011


Learn who the winners of this year's Techworld Awards are. Video footage coming soon...

Find out more
Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

Site Map

* *