Photonews Logo Photonews logo
  • Home
  • Pakistan
    • Punjab
    • Sindh
    • Khyber Pakhtunkhwa
    • Azad Jammu Kashmir
    • Balochistan
    • Gilgit – Baltistan
  • World
  • Business
  • Entertainment
  • Videos
    Hunger Games Sunrise on the Reaping trailer
    EntertainmentVideos

    Hunger Games Prequel Trailer Sparks Fan Frenzy Over 10-Second Silent Cliffhanger

    November 21, 2025 3 Min Read
    Billie Eilish Elon Musk
    EntertainmentVideos

    Billie Eilish Criticizes Elon Musk, Calls Billionaire Wealth “Pathetic”

    November 14, 2025 3 Min Read
    Gen V Season 2 trailer
    Videos

    Gen V Season 2 Trailer Cast, Plot, Premiere Details

    July 26, 2025 3 Min Read
  • Sports
  • Technology
  • Offbeat
  • Blog
  • Contact
Reading: Hackers turn mobile payment readers into crime tools
PhotoNews PakistanPhotoNews Pakistan
Font ResizerAa
Search
  • Home
  • Pakistan
    • Punjab
    • Sindh
    • Khyber Pakhtunkhwa
    • Balochistan
    • Azad Jammu Kashmir
    • Gilgit – Baltistan
  • World
  • Business
  • Entertainment
  • Videos
  • Sports
  • Technology
  • Offbeat
  • Blog
  • Contact
Have an existing account? Sign In
Follow US
© 2022 Photonews. All Rights Reserved.
PhotoNews Pakistan > Tech > Hackers turn mobile payment readers into crime tools
Tech

Hackers turn mobile payment readers into crime tools

Web Desk
By Web Desk Published August 7, 2015 4 Min Read
Share
SHARE

Hackers on Thursday showed how to turn the latest model Square mobile payments readers into crime tools.

Independent security researchers and self-described hackers Alexandrea Mellen and John Moore were at the Black Hat computer security conference in Las Vegas to demonstrate hacks targeting Square software or the dongle that plugs into audio jacks to read credit card magnetic strips.

“We converted a Square Reader into a credit card skimmer in under 10 minutes,” Mellen told AFP.

“Any layman could do it.”

She said the hardware hack can be done with simple tools including a screwdriver, wire and soldering iron, and that most of the time involved was spent carefully popping open the reader that Square provides to users of its mobile payments application.

Inside the reader a wire is soldered between two points to bypass an encryption chip.

After that, unscrambled information from swiped credit cards can be collected, essentially stolen, to be sold on a black market or abused in other ways, according to Mellen.

– Playback attack – 

On the software side, Moore provided details about a mobile application that enables a “playback attack” that lets merchants charge customs for bogus transactions in the weeks or months after legitimate purchases are consumated.

“We find this troubling because unless you are closely watching your credit card statements, you might not notice,” said Moore, a recent Boston University graduate on his way to a job with Internet giant Google.

Moore said that he and Mellen, also a recent graduate of Boston University, targeted the Square Reader because the company headed by Twitter co-founder Jack Dorsey is a leader in a booming trend of using smartphones for real-world financial transactions.

“Square, given its size and a bug bounty program, is no easy target,” Moore said.

“We suspect the vulnerabilities we found in Square might easily apply to other mobile point-of-sale service providers.”

An array of major Internet firms offer cash rewards, or bounties, for software bugs that can be exploited by hackers.

New hardware and software is quickly being fielded in the competitive mobile payments market, with pressure on to keep plug-ins compact and inexpensive, according to Moore.

Mobile payments software needs to be compatible with a variety of mobile phones, which can’t be secured as easily since they are used for many more purposes than making purchases.

Moore referred to the combination of factors as “a recipe for disaster.”

The hackers said they made their findings available to San Francisco-based Square but are not convinced fixes are planned.

Moore said Square told him they were watching for the kinds of bogus transactions that could be generated by “playback” hacks.

“They have the information to see the swipe of the credit card was taken weeks ago,” Moore said.

“They have chosen to monitor the behavior instead of preventing it.” (AFP)

Share This Article
Facebook Twitter Pinterest Whatsapp Whatsapp LinkedIn Email Copy Link Print
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Advertisement

HBL Saving Made Easy
HBL Saving Made Easy

Recent Posts

Sohail Afridi CM KP

KP CM Dares Federal Government to Impose Governor’s Rule

BYD revenue 2024 Tesla

 BYD’s Sales Decline for Third Straight Month

One UI 8.5 block apps excessive ads

One UI 8.5 Feature to Block Apps with Excessive Ads

Post Archives

More Popular from Photonews

Verstappen qualifying
Sports

Max Verstappen’s Bid for Fifth F1 Title Suffers Setback

2 Min Read
Celina Jaitly children
Entertainment

Celina Jaitly Requests Media to Protect Her Children’s Privacy Amid Legal Case

2 Min Read
Eminem vs Real Housewives Legal Battle
Entertainment

Eminem’s ‘Shady’ Trademark Clash With Real Housewives Stars Intensifies

2 Min Read
Sports

Faf du Plessis Joins PSL After Announcing IPL Retirement

Former South African cricket captain Faf du Plessis has confirmed his participation in the upcoming Pakistan…

November 29, 2025
Sports

Pakistan’s Muhammad Waseem Defends WBA Gold World Title in Lahore

Pakistani professional boxer Muhammad Waseem successfully defended his World Boxing Association Gold World Bantamweight title against…

November 30, 2025
Business

All Bank Branches Open Saturday, Nov 29 for Tax Payments

The State Bank of Pakistan has issued a directive requiring all commercial bank branches to operate…

November 28, 2025
Pakistan

FAFEN Reports Campaign Violations, Results Transparency in Recent By-Elections

The Free and Fair Election Network has released its observation report for the November 23 by-elections.…

November 29, 2025
PhotoNews Pakistan

Always Stay Up to Date

Subscribe to our newsletter to get our newest articles instantly!

Categories

  • World
  • Pakistan
  • Punjab
  • Sindh
  • Khyber Pakhtunkhwa
  • Balochistan
  • Azad Jammu Kashmir

 

  • Top News
  • Business
  • Entertainment
  • Sports
  • Videos
  • Tech
  • Offbeat
  • Blog

© 2024 Phototnews
All Rights Reserved.

Welcome Back!

Sign in to your account

Lost your password?