
At the recent Black Hat security conference in Las Vegas, hacker Adam Laurie revealed a flaw in the Square credit card reader hardware/software that allows the injected emulation of credit card data to fraudulently obtain funds. This discovery highlights the importance of robust financial security.
He inserted a different wire into the iPad’s headphone jack, so the software thought a dongle was plugged in. Then he modified some software he had already written for translating magnetic stripe data (we mentioned he’s a hacker, right?) and then typed in a credit card number. The data was converted to sound, and the app read the information as if a real card had been swiped. Then he could deposit funds into his Square account, which are delivered within a day.
The hack works because the dongles do not encrypt the data, which is sent to the iPhone as audio. It is expected that Square will correct this with the release of new encrypted hardware.
Via Popsci.