O'Reilly logo

Hacking Point of Sale: Payment Application Secrets, Threats, and Solutions by Slava Gomzin

Stay ahead with the world's most comprehensive technology and business learning platform.

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, tutorials, and more.

Start Free Trial

No credit card required

Introduction

False facts are highly injurious to the progress of science, for they often long endure; but false views, if supported by some evidence, do little harm, as everyone takes a salutary pleasure in providing their falseness; and when this is done, one path towards error is closed and the road to truth is often at the same time opened.

—Charles Darwin

Nearly five million point-of-sale (POS) terminals process about 1,500 credit and debit card transactions every second in the United States alone.1,2,3 Most of these systems, regardless of their formal compliance with industry security standards, potentially expose millions of credit card records—including those being processed in memory, transmitted between internal servers, sent for authorization or settlement, and accumulated on hard drives. This sensitive data is often weakly protected or not protected at all. It is just a matter of time before someone comes along and takes it away. Valuable cardholder information can be stolen from many places in a merchant's POS system, such as unprotected memory, unencrypted network transmission, poorly encrypted disk storage, card reader interface, or compromised pinpad device.

There are more than one billion active credit and debit card accounts in the United States.4 It is not surprising that such cards have become an attractive target for hackers. In 2011, payment card information was involved in 48% of security breaches—more than any other data type.5 In 2012, POS terminals and ...

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, interactive tutorials, and more.

Start Free Trial

No credit card required