Information Security News mailing list archives

Update: Credit card terminals have used same password since 1990s


From: InfoSec News <alerts () infosecnews org>
Date: Fri, 24 Apr 2015 11:38:07 +0000 (UTC)

http://www.computerworld.com/article/2913808/malware-vulnerabilities/credit-card-terminals-have-used-same-password-since-1990s.html

By Martyn Williams
IDG News Service
April 23, 2015

While retailers battle breaches that have resulted in tens of millions of credit card numbers stolen, word comes from the RSA Conference in San Francisco that a major vendor of payment terminals has been shipping devices for over two decades with the same default password.

The vendor wasn't named by the researchers, David Byrne and Charles Henderson, but they did disclose the password: 166816.

A Google search reveals that's the default password for several models of credit card terminal sold by Verifone, a Silicon Valley-based vendor that says it connects 27 million payment devices and has operations in 150 countries.

In a statement on Thursday, Verifone acknowledged that all its devices in the field came with the same default password, which the company said was Z66831. Over the years, the password has become known and can be found on the Internet along with instructions for programming terminals, Verifone said.

[...]



--
Evident.io - Continuous Cloud Security for AWS.
Identify and mitigate risks in 5 minutes or less.
Sign up for a free trial @ https://evident.io/


Current thread: