about the past For five years, security researcher Matt Birch has investigated the complex, high-stakes world of ATM security. Even a minor software flaw can put cash, customer data, and financial networks at risk. As Birch examines the systems that power ATMs and uncovers weaknesses in widely used security products, he is raising concerns about overlooked vulnerabilities in ATMs—and the broader risks posed when the same software is deployed across multiple critical industries.
At the Black Hat and DEF CON security conferences in Las Vegas this month, Birch presented nine findings, including a vulnerability in CryptoPro Secure Disk, disk-encryption and preboot-authentication software. Exploiting the flaw could allow an attacker to bypass CryptoPro’s integrity checks and gain complete access to an encrypted device.
Developed by German software company CryptWare, CryptoPro is sold to ATM manufacturers and is used in some cash machines, including as part of Diebold Nixdorf’s Vynamic Security Suite. The company also markets CryptoPro as a security solution for embedded-device manufacturers and large organizations running Microsoft Windows. Its broad deployment illustrates the software supply-chain challenges that emerge when a vulnerability affects products used across multiple industries.
“ATMs are what set me on this path, but I think these discoveries could have an even bigger impact beyond that,” Birch says. “When you look at it from an ATM and financial-network perspective, there are a lot of layers. As a result, I think systems are implemented in a certain way and there’s limited technical insight. Bugs can be overlooked or left unaddressed.”
Uwe Saame, managing director of CryptWare, told WIRED that the company patched all nine vulnerabilities in two phases: CryptoPro version 7.7.2 was released in early November, followed by version 7.7.3 in early December. Birch said CryptWare was prompt and cooperative throughout the responsible-disclosure process and confirmed that the vulnerabilities had been fixed. Although CryptWare does not appear to have published detailed update notes, Birch believes the company distributed patch information to its customers.
Diebold Nixdorf spokesperson Michael Jacobsen told WIRED that only two of the nine vulnerabilities affected the company’s Vynamic Security Hard Disk Encryption product, which incorporates CryptoPro software. Jacobsen said Diebold Nixdorf released fixes for those issues in December, adding that the vulnerabilities could not be exploited independently to compromise Diebold Nixdorf ATMs.
Across ATMs, embedded devices, and enterprise security systems, applying software patches can be just as challenging as developing them. After a software vendor releases a fix, companies that integrate the product may need to create customized updates. Customers must then receive, approve, and install those patches—often on systems operating in the field that cannot be easily paused or updated.
Jacobsen described Diebold Nixdorf’s general response process: “Once a security issue is identified, Diebold Nixdorf assesses the impact, identifies the affected products and configurations, and develops the necessary updates through our product security and engineering processes. We then notify affected customers and provide updates through our standard software distribution channels, including the Global Security Portal, if applicable. For deployed ATMs, updates are delivered to the operating system and change-management processes.”
Security researchers have warned for decades about the risks of relying on “security through obscurity”—the practice of hiding or restricting access to software rather than thoroughly testing and securing it. IoT manufacturers and companies in critical sectors, including financial services and medical-device manufacturing, have made progress in improving transparency and encouraging security updates. But Birch says the rise of artificial intelligence makes it even more important to examine specialized security products. AI tools can help researchers and attackers analyze software and identify vulnerabilities without requiring deep expertise in a particular industry.
“AI really blows away the model of ambiguity,” Birch says. “You no longer need to fully understand how something works to move forward and potentially have a big impact.”
Source: www.wired.com


