April 23, 2006
Payment News: Redspin, an independent auditing firm based in Carpinteria, Calif., suggests that additional enhancements made to ATM networks in correlation with mandated Triple DES upgrades have introduced new vulnerabilities. According to Redspin, unencrypted ATM transaction data is floating around bank networks, and bank managers are completely unaware of it. The PIN is encrypted, but because more banks now run ATMs through their own (online) computer networks - before the information goes on to a centralized processor - other information is not. Having ATMs on bank networks instead of dedicated lines is much more economical, but it can greatly increase security exposure.