Тёмный

Teardown of an Ingenico iWL250 Payment Terminal 

Mark Furneaux
Подписаться 46 тыс.
Просмотров 17 тыс.
50% 1

A look into the physical security techniques used to protect the digital secrets in a relatively modern wireless credit card POS terminal.
I have a second channel:
/ @markfurneaux2659

Опубликовано:

 

7 сен 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 23   
@WizardTim
@WizardTim 2 года назад
Those pieces of PCB material with a step machined in that are soldered on top of the legs for the connectors are very likely just to protect against someone drilling a hole in the back case and directly probing the connections to the card readers and thus stealing people’s card details.
@f83jg79
@f83jg79 2 года назад
The other slots on the modem board are likely for a SAM card or a similar smartcard in the standard ID-000 size used for additional authentication.
@jagdtigger
@jagdtigger 2 года назад
8:04 Its a fallback if the chip malfunctions on the card, i know because i had one if my cards fail in this way.
@donpalmera
@donpalmera 2 года назад
I doubt the key sram is in the PCB material. It'll be in one of the special SoC/Microcontrollers. The is a CCC (I think) presentation about extracting the keys from cable TV boxes that details breaking down similar setups (albeit with less tamper proofing). That guy eventually worked out enough of the chips to load a trojan onto the chip and extract the keys.
@jaro6985
@jaro6985 2 года назад
They might have got rid of it due to the 3G shutdown. Any sort of 3G comms equipment is basically worthless at this point. The devices I use seem to occasionally self-trip their tamper detection mechanism, rendering them useless. They also don't use epoxy potting, as you say, expensive to produce. I think it just relies on the numerous serpentine traces. There may be other small things like light sensors or accelerometers as well.
@jacobs8
@jacobs8 2 года назад
Is the device essentially broken after dismantle?
@jaro6985
@jaro6985 2 года назад
@@jacobs8 Yes. Only the manufacturer is able to reload the wiped volatile keys onto the device and re-enable it for use.
@unicodefox
@unicodefox Год назад
@@jaro6985 how does the device behave when it's been tripped? does it just die with no signs of life? show an error? fail transactions?
@jaro6985
@jaro6985 Год назад
@@unicodefox It sends an error to the user that shows its been physically tampered, and is unusable. Only the manufacturer is able to fix it at that point.
@devicemodder
@devicemodder 8 месяцев назад
​@jaro6985 what about the android based ones? Cause I have one that runs android 6.0.1, and I'm trying to hack it to install apk files as I want to get mine running DOOM.
@nickf3242
@nickf3242 2 года назад
I found this very fascinating. Thank you so much for sharing:)
@lucafrondoni
@lucafrondoni 2 года назад
Super awesome video! Love it! Looking forward for more content like this :)
@Stoner916sac
@Stoner916sac Год назад
It looks like one of them at least was an antenna. The other might be too for things like nfc wireless payments. For things like google pay and apple pay and physical cards
@chloevlog16
@chloevlog16 3 месяца назад
thank you for sharing your video. where did you get the screwdriver? thank you
@awuah
@awuah Год назад
Is it possible to use the inbuilt printer outside of the device itself. So at least there can be some use for it ??
@patricia739
@patricia739 Год назад
@MarkFurneaux How do you fix the port if it won’t charge with the wire in the port? It seems loose? It’s this same model. Please help! 🙏🏻 Thank you. 👍🏻
@maciejciurysek4953
@maciejciurysek4953 10 месяцев назад
Is it possible to convert this terminal into a thermal printer?
@saphaswbtw724
@saphaswbtw724 2 года назад
Awsome so interesting
@BenCampbell41573
@BenCampbell41573 Год назад
only one question has to be asked can it run doom
@FlCoastalcaster
@FlCoastalcaster 2 года назад
Hi your videos are super helpful, do you have discord ? I would like to contact you on that platform as I have some questions regarding my pc storage
@gabest4
@gabest4 2 года назад
I can't see why it should have any secrets, it can read it from the smart card each time there is a payment, the bank can hide it there. edit: or the card could do the communication itself and the terminal just relays the encrypted messages.
@INIUOfficial
@INIUOfficial 2 года назад
Hello Mark, we would like to invite you to try our products. Could you please send us an email?
Далее
Square Terminal Teardown & Tamper Testing (Part 1)
56:25
Why Credit Card Fraud Hasn't Stopped In The U.S.
12:59
Просмотров 785 тыс.
DOS Games On An Arduino?!
10:58
Просмотров 123 тыс.
Credit card terminal extreme teardown
18:24
Просмотров 48 тыс.
Using Credit Card Skimmers
14:42
Просмотров 1,1 млн
EEVblog #687 - EFTPOS PIN Pad Terminal Teardown
26:20
Просмотров 123 тыс.
iWL250 Out of the Box
3:07
Просмотров 10 тыс.
Booting the Raspberry Pi 4 with an External SSD
5:34