POS keys

26 views
Skip to first unread message

Chhil

unread,
Oct 25, 2009, 12:57:11 AM10/25/09
to Tod Myer, jpos-...@googlegroups.com
Hello Tod,

Not too familiar with POS device setup so I am redirecting your
question to the jpos mailing list. People on the list have great
knowledge and you should get an appropriate response. Please subscribe
to the mailing list and post questions there.

You should have a device manual that should guide you through the setup.

-chhil

On Oct 25, 2009, at 9:08 AM, Tod Myer <knoctur...@gmail.com> wrote:

> hello i seen your post on groups good i was doing some research on ZMK
> and TMK for POS terminals you seem to have knowledge. i was wondering
> for the terminals on the POS im going to be doing a demenstration and
> i wanted to know where and how the ZMK and or TMK could be found on
> the terminal.

Mark Salter

unread,
Oct 25, 2009, 6:58:22 AM10/25/09
to jpos-...@googlegroups.com
> On Oct 25, 2009, at 9:08 AM, Tod Myer <knoctur...@gmail.com> wrote:
>
> i was wondering
> for the terminals on the POS im going to be doing a demenstration and
> i wanted to know where and how the ZMK and or TMK could be found on
> the terminal.

All keys used to protect transactions will not - I would hope - be
'found' on the terminal.

I would think keys would be kept in memory, not persisted anywhere and
out of 'reach' of an api the terminal would provide.

If the keys were available, then the benefit of the cryptography would
be eliminated.

What are you trying demonstrate?

--
Mark

Chhil

unread,
Oct 25, 2009, 7:48:50 AM10/25/09
to jpos-...@googlegroups.com
Here is additional info that was emailed to me by Tod.
 
'the device manual wil never post this kind of info to find the ZMK for protection but im doing something in fornt of audience in few weeks and i want to show how insecure terminal are really with getting this kind of info some criminals can steal information'
-chhil

Mark Salter

unread,
Oct 25, 2009, 4:30:44 PM10/25/09
to jpos-...@googlegroups.com
Tod Myer <knoctur...@gmail.com> wrote to Chhil:-

>
> i want to show how insecure terminal are really with getting
> this kind of info some criminals can steal information'

Here lies the key...

Having to ask how to demonstrate such weaknesses, does - I think -
highlight where some weakness lies.

There are papers indexed by google covering the problems with POS
devices, one such paper:-

http://www.hackerfactor.com/papers/cc-pos-20.pdf

...made an interesting skim, including 'magic' key combinations for some
terminals to reset passwords. Primarily to gain access to the stored
transactions - only brief mentions of POS storage medium and protection.


--
Mark

Reply all
Reply to author
Forward
0 new messages