{"id":3788,"date":"2015-08-05T10:29:17","date_gmt":"2015-08-05T14:29:17","guid":{"rendered":"https:\/\/www.bu.edu\/federal\/?p=3788"},"modified":"2015-08-13T10:36:25","modified_gmt":"2015-08-13T14:36:25","slug":"hip-to-hacking-square","status":"publish","type":"post","link":"https:\/\/www.bu.edu\/federal\/2015\/08\/05\/hip-to-hacking-square\/","title":{"rendered":"Hip to Hacking Square"},"content":{"rendered":"<h2>ENG alums\u2019 class project earns spot at Black Hat USA 2015<\/h2>\n<div class=\"banner-container\"><img loading=\"lazy\" src=\"http:\/\/www.bu.edu\/today\/files\/2015\/08\/h_butoday_register.02-640859785726568a44d6465746406445.jpg\" class=\"banner\" alt=\"Square Reader\" height=\"367\" width=\"550\" \/><\/p>\n<p class=\"caption\"><em>The Square Reader mobile point-of-sale device is the small white object plugged into the iPad Mini in this photo. Photo courtesy of Square Inc.<\/em><\/p>\n<\/div>\n<p>The <a href=\"https:\/\/squareup.com\/reader?gclid=CjwKEAjwxYGuBRCtoqjkrIPDqDwSJAAnd-rCAb4Pv0HFbFkgoS_IBkS3dD2rllI0U4HE_RnrULuHARoC1Sbw_wcB&amp;pcrid=45554788177&amp;pdv=c&amp;pkw=square+reader&amp;pmt=e\">Square Reader<\/a>, used by millions of businesses in the United States, could at one point be converted in less than 10 minutes into a skimmer that could steal and save credit card information, according to three recent ENG grads. Their findings will be presented today at the <a href=\"https:\/\/www.blackhat.com\/us-15\/\">Black Hat USA 2015 <\/a>cybersecurity conference in Las Vegas.<\/p>\n<p>Computer engineering grads Alexandrea Mellen (ENG\u201915), John Moore (ENG\u201915), and Artem Losev (ENG\u201915) discovered the vulnerability last year in a project for their <a href=\"http:\/\/www.bu.edu\/riscs\/engec521\/\">Cybersecurity class<\/a>, taught by <a href=\"http:\/\/www.bu.edu\/ece\/people\/faculty\/o-z\/ari-trachtenberg\/\">Ari Trachtenberg,<\/a> an ENG professor of electrical and computer engineering.\u201cThe beauty of the hardware attack itself was that there would be no sure way to know if it was the merchant with the Square Reader that actually took your information,\u201d Mellen says.<\/p>\n<p>The trio also found that Square Register software could be hacked to enable unauthorized transactions at a later date.<\/p>\n<p>\u201cThe merchant could swipe the card an extra time at the point of sale,\u201d says Moore. \u201cYou think nothing of it, and a week later when you\u2019re not around, I charge you $20, $30, $100, $200\u2026 You might not notice that charge. I get away with some extra money of yours.\u201d<\/p>\n<p>Moore, who was valedictorian of his ENG class, says the three reported the vulnerabilities to <a href=\"https:\/\/squareup.com\/?gclid=CjwKEAjwxYGuBRCtoqjkrIPDqDwSJAAnd-rCnPAaIR1FF42FKuaHav7hUMpZPNiDtROTzkKGSHjW_RoCKEXw_wcB&amp;pcrid=44200438177&amp;pdv=c&amp;pkw=register+app&amp;pm=true&amp;pmt=b\">Square<\/a> last fall, and the company quickly moved to close them. Square also sent Moore a $500 \u201cbounty\u201d for the software hack.<\/p>\n<p>Moore says there is no evidence that either of the vulnerabilities has been used to scam credit card holders, but warns that the group\u2019s findings raise red flags for the fast-growing mobile commerce field in general.<\/p>\n<p>\u201cThis isn\u2019t just about Square,\u201d he says. \u201cOver the past six years, mobile point-of-sale has really taken off\u2026and all of these providers are offering new hardware and software to process payments, and customers are trusting their credit card information to new devices that haven\u2019t been tested as much as traditional point-of-sale devices. They\u2019re interacting with the personal cell phone of the merchant in a lot of cases. There\u2019s just a lot going on.\u201d<\/p>\n<p>The three turned their class project into a paper that submitted to the Black Hat conference and waited two months before learning it had been accepted, which was a huge thing, \u201cbecause Black Hat is the premiere information security conference in the world,\u201d Mellen says. The weeklong event draws everyone from hackers to government officials. Mellen and Moore will give <a href=\"https:\/\/www.blackhat.com\/us-15\/briefings.html#mobile-point-of-scam-attacking-the-square-reader\">a 25-minute presentation<\/a>\u00a0on their work at the conference, where they get free passes to the briefings at the Mandalay Bay Resort and Casino, worth $2,195.<\/p>\n<p><img loading=\"lazy\" src=\"http:\/\/www.bu.edu\/today\/files\/2015\/08\/headshots.jpg\" alt=\"From left, Alexandrea Mellen, Photo by Dmellendesigns, John Moore, Photo by Chris Welch Photography, Artem Losev, Photo by Alexandrea Mellen\" class=\"size-full wp-image-83588\" height=\"367\" width=\"550\" \/><br \/>\n<em><span style=\"line-height: 1.5;\">Alexandrea Mellen (from left) (photo by Dmellendesigns), John Moore (photo by Chris Welch Photography), and Artem Losev (photo by Alexandrea Mellen).<\/span><\/em><\/p>\n<p><span style=\"line-height: 1.5;\">Trachtenberg says students have derived papers from class projects before, but none were undergraduates and none of the conferences have had the stature of Black Hat. \u201cThis is a conference with a very high impact,\u201d he says. \u201cThere are 10,000 security professionals that pay a lot of money to come to this conference and listen to the latest interesting security research.\u201d<\/span><\/p>\n<p>Vulnerabilities in payment software present more of an inconvenience than a financial risk, he says, at least for consumers who check their credit card statements regularly, because losses are generally covered by the credit card companies.<\/p>\n<p>\u201cThe bigger reason to be scared is that Square had security in mind from the very beginning and designed these to be secure,\u201d he says. \u201cThey should have known better than to have left these kind of holes. It kind of bodes poorly for other vendors who might not be taking security quite as seriously and what kind of problems they might be having.\u201d<\/p>\n<p>Square doesn\u2019t disclose how many businesses use its software or how much revenue it derives by taking a small percentage of their transactions, but <a href=\"http:\/\/www.bloomberg.com\/\">Bloomberg<\/a> quoted one analyst as estimating that the company took in $300 million in merchant fees in 2013.<\/p>\n<p>Mellen and Moore say they made Square aware of the two potential problems late last fall, and the company was receptive to their warning.<\/p>\n<p>Through the winter and spring, Square staffers discussed possible solutions and their difficulties with Moore on a page on the <a href=\"https:\/\/hackerone.com\/reports\/38682\">HackerOne platform<\/a>, and they eventually settled on a solution that would alert the company if the hack was ever used.<\/p>\n<p>Square did not respond in detail and declined to discuss specific solutions on the record with <em>BU Today<\/em>, but a spokesperson offered a statement: \u201cWith so many sellers relying on Square to run their business, we\u2019ve made protecting them a priority. We protect sellers by encrypting transactions at the moment of swipe, tokenizing data once it reaches our servers, and monitoring every transaction to detect suspicious behavior. We\u2019ve also recently migrated the small percentage of remaining sellers who use an out-of-date, unencrypted card reader to new hardware. Today, those unencrypted card readers no longer work. We\u2019re always making advances in security, and we appreciate John Moore\u2019s research, which encouraged us to speed up our deprecation plans.\u201d<\/p>\n<p>All three alums have other plans now. In September, Mellen will return to running her own company, <a href=\"http:\/\/terrapincomputing.com\/\">Terrapin Computing LLC<\/a>\u00a0in Cambridge, which sells four iOS apps. Moore will start work as a software engineer for Google, and Losev will continue his computer science education at New York University.<\/p>\n<p>Moore says another lesson to draw from their experience has nothing to do with hackers or credit cards and everything to do with the classroom.<\/p>\n<p>\u201cDon\u2019t be afraid to take on a project that goes a little bit above and beyond what\u2019s required,\u201d he says. \u201cWe could have done a project that was a lot simpler and easier, but instead we decided to do something that was quite challenging for us. We learned a lot in the process. We put in a lot more time than we expected, and it ended up paying off in the long run.\u201d<\/p>\n<p><em>Author, Joel Brown can be reached at <a href=\"mailto:jbnbpt@bu.edu\">jbnbpt@bu.edu<\/a>.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>ENG alums\u2019 class project earns spot at Black Hat USA 2015 The Square Reader mobile point-of-sale device is the small white object plugged into the iPad Mini in this photo. Photo courtesy of Square Inc. The Square Reader, used by millions of businesses in the United States, could at one point be converted in less [&hellip;]<\/p>\n","protected":false},"author":7048,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[8],"tags":[88,13,39],"_links":{"self":[{"href":"https:\/\/www.bu.edu\/federal\/wp-json\/wp\/v2\/posts\/3788"}],"collection":[{"href":"https:\/\/www.bu.edu\/federal\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.bu.edu\/federal\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.bu.edu\/federal\/wp-json\/wp\/v2\/users\/7048"}],"replies":[{"embeddable":true,"href":"https:\/\/www.bu.edu\/federal\/wp-json\/wp\/v2\/comments?post=3788"}],"version-history":[{"count":3,"href":"https:\/\/www.bu.edu\/federal\/wp-json\/wp\/v2\/posts\/3788\/revisions"}],"predecessor-version":[{"id":3791,"href":"https:\/\/www.bu.edu\/federal\/wp-json\/wp\/v2\/posts\/3788\/revisions\/3791"}],"wp:attachment":[{"href":"https:\/\/www.bu.edu\/federal\/wp-json\/wp\/v2\/media?parent=3788"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.bu.edu\/federal\/wp-json\/wp\/v2\/categories?post=3788"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.bu.edu\/federal\/wp-json\/wp\/v2\/tags?post=3788"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}