Skip to main content

How safe is Square? Researchers find a number of holes

squareMobile credit card payment system Square has been on a quick rise. Twitter co-founder Jack Dorsey’s baby has been on the move since this May, since it announced improvements for the product at TechCrunch Disrupt. The ability for consumers to make mobile payments, find Square-accepting retailers, and receive digital receipts solidified Square as viable point of sale software that could be an influential piece in e-commerce evolution.

Consumers are experiencing a lot of changes when it comes to online retail, including a host of benefits: Stored transaction data, ease of use, and constant accessibility just being a handful of the upgrades. But no technology comes without its caveats, and Square is no exception. Cnet reported that at this week’s Black Hat security conference, researchers announced Square can be used to access stolen credit card data.

Recommended Videos

How thieves could do this is almost so impressive it’s hard to be upset about it. Instead of using the actual card in question, a person could convert magnetic strip data to an audio file using a microphone, then take this and using a stereo cable, they could play it to the Square gadget attached to a smartphone. And there you have it: The ability to go on a shopping spree (of the digital variety only) without a card.

That’s not all. At the moment, Square does not feature hardware encryption or authentication. This enables the device to be used to skim cards for data and then give scammers the ability to make replications. “The dongle [the Square device] is a skimmer. It turns any iPhone into a skimmer… now you need less technical hardware to do it and no technical skills at all,” researcher Adam Laurie said.

The former of the two hacks requires something of a technical mind, but the latter sounds easy for even some of the most electronically-inept to put to use. Skimming card data is the real concern here, as fraudulent merchants on Square have little to no success standing up to its security standards against this type of activity. But why Square’s hardware remains unencrypted remains a mystery, and is leaving a significant security hole in its system.

Major competitor Verifone pointed this concern out earlier this year, which was labeled a smear campaign. Regardless of intentions, it’s a valid point, especially considering the growing use of Square. Square said devices with encryption capabilities are due to be released this summer, but we’re all still waiting. 

Molly McHugh
Former Digital Trends Contributor
Before coming to Digital Trends, Molly worked as a freelance writer, occasional photographer, and general technical lackey…
Volvo’s much-anticipated EX30 EV to reach U.S. before year end
Front three quarter view of the 2025 Volvo EX30.

Volvo is switching gears again, this time to accelerate deliveries of its much-anticipated EX30 subcompact electric SUV so that it reaches the U.S. before the end of 2024.

The Swedish automaker last summer had postponed the U.S. launch of the EX30 to 2025, citing “changes in the global automotive landscape." The move followed the Biden administration’s 100% import tariff on electric vehicles made in China.

Read more
Rivian R2 EV’s new LG battery boosts storage capacity sixfold
Rivian R2

The Rivian R2, the EV maker’s much-anticipated affordable electric SUV, will be powered by U.S.-made batteries promising to store six times as much energy as those currently used.

South Korea’s LG Energy Solutions announced it will be supplying LG’s 4695 cylindrical batteries to Rivian as part of a five-year agreement.

Read more
Hyundai 2025 Ioniq 5 is under $44,000, with more range and NACS port
hyundai ioniq 5 44000 nacs 64149 large631652025ioniq5xrt

Hyundai is on a roll. In October, the South Korean manufacturer posted its best U.S. sales ever, largely driven by sales of its popular Ioniq 5 electric SUV.

Now, all eyes are on the Ioniq 5’s 2025 model, which is set to become available at dealerships before year-end. As Digital Trends previously reported, the crossover model adds a more rugged-looking trim level called XRT and provides additional driving range as well as new charging options.

Read more