Skip to main content

You can break into almost any retail store’s credit card reader with 2 passwords

credit card readers password problems cashier 1
Canadian Couponing
It’s common knowledge that point-of-sale machines aren’t exactly the most secure pieces of technology in the world — you need only look at last year’s pilfering of Home Depot, Target, Neiman Marcus, Michael’s customer data for evidence of that — but the reality may be worse than previously thought. Researchers at cybersecurity firm Trustwave discovered that a vast majority of retailers fail to change the default password on their credit card readers. It’s usually 166816 or Z66816.

The researchers examined machines at more than 120 clothing, electronics, and local stores. The default password in many instances granted administrative access to the machines, Trustwave executive Charles Henderson explained at last week’s RSA security last week in San Francisco. Worst case scenario, that could enable any ruffian with the know-how to scrape payment data like credit card numbers and names.

Recommended Videos

A majority of the vulnerable terminals are manufactured by Verifone, but the company’s not necessarily the one to blame. “No one is changing the password when they set this up for the first time; everybody thinks the security of their point-of-sale is someone else’s responsibility,” Henderson told CNN Money. “We’re making it pretty easy for criminals.”

It’d be risky to try at a crowded outlet — the passwords are just lengthy enough that entering them would probably make you the target of suspicion — but the real potential for hacking arises from unsecured systems. Speaking to Digital Munition, Henderson described an instance  in which an employee inadvertently downloaded keylogging software onto a retail PoS system while attempting to install a pirated video game.

Verifone doesn’t believe there’s too much cause for concern. The passwords on new payment terminals expire periodically, a spokesperson said, and the company “hasn’t witness[ed] any attacks on the security of terminals based on default passwords.” All the same, it said retailers are “strongly advised to change the default password.”

You’d think that’d be common sense.

Kyle Wiggers
Former Digital Trends Contributor
Kyle Wiggers is a writer, Web designer, and podcaster with an acute interest in all things tech. When not reviewing gadgets…
Google Messages is going to make backing up and restoring texts so much easier
Google messages versus samsung messages app icons side by side on Galaxy Z Fold 5.

Backing up and restoring Google Messages on Android is managed through Google One in the device’s Settings app. However, you can’t perform this action directly from the Google Messages app. This may change soon.

According to 9to5Google, a Google Messages app beta (version 20241118_02_RC00) includes references to a backup and restore option directly in the app.Android Authority has been able to view images of the new feature and offer early insight into how it works.

Read more
Own the Galaxy Watch 6 for less than $200, but act fast!
Samsung Galaxy Watch 6 on its charger.

Welcome to the world of wearables. From smartwatch deals to fitness deals, we always have our eyes peeled for the best discounts on top-rated tech from brands like Apple, Google, and Samsung. Speaking of the Big S, we came across this fantastic offer while vetting through Best Buy deals:

Right now, when you purchase the 44mm Graphite version of the Samsung Galaxy Watch 6, you’ll only pay $190. At full price, this model sells for $330. We tested the Galaxy Watch 6 well over a year ago, and our reviewer had this to say: “The Samsung Galaxy Watch 6 is the new go-to recommendation if you want an Android smartwatch. It's reliable, powerful, and still a great value.”

Read more
Yes, Reddit is down. Here’s everything you need to know
The Reddit app icon on an iOS Home screen.

Bad news, fellow Redditors. If you're trying to browse your favorite subreddit right now, you're probably unable to. Why? Because Reddit appears to be down due to technical difficulties.

What's going on with the outage? Do we know when it'll be back up? Here's a recap of everything we know.
Why is Reddit down?
On the Reddit status website, the company indicates an "unresolved incident" taking place on November 20. The company confirms "degraded performance for reddit.com," which appears to be accurate.

Read more