Skip to main content

You can break into almost any retail store’s credit card reader with 2 passwords

credit card readers password problems cashier 1
Canadian Couponing
It’s common knowledge that point-of-sale machines aren’t exactly the most secure pieces of technology in the world — you need only look at last year’s pilfering of Home Depot, Target, Neiman Marcus, Michael’s customer data for evidence of that — but the reality may be worse than previously thought. Researchers at cybersecurity firm Trustwave discovered that a vast majority of retailers fail to change the default password on their credit card readers. It’s usually 166816 or Z66816.

The researchers examined machines at more than 120 clothing, electronics, and local stores. The default password in many instances granted administrative access to the machines, Trustwave executive Charles Henderson explained at last week’s RSA security last week in San Francisco. Worst case scenario, that could enable any ruffian with the know-how to scrape payment data like credit card numbers and names.

Recommended Videos

A majority of the vulnerable terminals are manufactured by Verifone, but the company’s not necessarily the one to blame. “No one is changing the password when they set this up for the first time; everybody thinks the security of their point-of-sale is someone else’s responsibility,” Henderson told CNN Money. “We’re making it pretty easy for criminals.”

Please enable Javascript to view this content

It’d be risky to try at a crowded outlet — the passwords are just lengthy enough that entering them would probably make you the target of suspicion — but the real potential for hacking arises from unsecured systems. Speaking to Digital Munition, Henderson described an instance  in which an employee inadvertently downloaded keylogging software onto a retail PoS system while attempting to install a pirated video game.

Verifone doesn’t believe there’s too much cause for concern. The passwords on new payment terminals expire periodically, a spokesperson said, and the company “hasn’t witness[ed] any attacks on the security of terminals based on default passwords.” All the same, it said retailers are “strongly advised to change the default password.”

You’d think that’d be common sense.

Kyle Wiggers
Former Digital Trends Contributor
Kyle Wiggers is a writer, Web designer, and podcaster with an acute interest in all things tech. When not reviewing gadgets…
Upcoming OnePlus Watch 3 might have a rotating crown
Third part watch face on OnePlus Watch 2r.

After a less-than-exciting launch with the OnePlus Watch 2, it's time for a change — and hopefully, a wearable that more closely matches modern devices. We expect the OnePlus Watch 3 to release on January 7, but now new details suggest it might come with a rotating crown.

This update is a big win for OnePlus Watch fans. The crown has been a long-requested feature that will make it easier to navigate through the interface, and improved sensors give access to ECGs and other features that were missing in the previous generation, according to Yogesh Brar.

Read more
Google proposes big changes for the future of Search and Android apps
Google Chrome on an Android phone.

Google’s ongoing antitrust tussle spawned a list of sweeping policy suggestions — including a proposed sale of the Chrome business — by the Department of Justice. The focus of the lawsuit centers on the Search monopoly, but it has serious ramifications for Android and the overall browser situation.

Now, Google has shared its own “remedies proposal” to the DOJ’s recommendations, which it claims are going “far beyond what the Court’s decision is actually about.”

Read more
Gemini brings a fantastic PDF superpower to Files by Google app
step of Gemini processing a PDF in Files by Google app.

Google is on a quest to push its Gemini AI chatbot in as many productivity tools as possible. The latest app to get some generative AI lift is the Files by Google app, which now automatically pulls up Gemini analysis when you open a PDF document.

The feature, which was first shared on the r/Android Reddit community, is now live for phones running Android 15. Digital Trends tested this feature on a Pixel 9 running the stable build of Android 15 and the latest version of Google’s file manager app.

Read more