[ISN] Update: Credit card terminals have used same password since 1990s

http://www.computerworld.com/article/2913808/malware-vulnerabilities/credit-card-terminals-have-used-same-password-since-1990s.html By Martyn Williams IDG News Service April 23, 2015 While retailers battle breaches that have resulted in tens of millions of credit card numbers stolen, word comes from the RSA Conference in San Francisco that a major vendor of payment terminals has been shipping devices for over two decades with the same default password. The vendor wasn’t named by the researchers, David Byrne and Charles Henderson, but they did disclose the password: 166816. A Google search reveals that’s the default password for several models of credit card terminal sold by Verifone, a Silicon Valley-based vendor that says it connects 27 million payment devices and has operations in 150 countries. In a statement on Thursday, Verifone acknowledged that all its devices in the field came with the same default password, which the company said was Z66831. Over the years, the password has become known and can be found on the Internet along with instructions for programming terminals, Verifone said. […]