ASTM-E3017 › Standard Practice for Examining Magnetic Card Readers
The following bibliographic material is provided to assist you with your purchasing decision:
Scope
1.1 Magnetic card readers, when used for illegal purposes, are commonly referred to as skimmers. This practice provides information on seizing, acquiring, and analyzing skimming devices capable of acquiring and storing personally identifiable information (PII) in an unauthorized manner.
1.2 This standard cannot replace knowledge, skills, or abilities acquired through education, training, and experience and is to be used in conjunction with professional judgment by individuals with such discipline-specific knowledge, skills, and abilities.
1.3 This standard does not purport to address all of the safety concerns, if any, associated with its use. It is the responsibility of the user of this standard to establish appropriate safety, health, and environmental practices and determine the applicability of regulatory limitations prior to use.
1.4 This international standard was developed in accordance with internationally recognized principles on standardization established in the Decision on Principles for the Development of International Standards, Guides and Recommendations issued by the World Trade Organization Technical Barriers to Trade (TBT) Committee.
Significance and Use
4.1 As a skimming device is not typically deemed contraband in of itself, it is the responsibility of the examiner to determine if the device contains unauthorized account information. The purpose of this practice is to describe best practices for seizing, acquiring, and analyzing the data contained within magnetic card readers.
4.2 Limitations—Skimmers present unique examination challenges due to:
4.2.1 Rapid changes in technology;
4.2.2 Difficulty of device disassembly;
4.2.3 Use of alternate/repurposed components;
4.2.4 Use of encryption or examination countermeasures, or both;
4.2.5 Multiple data encoding/modulation formats;
4.2.6 Prevention of chip identification by obfuscation of the device;
4.2.7 Availability of training and documentation;
4.2.8 Lack of chip information/documentation;
4.2.9 Lack of adapters available for chip reading;
4.2.10 Expense of available equipment used in chip removal and reading;
4.2.11 Lack of software’s ability to support reading chip data; and
4.2.12 Lack of commercial software available to analyze encrypted data extracted from skimmers.
Keywords
Bluetooth; examinations; magnetic card readers; skimmers;
To find similar documents by ASTM Volume:
To find similar documents by classification:
This document comes with our free Notification Service, good for the life of the document.
This document is available in either Paper or PDF format.
Document Number
ASTM-E3017-19
Revision Level
2019 EDITION
Status
Current
Modification Type
Revision
Publication Date
June 1, 2019
Document Type
Practice
Page Count
17 pages
Committee Number
E30.12