Version 20220815:
New Features:
Server: Added support for Premium tier - a tier above Registered tier.
Server/Terminal: Added possibility to allow CAS users entering different parts of terminal administration.
Every user generates his own QR code for entering terminal administration.
Terminal: Added Montenegro flag in terminal UI.
Improvements:
Server: First half of admin UI is rewritten to ReactJS.
Server: Added ability to create restore points via batm-manage.
Server: Added ability to assign identity to sell and withdraw transactions.
Server: EveryTrade renamed to WhaleBooks.
Server: Don't report Binance rate source misconfiguration as an exception.
Server: Added ability to allow only withdrawals by same identity as sell was created.
Terminal: Printer disconnected should be a warning.
Terminal: Added ability to cancel diagnostic test.
Terminal: Faster camera preview on some screens.
Terminal: Terminal reboot action is performed only when terminal gets to a home screen or screensaver.
Bug Fixes:
Server: Various Veriff fixes.
New Features:
Server: Added support for Premium tier - a tier above Registered tier.
Server/Terminal: Added possibility to allow CAS users entering different parts of terminal administration.
Every user generates his own QR code for entering terminal administration.
Terminal: Added Montenegro flag in terminal UI.
Improvements:
Server: First half of admin UI is rewritten to ReactJS.
Server: Added ability to create restore points via batm-manage.
Server: Added ability to assign identity to sell and withdraw transactions.
Server: EveryTrade renamed to WhaleBooks.
Server: Don't report Binance rate source misconfiguration as an exception.
Server: Added ability to allow only withdrawals by same identity as sell was created.
Terminal: Printer disconnected should be a warning.
Terminal: Added ability to cancel diagnostic test.
Terminal: Faster camera preview on some screens.
Terminal: Terminal reboot action is performed only when terminal gets to a home screen or screensaver.
Bug Fixes:
Server: Various Veriff fixes.
π3π₯2
Version 20220930:
New Features:
Server/Terminal: Added experimental support for credit card payments using card reader for buy direction.
Server: Added support for secondary output queue. What queue transaction should be enqueued to is determined by extension only.
Improvements:
Server: Further rewrite of Admin UI to ReactJS.
Server: Resend of failed batch transaction is now able to resend all transactions that were in the batch.
Server: Overages in sell transactions now don't cause transaction to fail when new option Allow Overage is enabled.
Server: Added ability to enqueue also transactions for wallets that do not support sendMany.
Server: Added ability to import blacklisted addresses in admin via CSV.
Server: Added database index to GDPR audit log table.
Server: Added ability to mark transaction as withdrawn via server extensions.
Server: Chainalysis scoring provider now performs scoring of ERC20 tokens also on ETH main network.
Server: Identity images are now exported in zip.
Server: Added ability to set allowed period for transaction buy resending in the organization.
Server: Added new notifications for verification process.
Server: Added 3 attempts when connection to SMTP server fails when sending email.
Server: Removed DAI, BCH support from CoinMate.io exchange.
Server: Added ADA support to CoinMate.io and Kraken exchange.
Server: Added ability to read server configuration properties from extension.
Server/Terminal: Added custom transaction failed template for buy printed receipt.
Terminal/Server: Added possibility to set separate help videos for Buy and Sell flows.
Terminal: Added Privacy Policy & Custom Privacy Notice to standard terminal UI.
Terminal: Increased size of QR code image for Bitcoin Lightning on screen.
New Features:
Server/Terminal: Added experimental support for credit card payments using card reader for buy direction.
Server: Added support for secondary output queue. What queue transaction should be enqueued to is determined by extension only.
Improvements:
Server: Further rewrite of Admin UI to ReactJS.
Server: Resend of failed batch transaction is now able to resend all transactions that were in the batch.
Server: Overages in sell transactions now don't cause transaction to fail when new option Allow Overage is enabled.
Server: Added ability to enqueue also transactions for wallets that do not support sendMany.
Server: Added ability to import blacklisted addresses in admin via CSV.
Server: Added database index to GDPR audit log table.
Server: Added ability to mark transaction as withdrawn via server extensions.
Server: Chainalysis scoring provider now performs scoring of ERC20 tokens also on ETH main network.
Server: Identity images are now exported in zip.
Server: Added ability to set allowed period for transaction buy resending in the organization.
Server: Added new notifications for verification process.
Server: Added 3 attempts when connection to SMTP server fails when sending email.
Server: Removed DAI, BCH support from CoinMate.io exchange.
Server: Added ADA support to CoinMate.io and Kraken exchange.
Server: Added ability to read server configuration properties from extension.
Server/Terminal: Added custom transaction failed template for buy printed receipt.
Terminal/Server: Added possibility to set separate help videos for Buy and Sell flows.
Terminal: Added Privacy Policy & Custom Privacy Notice to standard terminal UI.
Terminal: Increased size of QR code image for Bitcoin Lightning on screen.
π10
Version 20221001:
New Featrues:
Server/Terminal: Added support for GMKit.
New Featrues:
Server/Terminal: Added support for GMKit.
acceptor_firmware_version.png
8 KB
Important security announcement:
There has been reported incident in eastern europe where an attacker was able to cheat CranePI MEI SCN bill acceptor due to old firmware present in the head of the bill acceptor device.
Please make sure your bill acceptor's application firmware is at least on version 5.30.
See attached picture describing how to find out what application version firmware is your bill acceptor on. Recyclers are not affected by this issue.
If you are not sure how to upgrade firmware of the bill acceptor remotely please contact our support department via email at support@generalbytes.com.
This security issue is important. It is not related to GB software however it can lead to significant financial loss if left unresolved.
There has been reported incident in eastern europe where an attacker was able to cheat CranePI MEI SCN bill acceptor due to old firmware present in the head of the bill acceptor device.
Please make sure your bill acceptor's application firmware is at least on version 5.30.
See attached picture describing how to find out what application version firmware is your bill acceptor on. Recyclers are not affected by this issue.
If you are not sure how to upgrade firmware of the bill acceptor remotely please contact our support department via email at support@generalbytes.com.
This security issue is important. It is not related to GB software however it can lead to significant financial loss if left unresolved.
π1
generalbytes.com
acceptor_firmware_version.png
Dear Operators.
Please note that mentioned the firmware upgrade is needed only for BILL ACCEPTORs not for RECYCLERs.
We are getting reports where operators bricked their RECYCLER heads by uploading BILL ACCEPTOR firmware into them.
DO NOT upload bill acceptor firmwares into recycler heads. As the only fix after this is to send them to CranePI service center.
Please note that mentioned the firmware upgrade is needed only for BILL ACCEPTORs not for RECYCLERs.
We are getting reports where operators bricked their RECYCLER heads by uploading BILL ACCEPTOR firmware into them.
DO NOT upload bill acceptor firmwares into recycler heads. As the only fix after this is to send them to CranePI service center.
Dear operators, please check the status of your invoices on your servers and on the cloud. Please note that if you have multiple unpaid invoices older than 60days you are in direct breach of licensing conditions and you might be operating machines illegaly. Lets be fair partners - we provide software updates plus making sure that solution is secure and you pay licensing fees.
Thank you
Thank you
π9π2β€1π1π₯1
Version 20221118:
New Features:
Server/Terminal: Added support for OpenVPN client running on terminal.
Server/Terminal: Hardware configuration pinning.
Server/Terminal: Added support for HNL currency (Honduran lempira)
Improvements:
Terminal: Showing insufficient limit before insert money screen.
Terminal: Cryptocurrency icons should show up faster on the screen
Terminal: Remote BNR firmware update is now possible when terminal is connected via USB.
Terminal/Server: Terminal displays QR code that user can scan to initiate Veriff verification.
Server: Wallet sending is now asynchronous from exchange re-buy.
Server: Server now waits only 50 seconds for response from wallet.
Server: Identities, Skins and Terminal permission templates, Message Templates should now load faster in admin.
Server: Transactions have newly separate statuses for exchange and wallet.
Server: Skin palette elements fixed.
Bug Fixes:
Server: Removed marker character from thread name in master log.
New Features:
Server/Terminal: Added support for OpenVPN client running on terminal.
Server/Terminal: Hardware configuration pinning.
Server/Terminal: Added support for HNL currency (Honduran lempira)
Improvements:
Terminal: Showing insufficient limit before insert money screen.
Terminal: Cryptocurrency icons should show up faster on the screen
Terminal: Remote BNR firmware update is now possible when terminal is connected via USB.
Terminal/Server: Terminal displays QR code that user can scan to initiate Veriff verification.
Server: Wallet sending is now asynchronous from exchange re-buy.
Server: Server now waits only 50 seconds for response from wallet.
Server: Identities, Skins and Terminal permission templates, Message Templates should now load faster in admin.
Server: Transactions have newly separate statuses for exchange and wallet.
Server: Skin palette elements fixed.
Bug Fixes:
Server: Removed marker character from thread name in master log.
π8
β οΈDear Customers,
We would like to warn you that some of our customers were contacted by fake GB tech support via Telegram asking them for SSH access to their CAS in order to fix 0-day security issue. Don't get yourself into trouble and don't fall for this scam technique.
We would like to warn you that some of our customers were contacted by fake GB tech support via Telegram asking them for SSH access to their CAS in order to fix 0-day security issue. Don't get yourself into trouble and don't fall for this scam technique.
π₯6β€2π2
Dear Customers,
We are currently migrating our phone line services to a new provider. You are not going to be able to reach us by phone.
Until the migration is finished please use our primary emails to reach us using the following emails: support@generalbytes.com or sales@generalbytes.com or using our support desk at https://generalbytes.atlassian.net/servicedesk/customer/portal/1
We are sorry for the temporary inconvenience.
We are currently migrating our phone line services to a new provider. You are not going to be able to reach us by phone.
Until the migration is finished please use our primary emails to reach us using the following emails: support@generalbytes.com or sales@generalbytes.com or using our support desk at https://generalbytes.atlassian.net/servicedesk/customer/portal/1
We are sorry for the temporary inconvenience.
Version 20230120:
New Features:
Server/Terminal: By terminal unrecognized QR codes containing wallet addresses are sent to server for second stage recognition processing.
Leads to improved readability of QR codes that do not follow standards.
This method is also used to collect QR codes that ATM doesn't recognizes, that may be used in future for software improvements.
Terminal: Added support for audio jack upgrade.
Server: Added automatic customer registration when customer is verified by external verification provider such as Veriff and ability to set required fields.
Improvements:
Server: Added possibility to enable rule to Output Queues that will require manual approval for transactions with Risk Score Classification Levels 8 and 9.
Server: Sprites, videos, skins and resource bundles pages rewritten to ReactJS.
Server: Address and phone blacklist pages are rewritten to ReactJS.
Server: Added address parsing for Veriff enterprise
Server: Added REST endpoint to see list of loaded extensions.
Server: Added links on terminal deployment page.
Server: Backup restore improvements
Server: Added option to optionally send information about sent transactions to Chainanalysis.
Server: Show deposit addresses for sell transactions in admin.
Server: Handle null properly when exporting NULL values to CSV.
Server: Increased number of possible withdrawal confirmations to 15.
Server: Added duplicate registration check when customer is registered automatically via Veriff/Onfido.
Server: Added possibility to enable url shortening via Twillio configuration parameters.
Server/Terminal: Added custom error message for blacklisted address
Terminal: No wallet screen contains App store and Google play icons.
Terminal: Welcome text on Welcome screen is auto-resizing to fit one line.
Terminal: Camera focus settings removed from terminal administration as they are no longer used.
Terminal: Improved fingerprint reader initialization.
Terminal: Use selfie camera when main camera is disconnected.
Terminal: Refactored code that works with locales.
Terminal: Updated Croatian translations.
Terminal: TRANSACTION ATTEMPTS REACHED notification text changed.
Bug Fixes:
Terminal: Fixed possible fingerprint detection crashes.
Terminal: Show error toast in terminal admin screen when there is issue with cash device
Server: Submitting cash collection note should not perform redirect
New Features:
Server/Terminal: By terminal unrecognized QR codes containing wallet addresses are sent to server for second stage recognition processing.
Leads to improved readability of QR codes that do not follow standards.
This method is also used to collect QR codes that ATM doesn't recognizes, that may be used in future for software improvements.
Terminal: Added support for audio jack upgrade.
Server: Added automatic customer registration when customer is verified by external verification provider such as Veriff and ability to set required fields.
Improvements:
Server: Added possibility to enable rule to Output Queues that will require manual approval for transactions with Risk Score Classification Levels 8 and 9.
Server: Sprites, videos, skins and resource bundles pages rewritten to ReactJS.
Server: Address and phone blacklist pages are rewritten to ReactJS.
Server: Added address parsing for Veriff enterprise
Server: Added REST endpoint to see list of loaded extensions.
Server: Added links on terminal deployment page.
Server: Backup restore improvements
Server: Added option to optionally send information about sent transactions to Chainanalysis.
Server: Show deposit addresses for sell transactions in admin.
Server: Handle null properly when exporting NULL values to CSV.
Server: Increased number of possible withdrawal confirmations to 15.
Server: Added duplicate registration check when customer is registered automatically via Veriff/Onfido.
Server: Added possibility to enable url shortening via Twillio configuration parameters.
Server/Terminal: Added custom error message for blacklisted address
Terminal: No wallet screen contains App store and Google play icons.
Terminal: Welcome text on Welcome screen is auto-resizing to fit one line.
Terminal: Camera focus settings removed from terminal administration as they are no longer used.
Terminal: Improved fingerprint reader initialization.
Terminal: Use selfie camera when main camera is disconnected.
Terminal: Refactored code that works with locales.
Terminal: Updated Croatian translations.
Terminal: TRANSACTION ATTEMPTS REACHED notification text changed.
Bug Fixes:
Terminal: Fixed possible fingerprint detection crashes.
Terminal: Show error toast in terminal admin screen when there is issue with cash device
Server: Submitting cash collection note should not perform redirect
π6
Dear operators,
Tonight we received number of reports from GB operators that their block.io wallets have been deplated by third party.
As a preliminary caution we decided to shutdown our cloud service until the issue is properly investigated.
The issue was reported by operators that use their own servers behind firewall.
Tonight we received number of reports from GB operators that their block.io wallets have been deplated by third party.
As a preliminary caution we decided to shutdown our cloud service until the issue is properly investigated.
The issue was reported by operators that use their own servers behind firewall.
π₯2π2
Dear Operators,
We are investigating numerous attacks on CAS servers that resulted in loss of crypto funds.
We are sorry but, as a matter of precaution we recommend you to shutdown your admin and master service.
Our cloud service was unfortunatelly breached and therefore it needs to be shut down until we finish the investigation.
The attackers tried to clean the traces by empting the admin.log and master.log evaluate your logs and if you miss data for some period then your server may have been breached.
Meanwhile please invalidate your API keys to your wallets and exchnages as they may have leaked from your server.
We will be providing more details in 2 hours.
We are investigating numerous attacks on CAS servers that resulted in loss of crypto funds.
We are sorry but, as a matter of precaution we recommend you to shutdown your admin and master service.
Our cloud service was unfortunatelly breached and therefore it needs to be shut down until we finish the investigation.
The attackers tried to clean the traces by empting the admin.log and master.log evaluate your logs and if you miss data for some period then your server may have been breached.
Meanwhile please invalidate your API keys to your wallets and exchnages as they may have leaked from your server.
We will be providing more details in 2 hours.
π₯3
Dear Operators,
We ask you to keep your master and admin services off until we provide you with a new software release that patches exploited vulnerability.
Here is the document describing security incident: https://generalbytes.atlassian.net/wiki/spaces/ESD/pages/2885222430/Security+Incident+March+17-18th+2023
We ask you to keep your master and admin services off until we provide you with a new software release that patches exploited vulnerability.
Here is the document describing security incident: https://generalbytes.atlassian.net/wiki/spaces/ESD/pages/2885222430/Security+Incident+March+17-18th+2023
π1
New server patch releases 20221118.48 and 20230120.44 fixing the vulnerability have been released.
Please note that even after upgrading to this version do not have ports 7741 or 7777 exposed to internet.
Keep them behind the VPN.
Make sure you read our security incident report.
If you know some operator that is operating GB ATM software please let them know about the issue.
Most of the breaches happen even after the fix is available.
We will be sending out information on social media and emails however not everybody reads those.
Please note that even after upgrading to this version do not have ports 7741 or 7777 exposed to internet.
Keep them behind the VPN.
Make sure you read our security incident report.
If you know some operator that is operating GB ATM software please let them know about the issue.
Most of the breaches happen even after the fix is available.
We will be sending out information on social media and emails however not everybody reads those.
β€10π4π₯1
GB just released a new patch that addresses many of the VPN issues that some of you faced during the CAS server installation, as well as minimizing sensitive information storage in the database.
We are working hard to help you transition to your own infrastructure - secured behind a VPN. Documentation updates and new patches will continue to be released in upcoming days.
More info on new patch releases is located here: generalbytes.com/patch
It is recommended to upgrade these patches.
We additionally encourage larger operators to conduct an independent security review of our software into their security polices.
We are ready to address any findings that such a review produces.
We are working hard to help you transition to your own infrastructure - secured behind a VPN. Documentation updates and new patches will continue to be released in upcoming days.
More info on new patch releases is located here: generalbytes.com/patch
It is recommended to upgrade these patches.
We additionally encourage larger operators to conduct an independent security review of our software into their security polices.
We are ready to address any findings that such a review produces.
π6
Operators that need IT help with installing and securing their own new standalone CAS servers behind VPN might find this interesting:
Exaio Systems Consultants ( https://exaio.com ) contacted General Bytes after the incident offering their help to other operators as they have been providing these services in past to one of the operators in the USA. Feel free to contact them via their website.
Please note that Exaio is not in any way affiliated with General Bytes.
Exaio Systems Consultants ( https://exaio.com ) contacted General Bytes after the incident offering their help to other operators as they have been providing these services in past to one of the operators in the USA. Feel free to contact them via their website.
Please note that Exaio is not in any way affiliated with General Bytes.
generalbytes.com pinned Β«Dear Operators, We ask you to keep your master and admin services off until we provide you with a new software release that patches exploited vulnerability. Here is the document describing security incident: https://generalbytes.atlassian.net/wiki/spacesβ¦Β»
generalbytes.com pinned Β«Dear Operators, We ask you to keep your master and admin services off until we provide you with a new software release that patches exploited vulnerability. Here is the document describing security incident: https://generalbytes.atlassian.net/wiki/spacesβ¦Β»
Dear Operators,
We have registered cases when ATM operators restored backups on their new server together with malware from the old server. Please see the new section βMoving data from old serverβ in our incident report.
We also released new patch releases 20230120.46 and 20221118.50 that contain more VPN fixes, improvements and simplifies creation of user VPNs to access CAS using batm-manage command. It is highly recommended to upgrade to this version.
And lastly we encourage operators that are still running 20221118 to upgrade to 20230120 as we plan next week to stop providing patch releases to 20221118.
Please do not operate your servers on the public internet. Please operate them only when moved behind VPN.
We have registered cases when ATM operators restored backups on their new server together with malware from the old server. Please see the new section βMoving data from old serverβ in our incident report.
We also released new patch releases 20230120.46 and 20221118.50 that contain more VPN fixes, improvements and simplifies creation of user VPNs to access CAS using batm-manage command. It is highly recommended to upgrade to this version.
And lastly we encourage operators that are still running 20221118 to upgrade to 20230120 as we plan next week to stop providing patch releases to 20221118.
Please do not operate your servers on the public internet. Please operate them only when moved behind VPN.
Dear Operators,
We put together an article in our KB that focuses on the security aspect of operating a Bitcoin ATM business.
Please make sure you read it.
GENERAL BYTES team
https://generalbytes.atlassian.net/wiki/spaces/ESD/pages/2893283329/Best+Practices+Security
We put together an article in our KB that focuses on the security aspect of operating a Bitcoin ATM business.
Please make sure you read it.
GENERAL BYTES team
https://generalbytes.atlassian.net/wiki/spaces/ESD/pages/2893283329/Best+Practices+Security
π₯3π2π2