8 ms·
Some background information. The fundamental reason why this is a big deal is that in the UK, the repercussions of fraud are skewed towards customers rather th
by randomwalker 16y ago
Some background information.
The fundamental reason why this is a big deal is that in the UK, the repercussions of fraud are skewed towards customers rather than the banks. The relevant legal standard is that customers must exercise "reasonable care" with their PIN if the bank is to bear the cost of fraud. Of course, banks always insist that their systems are secure, and that it was the customer's fault. http://www.timesonline.co.uk/tol/money/consumer_affairs/article6249940.ece http://www.timesonline.co.uk/tol/money/consumer_affairs/arti...
The Cambridge team has been investigating vulnerabilities in the EMV standard underlying Chip and PIN (ubiquitous in the UK) for a long time.
From 2006: http://www.lightbluetouchpaper.org/2006/03/15/chip-and-skim/ http://www.lightbluetouchpaper.org/2006/03/15/chip-and-skim/
If I understand correctly they first started to find serious vulnerabilities in 2009.
Blog post: http://www.lightbluetouchpaper.org/2009/08/25/defending-against-wedge-attacks/ http://www.lightbluetouchpaper.org/2009/08/25/defending-agai...
Paper: "Optimised to Fail: Card Readers for Online Banking" http://www.cl.cam.ac.uk/~sd410/papers/optimised_fail.pdf http://www.cl.cam.ac.uk/~sd410/papers/optimised_fail.pdf
Media: http://www.youtube.com/watch?v=U1QAnb-wnTs http://www.youtube.com/watch?v=U1QAnb-wnTs
They escalated that attack in 2010.
http://www.lightbluetouchpaper.org/2010/02/11/chip-and-pin-is-broken/ http://www.lightbluetouchpaper.org/2010/02/11/chip-and-pin-i...
Paper: http://www.cl.cam.ac.uk/~sjm217/papers/oakland10chipbroken.pdf http://www.cl.cam.ac.uk/~sjm217/papers/oakland10chipbroken.p...
Media: http://www.youtube.com/watch?v=1pMuV2o4Lrw http://www.youtube.com/watch?v=1pMuV2o4Lrw
- oasisbob 16y agoFor the original complaint, see this PDF (via Light Blue Touch): http://www.cl.cam.ac.uk/~rja14/Papers/20101221110342233.pdf http://www.cl.cam.ac.uk/~rja14/Papers/20101221110342233.pdf
- StavrosK 16y agoI don't really understand the logic behind chip and pin cards. Do you really want me to disclose my card and my PIN to a completely untrusted machine a stranger hands to me? How do I know the vendor won't just record both and replay them, charging me for things I didn't pay?
- weavejester 16y agoI guess the idea is that recording and copying the PIN is harder than recording and copying a signature.
- LabSlice 16y agoI am quite certain that the EMV chip, which is the chip on your card, must authenticate the POS machines it talks to. The authentication is done using public key cryptography. So it's not sufficient just to host a fake machine and expect it to be accepted within the EMV infrastructure (cards, POC machines and backend processors).
- pmjordan 16y agoOf course, extracting the entered PIN is trivial to do with a covertly modified terminal. (skimming) Short of the card being stolen, that shouldn't let anyone access your account, assuming the crypto implementation is sound. Likewise, the card without the PIN is designed to be equally useless, though support for legacy payment systems partially undermines all of this. I suspect a modified terminal which records entered PINs and clones the magnetic strips would let you withdraw cash from the victim's account via Cirrus/Visa Plus.
- huhtenberg 16y agoChip cards cannot be "replayed" or cloned, that's why there's a chip in the first place. The chip stores card's private key that is used to digitally sign a (purchase) transaction. Each transaction is a multi-message exchange in real-time between the terminal and the bank and it includes an unique ID generated by the bank, which is covered by the signature. This effectively prevents a replay. The private key cannot be read from the chip without the use of a tunneling microscope or other hardware exotics. In fact it is not untypical for a chip to have a built-in protection against key retrieval that is set to physically fry the chip. The PIN is used to tell the chip to do the digital signing. No PIN = no signing. That's how it works in general. This application of the smartcard technology is almost 20 years old, so while there are some variations one could still call it sufficiently mature :grin