4 ms·
For the record, Chip and PIN is kind of broken... • "Chip and PIN is Broken" (Murdoch/Drimer/Anderson/Bond, 2010) [PDF] http://www.cl.cam.ac.uk/~sjm217/papers/
by glitch 12y ago
For the record, Chip and PIN is kind of broken...
• "Chip and PIN is Broken" (Murdoch/Drimer/Anderson/Bond, 2010) [PDF] http://www.cl.cam.ac.uk/~sjm217/papers/oakland10chipbroken.pdf http://www.cl.cam.ac.uk/~sjm217/papers/oakland10chipbroken.p...
• "Chip and PIN is Broken" (Murdoch, 27C3, 2010) [Video]: http://www.youtube.com/watch?v=Ks_w352BS-Q http://www.youtube.com/watch?v=Ks_w352BS-Q
• "Chip & PIN is definitely broken" (Barisani/Bianco/Laurie/Franken, 2011) [Video]: http://www.youtube.com/watch?v=JABJlvrZWbY http://www.youtube.com/watch?v=JABJlvrZWbY ...and slides [PDF]: http://dev.inversepath.com/download/emv/emv_2011.pdf http://dev.inversepath.com/download/emv/emv_2011.pdf
- danielweber 12y agoIn the US, the big benefit of Chip and PIN will be that retailers don't have any credit card information to store.
- deleted 12y ago[deleted]
- wastedhours 12y agoDo they hold a unique token though? Here in the UK, I've definitely gotten "loyalty" offers printed with my receipt even though I've only ever used my debit card there and not a store card.
- Nursie 12y agoDepending on the system they can still get an account/card number. They shouldn't be storing it but... They can certainly get cardholder names and that sort of thing though. Maybe they've figured out a way to generate a unique token based only on non-secure data.
- bravo22 12y agoWell in defence of Chip and PIN (and I can't believe I'm saying this), the exploits listed above take advantage of "No Signature" provided. This is where the card just gives the basic CC information -- same as what is on the front. The bank can see this and banks only allow small transactions to go through with no signature. In the demo they buy coffee, etc. with it. You couldn't buy something more expensive with it because the bank would deny the charge. NFC is similar. You can use it for small transactions, but not larger ones.
- abritishguy 12y agoThat certainly isn't true of the Cambridge one.
- bravo22 12y agoFrom their paper: "We have observed variations between countries. While cards from Belgium and Estonia work like British cards, we have tested cards from Switzerland and Germany whose CVM lists specify either chip and signature or online PIN, at least while used abroad. The attack described here is not applicable to them. However, because UK point-of-sale terminals do not support online PIN, a stolen card of such a type could easily be used in the UK, by forging the cardholder’s signature." Their attack uses offline PIN mode. This is further expanded upon in section III. The simplified attack is such: Basically the PIN signed block doesn't get sent to the bank. Verification is only between the terminal and the card, and the card (or rather MITM hardware) returns a "all is well, transaction approved" message when in fact no such thing happened. The terminal doesn't go online and talk to the bank and verify the signed PIN block. This is essentially misconfiguration of the merchant terminal that ignores the result of the PIN verification. This is similar to when you tap a card to buy something. If the merchant system doesn't go online to verify it -- which it often doesn't for small transactions (<$10) then you can game the system.
- Nursie 12y agoIt is. It's easy to see there are ways that cards and terminals can be set up badly. It also looks like there are ways that both ends can be set up correctly to get around most of the problems. And cloning is still almost impossible. The largest risk appears to be copying card details which allows the fraudster to use cards online or in countries that don't yet have Chip and PIN. Personally I would like to see separate account numbers and details on the Chip compared to the main card number - i.e. you could copy some of the chip details but this wouldn't actually let you get anywhere because the number would immediately be flagged if it was found anywhere else. You'd then have another card number (maybe the one actually printed on the card) that you could use online. Or perhaps we could just scrap the whole card thing for non-physical use... (And I'm saying this as a guy who makes some of his money at this game)