Chip and Pin
Hi Pat and Listeners,
Looks like Chip and Pin is broken (did we ever think it wouldn't happen). It looks like they hit the big guns (BBC) for a story too.
http://www.lightbluetouchpaper.org/2010/02/11/chip-and-pin-is-broken/
Worth having a read.
Altonius
Right now anyone planning on rolling out chip and pin just went back to the drawing board. Why invest the cash now when you can wait for the fix and not have potentially costly firmware updates or card recalls to do?
The end result is a mag-stripe gets to hang around longer than it should while they sort this mess out.
But it makes perfect sense, especially in countries that haven't started rolling it out in earnest yet.
Oh well, the bad guys being busy means more work for everyone. Hooray! :)
While I love the research produced by the lightbluetouchpaper guys, the have pulled the "oh noes, chip and pin is ultimate fail" story out far too many times.
Yes, this is a flaw, but the only issue is that a transaction that is not PIN verified gets reported back as being PIN verified. There are implications for fraud profiling, but thats about it.
Now, I thoroughly agree with them on 3D Secure, which is full of fail.
Post new comment
User login
Recent podcasts
-
Symantec and McAfee kick off the year of the Dragon with some decent lulzā¦
-
Russians owned our pumps. Persians pwned our drones.
-
How to turn your Kindle into a free, global SSH and IRC modem...
-
Does the hype match the reality?
-
Rootkitting OS X, fun with EFI bootloaders and more...
Recent comments
- Dan Kaminsky better get on
1 day 5 hours ago - Welcome back
2 days 5 hours ago - Cool
1 week 5 days ago - Work on the next episode
1 week 6 days ago - Why U No Podcast?
1 week 6 days ago - Ironically enough....
3 weeks 3 days ago - ANZ Falcon ad
3 weeks 4 days ago - What about Stratfor?
5 weeks 2 days ago - Everything seems fine on this
5 weeks 3 days ago - Download
5 weeks 3 days ago




Ok, so people can use stolen cards. That's a bummer.
But saying chip and pin is broken is a massive overstatement.
The primary purpose for the switch to smart cards is to prevent cloning. The example the BBC provides of "cloning" isn't the real deal... they're sucking enough data off the cards to dummy up mag-stripe cards that can then be used in countries that don't have chip and pin terminals.
In fact, I'm told the use of stolen UK data in Australia is a massive problem.
But cloning the protected storage area of a smart card isn't currently feasible.
It's interesting research, but chip and pin is NOT dead.
Heh -- I guess chip and pin is the new SSL -- everyone loves to claim it's broken.