Feeds

Citibank gags crypto researchers

The Phantom (withdrawal) menace

  • alert
  • submit to reddit

Providing a secure and efficient Helpdesk

The High Court in London has imposed an injunction on Cambridge University security experts who claim to have uncovered serious failings in the system banks use to secure ATM PIN codes.

The gagging order, preventing public disclosure of cryptographic vulnerabilities, was made at the request of CitiBank and Diners' Club against experts due to testify in a 'phantom withdrawal' case to be heard in the South African High Court next month.

South African couple Anil and Vanita Singh say that £50,000 withdrawn through the Diners' Club account through British ATMs in March 2000 was never made by them. Diners Club say that its systems are secure, so the money must have been withdrawn by the Singhs.

The Singhs' solicitors have drafted in noted encryption expert Ross Anderson, of Cambridge University, along with his PhD students Mike Bond and Richard Clayton, to act as defence witnesses in the case.

In working on the case, Mike Bond discovered potentially serious vulnerabilities in the equipment used to protect PINs.

Last week, Bond and fellow researcher and fellow researcher Piotr Zielinski published a paper, which explains how a corrupt insider might be able to use a cryptographic attack to obtain PIN account codes for more easily than previously realised. This paper was publicised on security mailing list cryptome.org and the story was picked up by The Reg and numerous other news outlets.

So the secret is well and truly out.

Despite this a London Court judge last week granted an injunction preventing experts in the case (including the Cambridge security researchers) discussing anything likely to become testimony in the trial. Citibanks' petition can be found here.

A counterargument by Anderson arguing that the injunction, while appropriate for the bank experts involved, contravened academic freedoms and was bad for security was rejected, the Sunday Times reported yesterday. Citibank's court victory is yet to be recorded elsewhere, at least as far as we can see.

Neither Anderson, Bond nor anyone familiar with the case at Cambridge University could be reached for comment this morning so the scope of the injunction imposed remains unclear.

A posting by Anderson to cryptome.org gives links to documents relevant to the case. ®

Related Stories

How to get an ATM PIN in 15 guesses

External Links

Decimalisation table attacks for PIN cracking, by Mike Bond and Piotr Zielinski of Cambridge University
Bank gags scientists over case of the phantom withdrawals, by the Sunday Times (registration required)

New hybrid storage solutions

More from The Register

next story
Google recommends pronounceable passwords
Super Chrome goes into battle with Mr Mxyzptlk
Apple Pay is a tidy payday for Apple with 0.15% cut, sources say
Cupertino slurps 15 cents from every $100 purchase
Reddit wipes clean leaked celeb nudie pics, tells users to zip it
Now we've had all THAT TRAFFIC, we 'deplore' this theft
Infosec geniuses hack a Canon PRINTER and install DOOM
Internet of Stuff securo-cockups strike yet again
YouTube, Amazon and Yahoo! caught in malvertising mess
Cisco says 'Kyle and Stan' attack is spreading through compromised ad networks
TorrentLocker unpicked: Crypto coding shocker defeats extortionists
Lousy XOR opens door into which victims can shove a foot
Greater dev access to iOS 8 will put us AT RISK from HACKERS
Knocking holes in Apple's walled garden could backfire, says securo-chap
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
Top 5 reasons to deploy VMware with Tegile
Data demand and the rise of virtualization is challenging IT teams to deliver storage performance, scalability and capacity that can keep up, while maximizing efficiency.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.