Feeds

Cambridge security boffins slam banking card readers

'Optimised to fail'

Internet Security Threat Report 2014

Card readers for online banking are inherently insecure, according to a new study by Cambridge security researchers.

Researchers Saar Drimer, Steven J Murdoch and Ross Anderson found a number of serious security shortcomings after reverse engineering the underlying protocol (called the Chip Authentication Programme or CAP) that underpins hand-held card readers. Readers are typically used alongside customer's debit cards to generate one-time codes for online banking login and transaction authentication.

The devices are designed to thwart online banking fraud, but cost-saving measures have resulted in design compromises that have left customers open to risk of fraud.

The researchers' paper, Optimised to Fail: Card readers for online banking, presented at the Financial Cryptography 2009 conference on Thursday, explains the efforts to reduce the cost to the banks and the amount of typing done by customers have created the sort of security shortcomings akin to the introduction of Chip & PIN.

While the principle of CAP — two factor transaction authentication — is sound, the flawed implementation in the UK puts customers at risk of fraud, or worse.

When Chip & PIN was introduced for point-of-sale, the effective liability for fraud was shifted to customers. While the banking code says that customers are not liable unless they were negligent, it is up to the bank to define negligence. In practice, the mere fact that Chip & PIN was used is considered enough. Now that Chip & PIN is used for online banking, we may see a similar reduction of consumer protection.

The research was carried out by reverse-engineer hand-held card readers from UK banks NatWest and Barclays. Cryptographic problems uncovered by the Cambridge team include "reusing authentication tokens, overloading data semantics, and failing to ensure freshness of responses".

The researchers' paper, which details suggestions for increasing the security of readers, can be found here (pdf).

Previous work by the same Cambridge researchers including unpicking the security short-comings of Chip and PIN terminals, which are used to authorise card purchases in retail environments. This research highlighted the absence of encryption in the data exchanged between PIN entry devices and cards during transactions. ®

Internet Security Threat Report 2014

More from The Register

next story
George Clooney, WikiLeaks' lawyer wife hand out burner phones to wedding guests
Day 4: 'News'-papers STILL rammed with Clooney nuptials
Shellshock: 'Larger scale attack' on its way, warn securo-bods
Not just web servers under threat - though TENS of THOUSANDS have been hit
Apple's new iPhone 6 vulnerable to last year's TouchID fingerprint hack
But unsophisticated thieves need not attempt this trick
PEAK IPV4? Global IPv6 traffic is growing, DDoS dying, says Akamai
First time the cache network has seen drop in use of 32-bit-wide IP addresses
Oracle SHELLSHOCKER - data titan lists unpatchables
Database kingpin lists 32 products that can't be patched (yet) as GNU fixes second vuln
Researchers tell black hats: 'YOU'RE SOOO PREDICTABLE'
Want to register that domain? We're way ahead of you.
Stunned by Shellshock Bash bug? Patch all you can – or be punished
UK data watchdog rolls up its sleeves, polishes truncheon
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
The next step in data security
With recent increased privacy concerns and computers becoming more powerful, the chance of hackers being able to crack smaller-sized RSA keys increases.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.