Feeds

Cambridge security boffins slam banking card readers

'Optimised to fail'

Security for virtualized datacentres

Card readers for online banking are inherently insecure, according to a new study by Cambridge security researchers.

Researchers Saar Drimer, Steven J Murdoch and Ross Anderson found a number of serious security shortcomings after reverse engineering the underlying protocol (called the Chip Authentication Programme or CAP) that underpins hand-held card readers. Readers are typically used alongside customer's debit cards to generate one-time codes for online banking login and transaction authentication.

The devices are designed to thwart online banking fraud, but cost-saving measures have resulted in design compromises that have left customers open to risk of fraud.

The researchers' paper, Optimised to Fail: Card readers for online banking, presented at the Financial Cryptography 2009 conference on Thursday, explains the efforts to reduce the cost to the banks and the amount of typing done by customers have created the sort of security shortcomings akin to the introduction of Chip & PIN.

While the principle of CAP — two factor transaction authentication — is sound, the flawed implementation in the UK puts customers at risk of fraud, or worse.

When Chip & PIN was introduced for point-of-sale, the effective liability for fraud was shifted to customers. While the banking code says that customers are not liable unless they were negligent, it is up to the bank to define negligence. In practice, the mere fact that Chip & PIN was used is considered enough. Now that Chip & PIN is used for online banking, we may see a similar reduction of consumer protection.

The research was carried out by reverse-engineer hand-held card readers from UK banks NatWest and Barclays. Cryptographic problems uncovered by the Cambridge team include "reusing authentication tokens, overloading data semantics, and failing to ensure freshness of responses".

The researchers' paper, which details suggestions for increasing the security of readers, can be found here (pdf).

Previous work by the same Cambridge researchers including unpicking the security short-comings of Chip and PIN terminals, which are used to authorise card purchases in retail environments. This research highlighted the absence of encryption in the data exchanged between PIN entry devices and cards during transactions. ®

Secure remote control for conventional and virtual desktops

More from The Register

next story
NASTY SSL 3.0 vuln to be revealed soon – sources (Update: It's POODLE)
So nasty no one's even whispering until patch is out
Russian hackers exploit 'Sandworm' bug 'to spy on NATO, EU PCs'
Fix imminent from Microsoft for Vista, Server 2008, other stuff
Microsoft pulls another dodgy patch
Redmond makes a hash of hashing add-on
'LulzSec leader Aush0k' found to be naughty boy not worthy of jail
15 months home detention leaves egg on feds' faces as they grab for more power
Forget passwords, let's use SELFIES, says Obama's cyber tsar
Michael Daniel wants to kill passwords dead
FBI boss: We don't want a backdoor, we want the front door to phones
Claims it's what the Founding Fathers would have wanted – catching killers and pedos
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Win a year’s supply of chocolate
There is no techie angle to this competition so we're not going to pretend there is, but everyone loves chocolate so who cares.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.