Feeds

Cambridge boffins rebuff banking industry take down request

NO-PIN down

Providing a secure and efficient Helpdesk

Computer scientists from Cambridge University have rebuffed attempts by a banking association to persuade them to take down a thesis covering the shortcomings of Chip-and-PIN as a payment verification method.

Omar Choudary's masters thesis contains too much information about how it might be possible to fool a retailing terminal into thinking a PIN authorising a purchase had been entered, as far as the bankers are concerned. Noted cryptographer and banking security expert Professor Ross Anderson gives short shrift to the argument that publishing the research exceeds the bounds of responsible disclosure, politely but firmly telling the UK Cards Association that the research was already in the public domain and that Choudary's work would stay online.

Anderson is one of Choudary's supervisors in the latter's research.

Choudary's research on so-called NO-PIN attacks builds on work by Steven Murdoch, Saar Drimer and Anderson that was disclosed to the banking industry last year and published back in February.

Chip-and-PIN is used throughout Europe and in Canada as a method to authorise credit and debit card payments. The attack unearthed by the Cambridge researchers creates a means to trick a card into thinking a chip-and-signature transaction is taking place while the terminal thinks it’s authorised by chip-and-PIN. The flaw creates a means to make transactions that are "Verified by PIN" using a stolen (uncancelled) card without knowing the PIN code. The ruse works by installing a wedge between the card and terminal.

The same approach cannot be applied to make ATM transactions.

In the months since the potential loophole was uncovered only Barclays Bank has responded by modifying its technology to block the potential scam, Anderson reports.

Choudary is one of the authors of an upcoming paper on Chip-and-PIN security, due to be unveiled at the Financial Cryptography 2011 conference in February. ®

Choosing a cloud hosting partner with confidence

More from The Register

next story
SMASH the Bash bug! Apple and Red Hat scramble for patch batches
'Applying multiple security updates is extremely difficult'
Shellshock: 'Larger scale attack' on its way, warn securo-bods
Not just web servers under threat - though TENS of THOUSANDS have been hit
Apple's new iPhone 6 vulnerable to last year's TouchID fingerprint hack
But unsophisticated thieves need not attempt this trick
Hackers thrash Bash Shellshock bug: World races to cover hole
Update your gear now to avoid early attacks hitting the web
Oracle SHELLSHOCKER - data titan lists unpatchables
Database kingpin lists 32 products that can't be patched (yet) as GNU fixes second vuln
Who.is does the Harlem Shake
Blame it on LOLing XSS terroristas
Researchers tell black hats: 'YOU'RE SOOO PREDICTABLE'
Want to register that domain? We're way ahead of you.
Stunned by Shellshock Bash bug? Patch all you can – or be punished
UK data watchdog rolls up its sleeves, polishes truncheon
prev story

Whitepapers

A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.