Cambridge researchers Expose chip and pin vulnerability

Started by bobito, Sep 12, 2012, 09:35 PM

bobito

Researchers found cards to be open to a form of cloning, even though past assurances from banks that chip and pin could not be compromised.

Poor implementation of cryptography methods were behind the flaw. Pre-play attack works in the following way:

Each time a customer is involved in a chip and pin transaction, be it withdrawing cash or purchasing goods in a shop, a unique unpredictable number is created to authenticate the transaction.

The unpredictable number (UN), generated by software within cash points and other similar equipment, is supposed to be chosen at random.

But researchers discovered that in many cases lacklustre equipment meant the number was highly predictable, because dates or timestamps had been used.


image from anarok

If one can predict the UN, you can record everything you need from momentary access to a chip card to play it back and impersonate the card at a future date and location.

Previous research from the same team demonstrated how a relatively simple man-in-the-middle device - one that sits between two components in a process, such as a card and a chip and pin machine - can trick the system into thinking the correct pin has been entered.







ref: bbc