European Payment Cards Security Problem

Status
Not open for further replies.

Osiris

Golden Master
Messages
36,817
Location
Kentucky
European Payment Cards Security Problem


A recently released technical paper entitled “Chip and pin is broken” by security researchers Steven Murdoch, Saar Drimer, Mike Bond and Ross Anderson demonstrates a man in the middle attack that lets criminals use stolen payment cards without knowing the pin.
This is obviously a serious security problem as banks have always claimed that the security of the cards cannot be broken. The security exploit exists because the negotiation about how the cardholder should be authenticated is not authenticated itself which means that criminals can “card into thinking it's doing a chip-and-signature transaction while the terminal thinks it's chip-and-PIN” which means that it is possible to enter any four digit Pin to complete the transaction.
 
Status
Not open for further replies.
Back
Top Bottom