Credit card vulnerability still alive and well - AusCERT 2011
- 18 May, 2011 13:39
- Comments
Cambridge University professor, Ross Anderson.
Global banks are yet to solve a vulnerability in the Europay, Mastercard and Visa (EMV) integrated circuit standard first rolled out in 2003, allowing hackers to place Trojan devices on point of sale hardware to harvest user and credit card information.
EMV is the global standard used by card providers for integrated circuit (IC) debit and credit cards used in point of sale terminals and automatic teller machines (ATMs).
However, Cambridge University Professor, Ross Anderson, said he had found a vulnerability in 2007 with the PIN entry devices (PEDs) used as part of the standard. Anderson, along with two students, conducted reverse engineering on the devices in 2007.
“We found that if you went into the back of the product and drilled in, you could drop a paper clip on to the wire which is the serial port between the pin pad and the smart card,” he said.
With this paper clip, he said the device could become a Trojan with enough data harvested from every transaction to make a mag stripe version of a card and use it at any ATM.
“We told the banks in October 2007 and they said `it’s not a problem because the criminals aren’t as clever as you Cambridge University chaps’. But this wasn’t true because bad guys were already doing it.”
In July 2008, cyber criminals gained access to a warehouse in Dubai where the devices were stored and managed to store a Trojan device under the keyboard. This device was used to harvest information from the users' cards. “It was possible for people to have a transaction done in a bank and have their credentials stolen,” he said. “The bank would than sue the user for negilence because it was not their fault.”
“In 2003 we were the pioneers [of EMV] and were told it was going to solve problems,” he said. “From the bank’s point of view it was a great rollout because the deal with EMV was that if there was a dispute [with a payment], then the user was liable.”
According to Anderson, rather than solving the problem banks hoped fraud would decrease, rather than increase as happened in reality.
A worrying factor, Anderson said, was the continuing vulnerabilties with EMV chip and pin systems, coupled with the fact that banks, at least in the UK, do not share information about phishing and cybercriminal attacks.
“The banks need an incentive to get this right but they take a short term and country rather than global view of it,” he said.
“Banks could do better if they shared information on phishing,” said Anderson. “If bankers were rational than they wouldn’t have a problem.”
The lack of global and local laws mandating companies disclose phishing or hacking attempts against internal systems has continued to be a vocal point for many security experts.
Hamish Barwick travelled to AusCERT 2011 as a guest of AusCERT
Got a security tip-off? Contact Hamish Barwick at hamish_barwick at idg.com.au
Follow Hamish Barwick on Twitter: @HamishBarwick
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
- The Top 5 Server Monitoring Battles—and How You Can Win Them
- Get the Whole Picture Why Most Organizations Miss User Response Monitoring—and What to Do About It
- Case Study: Keeping information on the move: Clearswift protects Maman, the logistics experts
- Mobile Security: Don’t leave employees to their own devices
- Seven Tips for Securing Mobile Workers
-
Google Jumps Into Social Bookmarks Game
-
NBN build gaining momentum daily: Quigley
-
Face Time - Interview with John Brennan and Robert DiStefano
-
Monday Grok: Will Siri crack the walls of GOOG?
-
Face Time - Interview with John Brennan and Robert DiStefano
-
Eight things senior managers need to know about data encryption
Securing sensitive data is a must for every organization. Today’s encryption solutions don’t slow down your users, so you’re not compromising productivity for security. Here are eight things senior managers need to know about encryption to keep their data secure. -
Control your Print Environment
In your ongoing quest to maximize productivity and drive down costs, you might be surprised by the savings and greater competitive advantage you can achieve with a fully optimised and well-managed printing and imaging environment. In fact, studies have shown that managing your fleet holistically can save you upwards of 30% on your printing costs. And the savings increase exponentially when the scope of work includes automating your paper intensive workflows. Read more. -
Workshifting: a global market research report
New business requirements are transforming the demands placed on IT. To operate effectively in today’s fast-paced global environment, organisations need to be able to get work done anywhere, anytime, by any type of worker to achieve the best results. This is the context for the rise of workshifting—the practice of moving work to the most optimal location, time and resources. As one of the most comprehensive reports ever conducted into the role of desktop virtualisation in enabling workplace flexibility and mobility, it reflects the growing consensus of those using technology to improve the performance of their organisation.
-
Microsoft Official Academic Course
-
Mastering Microsoft Exchange Server 2003
-
Professional JavaScript for Web Developers
-
Google Power Tools Bible
-
Microsoft Windows Vista Simplified
-
Professional Visual Basic 2010 and .Net 4
-
Internet for Canadians for Dummies
-
Standard Pascal User Referance Manual
-
Introducing Maya








Comments
Post new comment