Showing posts with label Cambridge University. Show all posts
Showing posts with label Cambridge University. Show all posts



University of CambridgeChip and PIN has come under further scrutiny today as research shows a vulnerability allowing criminals to use cards without the owner’s number.
By Jennifer Scott, 26 Apr 2010 at 15:47
Chip and PIN
Cyber criminals are able to abuse the Chip and PIN system, even without the cardholder’s four digits, according to new research released today.
The study by Cambridge University’s Computer Laboratory has shown that thanks to a protocol flaw a “man in the middle” attack is possible, whereby criminals can insert an electronic device between the card and the terminal, fooling it into believing the PIN is verified.
Eli Jellenç, head of international cyber intelligence at iD...


Posted by John B. Frank Monday, April 26, 2010 0 comments



University of CambridgeChip and PIN has come under further scrutiny today as research shows a vulnerability allowing criminals to use cards without the owner’s number.
By Jennifer Scott, 26 Apr 2010 at 15:47
Chip and PIN
Cyber criminals are able to abuse the Chip and PIN system, even without the cardholder’s four digits, according to new research released today.
The study by Cambridge University’s Computer Laboratory has shown that thanks to a protocol flaw a “man in the middle” attack is possible, whereby criminals can insert an electronic device between the card and the terminal, fooling it into believing the PIN is verified.
Eli Jellenç, head of international cyber intelligence at iD...


Posted by John B. Frank 0 comments



ZDNet is reporting that "the body that oversees the technology behind chip-based payment cards is to investigate chip-and-PIN security, following claims that the protocol has been broken."



Chip-and-PIN flaw to be investigated by industry body  Tom Espiner ZDNet UK
The specification body, EMVCo, said it will analyze a paper by researchers from Cambridge University, who demonstrated an attack with a valid payment card that did not require a valid PIN to be entered to complete a transaction.



EMVCo, owned by American Express, JCB, MasterCard and Visa, said those debit- and credit-card payment companies will also scrutinize the paper.



"EMVCo will conduct its own analysis and draw its own conclusions," said the organisation on Wednesday. "The payment systems will do the same."



Last week researchers from Cambridge University said they had found a fundamental flaw in EMV, the protocol behind chip-and-PIN payments. The flaw had allowed them to build a device that modified and intercepted communications between a card and a point-of-sale terminal, and fool the terminal into accepting that a PIN verification had succeeded.



MasterCard confirmed that it would be working with the other card-payment providers to review security around chip-and-PIN, but said this was part of an ongoing process.



"The EMV standard is under constant review by MasterCard and many other major industry players to make sure it evolves to meet emerging product needs," said MasterCard. "These efforts include a frequent and regular review of security to make sure the latest, practical mechanisms are used."



Professor Ross Anderson of Cambridge University, who led the chip-and-PIN research, said there would be no easy fix for the protocol.



"There is much disagreement about [effective] industry measures to fix the vulnerability," said Anderson. "If you look at our blog post [publicising the vulnerability], a significant number of people who claim to be industry experts disagree."



One of the researchers' assertions in their paper, Chip and PIN is Broken, was that the consumer would bear the cost of a fraudulent card transaction if records showed a PIN had been entered into a terminal.



Continue Reading at ZDNet






Posted by John B. Frank Friday, February 19, 2010 0 comments




Chip and PIN Research Slammed...as "Alarmist"
Chip and PIN research slammed as ‘alarmist’



Industry analysts have defended the benefits

of chip and PIN payments security after computer scientists at the UK’s University of Cambridge announced they had discovered a flaw in the PIN verification feature of the EMV protocol.




Acccording to the scientists, a man-in-the-middle device can intercept and modify the communications between a payment card and the POS terminal, and then trick the terminal into believing that PIN verification has succeeded. In a draft paper entitled ‘Chip and PIN is Broken’, the scientists said: “A dummy PIN must be entered, but the attack allows any one to be accepted.”



The report added: “Attacks such as this could help explain the many cases in which a card has supposedly been used with the PIN, despite the customer being adamant that they have not divulged it.”



Gareth Wokes, chairman of The Logic Group, which manages information and transactions for businesses, described the Cambridge research as “alarmist”.








Why do we still type our numbers into boxes at web checkout?
Wokes said: “To position this as an overall failure of chip and PIN is misleading and counter-productive to the industry’s efforts against fraud. Chip and PIN successfully addressed the issue that it was created to address: that the person making a transaction is who they say they are. As such, a year after chip and PIN was introduced, card fraud dropped by 48 percent.”



He added that fraudsters have since moved on to e-commerce fraud, where chip and PIN technology is irrelevant,
Editor's Note:  "irrelevant" ONLY because we still conduct online transactions as if we live in the stone ages, i.e. typing Primary Account Numbers into boxes at website merchant checkouts worldwide.  which is why fraud figures have subsequently begun to increase.










Continue Reading at Lafferty











Posted by John B. Frank Tuesday, February 16, 2010 0 comments

University of CambridgeImage via Wikipedia

Todos addresses Cambridge University research concerned with ecommerce security

A study by the University of Cambridge shows that 3D Secure (3DS) technology may boast more than the security it actually provides. According to the report’s authors, Steven Murdoch and Ross Anderson, concern has been expressed with the current approach to e-commerce security, saying that there have been many serious problems in the 3DS environment.





The study revealed that the main problems come from the reliance on static passwords and the need to authenticate users at the point when they first enter their password.


Todos technology has addressed this works within the 3DS environment to offer merchants and card issuer two-factor authentication solutions. This would replace the static password and be available to use on a Todos device or mobile application and a private PIN.



With the two-factor authentications, users can securely validate online transactions without disclosing any sensitive personal information.






Posted by John B. Frank Thursday, February 11, 2010 0 comments

Flaw 'calls entire architecture' of chip and pin into question

The BBC's Newsnight reveals a serious flaw in the chip and pin system uncovered by Cambridge University researchers which could allow criminals to make bank card payments without knowing the correct pin number.

Watch Susan Watts' full report on Newsnight on Thursday at 10.30pm on BBC Two, then afterwards on the BBC iPlayer and Newsnight website.

Posted by John B. Frank 0 comments











Evan Schuman, Editor of StorefrontBacktalk.com, released the full text of the recent Cambridge Report that, in no uncertain terms, states that: Verified by Visa is a "Textbook Example of How NOT to Design an Authentication Protocol"



If you are unfamiliar with Evan's blog, take a moment to visit. I've provided a link (title of post) to StorefrontBacktalk below:



Full Text Of Cambridge Report On Verified by Visa and MasterCard SecureCode



Written by Evan Schuman, today, February 6th, 2010



Verifed by Visa and MasterCard SecureCode: or, How Not to Design Authentication

Steven J. Murdoch and Ross Anderson: Computer Laboratory, University of Cambridge, UK






Editor's Note:  Way back, In October 2008  I posted a story from The Register regarding the the lack of protection afforded Verified by Visa users. Is Verified by Visa also Verified by Hackers?  Here's what they had to say about VbV back then.  I dug it back up and am republishing a comment that stuck in my head at the time. 



Verified by Visa and Mastercard SecureCode are there purely to protect the banks, not the card holder. They offer zero additional protection to the consumer, but allow the bank to claim that transactions using purloined credit card credentials were really made by the card holder. It is as simple as that. 



The issue has been noted, and commented on in the blogosphere as far back as June 2008, but has received little attention in the mainstream media, despite the obvious security implications.




Editor's Note from October 2008: The more I learn about securing a transaction on the web, the more I realize how unsafe many transactions actually are. Here's an interesting article in the Register regarding Visa's supposedly more secure program designed to fool cardholders into thinking their transactions are more secure. They call it "Verified by Visa." Caveat:  First it has to verified by consumers, (by typing into a web browser) which means it can also be keystroke logged and  "Verified by Hackers." (VbH?)



"VbyV login credentials
make it easier for crooks to make purchases online while simultaneously making it harder for consumers to deny responsibility for a fraudulent transaction".


Since card information is can be bought online for as low as $2.50, "Stolen Card Info Plunges to $2.50 in Black Market" and obtaining a DOB is so easy a caveman could do it, it's looking like VbV is more of a marketing ploy than of any real value when it comes to protecting the security of an online transaction. What I found even more interesting was Visa's declination to comment about the story which the Register tells us at the end of this article:


VbyV password reset is childishly simple • The Register



Both VbyV and SecureCode are based on 3DSecure, a name that hints at the introduction of some kind of three-factor authentication scheme. But unlike robust authentication techniques, hackers don't have a hardware token generating one-time passwords to worry about - it's just more of the same.



And since card details + CVV number is no longer considered as secure enough then it's hard to see how card details + CVV number + VbyV login is any more robust.



Much was made of how easy it was for a hacker to reset Sarah Palin's webmail account password and gain illicit access to emails, but resetting passwords for Verified by Visa - which supposedly makes online transactions more secure is arguably even easier. To reset Palin's email account a hacker needed to know the Republican VP candidate's birth date, her zip code and the answer to a secret question on where she met her husband. Resetting a Verified by Visa password, by contrast, requires only card details (got $2.50?) and a date of birth.



Register commenter Anthony explains.



Verified by Visa (VbV) allows anyone who has the credit card number in their hands to set a new password for VbV with just the card details and the card owner's date of birth. Since the latter is trivial to discover for most people, this adds almost no additional security to the process.



Register reader Jusme reports the same issue. Verified by Visa is one of the reasons I no longer use Barclaycard. Pretty much every time I had to use it the password was not recognised and I had to "reset it", which just meant entering my DOB and a new password, hardly very secure.



Online shoppers who buy goods and service with participating retailers are asked to submit a VbyV or SecureCode password to authorise transactions. These additional checks are typically submitted via a website affiliated to a card-issuing bank but with no obvious connection to a user's bank. Punters aren't informed up front that a merchant has signed up to Verified by Visa. Sites used to authenticate a VbyV or SecureCode password routinely deliver a dialogue box using a pop-up window or inline frame, making it difficult to detect whether or not a site is genuine.  The appearance of phishing attacks hunting for Verified by Visa passwords are among the reasons some punters are wary of the technology. Once obtained by fraudsters, either by direct phishing attack or through other more subtle forms of social engineering trickery,





An anonymous commenter to our original stories agrees:

Verified by Visa and Mastercard SecureCode are there purely to protect the banks, not the card holder. They offer zero additional protection to the consumer, but allow the bank to claim that transactions using purloined credit card credentials were really made by the card holder. It is as simple as that.
The issue has been noted, and commented on in the blogosphere as far back as June, but has received little attention in the mainstream media, despite the obvious security implications.


Read more: http://pindebit.blogspot.com/2008/10/is-verified-by-visa-also-verified-by.html#ixzz0emaZgxJW









Posted by John B. Frank Saturday, February 6, 2010 0 comments

In a TG Daily story, Emma Woolacott writes about the recent revelation that Verified by Visa and MasterCard SecureCode are NOT SECURE...

Credit card verification systems 'not secure'

Emma Woollacott | Fri 29th Jan 2010, 05:41 am

  • The Verified by Visa and MasterCard SecureCode credit card checks are fundamentally flawed, according to security researchers.




  • The 3-D Secure protocol, which underlies both, "might be a textbook example of how NOT to design an authentication protocol," say Steven Murdoch and Ross Anderson of the University of Cambridge Computer Lab.




  • "It ignores good design principles and has significant vulnerabilities, some of which are already being exploited. 



Posted by John B. Frank Friday, January 29, 2010 0 comments

Payments Industry News Blog

Search the PIN Debit Blog by Subject

Kapersky Calls for Mass Adoption of Card Readers

Kapersky Calls for Mass Adoption of Card Readers