Merchant Terminals Provide New Method For Stealing Customer's Credit Cards

March 4, 2008 by Mary Anne Simpson

UK based Timesonline reports a flurry of credit card fraud in the first half of 2007. Researchers at Cambridge found chip and PIN merchant terminals lack necessary security encryption. The merchant terminal can be programmed to capture pin and card numbers in order to produce a clone card. The programming takes only 10 minutes.

As reported by Timesonline recently, the popular use of chip and PIN cards has a fraudster in the mix. A merchant can program a chip and PIN terminal to capture all the information needed to create a clone card including the PIN number. Researchers from the Computer Laboratory at Cambridge who conducted the investigation found the vulnerability in the device. There are several reported instances, including an incident at a Shell garage.

The apparent vulnerability of the merchant terminals involves the manufacturer´s failure to build in the necessary encryption technology into the device. The specific encryption required is absent from the present terminal model. Thus, the card runs through the device unproteced.

APACS, the UK payment association in charge of the introduction of the chip and PIN technology acknowledged the possibility cited by the Cambridge researchers. An APACS spokesman stated, "We´re not denying this type of fraud is achievable, but there are easier ways of achieving the same type of fraud, including skimming cards and capturing the PIN using a pin-hole camera." This type of fraud is the current focus of APACS.

In January, 2008 Visa announced that all new cards issued would include a new chip-based technology called "ICVV". The technology is designed to alert banks and merchants when a clone card is being used for products or services. Unfortunately, not all banks have made the new cards available to customers.

According to the Cambridge researchers, the problem with the chip and PIN cards is systemic. According to Saar Drimer, one of the Cambridge researchers part of the problem is that lack of an independent evaluation device´s security technology. In fact, GCHQ a govenmental and industry comprised security group confirmed it had not certified the card system technology.

ASPACS says it tested the security of the device utilizing internationally accepted standards called the "Common Criteria." Further stating that other secure devices are tested using these same standards.

The manufacturer of the terminal device, Ingenico disputed the ease in which the device can be manipulated. Stating in pertinent part, " the method ... requires specialist knowledge and has inherent technical difficulties ... and not reproducible on a large scale."

Be that as it may, ASPACS reports losses resulting from credit card fraud rose 26 percent in the first half of 2007. The monetary loss is 263.6 million GBP.


print this article email this article download pdf blog this article bookmark this article     Stumble it Digg this share on Facebook retweet share on Reddit add to delicious
Rate this story - 4.3 /5 (20 votes)


March 4, 2008 all stories

Comments: 0

4.3 /5 (20 votes)
  • Stumble this up

  • Digg this

  • share this

  • hide
  • Related Stories




  • hide
  • Relevant PhysicsForums posts

Other News

Oracle logo

EU objects to Oracle's takeover of Sun

Technology / Business

created 34 minutes ago | popularity not rated yet | comments 0

(AP) -- European antitrust regulators have formally objected to Sun Microsystems Inc.'s planned $7.4 billion sale to Oracle Corp., escalating a battle over a deal that has already been cleared in the U.S.


Video fingerprinting offers search solution

Video fingerprinting offers search solution

Technology / Computer Sciences

created 5 hours ago | popularity not rated yet | comments 0

(PhysOrg.com) -- The explosive growth of video on the internet calls for new ways of sorting and searching audiovisual content. A team of European researchers has developed a groundbreaking solution that is ...


Commercialization of new solar technology to boost solar efficiency

Technology / Energy

created 6 hours ago | popularity 5 / 5 (3) | comments 0

A pioneer in solar power in the 1990s before it became "sexy," University of Houston Professor Alex Freundlich recently entered into a collaborative research agreement with U.K.-based start-up QuantaSol for the development ...


Rubens Barrichello

Google ordered to pay 500,000 dlrs to F1 racer Barrichello

Technology / Business

created 3 hours ago | popularity 1 / 5 (1) | comments 0

Internet giant Google has been ordered to pay 500,000 dollars in damages to Formula 1 racer Rubens Barrichello for hosting fake online profiles of him on its social network Orkut.


A man uses a laptop computer at a wireless cafe

'Cloud' computing market 14 bln dollars by 2014: Gartner

Technology / Business

created 3 hours ago | popularity not rated yet | comments 0

Industry tracker Gartner forecast on Monday that revenue from Internet-based "cloud computing" will top 14 billion dollars annually by the end of 2013.