Cambridge researchers show Chip and PIN system vulnerable to fraud
February 11, 2010
(PhysOrg.com) -- Researchers at the University of Cambridge Computer Laboratory have uncovered flaws in the Chip and PIN system that allow criminals to use stolen credit and debit cards without knowing the correct PIN.
Fraudsters can easily insert a "wedge" between the stolen card and terminal, which tricks the terminal into believing that the PIN was correctly verified. In fact, the fraudster can enter any PIN, and the transaction will be accepted, Steven Murdoch, Saar Drimer, Ross Anderson and Mike Bond have found.
According to Dr Murdoch: "We have tested this attack against cards issued by most major UK banks. All have been found to be vulnerable."
Victims of this attack may have a difficult time being refunded by their bank. The receipt produced will state "Verified by PIN", and bank records will show that the correct PIN was used. Banks may then argue that the customer must have been negligent and had allowed the criminal to know their PIN.
Dr Drimer says: "The technical sophistication for carrying out this attack is low, and the compact equipment will not be noticed by shop staff. A single criminal can develop and industrialise a kit to be used by others who do not need to understand how the attack works."
The Cambridge attacks - being broadcast on BBC Two's Newsnight - call into question both the design of the Chip and PIN system, and the security of card payments. Victims of fraud are commonly told that bank systems can be relied upon. However, this attack shows that criminals are able to not only defraud customers, but cause bank systems to make the false assertion that the PIN was verified correctly.
Professor Anderson says: "Over the past five years, thousands of cardholders have had stolen chip and PIN cards used by criminals. The banks often tell customers that their PIN was used and so it's their fault. Yet we've shown that it's easy to use a card without knowing the PIN - and the receipt will say the transaction was 'verified by PIN' even though it wasn't."
"This is not just a failure of bank technology. It's a failure of bank regulation. The ombudsman supported the banks and the regulators have refused to do anything. They were just too eager to believe the banks."
The attack - including a demonstration of it being deployed in practice - will be featured BBC Two's Newsnight at 10:30pm on Thursday 11 February 2010.
The Cambridge team's results are also to be presented at the academic conference "IEEE Symposium on Security and Privacy", Oakland, CA, US, in May 2010.
-
Software defect hits millions of German bank cards
Jan 05, 2010 |
not rated yet |
0
-
Phishers Use Call Forwarding to Mask Fraud
Apr 28, 2007 |
not rated yet |
0
-
Human error puts online banking security at risk
Nov 07, 2007 |
not rated yet |
0
-
Too much security reduces trust in online banking
Jan 29, 2008 |
not rated yet |
0
-
Feds bolstering online banking security
Oct 19, 2005 |
not rated yet |
0
-
Engineers build first sub-10-nm carbon nanotube transistor
Feb 01, 2012 |
4.9 / 5 (29) |
30
-
Something old, something new: Evolution and the structural divergence of duplicate genes
Jan 31, 2012 |
4.6 / 5 (7) |
1
-
The hidden nanoworld of ice crystals: Revealing the dynamic behavior of quasi-liquid layers
Jan 30, 2012 |
5 / 5 (3) |
1
-
Stock market network reveals investor clustering
Jan 27, 2012 |
3.9 / 5 (23) |
8
-
Of microchemistry and molecules: Electronic microfluidic device synthesizes biocompatible probes
Jan 26, 2012 |
5 / 5 (1) |
0
-
Synergistic relations between computer science and technology.
Feb 06, 2012
-
how do iphone gloves work?
Feb 05, 2012
-
iPhone battery over time
Jan 30, 2012
-
Best alternate Tablet to an iPad for writing math or physics equations?
Jan 26, 2012
-
Sending SMS to a website
Jan 20, 2012
-
Need help with my technical fest!
Jan 19, 2012
- More from Physics Forums - Computing & Technology
More news stories
Windows 8 preview set for February 29
Microsoft on Wednesday revealed plans to unveil a test version of its latest Windows computer operating software later this month.
6 hours ago |
3.8 / 5 (4) |
5
Solar start-ups set new efficiency records
(PhysOrg.com) -- Although Alta Devices and Semprius make different types of solar panels, both start-ups have been breaking records in the past few days. Santa Clara, Calif.-based Alta Devices announced that ...
Groupon fails to turn profit as revenue grows
Daily deals site Groupon on Wednesday issued its first earnings report as a publicly traded company, saying it failed to turn a profit despite revenue nearly tripling from a year earlier.
4 hours ago |
not rated yet |
0
Lawsuit seeks to block Google's privacy changes
(AP) -- A consumer watchdog group is suing the Federal Trade Commission in an attempt to prevent Google from making sweeping changes to its privacy policies next month.
4 hours ago |
not rated yet |
0
Romanian accused of hacking NASA-JPL computers
(AP) -- The Los Angeles U.S. attorney's office says a federal grand jury has indicted a Romanian citizen on charges he hacked into 25 climate-research computers at NASA's Jet Propulsion Laboratory in Pasadena.
4 hours ago |
not rated yet |
0
Astronomy team discovers nearby dwarf galaxy
(PhysOrg.com) -- A team led by UCLA research astronomer Michael Rich has used a unique telescope to discover a previously unknown companion to the nearby galaxy NGC 4449, which is some 12.5 million light years ...
Amasia: As next supercontinent forms, Arctic Ocean, Caribbean will vanish first
(PhysOrg.com) -- Geologists at Yale University have proposed a new theory to describe the formation of supercontinents, the epic process by which Earths major continental blocks combine into a single ...
Why are there so few fish in the Earth's oceans?
(PhysOrg.com) -- A Stony Brook University researcher has found that, contrary to popular belief, there are not plenty of fish in the sea.
Transparent iron? For the first time, an experiment shows that atomic nuclei can become transparent
At the high-brilliance synchrotron light source PETRA III, a team of DESY scientists headed by Dr. Ralf Röhlsberger has succeeded in making atomic nuclei transparent with the help of X-ray light. At the ...
Physicists build highly efficient 'no-waste' laser
A team of University of California, San Diego researchers has built the smallest room-temperature nanolaser to date, as well as an even more startling device: a highly efficient, "thresholdless" laser that ...
Scientists strengthen memory by stimulating key site in brain
Ever gone to the movies and forgotten where you parked the car? New UCLA research may one day help you improve your memory.