brianpuccio.net

it's dot com

No Encryption Is Used On PIN Entry Devices, Making It Easy To Steal PINs

The UK banking industry chose to deploy Chip & PIN cards that do not encrypt the data exchanged between the card and the PED during a transaction. By tapping these communications, fraudsters can obtain the PIN and create a magnetic strip version of the card to make ATM withdrawals in the UK and abroad. We examined two of the most popular PEDs used in the UK and found that cardholders are exposed to simple and cheap attacks.

Our investigations of why this failure took place also discovered flaws in the certification system which is supposed to protect customers. Overall responsibility for certification lies with the banking industry itself and the process of evaluation is hidden from the public. Despite our findings, none of the PEDs we examined are to be removed from service.

Local mirror of paper detailing PED insecurities

Syndicate

Syndicate content

User login