R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

Chip and pin vulnerable to relay attack

Tetris hackers strike again

Clement James, vnunet.com 07 Feb 2007
ADVERTISEMENT

The Cambridge University computer scientists who hacked a chip and Pin terminal to play Tetris are back with a new exploit.

Saar Drimer and Steven Murdoch claimed that the system is vulnerable to a new kind of fraud which involves "relaying" information from a genuine card.

Using this technique, a chip and Pin terminal in a remote location could be made to accept a counterfeit card.

During a test described on the duo's Light Blue Touchpaper website, a fraudster sets up a fake terminal in a busy shop or restaurant.

When a genuine customer inserts their card into this terminal, the fraudster's accomplice inserts their counterfeit card into the merchant's terminal in another shop.

The fake terminal reads details from the genuine card, and relays them to the counterfeit card so that it will be accepted.

The Pin is recorded by the fake terminal and sent to the accomplice for them to enter, at which point they can walk off with the goods.

The researchers claimed that foul play would only be detected when the victim receives their statement.

"There will be nothing unusual about this transaction from the bank's perspective as it will seem as if the real card was used, with a chip and the correct Pin," the researchers said.

"It should also work equally well via a mobile phone to the other side of the world."

Drimer and Murdoch conceded that it is unlikely that criminals are using techniques such as this, as there are less sophisticated attacks to which chip and Pin remains vulnerable.

However, the researchers warned that, as security is improved, the relay attack may become a significant type of fraud.


All Ecommerce

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Greythorn IT
Leading Mobile Network vendore is currently seeking a Process consultant for a positions based either in the Middle east or Africa. We are looking for around 10 years experience with at least 5 years business ... more >
| Greythorn IT
Tier 1 Network solutions provider is currently seeking an experienced Telecommunications sales manager to work in their Abu Dhabi office. There is a brilliant benefits package as well as an attractive salary available for the ... more >
| Greythorn IT
Leading network solutions provider in Egypt is currently seeking and experienced Egyptian Network Operation /Supervision Engineer. There are competitive packages and attractive benefits package on offer for the right candidate. You will be responsible to ... more >
| Greythorn IT
A leading network Solutions vendor is currently seeking an Egyptian national to act as a Service Assurance manager out of their Egyptian office. Ideally we are looking for someone with Vendor based experience however other ... more >
More job opportunities