Showing posts with label Man-in-the-middle attack. Show all posts
Showing posts with label Man-in-the-middle attack. Show all posts

Monday, April 26, 2010

No PIN Needed to Fool Chip and PIN Technology - Cambridge



University of CambridgeChip and PIN has come under further scrutiny today as research shows a vulnerability allowing criminals to use cards without the owner’s number.
By Jennifer Scott, 26 Apr 2010 at 15:47
Chip and PIN
Cyber criminals are able to abuse the Chip and PIN system, even without the cardholder’s four digits, according to new research released today.
The study by Cambridge University’s Computer Laboratory has shown that thanks to a protocol flaw a “man in the middle” attack is possible, whereby criminals can insert an electronic device between the card and the terminal, fooling it into believing the PIN is verified.
Eli Jellenç, head of international cyber intelligence at iD...


No PIN Needed to Fool Chip and PIN Technology - Cambridge



University of CambridgeChip and PIN has come under further scrutiny today as research shows a vulnerability allowing criminals to use cards without the owner’s number.
By Jennifer Scott, 26 Apr 2010 at 15:47
Chip and PIN
Cyber criminals are able to abuse the Chip and PIN system, even without the cardholder’s four digits, according to new research released today.
The study by Cambridge University’s Computer Laboratory has shown that thanks to a protocol flaw a “man in the middle” attack is possible, whereby criminals can insert an electronic device between the card and the terminal, fooling it into believing the PIN is verified.
Eli Jellenç, head of international cyber intelligence at iD...


Wednesday, March 17, 2010

Todos says Gartner Report Vindicates Transaction Verification

Gothenburg, Sweden, March 17, 2010 -- "Fraudsters are beating strong two-factor authentication and are proving that any authentication method that relies on browser communications can be defeated," says a recent report from Gartner, an IT research firm.



Using malware, fraudsters have been able to intercept users' logins and hijack authorised sessions or overwrite the legitimate transactions with their own. Even systems that rely on phone or SMS authentication are vulnerable to call redirection and social engineering.



Gartner makes a number of recommendations to defeat this threat. First, the report recommends that banks verify individual transactions as well as online banking logins. Todos's Sign-what-you-see technology allows banks to do exactly that. The user can verify the payee and amount of individual transactions on selected Todos authenticators and via our onMobile solution. This makes it harder for criminals to overwrite legitimate user transactions.



Second, Gartner says "enterprises should not deluge users with transaction verification requests, and should keep them simple and confined to high-risk transactions, so that users are sure to pay detailed attention to them." Todos has a solution for that too: Dynamic Signatures. This allows banks to request additional verification (such as a sign-what-you-see request) for transactions based on 'riskiness'. So, for example, a small payment to regular recipient is fine but a large, one-off payment triggers additional authentication.



Third, the company recommends the use of out-of-band communications that prevent calls being forwarded. Todos's next-generation connectible smart card readers support a secure channel between the reader and the bank that bypasses the browser altogether. This patent-protected innovation called Autograf is unique to Todos and prevents man-in-the-middle attacks.



These technologies - Sign-what-you-see, out of band communication channels and Dynamic Signatures are also available on smart phones using Todos onMobile. In addition, Secure Domain Separation - another unique Todos technology - keeps banking and ecommerce authentication separate so that a breach in one area does not compromise the other.



"Gartner have done a great service in highlighting the latest threats to online banking (and other web services)," says Håkan Nordfjell, COO at Todos. "The good news is that we're doing a good job of defeating these threats. This report vindicates our strategy in the fight against online fraud."



###

Todos AB helps banks and other businesses create trusted, secure relationships with their customers online. Founded in 1987, Todos designs, develops, delivers and supports security solutions for remote authentication. We have delivered over 20m products to 100+ financial institutions in more than 30 countries. When trust matters, trust Todos.



Source: Company press release.

Tuesday, February 16, 2010

Chip and PIN Cambridge Research Slammed as "Alarmist"




Chip and PIN Research Slammed...as "Alarmist"
Chip and PIN research slammed as ‘alarmist’



Industry analysts have defended the benefits

of chip and PIN payments security after computer scientists at the UK’s University of Cambridge announced they had discovered a flaw in the PIN verification feature of the EMV protocol.




Acccording to the scientists, a man-in-the-middle device can intercept and modify the communications between a payment card and the POS terminal, and then trick the terminal into believing that PIN verification has succeeded. In a draft paper entitled ‘Chip and PIN is Broken’, the scientists said: “A dummy PIN must be entered, but the attack allows any one to be accepted.”



The report added: “Attacks such as this could help explain the many cases in which a card has supposedly been used with the PIN, despite the customer being adamant that they have not divulged it.”



Gareth Wokes, chairman of The Logic Group, which manages information and transactions for businesses, described the Cambridge research as “alarmist”.








Why do we still type our numbers into boxes at web checkout?
Wokes said: “To position this as an overall failure of chip and PIN is misleading and counter-productive to the industry’s efforts against fraud. Chip and PIN successfully addressed the issue that it was created to address: that the person making a transaction is who they say they are. As such, a year after chip and PIN was introduced, card fraud dropped by 48 percent.”



He added that fraudsters have since moved on to e-commerce fraud, where chip and PIN technology is irrelevant,
Editor's Note:  "irrelevant" ONLY because we still conduct online transactions as if we live in the stone ages, i.e. typing Primary Account Numbers into boxes at website merchant checkouts worldwide.  which is why fraud figures have subsequently begun to increase.










Continue Reading at Lafferty











Thursday, March 5, 2009

Nostra(para)digmus


I
've posted quite a few times that we're in the midst of a major Paradigm Shift. (use the HomeATM search bar on the right and "enter paradigm shift" to read) I took a moment to outline (see graphic on left) some of the finer points which provide e-vidence of this impending shift.

I am positive that convenience will be forced to take a backseat to security which is clearly going to be in the drivers seat.

Likewise, I am more confident that in order to secure a transaction it has to be done by Hardware. No predictions there...just fact. To the engineers at HomeATM...it's a foregone conclusion. It doesn't matter what anyone says today... tomorrow always shows us the truth.

Truth is, hardware is not a "better" option, it's the only option. Software is breached 92% of the time vs. only 1% for hardware.

One doesn't need to be Einstein to figure out that if something is breached 92 times more than something else, then the "something else" MUST be more secure.

Question: If something is breached 1% of the time vs. 92%, then wouldn't it be at least 92 times easier to to "fix" what causes 1% of breaches?  In the case of hardware being breached, tampering was virtually to blame everytime. So we made our SwipePIN device tamper proof. We're done.



When you consider new cracks in Secure Socket Layer(SSL) websites , DNS hijacking, Man-in-the Middle Attacks (MITM) Malware, bots, and combine that with the fact that there's been3 Major Processor Hacks in 3 Months, these are indeed dangerous times. This doesn't even take into account the YTBD hacks which will occur in the near future.


We're all at risk for loss if we believe that a PIN Based solution can be peripheraless. Once again, Hardware is not an option. IBM came to the same conclusion whilst looking at how to best secure online banking. See: IBM Agrees with HomeATM....Hardware Required.

Information security will become the number one priority for EVERYONE, and the ONLY way to securely transact an e-commerce transaction is via hardware. There is NO other way. Besides...what's the anti-convenience rhetoric about Hardware anyway?  Doesn't it make it more convenient when you don't have to type in a bunch of digits, expiration dates or CVV's. 

Besides...we're used to hardware...don't you have to plug a cigarette adapter into your iPhone or Blackberry to charge it? How hard is that?  Well, in addition to processing PIN Debit, you can plug in the HomeATM SwipePIN device and "charge it."  What's the difference?  Plug in cell-phone to charge it...Plug in SwipePIN device to charge it. 
(Don't forget about our PIN my Card application which allows you to securely assign a PIN number to your credit card, providing a more secure dually-authenticated transaction) 


The Internet is demonstrating significant power to provide "Net"profit", Cash has been replaced as King, having being "overthrone" by King Debit, and information security is more important than ever. It doesn't take Nostradamus to write a quatrain predicting that EFT Networks will want their piece of the PIN Debit/Credit Internet Pie.  And rightly so!  Why should they be "shut out" from Internet transactions?  

PIN Debit leads Signature Debit 45%-35% in the physical world, but doesn't yet exist in the virtual one. Can you possibly disagree that the paradigm shift will contribute towards bringing PIN Debit to the web? Problem is...in the past retailers were the focal point of hackers. Got the Personal Account Numbers but never the PIN. Now it's processors. 100 Million Personal Account Numbers...Zero PIN's.

PIN's are the Holy Grail to Hackers. Doesn't ANYONE SEE (beside's Avivah Litan, HomeATM and IBM) what's going to happen if we attempt to secure them in a software environment?

Nostra(para)digmus predicts that no matter what we see today, tomorrow will show us the truth.

















Reblog this post [with Zemanta]

Disqus for ePayment News