R E L A T E D   C O N T E N T
ADVERTISEMENT

Chip and pin vulnerable to relay attack

Tetris hackers strike again

Clement James, vnunet.com 07 Feb 2007
ADVERTISEMENT

The Cambridge University computer scientists who hacked a chip and Pin terminal to play Tetris are back with a new exploit.

Saar Drimer and Steven Murdoch claimed that the system is vulnerable to a new kind of fraud which involves "relaying" information from a genuine card.

Using this technique, a chip and Pin terminal in a remote location could be made to accept a counterfeit card.

During a test described on the duo's Light Blue Touchpaper website, a fraudster sets up a fake terminal in a busy shop or restaurant.

When a genuine customer inserts their card into this terminal, the fraudster's accomplice inserts their counterfeit card into the merchant's terminal in another shop.

The fake terminal reads details from the genuine card, and relays them to the counterfeit card so that it will be accepted.

The Pin is recorded by the fake terminal and sent to the accomplice for them to enter, at which point they can walk off with the goods.

The researchers claimed that foul play would only be detected when the victim receives their statement.

"There will be nothing unusual about this transaction from the bank's perspective as it will seem as if the real card was used, with a chip and the correct Pin," the researchers said.

"It should also work equally well via a mobile phone to the other side of the world."

Drimer and Murdoch conceded that it is unlikely that criminals are using techniques such as this, as there are less sophisticated attacks to which chip and Pin remains vulnerable.

However, the researchers warned that, as security is improved, the relay attack may become a significant type of fraud.


All Ecommerce

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
Java, J2EE, Developer, Spring, Hibernate, London, city, Graduate. This is an amazing opportunity to join a successful city based team working at the cutting edge of development. My client is looking for strong Java/J2EE developers ... more >
| Aston Carter
E-Commerce, Greenfield, Agile, Java, J2EE, , JavaScript, SQL, London, City Graduate This is an exceptional opportunity for a talented Java, J2EE developer keen to work in a successful development team within arguable the best agile ... more >
| Rullion Computer Personnel Ltd
2nd Line Support Analyst London £35, 000 to £40, 500 My client is a global market leader in the Internet Applications Industry. The company is continually progressing and looking for areas of growth and this ... more >
| Rullion Computer Personnel Ltd
Security Architect / Information Security Specialist – St Albans - Global Leader - Shine At The Highest Level Security Solution Architect / Information Security Architect required by renowned blue-chip organisation offering the finest security projects ... more >
More job opportunities