Access member only content, take part in discussions with comments on blogs, news and reviews and receive all the latest security industry news directly to your inbox. Join now for free.
A confirmation email has been sent to your email address - SUPPLIED EMAIL HERE. Please click on the link in the email to verify your email address. You need to verify your email before you can start posting.
If you do not receive your confirmation email within the next few minutes, it may be because the email has been captured by a junk mail filter. Please ensure you add the domain @scmagazine.com.au to your white-listed senders.
Researchers at Cambridge University have claimed in a new paper that chip and PIN systems are not as secure as once thought.The paper, entitled Chip and Pin is Broken (PDF), said that chip and PIN readers could be " fooled" into accepting transactions, despite not having the relevant PIN.The researchers explained that it is possible to launch a man-in-the-middle attack, effectively blinding the machine to the fraud and letting criminals exploit lost or stolen cards.Chip and PIN has often been described as a silver bullet for securing transactions, and has been credited with causing a drop in fraud levels. Just this week Home Office minister Alan Campbell said that the system had "reduced fraud on lost or stolen cards to an all time low".However, the Cambridge researchers claim to have demonstrated how a hacker could use a stolen card without knowing the PIN."Since verified by PIN - the essence of the system - does not work, we declare the chip and PIN system to be broken," the paper said.The risk does not apply to cash machines, but could be exploited on the majority of cards using offline systems, such as those found in shops which connect elsewhere to approve a transaction.The researchers added that it is during this verification process that the flaw could be exploited.
To begin commenting right away, you can log in below or register an account if you don't yet have one. Please read our guidelines on commenting. Offending posts will be removed and your access may be suspended. Abusive or obscene language will not be tolerated. The comments below do not necessarily reflect the views or opinions of SC Magazine, Haymarket Media or its employees.