No. 1 Story

HP job cuts loom for Australian employees

A number of Australian employees of Hewlett-Packard are facing the loss of their jobs as the global computer giant looks to slash its worldwide workforce by up to 30,000.

read more

Related Articles

ChipandPIN, card, security, easily, bypassed
Australian businesses are becoming soft targets for malicious hackers and they lag significantly behind...
To address the ever growing concerns of CIOs around security of mobile devices, US...
Juniper Networks has extended its SSL VPN security to the iPad with the release...
A recent survey by security company Sophos exposes the dilemma to business posed by...
A security vulnerability in Adobe's ColdFusion has been identified and fixed through a configuration...

Chip-and-PIN card security easily bypassed

Business IT - Security

Perhaps criminals have known about this for a long time, but security researchers have just announced the discovery of fundamental problems with the security of so-called Chip-and-PIN cards.

University of Cambridge researchers have demonstrated fundamental flaws in the operation of Chip-and-PIN cards during online, bank-verified transactions.

These flaws are so easily exploited that during a public demonstration of the problem, card after card owned by journalists present was verified for a transaction using the PIN 0000.  In no case was this the correct PIN.

The researchers inserted a "wedge" between the stolen card and terminal, which tricks the terminal into believing that the PIN was correctly verified. In fact, the fraudster can enter any PIN, and the transaction will be accepted.

Steven J Murdoch, one of the team-members noted that, "We have tested this attack against cards issued by most major UK banks. All have been found to be vulnerable."

Saar Drimer, another member of the team also observed that "The technical sophistication for carrying out this attack is low, and the compact equipment will not be noticed by shop staff. A single criminal can develop and industrialize a kit to be used by others who do not need to understand how the attack works."

A video of the problem is available here.

Read on for details of the vulnerability.