Slashdot Mirror


Researchers Expose New Credit Card Fraud Risk

An anonymous reader writes "Researchers from the University of Cambridge have discovered flaws in the card payment systems used by millions of customers worldwide. Ross Anderson, Saar Drimer, and Steven Murdoch demonstrated how a simple paper clip can be used to capture account numbers and PINs from so-called 'tamper-proof' equipment. In their paper (PDF), they warn how with a little technical skill and off-the-shelf electronics, fraudsters could empty customers' accounts. British television featured a demonstration of the attack on BBC Newsnight."

21 of 219 comments (clear)

  1. Is anyone here really surprised? by suso · · Score: 5, Insightful

    Proprietary software AND hardware companies basically cannot be trusted. I've encountered countless amounts of commercial software, hardware products and services where the company states that they are very secure, but when investigating things myself, I find that its trivial to circumvent their security. You can read about some of the read about some of the poor security I've discovered recently with web hosting providers. Consumers deserve better than this and its all of our responsibilities to make all people aware of these problems. Ironically, this news program itself doesn't understand the value of open disclousure. I guess I can understand that as its human nature to want to hide things for fear of liability. But its not like they were doing something that's not so obvious that someone determined enough could figure out.

    First rule of security in my book: Someone who wants something bad enough, they will be able to circumvent nearly anything in order to get it. So its a matter of how badly they want it. Since its money in question, I'd say that a variety of organizations and people want it pretty bad.

    1. Re:Is anyone here really surprised? by irongroin · · Score: 2, Insightful

      First rule of security should be: Physical access is all access.

    2. Re:Is anyone here really surprised? by Anonymous Coward · · Score: 0, Insightful

      "...if you need to bring something and remember something, then it makes life a lot harder for hackers."

      But you're already bringing your card and remembering your PIN....

  2. They're looking in the wrong place by blhack · · Score: 5, Insightful

    The huge security hole in the credit card system is the users. I flipped out at one of our vendors when they STORED my credit card number in their database, and just went ahead an charged it next time I was in the store.
    People will gladly give their credit card number over the phone to a shady pizza shop, just to get a 15 dollar pizza delivered to their door.
    We could build the most secure credit card system in the world, but the problem is that it has to be simple enough for idiots to use.

    --
    NewslilySocial News. No lolcats allowed.
  3. Re:Get rid of the damn things! by ShadowsHawk · · Score: 3, Insightful

    There are plenty of merchants that will not accept a $50 let alone a $100.

  4. Re:Get rid of the damn things! by Anonymous Coward · · Score: 5, Insightful

    The data mining industry is so ingrained in our society that even if people started using $100 bills to pay for major purchases, the serial numbers on the bills would probably be scanned for tracking information. The only way you are going to get privacy in your monetary transactions is with a national privacy overhaul with penalties for data mining without permission. Since the government is one of the entities doing the data mining, this is probably not going to happen anytime soon.

  5. Why isn't it a PIN = SecurID + PIN by apenzott · · Score: 4, Insightful

    The PIN needs to be a moving target and much longer than 4 digits. Note that stateside that most automatic car washes are using at least 5 digit numbers to authenticate the sale as sold by the gas pump. (Example: SecurID or one-time pad.)

    (offtopic)
    My biggest pet peeve is why are account numbers (on checks) in the clear while the same is basically true of PIN numbers (without any added "salt")

    For checks I would like to see the account number + check number translated a 16 to 20 digit hash of which only the bank knows how to decipher to the correct account and check number?
    (/offtopic)

    --
    The Roman Rule: The one who says it cannot be done shall not interrupt the one who is doing it.
  6. Tough Interview by Crazy+Man+on+Fire · · Score: 5, Insightful

    Wow. The interview at the end of that piece has me floored. Imagine if industry people and politicians in the US were subjected to this sort of probing interview and actually responded. The interviewer had the representative from the credit card companies on the ropes the entire interview. Props to the BBC for doing some serious journalism.

    1. Re:Tough Interview by giorgiofr · · Score: 1, Insightful

      Yup! Instead, they are managed by the gov't. Isn't that great!

      --
      Global warming is a cube.
  7. Most will for large-ticket items by davidwr · · Score: 4, Insightful

    While it's true they don't have to do business with you, most stores will accept a $50 rather than lose out on a $55 purchase. Ditto a $100 and lose out on a $101 purchase.

    It boils down to risk:
    Most people passing funny money will want to get change rather than goods they can only resell at diminished value.

    Also, many merchants use basic anti-counterfeit measures when accepting $20s and higher. Granted these measures have a high miss rate but they do catch amateurs.

    --
    Knowledge is how to play a game, intelligence is how to win, wisdom is knowing what game to play.
  8. Jail Time? by Frosty+Piss · · Score: 2, Insightful

    British television featured a demonstration of the attack on BBC Newsnight."
    I'll bet that would land you in jail over here (USA) ...
    --
    If you want news from today, you have to come back tomorrow.
  9. I can build an atomic weapon with a paper clip by wsanders · · Score: 5, Insightful

    >> "As described in some detail in our paper, the basic attack tool is a paper clip. In order to record and analyze transactions a couple hundred pounds' worth of equipment is required, in addition to some digital design experience."

    OK, a paper clip. PLUS A BUNCH OF OTHER STUFF.

    Well, shoot, I could probably build an atomic weapon with a paper clip. PLUS A BUNCH OF OTHER STUFF.

    --
    Give a man a fish and you have fed him for today. Teach a man to fish, and he'll say "WHERE'S MY FISH, YOU IDIOT?"
  10. Another hole in the sieve? by syousef · · Score: 2, Insightful

    Credit cards are so incredibly insecure that the only reason people use them is that the banks so far have been willing to cover the costs of fraud (in most cases and as long as the card holder hasn't contributed to it through negligence).

    This is just one more flaw.

    --
    These posts express my own personal views, not those of my employer
  11. Re:Get rid of the damn things! by geekoid · · Score: 2, Insightful

    This is a manufacturing design problem.
    These boxes can be made to make this attack nearly impossible.
    But it would cost another 5 bucks to manufacture it.

    Hell, if the designed them so the case was steel, and as thin as an iPhone this problem goes away because:
    a) it would take serious effort even AFTER you knew what to do. Raises the risk.
    b) You couldn't attach something to it without it being noticed.

    As far as the software goes, encrypt the data.

    --
    The Kruger Dunning explains most post on /. http://en.wikipedia.org/wiki/Dunning%E2%80%93Kruger_effect
  12. Doesn't apply to US card systems by 33tango · · Score: 2, Insightful

    US Cards do not have the pin stored on the card. That's like keeping your password in your top desk drawer. This attack will not affect US Cardholders. Could you accomplish the same thing? Yes, but much more difficultly. And that's what security really is about, making a target so difficult thieves go elsewhere.

  13. Re:[Encrypted account and check numbers] by apenzott · · Score: 2, Insightful

    Given that a one way hash can't really be reversed, that idea doesn't make much sense in the way that you posted it. A one way hash at first makes sense, except in reality it doesn't, as currently deployed. The numbers on your check have a routing number and account number. Both are numeric values with relatively few permutations when contrasted against case sensitive alphanumeric hashing. The routing numbers of banks are also no secret. Put simply, it'd be a trivial matter to brute force the hash with the simple numeric values we use today. OK, I'm using the wrong terminology.

    Routing number keeps the same public self (we need to send the check to the correct bank for processing.)

    Account number xxxxxxxx Check number yyyyy becomes zzzzzzzzzzzzzzzz.

    Issuing bank has key to turn zzzzzzzzzzzzzzzz back into original component numbers and verify that z... was not some made-up number in attempt to create a "bad check" of which there is no real account number attached to. Also xxxxxxxx, once extracted is verified to the name printed on the check. After about five or more bad values of z... in a day, a human is brought into the equation to look for the underlying cause.

    If check is good, then issuing bank electronically clears the bank draft with bank (or presents cash to individual) that presented the check. This allows for a pre-verification of check prior to verifying the signature (which most banks no longer do anyways.)

    I won't go into recurring drafts (automatic payments) as that makes things a bit more complicated.

    --
    The Roman Rule: The one who says it cannot be done shall not interrupt the one who is doing it.
  14. Re:Get rid of the damn things! by Raistlin77 · · Score: 3, Insightful

    Not everybody can have a checking account, especially if they are unfortunate or irresponsible. And which would you rather have, cash or an electronic transaction that can be reversed or check that can bounce?

  15. Re:Get rid of the damn things! by Mr.+Underbridge · · Score: 2, Insightful

    he failure of our government to (re-)introduce a $1000 bill, in spite of massive inflation, is a deliberate scheme to make it impractical for us to use untraceable funds for any substantial purchase. And it has nothing to do with tracking terrorists or drug money, it's just to keep tabs on and control over the law abiding populous.

    It might also have something to do with the fact that most people aren't crazy enough to walk around with thousands of dollars on them. In the end, it wouldn't matter, because any transaction of $10,000 or more with a bank will get reported anyway.

    Besides, a suitcase full of stacks of $100 bills has more class.

  16. Re:Get rid of the damn things! by the+brown+guy · · Score: 2, Insightful

    That's great to know, but it doesn't really help in a practical sense, legally I could pay $4000 in pennies (only 4000 because I'm in Canada), but I doubt they would accept that. I have a debit card, but use that to fund my eBay addiction via paypal, and I think that the government would be wondering why an "unemployed" university student is depositing a few thousand dollars a month into his bank account.

    --
    Orbis terrarum est non altus satis
  17. Re:Get rid of the damn things! by John3 · · Score: 3, Insightful

    I'm pretty sure the connection between the card reader and all external devices (POS stations, authorization network) is always encrypted. That's one of the basics for certification by Visa and the rest of the industry. The vulnerability demonstrated (based on my reading of TFA) occurs totally in the card reader/pad.

    --
    "We make our world significant by the courage of our questions and by the depth of our answers." Carl Sagan
  18. banks should be liable by nguy · · Score: 4, Insightful

    When banks deploy inadequate security, they should be liable for the distress and costs they cause their customers.