European Payment Card Protocols Wide Open To Fraud
Trailrunner7 writes: Researchers have discovered serious security vulnerabilities in a pair of protocols used by software in some point-of-sale terminals, bugs that could lead to easy theft of money from customers or retailers. The vulnerabilities lie in two separate protocols that are used in PoS systems, mainly in Germany, but also in some other European countries. Karsten Nohl, a prominent security researcher, and two colleagues, discovered that ZVT, an older protocol, contains a weakness that enables an attacker to read data from credit and debit cards under some circumstances. In order to exploit the vulnerability, an attacker would need to have a man-in-the-middle position on the target network, which isn't usually a terribly high barrier for experienced attackers.
In order to exploit the vulnerability, an attacker would need to have a man-in-the-middle position on the target network
If an attacker already has a MITM presence on the network, you have larger problems. At least 75% of these "push the panic button" vulnerability reports assume the target has already been compromised in some way.
not that great after all....
shitty implementation makes even better, supposedly more secure cards, just as vulnerable as good ol' fashioned american cards.
But Germans don't use cards!
What? I can't? They're going cashless? Oh well, can I offer my goat as payment?
“He’s not deformed, he’s just drunk!”
Researcher have found a way to abuse the system. When it comes to the American payment cards everyone knows someone who has been the victim of actual fraud.
And I know lots of people who do the same.
When the banks in the UK implemented chip&pin they messed up in many ways:
https://www.youtube.com/watch?...
They made architectural mistakes. In theory chip&pin could be more secure.
To me the most important difference between the US and Europe is that the new rules in the US from a couple of years ago is that the shop can be made responsible for fraud with payment terminals.
At least in Europe as far was I know this isn't the case, so this is a problem for the banks to solve and shouldn't impact the shops or customers as much.
New things are always on the horizon
That was left open and 230 million Americans had all their private details exposed, available for wholesale tax fraud.
Last week.
-- Tigger warning: This post may contain tiggers! --
Apple pays marketing department is in full swing.
You seem like a hate-fueled loser. Why should anyone care what you think?
Wasn't the Target hack a man in the middle attack effectively done the same way?
If you watch the presentation, they broke 2 protocols.
One applies to at least both mag-strape and chip&pin systems. That protocol is the protocol used between the terminal the cashier uses and the payment terminal, supposedly newer models use a standard network connection (can be wireless) instead of the old serial protocols.
The presentation:
https://media.ccc.de/v/32c3-73...
On the download tab you can download the english-only video of the talk.
New things are always on the horizon
If by this you mean "my bank", then you're right. But I suspect you meant someone that I (as an American) know personally, which makes your assumption wrong.
The laws in the US are structured very differently to what you're used to. In most instances of credit card fraud, the issuer (the bank, usually) is on the hook for it. If they can prove a case against the cardholder, then they can take it to court and get paid back. If they merely suspect the cardholder, they're free to cancel the account. But otherwise, that money comes out of their hide, not the cardholder's.
On the other side of the transaction, there are the processor (Visa, MC, et al) and the merchant. They have roughly the same relationship to each other as the issuer and cardholder have, and things work similarly. The merchant has a slight disadvantage in that they're a bigger target for investigation, and their aggregated transaction data may reveal fraud or negligence more quickly.
In the middle, there's the issuer and the processor, which have contractual obligations to each other, and most of the grievances between these parties are handled via contract law.
Of these four entities, cardholder, issuer, processor, and merchant, the cardholder is the least touchable under US law. Europe has a hodgepodge of laws that may or may not follow this model, and vary in degree. Thus, something more concrete is needed to nail down these interactions and liabilities in Europe. And on top of that, the laws around invoices date back to the 1100's, which the US doesn't have the burden of dealing with. Lines of credit here are billed via a monthly statement with no need to track exact invoicing dates due to centuries-old legal cruft.
TL;DR: Shut up, Eurotrash, we don't care what you think because you're not relevant to our situation.
Open or closed, pick one :)
Best way to encourage secure protocols, publish the protocol. Wait for hacks and exploits to tear it appart, then back to the drawing board.
Note that continental Europe are civil law countries, so laws are normally recent (whatever is voted by the Parliament when they update the codes). The 1100s are more connected to the birth of common law, which indeed carried its burden to our days in the UK (and the US). In continental Europe, old laws still in place are rare and mostly funny anecdotes. You have the Reinheitsgebot (German Beer Purity Law from 1516) and the Ordinance of Villers-Cotterêts (a justice reform in France from 1539). The laws defining payments are kept up to date in the Handelsgesetzbuch book in Germany and the Code de commerce in France.
Shut up and kiss me, you fool.
Why must you pretend, as you do?
And these generous benefactors that we call banks of course completely eat the money and never pass any of those fees onto the consumer! That would be like saying retail establishments up the price on their merchandise to compensate for shoplifting, would never happen!
Europe has a hodgepodge of laws that may or may not follow this model, and vary in degree.
But that's not stopping you from throwing insults. Great.
FWIW, a friend whose American accounts had fraudulent charges seemed a lot more stressed about the situation than I'm used to in the UK or Germany.
Hey!!! I thought chip & pin was going to save the world? I am sure the chip & pin fanboys (odd that a person is a fanboy of it) will have excuses. "Well if the software was impla....blah blah blah".
Shut up, Eurotrash
You keep using that word, but you don't seem to understand what it means. "Eurotrash" are American people of European decent whose ancesters were disposed of by their fellow Europeans for good reasons.
Actually, it just means that you live in Europe and are trash.
You're welcome. Please pour hot grits down your pants.
It was Portugal (that's in Europe, idiot) who legalized marriage between close familiar members - I believe it was half-siblings and direct cousins. See Google for more information.
That's not the American way of life. No true Murican settles for anything less than their full suibling.