Chip-and-PIN under attack

Security is questioned as researchers demonstrate simple tampering techniques

Written by Angelica Mari

The security of Chip-and-PIN-equipped ATMs is being questioned following a demonstration at Cambridge University that the devices can be cracked.

Two widely deployed models of PIN Entry Devices (PEDs) fail to protect customers' card details and PINs adequately, according to the researchers.

By attaching a recording device to the PED, criminals can record account details and use the information along with counterfeit cards.

"We have successfully demonstrated this attack, on a real terminal borrowed from a merchant," Cambridge researcher Steven Murdoch told Computing.

"At first, we thought this would be a straightforward study, but a number of issues have come up, such as inefficient certification procedures," he said.

Visa and UK trade payments association Apacs certified the devices currently in use as secure and evaluators did not find the flaws identified by the Cambridge team.

The credit card company and the trade body claimed the devices were evaluated under the Common Criteria, an international evaluation scheme administered in the UK by the Government Communications Headquarters (GCHQ).

But GCHQ was unaware of the work and now says that the devices were never certified under the Common Criteria, said Murdoch.

And the problem is not limited to the banking industry, said Cambridge professor of Security Engineering Ross Anderson.

"Other fields, from as voting machines to electronic medical record systems, suffer from the same combination of stupid mistakes, sham evaluations and obstructive authorities," he said.

"Where the public are forced to rely on the security of a system, we need honest security evaluations that are published and subjected to peer review."

  • Have your say
  • Send to a friend
  • Print this
  • Share

Tags:

reader comments

related articles

Pin pad

Maestro users hit by down time

Saturday's network breakdown affected thousands of cardholders 25 Feb 2008

 

Taking chip-and-PIN further

Contactless payments and near-field communications are the next steps for card technology 21 Feb 2008

Contactless cards trial begins

Lloyds TSB scheme is first step to cash-free 2012 Olympics 14 Feb 2008

Researchers slam 3-D Secure as insecure

Verified by Visa and SecureCode 'fatally flawed', say Cambridge University experts 27 Jan 2010

Frauds put forensic accountants in the spotlight

High profile cases piling the pressure on forensic accountants 22 Oct 2009

US agencies toughen up Energy Star standards after embarrassing lapses

Undercover investigators gain Energy Star accreditation for phony gas-powered alarm clock 16 Apr 2010

related white papers

today's top stories

ARM-based servers to carve out a datacentre niche

ARM architecture is ideal for power efficiency, but faces the market dominance of x86 servers 03 Sep 2010

Openreach wants comms providers to nominate exchanges for upgrade

It's a broadband beauty contest, says analyst. 03 Sep 2010

Amazon Kindle 3 e-book reader review

Amazon trims the size and price of its newest Kindle, and adds a bargain Wi-Fi-only model 02 Sep 2010

RBS to cut 1,000 IT roles

Royal Bank of Scotland has announced it will cut 3,500 jobs, 1,000 of which are in IT support 02 Sep 2010

Apple overhauls iPod Shuffle, Nano and Touch

New models come with iTunes update and social networking tool 02 Sep 2010

Most read stories

Advertisement

Best practices to secure and protect backup data
Exploding the myths about data security and backup encryption

Using data integration to drive down costs and increase profits
This paper outlines why data integration is an important weapon in an enterprise’s competitive arsenal

Advertisement

Citrix

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you thousands of white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

Latest poll

The Chinese Market

The Chinese Market

Is your company considering expansion into the Chinese market?

View poll results

Latest audio and video articles

A microphoneAudio

Computing Podcast: Tech Talk episode 5

Join Tech Talk for an overview of the week's top IT stories, and a debate on IT self-service. Will it provide value? 27 Aug 2010

A microphoneAudio

Computing podcast: Tech Talk episode 4

Join Tech Talk for an overview of the week's top IT stories, and a debate on IT skills. Is the UK slipping behind? 20 Aug 2010

Latest in-depth articles

DatacentreAnalysis

ARM-based servers to carve out a datacentre niche

ARM architecture is ideal for power efficiency, but faces the market dominance of x86 servers 03 Sep 2010

picture of a TV studioAnalysis

Salford's MediaCity pushes technology boundaries

In preparation for 3D, ultra HD and a tapeless workflow 02 Sep 2010

Primary Navigation