Welcome to World-of-Digital.com...one of the best forums on the Net..if not the Best....to get the best from this forum you will need to register with us, its the only way that you can get to see what we have got to offer you (plus it's FREE to join that means NO donation's or payments 100% free ) come and join one of the friendliest forums around on the Net....world of digital.com ....... We are always looking into the future for you Guys......
World of Digital


Welcome to the World of Digital forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact contact us.
Home Register FAQ Members List Arcade Calendar vBRadio Mark Forums Read
User Info Statistics
Go Back   World of Digital > Main News & Polls > Main Site News

World of Digital's Shoutbox ...... "no cable or illegal software talk in here"
Loading...

 
Main Site News This will End up on the front main page for all to see

World of Digital Latest News
Cable forums are open again
After recent events with Modshack and the cable companies in the news just latly we have started to check all our satellite and cable forums to make sure that we fully comply with the law in every way that we can. We do not condone people stealing or defrauding satellite and cable companies and if we find out that this is happening on here we will close them forums down for good. These forums were started up for educational purposes only and always will be just that. We have never asked for any donation's or payments from any member on this site and we never will, it as always been a free forum and will always stay that way. The Team that help and run world-of-digital.com give up there own time and do so for free. And as we say in our RULES anyone found to be using our forums for illegal services and making money out of this site or the satellite and cable companies will be removed and details passed on to the above companies....Please help us to help you, so that we can keep cable alive and kicking.

Chip and PIN unsecure shock (actually it isnae a shock at all)

 
Prev Previous Post   Next Post Next
  #1 (permalink)  
Old 28-02-2008, 08:01 AM
nss1888's Avatar
nss1888 nss1888 is online now
Respected

Thanks: 61
Thanked 171 Times in 116 Posts
 
Join Date: May 2006
Gender: male
Gallery: 0
Posts: 478
Points: 22,708.10
Bank: 159,955.83
Total Points: 182,663.92
Donate
Groans: 0
Groaned at 0 Times in 0 Posts
Rep Power: 3
nss1888 is on a distinguished road
This member is the original thread starter. Angry Chip and PIN unsecure shock (actually it isnae a shock at all)

Well after being one of the folk who got very pi$$ed off when this "system" was implemented, it's turns out that what I knew all along is, in fact, correct....

Chip and PIN is a usless waste of time...

You hear: It's secure, it;s uncracakable..

What a big pile of sh1te...

Full story HERE

or below

Quote:

Paper clip attack skewers Chip & PIN
Tapping up

Published Wednesday 27th February 2008 17:05 GMT


UK researchers have uncovered a serious flaw in the Chip and PIN machines that authenticate debit and credit card transactions.

Two of the most popular PIN entry devices (PED) in the UK — the Ingenico i3300 and Dione Xtreme — are vulnerable to a "tapping attack", using nothing more sophisticated than a paper clip, a needle and a small recording device.

This basic kit enabled University of Cambridge Computer Labs researchers to record data exchanged between a card and the device's processor without triggering tamper-proofing mechanisms. "This attack can capture the card’s PIN because UK banks have opted to issue cheaper cards that do not use asymmetric cryptography to encrypt data between the card and PED," they note here.

It gets worse. To ensure backward compatibility, PIN entry devices read data on magnetic strips, as well as on chips on newer credit cards. Hackers tapping into the link between a card and the processing device could get all the data needed to make a cloned card. Add in the corresponding PIN, and fraudsters could withdraw cash at the many ATMs overseas not upgraded to read chips and therefore solely reliant on easily-fakeable magnetic stripes.

Tampered PIN entry devices have already been used for fraud. Last December, £80,000 was stolen from 1,500 people in Leicestershire when crooks cloned their cards using a doctored device in a local petrol station.

The process to determine PIN reader security is substandard, the Cambridge team argues. Evaluation should be more open and defective devices should be refused certification, they say..

The Cambridge Chip and PIN scenarios pose little threat in the real world, according to APACS, the banking association which spearheaded the introduction of Chip and PIN in the UK. "The types of attack on PIN entry devices detailed in this report are difficult to undertake and not currently economically viable for a fraudster to carry out," a spokesman said.

Ross Anderson, a member of the research team and professor of security engineering at Cambridge, said: "The lessons we learned are not limited to banking. Other fields, from voting machines to electronic medical record systems, suffer from the same combination of stupid mistakes, sham evaluations and obstructive authorities. Where the public are forced to rely on the security of a system, we need honest security evaluations that are published and subjected to peer review."

The Cambridge team presents its findings in full in May at the IEEE Symposium on Security and Privacy conference in Oakland, California in May. Anderson's colleagues are Saar Drimer and Steven Murdoch. ®
So, as per usual (wait for this to happen with ID cards if they ever are forced upon us) the the technology used is weak. No encryption in the box between the card reader and the central part of the device...

sigh.... I dispear at the ineptness of thee governmental technical solution finders, or whatever the feck the wanna call themselves, because they, apparently, don't actually know a secure system if it appears in front of them waves a wee flag then bytes them on the baws...

feckin ejits.
__________________
Ahh if only..


Hmmm, Uber Dorky Nerd King... I feel like I belong
Reply With Quote
The Following 4 Users Say Thank You to nss1888 For This Useful Post:
DessertDog (28-02-2008), Diablo13 (28-02-2008), Sicilian (28-02-2008), wullboy (28-02-2008)
 



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Points Per Thread View: 1.00
Points Per Thread: 15.00
Points Per Reply: 5.00


All times are GMT +1. The time now is 03:42 PM.

Powered by vBulletin Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.0.0 RC8
World-of-Digital.com © 2006 - 2008 does not take any responsibility with the information presented. Any information provided on this site is not guaranteed in any way. Some articles may discuss topics that are illegal, so this information is provided for educational purposes only, use at your own risk. If you blow up your home, computer, or anything else -- it's not our fault, use good judgement and play nice....

[Output: 117.22 Kb. compressed to 114.98 Kb. by saving 2.24 Kb. (1.91%)]