Blog article
See all stories »

An article relating to this blog post on Finextra:

Cambridge boffins crack banks' CAP protocol

Steven Murdoch, researcher in the Security Group at the Computer Laboratory of the University of Cambridge, talks with Finextra about the vulnerabilities of the CAP Protocol.


See article

Finextra video interview on CAP vulnerabilities

Today, Finextra published a video interview with me, discussing my research on banks using card readers for online banking, which was recently featured on TV.

In this interview, I discuss some of the more technical aspects of the attacks on card readers, including the one demonstrated on TV (which requires compromising a Chip & PIN terminal), as well as others which instead require that the victim’s PC be compromised, but which can be carried out on a larger scale.

I also compare the approaches taken by the banking community to protocol design, with that of the Internet community. Financial organizations typically develop protocols internally, and so are subject to public scrutiny late in deployment, if at all. This is in contrast with Internet protocols which are commonly first discussed within industry and academia, then the specification is made public, and only then is it implemented. As a consequence, vulnerabilities in banking security systems are often more expensive to fix...

Read more at Light Blue Touchpaper...

4442

Comments: (0)

Steven Murdoch

Steven Murdoch

Royal Society University Research Fellow

University College London

Member since

01 Jul 2009

Location

London

Blog posts

9

Comments

35

This post is from a series of posts in the group:

Information Security

The risks from Cyber cime - Hacking - Loss of Data Privacy - Identity Theft and other topical threats - can be greatly reduced by implementation of robust IT Security controls ...


See all

Now hiring