Community
I can see how lifting account details from a terminal device can help an attacker take over a bank account via conventional channels, but I am not sure that this is an attack on the Chip and PIN system is it? I assume that the attackers are not able to clone any smartcards using the stolen data (because of the fundamental security measures in the chips, which for one thing include secret cryptgraphic codes that are not revealed to the terminals).
Can anyone shed more light on what is actually achieved by these attacks?
And why wouldn't these organised attackers -- so organised they can interfere with the design and manufacture of terminal devices in the factory -- target magnetic stripe devices, as still used in the US? That would lead to wholesale cloning of cards on a gigantic scale not possible with Chip and PIN.
Stephen Wilson, Lockstep.
This content is provided by an external author without editing by Finextra. It expresses the views and opinions of the author.
Taras Boyko Founder at BTG Corporate Services Provider
12 May
Ted Sausen Director - AML Subject Matter Expert at NICE Actimize
09 May
Scott Dawson CEO at DECTA
08 May
Vitaliy Shtyrkin Chief Product Officer at B2BINPAY
07 May
Welcome to Finextra. We use cookies to help us to deliver our services. You may change your preferences at our Cookie Centre.
Please read our Privacy Policy.