Finextra Research
Sign in
Sign up
  • News
    • Latest news
    • Company updates
    • Long reads
  • TV
  • Research
  • Events
    • All
    • Conferences
    • Webinars
    • Popular
  • Community
    • Community latest
    • Latest expert opinions
    • Groups
    • Search members
  • Jobs
  • APIs
Sign in
Sign up
  • News
    • Back
    • News
    • Latest news
    • Company updates
    • Long reads
  • TV
  • Research
  • Events
    • Back
    • Events
    • All
    • Conferences
    • Webinars
    • Popular
  • Community
    • Back
    • Community
    • Community latest
    • Latest expert opinions
    • Groups
    • Search members
  • Jobs
  • APIs
  • payments
  • markets
  • retail
  • wholesale
  • wealth
  • regulation
  • crime
  • crypto
  • sustainable
  • startups
  • devops
  • identity
  • security
  • cloud
  • ai

Community

  • Your feed
  • Latest expert opinions
  • Groups

Join the Community

23,802
Expert opinions
40,563
Total members
397
New members (last 30 days)
201
New opinions (last 30 days)
29,223
Total comments
Join Sign in
Follow Unfollow

Adam Nybäck

System Developer
Anyro
Member since
08 Jan 2008
Location
Stockholm
Followers
0
Following
0
Opinions
4
Long reads
0
Followed by John Sims, Martha Boyle and 5 others you follow
View Adam Nybäck's full profile

Adam's comments

clear
Starbucks Mobile App - Payments reinvented

Is the QR-code the same all the time or is it generated dynamically for each purchase? That would make it very secure (can't be skimmed).

Other security can easily be added such as PIN-code so you could use it for higher value payments.

Another interesting thing about this technology is that it could be extended to P2P payments since smart phones have cameras too.

02 Feb 2011 07:00 Read comment

Google considers PayPal payments option for Android apps

I hope this will make it possible to buy and sell apps in more than just 13 countries (http://market.android.com/support/bin/answer.py?hl=en&answer=138294).

16 Aug 2010 15:07 Read comment

Is Apple killing Flash-Flex?

I don't think Apple can kill Flash. Sure, lots of developers will eventually concider using HTML5 instead for menus, ads and movies, but what about games? Is there any alternative to Flash for games that can run in various browsers and operating systems?

09 Mar 2010 20:05 Read comment

Apacs staffer outed as anonymous Chip and PIN research basher

If this is something "a first year electronic engineering student could achieve", then it's even more likely that criminals have used this attack already.

24 Feb 2010 18:30 Read comment

Chip and PIN is broken

Steven,

"Are you referring to the ISO 8583 Point of service entry mode? I saw this mentioned in a blog post by Dave Birch. There is apparently a single-digit field which states how cardholder verification occurred, but I haven't been able to find out the encoding."

Actually, this single-digit field does not necessarily include how cardholder verification occured. I just added a comment about this on Dave's blog.

Adam.

20 Feb 2010 05:02 Read comment

Chip and PIN is broken

Richard,

The attack doesn't work on ATMs. This is explained in the report on page 3.

Steven mentioned ATM above to explain that this non-ATM attack is more efficient than attacking ATMs. You can get £10,000, in cash, in an hour, compared to £500 per day from an ATM.

17 Feb 2010 10:32 Read comment

Chip and PIN is broken

"Are you referring to the ISO 8583 Point of service entry mode?"

Yes, in ISO 8583 it's part of that field.

16 Feb 2010 20:00 Read comment

Chip and PIN is broken

In addition to CVMR, the terminals usually sends similar information in a general (non-EMV) field to the aquirer. This field has previously been used for magstripe transactions and should have correct values for chip as well. If this is included in APACS 70 and if this is sent to the issuer by the acquirer, then the issuer could use it instead of CVMR to detect the attack by comparing it to the IAD.

16 Feb 2010 06:59 Read comment

Chip and PIN is broken

"the issuer will use the legitimate CVMR from the terminal"

So including the CVMR in the CDOL will make the terminal send the CVMR separately to the chip and to the acquirer, even if the CVMR wasn't part of the terminal/acquirer protocol?

You also mentioned the possibility "that terminals do not set the CVMR correctly". If this is the case, then the issuer still cannot use it, since it would lead to false positives, right?

14 Feb 2010 07:07 Read comment

Chip and PIN is broken

Seems like the Norwegians made the right decision requiring online PIN for their BankAxept brand (with fallback to offline signature). I think there is a similar solution for the Dancard in Denmark.

Here in Sweden there are many cards with offline PIN. However, CVMR is a requirement in the transaction data, so I hope the issuers can and do take advantage of that, at least for domestic transactions.

You suggest that the issuer could include the CVMR in the CDOL of the chip. What if the attacker then tries to alter the CVMR when it's sent from the terminal to the chip?

14 Feb 2010 03:49 Read comment

  • 1
  • 2
  • 3
  • 4

Adam writes about

  • security
  • payments

Adam's opinion archive

  • 2011 (3)
  • 2008 (1)

Latest groups joined by Adam

  • Futuristic Banking

  • Information Security

  • SEPA and European Payments

See all groups joined

Welcome to Finextra. We use cookies to help us to deliver our services. You may change your preferences at our Cookie Centre.

Please read our Privacy Policy.

Accept
Finextra

Finextra

  • About

Community

  • Rules
  • Contact the community team

News

  • Guidance
  • Contact the news desk

Sales

  • Media pack
  • Contact the sales team

Get involved

  • Finextra Live@
  • Webinars
  • Finextra TV
  • Research
  • Finextra.jobs

Events

  • Sustainable Finance Live
  • NextGen Nordics
  • EBAday
  • NextGen:AI
Join the community Register for news alerts
Apple App Store Google App Store

© Finextra Research 2025

Terms of usePrivacy PolicyCookie Centre