Re: Chip & Pin @ Tescos



At 16:56:50 on 19/06/2006, Jonathan Bryce delighted uk.finance by announcing:

Tom Anderson wrote:

It's not as simple as you think. It is impossible to have both off-line
operation and PIN security: the thing is, if you want offline operation,
then even if you don't have the PIN on the card, you do have to have
enough information to validate the PIN - a hash of the PIN or something.
If an attacker gets hold of that, then since the PIN is a four-digit
number, it's trivial to recover it: you just run through all the possible
PINs and check whether they validate against the information on the card.

Unless of course, the chip self destructs after a certain number of
unsuccessful attempts,

Not self-destructs, as such, but either blocks further PIN entry attempts
(reversible at an ATM) or blocks access to the card completely (only reversible
with specialised terminals).

which might be possible to implement,

So possible, in fact, that the above is already implemented.

and is
probably also possible to circumvent.

Possible, but probably really not worthwhile.
.



Relevant Pages

  • Re: Passwords et al.
    ... The set of three integers above might well become the numbers on an ‘atm’ card say or indeed on any device that is used to control access to anything. ... ciphertext of a single alphanumeric item – lower case letter e – ... midnight say) by the bank or other that owns it. ... might be used as the user's PIN in each case. ...
    (sci.crypt)
  • Re: SDS PROM-100 software
    ... 2708 EPROM and to consistently read the content of another used 2708 ... card which worked great with Dave Dunfield's RAMless ROM monitor ... socket) with the IA 1010B the 2708 simulator has been a disaster. ... First the original IA 1010B used a weird and probably damaged 24 pin ...
    (comp.os.cpm)
  • Re: HELP, Vulnerability in Debit PIN Encryption security, possibly
    ... > not the case where PIN encryption had to be ... > derived from the card number because the card PIN was checked at the ... It is unlikely that the banks should have been able to hide such ... Smartcard terminals are used in environments over which the ...
    (sci.crypt)
  • Re: smart card versus credit card
    ... fraud must be low due to card fraud going unreported. ... >> me one good reason for wanting a PIN with a credit card? ...
    (sci.crypt)
  • Re: smart card versus credit card
    ... > That's why I was complaining that if the banks want to place more trust ... > in the PIN verification process they ... Own Plastic Savings Cards, PO Card Acoount Cards, Store Cards to name ... implemented the Chip and sPIN System. ...
    (sci.crypt)