Skip to content

Comment on X-Ray Scans Expose Chip-And-Pin Card Hackparent

Comments

It's a clever hack, but shouldn't people have thought of this before they developed the whole protocol? How can any random chip answer a "true" response to the pin request? Shouldn't it have some sort of authorization built-in? Maybe public / private key with a bunch of implicitly trusted public keys?

As I say that, I guess this relies on having a network connection which cannot be assumed when you're developing a POS. Hmm.

Yeah, it'd be a huge complication to maintain and update the keys across all the terminals, many of which are not network attached. Plus an attacker could extract a key from the chip (probably hard, due to anti-tampering technology, but not impossible)

Although I'm pretty sure when you are talking about validating a credit card, a network connection is a given. Otherwise how do you authorize or deny the purchase?

Maybe it's a possibility that the POS is networked but the physical card reader hardware is not?

The reverse is more likely in the US. There's plenty of old legacy POS systems/registers, which have a card reader that's with it, attached or not. The only way I've ever seen a card run without a network (whether it be an existing network or an integrated modem and phone line), is when there's a power outage and someone busts out one of the old carbon copy manual card machines, where they take an impression of the card. Those may not even be accepted anymore, since they don't deal with CVV numbers and some cards don't even have embossed numbers anymore.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.