Skip to content

Comment on X-Ray Scans Expose Chip-And-Pin Card Hackparent

Comments

I share your amazement. That said, apparently the functional security was "how could you put a system physically between the card and the reader?" which seems silly. The chip is capable of signing the response with the secret key of the card, why wouldn't it do that?

It's fucking ridiculous, especially since this was already commonplace with mobile phone SIM cards when they said it, but it allowed UK banks to force their customers to accept potentially-fraudulent payments by claiming that their PIN must have been used. (Otherwise they'd have had to eat the loss and no bank wants to do that.)

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.