Skip to content

Comment on German security experts find major flaw in credit card terminals

Comments

Isn't the fact that Chip and Pin is susceptible to "Man in the Middle" attacks, affecting all terminals, the bigger issue?

http://www.cl.cam.ac.uk/~sjm217/papers/oakland10chipbroken.p...

Chip and Pin is secure on these devices (the HSM is safe). The attack vector is simulating "there was an error processing your transaction, please retry", where the first transaction went through and you only want to collect the PIN. It seems these devices can route the keypad to _either_ software _or_ HSM, with no way of routing the pin from software to HSM.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.