Chip and Pin is secure on these devices (the HSM is safe). The attack vector is simulating "there was an error processing your transaction, please retry", where the first transaction went through and you only want to collect the PIN. It seems these devices can route the keypad to _either_ software _or_ HSM, with no way of routing the pin from software to HSM.
Comments
Isn't the fact that Chip and Pin is susceptible to "Man in the Middle" attacks, affecting all terminals, the bigger issue?
http://www.cl.cam.ac.uk/~sjm217/papers/oakland10chipbroken.p...
Chip and Pin is secure on these devices (the HSM is safe). The attack vector is simulating "there was an error processing your transaction, please retry", where the first transaction went through and you only want to collect the PIN. It seems these devices can route the keypad to _either_ software _or_ HSM, with no way of routing the pin from software to HSM.