Chip and Pin is secure on these devices (the HSM is safe). The attack vector is simulating "there was an error processing your transaction, please retry", where the first transaction went through and you only want to collect the PIN. It seems these devices can route the keypad to _either_ software _or_ HSM, with no way of routing the pin from software to HSM.
Comments
Chip and Pin is secure on these devices (the HSM is safe). The attack vector is simulating "there was an error processing your transaction, please retry", where the first transaction went through and you only want to collect the PIN. It seems these devices can route the keypad to _either_ software _or_ HSM, with no way of routing the pin from software to HSM.