Follow Us

Massive security flaw in credit card transaction process

Has card payment system had its chips?

Hundreds of millions of payment cards throughout Europe have a flaw that could allow criminals with a stolen card to enter any random PIN to complete a transaction, according to researchers from the University of Cambridge.

The findings, which will be presented at the IEEE Symposium on Security and Privacy in California in May, cast new doubts on chip-and-PIN or EMV cards. The cards contain a microchip that verifies a correct PIN in order to complete a transaction.

European banks hail the system as more secure, as US cards do not have the microchip, which has so far prevented some types of card cloning.

But the Cambridge researchers have found a weakness in the complicated EMV protocol that allows for a man-in-the-middle attack. It essentially tricks the point-of-sale terminal into believing it has received a correct PIN no matter what digits are entered.

The card thinks that the transaction was authorised by a signature. In some instances, point-of-sale terminals may have trouble connecting back to a card's issuing bank but allow a transaction anyway if completed by a signature.

The attack requires high-level knowledge of the chip-and-PIN system and some external hardware as the researchers demonstrated on the BBC's Newsnight program on Thursday.

Nonetheless, "this flaw is really a popper," said Ross Anderson, professor of security engineering, on Newsnight.

On the programme, Anderson's colleague, Saar Drimer, is shown illustrating the attack at the University of Cambridge's cafeteria. He wore a backpack containing a laptop computer and an FPGA (field programmable gate array) board. A dummy card is actually inserted into the point-of-sale device, which is wired to the stolen card.

For the demonstration, the researchers used a credit card from HSBC, one from the John Lewis department store, and debit cards from Barclays and The Cooperative Bank. Drimer is seen slyly inserting the dummy card - which has a protruding wire - into the point-of-sale terminal. The transaction is authorised even though Drimer enters an incorrect PIN of "0000."

The banking industry was informed about two months ago by the researchers of the attack. HSBC and Barclays referred comment to UK Payments, a banking trade association.

"We never said chip-and-PIN was completely infallible," a spokeswoman said. "We firmly believe it [the attack] is not really plausible in a day-to-day environment. They've created a convoluted way of committing this fraud."

Cambridge researchers have been highly critical in the past of chip-and-PIN, finding numerous technical problems with the specification and criticising the lack of transparency under which it was developed.

They argue that's troubling since the banks tend to hold customers responsible for losses for transactions in which their PIN was used, even if the customer says no one else knew the PIN, they say.

"So far, banks have refused to refund such victims because they assert that a card cannot be used without the correct PIN," according to their paper, entitled Chip and PIN is Broken. "This paper shows their claim is false."

The equipment looks complicated but is doing something very simple and could be condensed, said Steven J. Murdoch, one of the researchers.

The PC, which does computational work, could be replaced with a tiny microprocessor. The FPGA, which is used to modify voltages and data rates between the PC and payment cards, could be replaced with much smaller technology. Both of the payment cards could also be modified to communicate wirelessly, which would eliminate the wire shown in their current demonstration, Murdoch said.

In both the latest Newsnight demonstration and in tests last December, the banks did not apparently detect the fraud. "It looks like if you were to do this, you would not be caught," Murdoch said.

About 730 million chip-and-PIN cards are in use worldwide. Most European countries use the cards, and they are also being introduced in Canada and discussed in the US Murdoch and Anderson are scheduled to speak on Wednesday to the Federal Reserve Bank of Philadelphia about security issues associated with EMV cards.

In addition to Drimer and Anderson, the research was done by Steven J. Murdoch and Mike Bond. More information is available on the Light Blue Touchpaper blog.






Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

State of software security report volume 4

If your business has anything worth protecting, be it money, intellectual property or a trusted...

Download Whitepaper

New threats demand innovative responses

Financial institutions in the UK remain susceptible to further systemic problems, as challenging...

Download Whitepaper

Delivering a competitive advantage through IT

IT organisations share a common mission; to optimise investments and streamline operations to...

Download Whitepaper

6 tips to mobilise your existing ERP

Enterprise mobile users throughout the global business community will number 1.19 billion by...

Download Whitepaper

Techworld UK - Technology - Business

Techworld Awards

Techworld Awards Winners 2011


Learn who the winners of this year's Techworld Awards are. Video footage coming soon...

Find out more
Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

Site Map

* *