UK chip and pin credit / debit cards are insecure (11Feb10)
February 19th, 2010 | by admin |
A not totally unsurprising development from those that look at security, the supposedly secure chip and pin facility in UK credit and debit cards is easily broken and fraudulent transactions are easily made. Unsurprisingly, the useless UK banks say it’s not our problem. The chip and pin system was designed to offload blame for fraud onto the customer away from the banks that enable the fraud in the first place. And now with RFID in UK credit and debit cards, fraud will be even easier and impossible to dispute.
Recorded from Newsnight, 11 February 2010.
Duration : 0:9:58
16 Responses to “UK chip and pin credit / debit cards are insecure (11Feb10)”
By billandyeng on Feb 19, 2010 | Reply
cambridge branded …
cambridge branded water for the 800-year anniversary. makes you smart enough to hack chip&pin, so i say it’s a price worth paying for! lol
By Tabrisius on Feb 19, 2010 | Reply
Chips , thats …
Chips , thats things are very insecures, ¿UK don’t use magnetic band?, the chips are insecures since phone credit card based on chips.
By GLeNss on Feb 19, 2010 | Reply
5 pound for a …
5 pound for a bottle of water, what the fuck?!?!
By indrekSin on Feb 19, 2010 | Reply
Banks can set up …
Banks can set up their card system to authorize purchase via PIN only. So it can not be done by signature. This kind of apporach can be done when all merchants have PINpad POS terminals. It is still more efficent than to rewrite the whole Chip&PIN system.
By extremesickness2 on Feb 19, 2010 | Reply
DANG
DANG
By richardbirch2007 on Feb 19, 2010 | Reply
No system is ever …
No system is ever secure.
By Mackingster on Feb 19, 2010 | Reply
Ya we still use …
Ya we still use that. Then their are RFID chiped credit cards to that are easy to crack. Only place I see the cards like above is government id cards.
By beezerandchips on Feb 19, 2010 | Reply
Aren’t you still …
Aren’t you still using Mag-stripe and Signature in the US?
Mag-stripe cards are breakable with a $30 piece of equipment and it don’t even necessarily need your original card, just a card receipt will do.
By beezerandchips on Feb 19, 2010 | Reply
What I’m getting at …
What I’m getting at is that the banks should be able to re-implement Chip and PIN without replacing huge amounts of infrastructure. They will most likely have to replace cards, but the card readers should be reprogrammable.
By beezerandchips on Feb 19, 2010 | Reply
Chip and PIN would …
Chip and PIN would be *very* secure, if only it had been implemented correctly. Most card fraud now is something called CNP (Card Not Present) fraud (CNP is the system used for paying by reading your card details out over the phone for example).
Unfortunately, the particular way the banks have chosen to implement Chip and PIN means that the PIN part is now completely ineffective. The Cambridge research demonstrates that all you need to have to validate a fraudulent transaction is a stolen card.
By beezerandchips on Feb 19, 2010 | Reply
Wow. I just read …
Wow. I just read the technical white paper on the Cambridge CS site about this.
The hack is incredibly simple. An undergraduate CS student studying security would spot the flaw in this system in 5 minutes if they were shown the conversation that happens between the terminal and the card.
Of course, the only real impact to consumers is that banks can no longer claim that Chip and PIN transactions are never fraudulent. One less excuse for the banks to pay out in the case of fraud!
By no2id on Feb 19, 2010 | Reply
so whats going to …
so whats going to replace it – biometric purchase here we come – get ready to give your finger print and/or eye and/or face scan for your loaf of bread – truly what I have said for years is coming to pass. BIOMETRICS = 666, no im not no relegious freak but its just to close to what is happening.
By geostar1711 on Feb 19, 2010 | Reply
£5.00 for water?!?! …
£5.00 for water?!?!?!
By Mackingster on Feb 19, 2010 | Reply
Joy, we don’t need …
Joy, we don’t need this in the USA. I don’t want it! I don’t even like the RFID based cards.
By liarpoliticians on Feb 19, 2010 | Reply
The ones when I …
The ones when I first started this channel I had disabled embedding on some, if you find one that you want to use, let me know via private message and I’ll change it’s status.
By Iseeksdatruth on Feb 19, 2010 | Reply
L P your channel is …
L P your channel is the bomb, I share as much as I can, can I ask why some of your vids cant be embeded & others can?
1,000000 kudos for all your effort & dedication in bringing the truth to the masses!
Namaste