ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Researchers hack 'tamper-proof' PIN terminals

Tom Espiner ZDNet.co.uk

Published: 26 Feb 2008 18:34 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Researchers from Cambridge University have succeeded in capturing both PIN numbers and card details from supposedly tamper-proof PIN terminals.

Saar Drimer and Steven Murdoch, overseen by Professor Ross Anderson, managed to hack two widely used PIN terminals: the Ingenico i3300 and the Dione Xtreme.

In a research paper seen by ZDNet.co.uk, the researchers outline the hack. Both terminals have tamper-proof mechanisms inside, but both can be circumvented by tapping the data line of the PIN Entry Device/smartcard interface. The data exchanged on this line is not encrypted.

The Ingenico i3300 has a tamper-response switch inside which is tripped if the terminal is forced open, and also has its innards wrapped in a tamper-proof mesh, to detect drilling. However, there is a user-accessible compartment to insert SIM cards that is not intended to be tamper-proof. The PCB has various holes that an attacker can use to insert a conductor into the serial data line, to tap both the PIN and card details. The researchers used a paper clip as the conductor, linked to the data line.

The Dione Xtreme also has a tamper-response switch, but no mechanisms to detect drilling from the rear. The main keypad and processor are "potted together", making it more difficult to incept the signal passing between them. However, by drilling a 0.8mm hole from the rear, the researchers inserted a 4cm needle into a flat ribbon connector socket and tapped the data.

In both cases, the conductors were connected to a thin wire connected to a logic board containing a field programmable gate array (FPGA), which translated the data and sent it to a laptop.

Both devices were Visa-certified to be secure, which requires that defeating the tamper detection would cost over $25,000 (£12,500) per-PIN entry device; or that inserting a PIN-stealing bug would be detected, or take more than 10 hours.

Neither terminal meets any of these requirements, said the researcher paper.

"What should have required $25,000 needed just a bent paperclip, a needle, a short length of wire and some creative thinking; attaching them to the data line takes minutes with some practice," said the paper.

Read this

Feature
Special report: Anatomy of a hack attack

We recreate a typical attack on two large organisations

Read more +

"What this shows is that PIN entry devices in the UK are very insecure," said Professor Anderson about the research. "What's more, the [device] certification process is completely defective. Certified devices are easy to breach. That's bad news for retailers, and bad news for customers."

Drimer added that this hack showed the complete process from design to implementation of these devices was broken.

"These devices should not have been certified because they clearly fail the criteria under which they were evaluated," Drimer told ZDNet.co.uk. "Something went wrong in the design of these devices, the certification process, and the EMV implementation choices made by the banks."

Ingenico admitted that the hack was successful, but said that its device "still remained one of the safest on the market".

A spokesman for Ingenico Northern Europe said: "Retailers and card users should rest assured that the devices, from various suppliers, identified by the Cambridge University scientists, remain among the most secure terminals on the market and have contributed to card fraud at UK retailers falling by up to 47 percent year-on-year since the introduction of chip and PIN. The banking industry has already expressed its confidence in the security capabilities of all chip and PIN payment devices being used in the UK today.

"The method identified by the Cambridge University paper requires specialist knowledge and has inherent technical difficulties. This method is therefore not reproducible on a large scale, nor does it take into account the fraud monitoring used throughout the industry."

"Security remains a top priority for Ingenico and we invest around €40m each year in research and development to ensure our customers remain at the forefront of the fight against fraud."

"This investment is highlighted in the latest generation of our terminals which are approved under the latest security standards. These meet the higher security required by industry mandates introduced on 1 January, 2008 and are designed to stay one step ahead of the evolving security threat."

Dione, which is manufactured by Verifone, had not responded to a request for comment at the time of writing.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
20 out of 22 people found this useful


Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

2nd line support & implementation : CCNA, CCNP : Contract : ASAP

You should have solid Cisco routing and switch knowledge. The ideal candidate is likely to be CCNP certified or at that level and have plenty of ...

MS BizTalk (.Net) Specialist Permanent - Cambridge - 42,000

MS BizTalk Specialist Permanent - Cambridge (Biztalk/C#/.Net) My client is the leading Company of its kind. Based in Cambridge, they are looking to ...

Data Solutions developer Oracle, SQL server. South Manchester To 28k

Largely identified as the leading provider of security software in the prevention of fraud & data protection using the latest Microsoft development ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation