<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-3599452548077943366.post6778142400555895456..comments</id><updated>2011-08-29T21:19:12.389-03:00</updated><category term='Free Software'/><category term='Backlog'/><category term='Development'/><category term='Humor'/><category term='Rants'/><category term='Agile'/><category term='Web 2.0'/><category term='Linux'/><category term='Utilities'/><category term='Books'/><title type='text'>Comments on Shawn on Technology: Cover your …um… PIN</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.shawncrosby.com/feeds/6778142400555895456/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3599452548077943366/6778142400555895456/comments/default'/><link rel='alternate' type='text/html' href='http://blog.shawncrosby.com/2009/09/cover-your-um-pin.html'/><author><name>Shawn Crosby</name><uri>http://www.blogger.com/profile/12093823138737535996</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/__S14ux89bFY/Soabhg77_pI/AAAAAAAAAqs/N84Ol381kTA/S220/Picture+6.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>1</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-3599452548077943366.post-7004262528931294971</id><published>2011-08-29T21:19:12.389-03:00</published><updated>2011-08-29T21:19:12.389-03:00</updated><title type='text'>The worrisome thing about chip and PIN is that it ...</title><content type='html'>The worrisome thing about chip and PIN is that it is backwards compatible. Chip gets damaged? you still need to be able to buy your twinkies so it will fallback to mag stripe. The information encoded on the stripe is not encrypted and the format is well known. Generally speaking all the black hat needs is your card number and your pin. &lt;br /&gt;&lt;br /&gt;In general the chip is given a PIN to verify and will return a code based on success or failure. This is done as an offline verification. After so many failures (generally 3 but can vary) the chip will lock itself until repined or a successful online verification. &lt;br /&gt;&lt;br /&gt;There have been hacks where a specially crafted card has a very thin cord coming out the opposite end of the card into a netbook. The netbook then responds with the PIN_CORRECT code, and the transaction is verified by CHIP and PIN (the banks wont tell you this, but they won&amp;#39;t refund a chip and pin transaction as it is &amp;#39;secure&amp;#39;). Generally speaking a cashier is smart enough to notice the cord going down the black hat&amp;#39;s sleeve, but with bulky coats and unmanned cash registers it can be done.&lt;br /&gt;&lt;br /&gt;The chip&amp;#39;s are also fairly finnicky and break easily enough. At that point either the failback to mag stripe will wortk, or the cashier can manually enter the card number into the terminal and it will work like a credit card. &lt;br /&gt;&lt;br /&gt;Chip and pin is broken. WEP broken.&lt;br /&gt;&lt;br /&gt;Not to mention that most terminals are made in China and some have been shown to have malware and trojans in the PCB that skim the card number and PIN and dial home.&lt;br /&gt;&lt;br /&gt;The entire system is scary bad.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3599452548077943366/6778142400555895456/comments/default/7004262528931294971'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3599452548077943366/6778142400555895456/comments/default/7004262528931294971'/><link rel='alternate' type='text/html' href='http://blog.shawncrosby.com/2009/09/cover-your-um-pin.html?showComment=1314663552389#c7004262528931294971' title=''/><author><name>openid.html</name><uri>http://tristandyer.ca/openid.html</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/openid16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.shawncrosby.com/2009/09/cover-your-um-pin.html' ref='tag:blogger.com,1999:blog-3599452548077943366.post-6778142400555895456' source='http://www.blogger.com/feeds/3599452548077943366/posts/default/6778142400555895456' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-45949889'/></entry></feed>
