Community
I can see how lifting account details from a terminal device can help an attacker take over a bank account via conventional channels, but I am not sure that this is an attack on the Chip and PIN system is it? I assume that the attackers are not able to clone any smartcards using the stolen data (because of the fundamental security measures in the chips, which for one thing include secret cryptgraphic codes that are not revealed to the terminals).
Can anyone shed more light on what is actually achieved by these attacks?
And why wouldn't these organised attackers -- so organised they can interfere with the design and manufacture of terminal devices in the factory -- target magnetic stripe devices, as still used in the US? That would lead to wholesale cloning of cards on a gigantic scale not possible with Chip and PIN.
Stephen Wilson, Lockstep.
This content is provided by an external author without editing by Finextra. It expresses the views and opinions of the author.
Andrew Ducker Payments Consulting at Icon Solutions
19 December
Jamel Derdour CMO at Transact365 / Nucleus365
17 December
Alex Kreger Founder & CEO at UXDA
16 December
Dan Reid Founder & CTO at Xceptor
Welcome to Finextra. We use cookies to help us to deliver our services. You may change your preferences at our Cookie Centre.
Please read our Privacy Policy.