Join the Community

22,705
Expert opinions
43,928
Total members
372
New members (last 30 days)
184
New opinions (last 30 days)
28,916
Total comments

Information Security

The risks from Cyber cime - Hacking - Loss of Data Privacy - Identity Theft and other topical threats - can be greatly reduced by implementation of robust IT Security controls ...

Steven Murdoch

Steven Murdoch Royal Society University Research Fellow at University College London

Chip and PIN is broken

There was a 9-minute film on Newsnight yesterday evening (available online) showing some research by Saar Drimer, Ross Anderson, Mike Bond and me. We demonstrate a middleperson attack on EMV which lets criminals use stolen chip and PIN cards without knowing the PIN. Our technical paper “Chip and PIN is Broken” explains how. It has been causing qui...

/security

Retired Member

Retired Member 

False Accusation leads PAYPAL to disclose Accounts of others

If you find your name in this list, it means that you are one of the many collateral victims of a psychopath who was able to manipulate the french authorities (in the south of france) to requisition information from EBAY and Paypal by making a false accusation against someone. One of the collateral victims is the wife of Senator John Kerry. One c...

/security /payments

Steven Murdoch

Steven Murdoch Royal Society University Research Fellow at University College London

Verified by Visa and MasterCard SecureCode

This week, the 2010 Financial Cryptography conference is being held in Tenerife. The papers to be presented are likely of interest to the Finextra audience. Unfortunately, most are not available online, but searching for the title might show up a copy on the authors' home page. My paper at FC'10 is on the security of Verified by Visa and MasterCard...

/security /payments

Steven Murdoch

Steven Murdoch Royal Society University Research Fellow at University College London

Encoding integers in the EMV protocol

On the 1st of January 2010, many German bank customers found that their banking smart cards had stopped working. Details of why are still unclear, but indications are that the cards believed that the date was 2016, rather than 2010, and so refused to process a transaction supposedly after their expiry dates. This problem could turn out to be quite...

/security

Retired Member

Retired Member 

Cheques are on the way out - so what's the alternative?

Today the Payments Council has announced the target deadline of October 2018 for the end of cheques as a form of payment in the UK. For banks, this is welcome news. Cheques are one of the most expensive forms of payment transaction costing banks around £1 per transaction to process. However, if the cheque is to disappear altogether, the Council re...

/payments

Matt White

Matt White North America editor at Finextra

Shaking up digital security

As Finextra community members are well aware, digital security is a hot topic of debate and there's little consensus out there. Enter the Global Trust Council, a non-profit that is proposing a serious shake-up of the way we conduct our digital lives. It argues that we are forced to hand over far too much personal information when going about our d...

/security /retail

Retired Member

Retired Member 

IDs FOR SALE! IDs FOR SALE! Who wants to Buy One?

The Financial Times this morning has a video that just gobsmacked me. I know I've been vocal in the past about ID protection but I'm now at the point that I've been terribly enlightened...and saddened! An American journalist takes us to see another journalist in Russia who visits a store that sells databases on everyone. I mean everyone! Poo

/security /regulation

Retired Member

Retired Member 

How to cut US Merchants' card fraud costs by 50 billion

Two news items came out this week that caught my attention and got me thinking. The first was a report from LexisNexis - the 2009 LexisNexis True Cost of Fraud Study. The shocking headline figure in this report was that US merchants are paying $100 billion in fraud losses due to unauthorized transactions and fees/interest associated with chargeba...

/payments

Steven Murdoch

Steven Murdoch Royal Society University Research Fellow at University College London

Finextra video interview on CAP vulnerabilities

Today, Finextra published a video interview with me, discussing my research on banks using card readers for online banking, which was recently featured on TV. In this interview, I discuss some of the more technical aspects of the attacks on card readers, including the one demonstrated on TV (which requires compromising a Chip & PIN terminal),...

/security

Steven Murdoch

Steven Murdoch Royal Society University Research Fellow at University College London

Demonstration of CAP vulnerability on BBC One today

This evening (Monday 26th October 2009, at 19:30 UTC), BBC Inside Out will show Saar Drimer and I demonstrating how the use of smart card readers, being issued in the UK to authenticate online banking transactions, can be circumvented. The programme will be broadcast on BBC One, but only in the East of England and Cambridgeshire, however it shoul...

/security

Now Hiring