Quantcast StorefrontBacktalk » Blog Archive » Chip-And-PIN Breach: Bluetooth, Burned Hole In Back Of Card Reader
advertisement
advertisement

Chip-And-PIN Breach: Bluetooth, Burned Hole In Back Of Card Reader

Written by Frank Hayes
June 24th, 2010
Like this story? Share it
To share this story with people in your social network, please click on the network icons below.

For those who are arguing that Chip-and-PIN represents the gold standard in card security, there was a cold splash of reality this week. Four fraudsters from London were sentenced to jail for their parts in a nine-month string of thefts that netted almost $1.1 million by tampering with Chip-and-PIN card readers at gas stations. According to a BBC report, the group burned a small hole in the back of each reader and then inserted a memory device and BlueTooth reader that allowed it to capture information and then clone customers’ cards.

One gas station owner saw business drop by 47 percent once customers realized money was being taken from their accounts after visiting the station. The gang’s 29-year-old leader, software engineer Theogenes De Montford, was arrested with information from 35,000 cards on his laptop–7,000 of them from a single gas station.


advertisement

One Comment | Read Chip-And-PIN Breach: Bluetooth, Burned Hole In Back Of Card Reader

  1. A Reader Says:

    To be fair, Chip and PIN was not breached. The mag stripe was cloned.

    The only reason their cards have mag stripes is so they can be used in third-world countries that don’t have chip and PIN terminals, such as the United States.

Leave a Reply

Newsletter

Quickly catch-up on the latest in E-Commerce and Retail Tech with our free weekly newsletter, with urgent bulletins as news merits.
advertisement

Most Recent Comments

Kill All The Passwords

This article does mention, but does not give enough attention to, the fact that the attacks discussed are only feasible when the encrypted password file can be copied and subjected to an offline attack. The trick is to have authentication performed on a separate, much more strongly secured host - such as an Active Directory Domain Controller, or a Kerberos server, or a NIS+ server, or even using something as banal as an LDAP-over-SSL authentication dialog. In these environments, the odds of the "password file" being stolen and subjected to an offline attack go to near zero, and only online attacks may be carried out by the attacker. With sensible exponential backoff between failed password attempts, lockout after a modest number of failed attempts on a single account, and pattern detection, that minimum 7 character password is quite secure enough. Passwords aren't dead yet for security purposes, and they will be with us for a very long while to come for practical purposes. The trick is to employ them correctly. Read more...
The possibilities you describe are years away from being implemented at best, so for the moment passwords are an ugly reality. Luckily, password managers can easily manage hundreds of passwords of any length. The only thing a user needs to remember is the master password. It seems like an easier task to educate users on how to use password managers rather than implement complex security technology on a global basis. Read more...