We present an attack on hardware security modules used by retail banks for the secure storage and verification of customer PINs in ATM (cash machine) infrastructures. By using adaptive decimalisation tables and guesses, the maximum amount of information is learnt about the true PIN upon each guess. It takes an average of 15 guesses to determine a four digit PIN using this technique, instead of the 5000 guesses intended. In a single 30 minute lunch-break, an attacker can thus discover approximately 7000 PINs rather than 24 with the brute force method. With a $300 withdrawal limit per card, the potential bounty is raised from $7200 to $2.1 million and a single motivated attacker could withdraw $30{50 thousand of this each day. This attack thus presents a serious threat to bank security.
http://cryptome.org/pacc.htm
Thursday, February 20, 2003
Popular Posts
-
... or, Decemberween. Whatever. http://www.homestarrunner.com/xmas04.html
-
It's been almost exaclty three years since I've updated this blog. In that three years, I've achieved a lot -- I've gone aft...
-
Very dry, dull book with some basic financial info like ROI and cash flow. Not a lot here.
-
Here's my (edited) journal entry for this event dated 12/01/98: Wow. I just sessioned and started reading "The Tao of Physics...
-
"The fish was delish and it made quite a dish." http://www.homestarrunner.com/sbemail120.html
-
After a year of hell, I've been given a reprieve. I've spent the last year dealing with contracts, negotiation, budgeting, and confl...
-
Kids sick. Hiyat sick. Me sick. Everybody sick. No fun. Seriously. Zack just gets over having baby measels and everybody in the house co...
-
I'm sure someone else has written the rules of business out in terms of the Bushido, but here's my take: Truthfulness You must speak...
-
Somewhere along the way I learned about this magic trick. It was probably from one of those “Owl” magazines you used to get for free or an e...
-
Nother confirmation Of einstein... the first images of light escaping a black hole show that they lose energy. In this case, it was a superm...