Showing posts with label card fraud. Show all posts
Showing posts with label card fraud. Show all posts

Monday, November 30, 2009

Breaking The SmartCard Payment Security System

In the recent years, there has been a huge amount of development within e-commerce industry. One of the remarks to secure POS(point of sale) and other electronic payments is to use SmartCard Payment System (Chip & PIN technology). Its simple procedure allow customers to insert contact-smartcard at any POS and enter the PIN code into PED (Pin Entry Device) before authorizing the transaction.

SmartCard Protocol

1. Card To PED
Cardholder details captured (cardholder name, account, expiry, CVC, etc) and other magnetic strip information.

2. PED Display
Transaction description (currency type, value) and PIN entered by customer.

3. Final Authorization
PIN verification results and authorization code.

For this protocol standard to work securely, it is required to develop PED being tamper proofed. This foundation has been forced and practiced widely by VISA, EMV, PCI and APACS (UK). The evaluation of PED is then performed by well-established standards such as "Common Criteria".

Protection Measures and Possible Tampering

Tampered Switches within PED

Dione Xtreme

Ingenico i3300

Tamper Resistance

As of the current protection mechanisms deployed under PED help banks to secure their keys but not the actual customer details. Cardholder details including PIN code are sent unencrypted between card and PED. Thus, if a fraudster intercept these details a fake or clone of the card can be used to withdraw cash on ATMs worldwide depending on the capability of card type and issuer. Following are the key points highlighting weaknesses from the past done by various researchers.

-Loop holes in the tamper mesh allows commnication to be intercepted. Such that an easily accessible compartment can hide a recording device.

-Dione PED is vulnerable to route the card details outside resistance controller. A customized FPGA design can be used to capture the data.
-The relay attack scenario.


Root Causes For SmartCard Security Failure

-Engineering Challanges: 3,662 pages of Visa Chip & PIN specifications.
-Economic Incentives: Standard PED security works well to protect bank keys but customer's PIN left vulnerable.
-Certification Failure: PED passed its necessary certification requirements despite of the technical/design flaws mentioned above.


Security Measures

-PED design can be improved but the smartcard communication with PED is inherently difficult to protect.
-Encrypted PIN verification is mandatory and the copy of magnetic strip data should never be stored on the chip.
-Banks can improve the security but are not responsible for any fraud, putting liability on banks correct the incentives.
-Protocol designers making unrealistic assumptions of tamper resistance can put the bank customers at risk of fraud.

Friday, March 20, 2009

Hackers inside the ATMs: A red alert to world's major financial institutions


When talking about electronic disobedience, many different aspects come forward to point the criminal activities launched using electronic media (computers and internet). Apart from those of money laundering and vandalism issues one is considered to be the most intenseful fraud, "credit card fraud" or "e-fraud". As from the years of data breaches and theft reports, such as:

"11 Mar 2009 - Computerweekly.com: Data theft Trojans fastest growing cyber threat"
http://www.computerweekly.com/Articles/2009/03/11/235229/data-theft-trojans-fastest-growing-cyber-threat-says.htm

"The ITC 2008 Reports: Data Theft/Data Breaches - by industry/cause"
http://idtheftmostwanted.org/ITRC Breach Report 2008.pdf

It has been proved that the underground criminal market is growing fast and find new ways to remain undetectable in almost every first attempts. These changes of development can be noticeable from 2002-2009, an enormous increase in data theft pushed at various firms in the world. Cracking the ATMs is not new, but quite far changing the shape of existing attack in new ways.

Recently there was a news published at DarkReading.com, in which it has been stated clearly about how cyber criminals are moving and driving their thirst of money by passing any sort of security infrastructure to accomplish their goals. From time to time these criminals are changing and adobting new methods, for instance, a creation of normal phishing attack using DIY toolkits driven more towards serving the automated information-stealing malware today.

Sophos recently revealed a latest hack which affects the Diebold based ATM machines:
http://www.sophos.com/blogs/gc/g/2009/03/18/details-diebold-atm-trojan-horse-case/

Although, Diebold has published the security update in late January for their Windows-based Opteva platform. A trojan identified gave complete access to the criminal. One thing to notice that how far today's high-tech criminals have moved a step forward to understand the internal functions and API calls of the cash machines. This has not only to deal with virtual access of ATM but also a physical access (or internal access) to install the malware. The trojan was silently collecting PINs (aka. Track2 information) from the magnetic strips which further allows an attacker to clone real cards.

Looking at other perspectives where the recent incident in Europe "Several Checkout card readers in major supermarket chains", a news reported by Sophos in which the card readers were tampered with built-in sniffers. Among the known victims were Wal-Mart and Asda chains. These all aspects give a clear high-lights on how the cyber criminals of past moving faster in finding their ways to inject new ideas to steal the financial records.