Live data from Hacker News

Verified by Visa and Mastercard SecureCode are broken and need to be fixed

cxpartners.co.uk

61–64 of 64 posts

Re: Verified by Visa and Mastercard SecureCode are broken and need to be fixed

#61
post #60
post #36

Earlier quoted context omitted.

A very similar system is already in use in the UK and other parts of Europe. It's called "chip & pin". You plug your card in to a card reader and check the LCD display and type in your PIN to authorise a transaction. In a shop, the card reader is owned by the shop and is similar to point-of-sale card readers used in the USA. However, most banks now provide customers with a small reader (that looks like a calculator)…

Someone wrote a criticism of the chip&pin system a while ago. I don't remember the link, but they were arguing that this system also had serious security flaws. The most memorable one was that while before people who held you up for your ATM card and PIN had to physically go to an actual ATM to see if the PIN you gave them worked, now they can get to work on you with a pair of pliers and a blowtorch until the card re…

The fix for that, if we're remembering the same article, was simply to have the card reader display junk output instead of "bad pin". The bad output could then be entered into the bank website three times, and then block the account from there too.

Re: Verified by Visa and Mastercard SecureCode are broken and need to be fixed

#62
post #12

VbV is badly broken, but the suggestions here miss one of the most important points. The use of an iframe means that users can't tell where VbV is coming from and can't be sure either that it is secured or that it's really coming from the bank. This is just begging for copycat phising and MITM attacks.

The security is up to the bank. Some banks implement "something you have" security which mitigates the risk.

I have Australian and UK bank accounts. Both require Verified by Visa. The Australian account asks me to enter a single-use number from a battery-powered token. The UK account asks me to enter three randomly-selected digits of my password. The former is obviously immune to phishing attacks. The latter is not completely, but to get the complete password would require several sessions. Neither of them are immune to MITM attacks, but I'm not sure how MITM would help an attacker here: VbV authorises a transaction but doesn't allow you to place one. You can't do anything with the information you have snooped upon because it's single-use (in the first case) or because you don't have enough of the password (in the second case).

Re: Verified by Visa and Mastercard SecureCode are broken and need to be fixed

#63
post #32

Earlier quoted context omitted.

While we are in public-service-announcement mode: I believe that the above protections are still a lot smaller for debit cards than credit cards. You still have $50 limit on liability with debit cards, but you must report the theft very quickly indeed and the thief is emptying your personal account in the meantime: http://banking.about.com/od/checkingaccounts/a/stolendebitca... This is why I never use a debit card fo…

In defense of debit cards, in the event you do lose it and someone's emptying your account, your bank should still restore your funds after the theft. I say this because it happened to my wife; Chase's fraud prevention kicked in after about $300, all of which was refunded as soon as she figured out what had happened.

I lost a little over £1000 from my debit card once; the bank did refund it but it took 5 internal forms, a police fraud report and a month to get the money back.

Re: Verified by Visa and Mastercard SecureCode are broken and need to be fixed

#64
post #61
post #60

Earlier quoted context omitted.

Someone wrote a criticism of the chip&pin system a while ago. I don't remember the link, but they were arguing that this system also had serious security flaws. The most memorable one was that while before people who held you up for your ATM card and PIN had to physically go to an actual ATM to see if the PIN you gave them worked, now they can get to work on you with a pair of pliers and a blowtorch until the card re…

The fix for that, if we're remembering the same article, was simply to have the card reader display junk output instead of "bad pin". The bad output could then be entered into the bank website three times, and then block the account from there too.

Yes that would be possible. Only my card reader still says "pin ok".
Post reply on HN