Live data from Hacker News

Prof. Ross Anderson's response to a takedown request about security research

cl.cam.ac.uk

1–10 of 56 posts

Re: Prof. Ross Anderson's response to a takedown request about security research

#4
post #2

Do you have some details on the background of this issue?

No the OP, but:

A news story about the initial issue: http://www.lightbluetouchpaper.org/2010/02/11/chip-and-pin-i...

The take down notice (pdf): http://www.cl.cam.ac.uk/~rja14/Papers/20101221110342233.pdf

Re: Prof. Ross Anderson's response to a takedown request about security research

#6
If one of the smartest computer security guys was prepared to do all this work and throw lots of expensive experts (well grad students) at finding your bugs - would you:

1, Send developers to all their seminars to learn something

2, Buy them drinks

3, Sue them

Re: Prof. Ross Anderson's response to a takedown request about security research

#9
Dear Jeff Bezos and Amazon: Take note of how it's done by real men. By your actions WRT Orwell and Wikileaks, you've shown that you aren't worthy to shine the shoes of a real information-bearer, and you aren't fit to host my cloud nodes either. Sincerely, Marsh Ray

Re: Prof. Ross Anderson's response to a takedown request about security research

#10
Some background information.

The fundamental reason why this is a big deal is that in the UK, the repercussions of fraud are skewed towards customers rather than the banks. The relevant legal standard is that customers must exercise "reasonable care" with their PIN if the bank is to bear the cost of fraud. Of course, banks always insist that their systems are secure, and that it was the customer's fault. http://www.timesonline.co.uk/tol/money/consumer_affairs/arti...

The Cambridge team has been investigating vulnerabilities in the EMV standard underlying Chip and PIN (ubiquitous in the UK) for a long time.

From 2006: http://www.lightbluetouchpaper.org/2006/03/15/chip-and-skim/

If I understand correctly they first started to find serious vulnerabilities in 2009.

Blog post: http://www.lightbluetouchpaper.org/2009/08/25/defending-agai...

Paper: "Optimised to Fail: Card Readers for Online Banking" http://www.cl.cam.ac.uk/~sd410/papers/optimised_fail.pdf

Media: http://www.youtube.com/watch?v=U1QAnb-wnTs

They escalated that attack in 2010. http://www.lightbluetouchpaper.org/2010/02/11/chip-and-pin-i...

Paper: http://www.cl.cam.ac.uk/~sjm217/papers/oakland10chipbroken.p...

Media: http://www.youtube.com/watch?v=1pMuV2o4Lrw

Post reply on HN