Prof. Ross Anderson's response to a takedown request about security research
1–10 of 56 posts
Re: Prof. Ross Anderson's response to a takedown request about security research
#2Re: Prof. Ross Anderson's response to a takedown request about security research
#3Do you have some details on the background of this issue?
Re: Prof. Ross Anderson's response to a takedown request about security research
#4Do you have some details on the background of this issue?
A news story about the initial issue: http://www.lightbluetouchpaper.org/2010/02/11/chip-and-pin-i...
The take down notice (pdf): http://www.cl.cam.ac.uk/~rja14/Papers/20101221110342233.pdf
Re: Prof. Ross Anderson's response to a takedown request about security research
#5http://www.cl.cam.ac.uk/~osc22/scd/ "Smart Card Detective"
Re: Prof. Ross Anderson's response to a takedown request about security research
#61, Send developers to all their seminars to learn something
2, Buy them drinks
3, Sue them
Re: Prof. Ross Anderson's response to a takedown request about security research
#7Do you have some details on the background of this issue?
Re: Prof. Ross Anderson's response to a takedown request about security research
#8http://docs.google.com/viewer?url=http://www.cl.cam.ac.uk/~r...
Re: Prof. Ross Anderson's response to a takedown request about security research
#9Re: Prof. Ross Anderson's response to a takedown request about security research
#10The fundamental reason why this is a big deal is that in the UK, the repercussions of fraud are skewed towards customers rather than the banks. The relevant legal standard is that customers must exercise "reasonable care" with their PIN if the bank is to bear the cost of fraud. Of course, banks always insist that their systems are secure, and that it was the customer's fault. http://www.timesonline.co.uk/tol/money/consumer_affairs/arti...
The Cambridge team has been investigating vulnerabilities in the EMV standard underlying Chip and PIN (ubiquitous in the UK) for a long time.
From 2006: http://www.lightbluetouchpaper.org/2006/03/15/chip-and-skim/
If I understand correctly they first started to find serious vulnerabilities in 2009.
Blog post: http://www.lightbluetouchpaper.org/2009/08/25/defending-agai...
Paper: "Optimised to Fail: Card Readers for Online Banking" http://www.cl.cam.ac.uk/~sd410/papers/optimised_fail.pdf
Media: http://www.youtube.com/watch?v=U1QAnb-wnTs
They escalated that attack in 2010. http://www.lightbluetouchpaper.org/2010/02/11/chip-and-pin-i...
Paper: http://www.cl.cam.ac.uk/~sjm217/papers/oakland10chipbroken.p...