We have had enough "Dark Ages" in the past. Let's learn something from history.
Prof. Ross Anderson's response to a takedown request about security research
31–40 of 56 posts
Re: Prof. Ross Anderson's response to a takedown request about security research
#32On Google docs viewer: http://docs.google.com/viewer?url=http://www.cl.cam.ac.uk/~r...
Re: Prof. Ross Anderson's response to a takedown request about security research
#33Some background information. The fundamental reason why this is a big deal is that in the UK, the repercussions of fraud are skewed towards customers rather than the banks. The relevant legal standard is that customers must exercise "reasonable care" with their PIN if the bank is to bear the cost of fraud. Of course, banks always insist that their systems are secure, and that it was the customer's fault. http://www.t…
I don't really understand the logic behind chip and pin cards. Do you really want me to disclose my card and my PIN to a completely untrusted machine a stranger hands to me? How do I know the vendor won't just record both and replay them, charging me for things I didn't pay?
Re: Prof. Ross Anderson's response to a takedown request about security research
#34Some background information. The fundamental reason why this is a big deal is that in the UK, the repercussions of fraud are skewed towards customers rather than the banks. The relevant legal standard is that customers must exercise "reasonable care" with their PIN if the bank is to bear the cost of fraud. Of course, banks always insist that their systems are secure, and that it was the customer's fault. http://www.t…
I don't really understand the logic behind chip and pin cards. Do you really want me to disclose my card and my PIN to a completely untrusted machine a stranger hands to me? How do I know the vendor won't just record both and replay them, charging me for things I didn't pay?
So it's not sufficient just to host a fake machine and expect it to be accepted within the EMV infrastructure (cards, POC machines and backend processors).
Re: Prof. Ross Anderson's response to a takedown request about security research
#35CMOA
Re: Prof. Ross Anderson's response to a takedown request about security research
#36Earlier quoted context omitted.
If anything, the banks promoting this technology should be sued for false advertising. in many cases banks refused to reimburse cardholders who reported unauthorised card use, claiming that their systems could not fail http://en.wikipedia.org/wiki/Chip_and_PIN
2 decades earlier they prosecuted people who reported ATM losses for fraud - because ATMs were perfectly secure.
p.s my reference is a blue screen of death on one :)
Re: Prof. Ross Anderson's response to a takedown request about security research
#37Some background information. The fundamental reason why this is a big deal is that in the UK, the repercussions of fraud are skewed towards customers rather than the banks. The relevant legal standard is that customers must exercise "reasonable care" with their PIN if the bank is to bear the cost of fraud. Of course, banks always insist that their systems are secure, and that it was the customer's fault. http://www.t…
I don't really understand the logic behind chip and pin cards. Do you really want me to disclose my card and my PIN to a completely untrusted machine a stranger hands to me? How do I know the vendor won't just record both and replay them, charging me for things I didn't pay?
The private key cannot be read from the chip without the use of a tunneling microscope or other hardware exotics. In fact it is not untypical for a chip to have a built-in protection against key retrieval that is set to physically fry the chip. The PIN is used to tell the chip to do the digital signing. No PIN = no signing.
That's how it works in general. This application of the smartcard technology is almost 20 years old, so while there are some variations one could still call it sufficiently mature :grin
Re: Prof. Ross Anderson's response to a takedown request about security research
#38Earlier quoted context omitted.
Canadian constitutional law has something called the 'living tree doctrine', which states that the constitution can grow and evolve over time, being reinterpreted in new contexts. To push the metaphor a bit further, I'd point out that a living tree is considerably more resilient than a dead tree, and is likely to adapt to conditions which might otherwise destroy it. I don't think anyone can seriously claim that the c…
The Congress shall have Power... To regulate Commerce with foreign Nations, and among the several States, and with the Indian tribes;" It's not really a matter of living versus dead trees. The US judicial system has just plainly ignored the "among the several States" caveat for the last 100 years. I'm not advocating either side of this example, by how does growing and consuming marijuana on your own property fall und…
Again, I mention this without endorsement of either side; I mention this just because I only recently learned about this myself.
Re: Prof. Ross Anderson's response to a takedown request about security research
#39Earlier quoted context omitted.
I don't really understand the logic behind chip and pin cards. Do you really want me to disclose my card and my PIN to a completely untrusted machine a stranger hands to me? How do I know the vendor won't just record both and replay them, charging me for things I didn't pay?
Chip cards cannot be "replayed" or cloned, that's why there's a chip in the first place. The chip stores card's private key that is used to digitally sign a (purchase) transaction. Each transaction is a multi-message exchange in real-time between the terminal and the bank and it includes an unique ID generated by the bank, which is covered by the signature. This effectively prevents a replay. The private key cannot b…
Re: Prof. Ross Anderson's response to a takedown request about security research
#40Earlier quoted context omitted.
while there's no universal freedom of speech in British Law... Perhaps not in written law, but I think you'd have a hard time convincing a judge that the British constitution does not guarantee freedom of speech. As my legal friends as fond of pointing out, an unwritten constitution has the important advantage that its words can't be twisted the way that a written constitution can.
The Felony Treason Act 1848 is still on the books. Sure, a couple of Lords may have said that expressing anti-monarchist sentiment won't be punished, but where is the line drawn? [1] Can you be transported to Australia for poking the Duchess of Cornwall with a stick? What about shouting "Off with their heads!" at the Prince of Wales? [2] The absence of a constitutional guarantee of free speech, and the persistence of…
No, and no.
The British constitution is not a computer program applied by an automaton; issues are decided by experienced judges who, above all else, apply common sense.
(The British constitution isn't even self-consistent: The supremacy of parliament is absolute, but the 1931 Statute of Westminster places limits on that power. Constitutional scholars routinely shrug their shoulders at such matters and fall back to "well, we all know what they meant".)