Apart from this, awesome read.
How I reverse engineered my bank's security token
61–67 of 67 posts
Re: How I reverse engineered my bank's security token
#62While I don't know about the situation elsewhere in the world, here in Germany most banks retired the single use codes (called TANS or (if indexed) iTans) quite some years ago for being insecure. Most online banking will now require a code created per transaction that is 1. either send to you via text on your mobile phone (and is thus prone to phone malware) or 2. is generated using an external device and the chip on…
Luckily, that's not true! First, I think chipTAN is not publicly documented, and given banks' track record in security matters, I certainly would not want to trust a system that is not publicly documented, and secondly, using a card that I am supposed to carry around all day instead of putting it into my safe at home for transaction authentication doesn't sound like that bright an idea to me. mTAN is completely brain…
So until something better comes around chipTANs "hopefully/maybe some level of cryptographic based security" beats "sheet of paper with no verification at all" ;).
Re: How I reverse engineered my bank's security token
#63Think about it for a moment. He did all this (impressive) work just because the application that the bank provided sucked. Now, once he writes a better app, what do you think the bank will do? Hire him (or buy the app), or fight him? How much effort do we collectively waste because of moronic organizations that force their crap upon us, that we cannot escape from? (You can go to a different bank, but what if they all…
Could we at least wait for the bank to give its response before we start condemning it?
Re: How I reverse engineered my bank's security token
#64Earlier quoted context omitted.
Phishing. A MITM attack could "intercept" real transactions and exchange the receiving bank account ID without the user noticing (some even will manipulate the account transaction history!) so you'll only notice it when your bank calls you or your ATM/debit card won't work anymore because your account is empty.
isn't the same attack valid with token based cards (I'm only familiar with RSA's tokens) .. as long as you're in the middle, anything goes..
Re: How I reverse engineered my bank's security token
#65Earlier quoted context omitted.
Luckily, that's not true! First, I think chipTAN is not publicly documented, and given banks' track record in security matters, I certainly would not want to trust a system that is not publicly documented, and secondly, using a card that I am supposed to carry around all day instead of putting it into my safe at home for transaction authentication doesn't sound like that bright an idea to me. mTAN is completely brain…
While that are definitely a valid concerns I prefer that closed undocumented system over others that have actively been used to steal money(sometimes even undetected for some days). The probability that a virus infects my computer is (even with up-to-date software and AV) magnitudes greater than someone breaking the debit card transaction authentication. So until something better comes around chipTANs "hopefully/mayb…
Also, how do you know that chipTAN has not been used for stealing money yet? Criminals commonly don't publish their methods, and as far as banks are concerned, the customer did something wrong and is lying unless the customer can prove that the (proprietary) security system is broken. Not exactly favourable conditions for finding out about security problems.
Also, how do you know that finding a security flaw in chipTAN/some chipTAN implementation is more difficult than finding a security flaw in your webbrowser for someone who is motivated by the monetary reward of doing so? You are aware of the gaping security holes in GSM SIM card software, for example?
I think you are making a whole lot of not particularly well-supported assumptions there.
Re: How I reverse engineered my bank's security token
#66Earlier quoted context omitted.
> The only thing he didn't like about the app was that when he reflashed the phone he had to re-register it. Lots of apps require you flash a new ROM actually. Dropbox and Gmail to name a couple.
Huh? I installed dropbox without doing anything special. Gmail may not be installable from the internet, but gapps can be added without flashing the whole phone.