<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Optimised to fail: Card readers for online banking</title>
	<atom:link href="http://www.lightbluetouchpaper.org/2009/02/26/optimised-to-fail-card-readers-for-online-banking/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.lightbluetouchpaper.org/2009/02/26/optimised-to-fail-card-readers-for-online-banking/</link>
	<description>Security Research, Computer Laboratory, University of Cambridge</description>
	<lastBuildDate>Fri, 10 Feb 2012 17:31:40 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Financial Advisor</title>
		<link>http://www.lightbluetouchpaper.org/2009/02/26/optimised-to-fail-card-readers-for-online-banking/comment-page-1/#comment-108655</link>
		<dc:creator>Financial Advisor</dc:creator>
		<pubDate>Thu, 07 Apr 2011 11:36:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=704#comment-108655</guid>
		<description>To avoid the frauds in the banking &amp; making online banking more &amp; more secure this thing has to be happen.There should not be any trouble having CHIP &amp; PIN.It will certainly raise confidence in the mind of user about security of his banking.</description>
		<content:encoded><![CDATA[<p>To avoid the frauds in the banking &amp; making online banking more &amp; more secure this thing has to be happen.There should not be any trouble having CHIP &amp; PIN.It will certainly raise confidence in the mind of user about security of his banking.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aaron</title>
		<link>http://www.lightbluetouchpaper.org/2009/02/26/optimised-to-fail-card-readers-for-online-banking/comment-page-1/#comment-90804</link>
		<dc:creator>Aaron</dc:creator>
		<pubDate>Mon, 20 Dec 2010 22:08:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=704#comment-90804</guid>
		<description>Hi everyone - Thanks for the revealing paper and great comments.  Does anyone know if the CHIP and PIN are being used here in the US?</description>
		<content:encoded><![CDATA[<p>Hi everyone &#8211; Thanks for the revealing paper and great comments.  Does anyone know if the CHIP and PIN are being used here in the US?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Marite Ferrero</title>
		<link>http://www.lightbluetouchpaper.org/2009/02/26/optimised-to-fail-card-readers-for-online-banking/comment-page-1/#comment-37837</link>
		<dc:creator>Marite Ferrero</dc:creator>
		<pubDate>Thu, 12 Nov 2009 12:21:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=704#comment-37837</guid>
		<description>Jad&#039;  &#124;  April 21st, 2009 at 13:20 UTC said &quot; In France, we use CHIP&amp;PIN for more than 20 years… As a result there is less fraud, and there is no case of assault for PIN, yet.&quot;

Hi Jad, April 12, 2002, 4 men broke into my house while I was sleeping. They stayed for about an hour, asking me for my pin-codes and choosing what they wanted to take from me. 

Let me tell you something you might not have heard of. I told them that they can take all my cards but I cant give them the pincodes since they (my american cards) didn&#039;t have pin-codes. They took many things with them (cash, laptops, mobile phones, jewelries) but they left all my american cards. This incident was reported with the gendarme in my area.

The gendarme and police told me that thieves often assault cardholders for the cards and the pin-codes.</description>
		<content:encoded><![CDATA[<p>Jad&#8217;  |  April 21st, 2009 at 13:20 UTC said &#8221; In France, we use CHIP&amp;PIN for more than 20 years… As a result there is less fraud, and there is no case of assault for PIN, yet.&#8221;</p>
<p>Hi Jad, April 12, 2002, 4 men broke into my house while I was sleeping. They stayed for about an hour, asking me for my pin-codes and choosing what they wanted to take from me. </p>
<p>Let me tell you something you might not have heard of. I told them that they can take all my cards but I cant give them the pincodes since they (my american cards) didn&#8217;t have pin-codes. They took many things with them (cash, laptops, mobile phones, jewelries) but they left all my american cards. This incident was reported with the gendarme in my area.</p>
<p>The gendarme and police told me that thieves often assault cardholders for the cards and the pin-codes.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Marite Ferrero</title>
		<link>http://www.lightbluetouchpaper.org/2009/02/26/optimised-to-fail-card-readers-for-online-banking/comment-page-1/#comment-37819</link>
		<dc:creator>Marite Ferrero</dc:creator>
		<pubDate>Thu, 12 Nov 2009 08:10:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=704#comment-37819</guid>
		<description>Gerald Levin&#039;s (CNN&#039;s former CEO) son (Jon Levin) was tortured and murdered by one of his students for the pin-code of his ATM card.

http://www.google.com/search?hl=en&amp;source=hp&amp;q=Gerard+Levin+pin-code+son+murder&amp;aq=f&amp;oq=&amp;aqi=</description>
		<content:encoded><![CDATA[<p>Gerald Levin&#8217;s (CNN&#8217;s former CEO) son (Jon Levin) was tortured and murdered by one of his students for the pin-code of his ATM card.</p>
<p><a href="http://www.google.com/search?hl=en&amp;source=hp&amp;q=Gerard+Levin+pin-code+son+murder&amp;aq=f&amp;oq=&amp;aqi=" rel="nofollow">http://www.google.com/search?hl=en&amp;source=hp&amp;q=Gerard+Levin+pin-code+son+murder&amp;aq=f&amp;oq=&amp;aqi=</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David Haslam</title>
		<link>http://www.lightbluetouchpaper.org/2009/02/26/optimised-to-fail-card-readers-for-online-banking/comment-page-1/#comment-31130</link>
		<dc:creator>David Haslam</dc:creator>
		<pubDate>Tue, 16 Jun 2009 14:16:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=704#comment-31130</guid>
		<description>While on the subject of online banking, has anyone in the group looked at the Rapport software that RBS is advising their customers to install? Several other banks are doing the same.

http://www.rbs.co.uk/global/f/security/security-advice/protect-yourself/computer/rapport.ashx?DCMP=OTC-rapportFURL

Can the security claims for Rapport can be demonstrated?
Does this product introduce more security risks than it claims to solve?

Here&#039;s the supplier&#039;s web page about the product.
http://www.trusteer.com/the-problem

David</description>
		<content:encoded><![CDATA[<p>While on the subject of online banking, has anyone in the group looked at the Rapport software that RBS is advising their customers to install? Several other banks are doing the same.</p>
<p><a href="http://www.rbs.co.uk/global/f/security/security-advice/protect-yourself/computer/rapport.ashx?DCMP=OTC-rapportFURL" rel="nofollow">http://www.rbs.co.uk/global/f/security/security-advice/protect-yourself/computer/rapport.ashx?DCMP=OTC-rapportFURL</a></p>
<p>Can the security claims for Rapport can be demonstrated?<br />
Does this product introduce more security risks than it claims to solve?</p>
<p>Here&#8217;s the supplier&#8217;s web page about the product.<br />
<a href="http://www.trusteer.com/the-problem" rel="nofollow">http://www.trusteer.com/the-problem</a></p>
<p>David</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jad'</title>
		<link>http://www.lightbluetouchpaper.org/2009/02/26/optimised-to-fail-card-readers-for-online-banking/comment-page-1/#comment-31002</link>
		<dc:creator>Jad'</dc:creator>
		<pubDate>Tue, 21 Apr 2009 13:20:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=704#comment-31002</guid>
		<description>Guys, look around you. UK is not the only country ro use CAP, and it&#039;s no even new!
In France, we use CHIP&amp;PIN for more than 20 years...
As a result there is less fraud, and there is no case of assault for PIN, yet.</description>
		<content:encoded><![CDATA[<p>Guys, look around you. UK is not the only country ro use CAP, and it&#8217;s no even new!<br />
In France, we use CHIP&amp;PIN for more than 20 years&#8230;<br />
As a result there is less fraud, and there is no case of assault for PIN, yet.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Haitham</title>
		<link>http://www.lightbluetouchpaper.org/2009/02/26/optimised-to-fail-card-readers-for-online-banking/comment-page-1/#comment-30959</link>
		<dc:creator>Haitham</dc:creator>
		<pubDate>Fri, 03 Apr 2009 19:29:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=704#comment-30959</guid>
		<description>I&#039;ve read the Paper with the title of &quot;the Man-in-the-Middle Defence&quot; by Ross Anderson and Mike Bond and it seems very help and very rich-in-content! 
Still any help on how to encounter the real-time MITM attack would be much appreciated!</description>
		<content:encoded><![CDATA[<p>I&#8217;ve read the Paper with the title of &#8220;the Man-in-the-Middle Defence&#8221; by Ross Anderson and Mike Bond and it seems very help and very rich-in-content!<br />
Still any help on how to encounter the real-time MITM attack would be much appreciated!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Haitham</title>
		<link>http://www.lightbluetouchpaper.org/2009/02/26/optimised-to-fail-card-readers-for-online-banking/comment-page-1/#comment-30958</link>
		<dc:creator>Haitham</dc:creator>
		<pubDate>Fri, 03 Apr 2009 18:52:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=704#comment-30958</guid>
		<description>Indeed, best-read in ages! I think I am just losing faith in our online banking security! This is all scary and something must be done about it SOONER rather than later!
Our great authors, in Page 2, where you talked about the real-time MITM attack and where you wrote this: &quot;This class of attack can be resisted by cryptographically binding the one-time code to the data of the transaction being attempted – transaction authentication. A robust way to do this is to provide the customer with an electronic signature device with a trustworthy display on which she could verify the transaction data, a trusted path to authorise a digital signature, and a tamper-resistant store for
the signing key.&quot;, 
Is there any chance that you could possibly forward me to where I can find some more details on how to encounter the real-time MITM attack, please?
Thanks in advance!</description>
		<content:encoded><![CDATA[<p>Indeed, best-read in ages! I think I am just losing faith in our online banking security! This is all scary and something must be done about it SOONER rather than later!<br />
Our great authors, in Page 2, where you talked about the real-time MITM attack and where you wrote this: &#8220;This class of attack can be resisted by cryptographically binding the one-time code to the data of the transaction being attempted – transaction authentication. A robust way to do this is to provide the customer with an electronic signature device with a trustworthy display on which she could verify the transaction data, a trusted path to authorise a digital signature, and a tamper-resistant store for<br />
the signing key.&#8221;,<br />
Is there any chance that you could possibly forward me to where I can find some more details on how to encounter the real-time MITM attack, please?<br />
Thanks in advance!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Vicky Larmour</title>
		<link>http://www.lightbluetouchpaper.org/2009/02/26/optimised-to-fail-card-readers-for-online-banking/comment-page-1/#comment-30894</link>
		<dc:creator>Vicky Larmour</dc:creator>
		<pubDate>Tue, 17 Mar 2009 12:25:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=704#comment-30894</guid>
		<description>@Steven: Thanks very much for the pointers. I&#039;m sure that having more voices adding to the pile of complaints can&#039;t hurt.</description>
		<content:encoded><![CDATA[<p>@Steven: Thanks very much for the pointers. I&#8217;m sure that having more voices adding to the pile of complaints can&#8217;t hurt.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steven J. Murdoch</title>
		<link>http://www.lightbluetouchpaper.org/2009/02/26/optimised-to-fail-card-readers-for-online-banking/comment-page-1/#comment-30892</link>
		<dc:creator>Steven J. Murdoch</dc:creator>
		<pubDate>Tue, 17 Mar 2009 11:27:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=704#comment-30892</guid>
		<description>@Vicky

&lt;a href=&quot;http://www.apacs.org.uk/&quot; rel=&quot;nofollow&quot;&gt;APACS&lt;/a&gt;, who are the official spokesman for the banks, said that they were &lt;a href=&quot;http://news.zdnet.co.uk/security/0,1000000189,39621475,00.htm&quot; rel=&quot;nofollow&quot;&gt;already aware&lt;/a&gt; of the vulnerabilities. &lt;a href=&quot;http://www.barclays.co.uk/&quot; rel=&quot;nofollow&quot;&gt;Barclays&lt;/a&gt; claimed their system was &lt;a href=&quot;http://www.computerweekly.com/Articles/2009/03/02/235091/online-card-readers-will-become-fraud-target.htm&quot; rel=&quot;nofollow&quot;&gt;infallible&lt;/a&gt;!  You still might get something different from the customer care representatives, rather than their PR side.

The &lt;a href=&quot;http://www.bba.org.uk/&quot; rel=&quot;nofollow&quot;&gt;BBA&lt;/a&gt;, like APACS, represent the bank and not the customer, so are unlikely to help. The &lt;a href=&quot;http://www.financial-ombudsman.org.uk/&quot; rel=&quot;nofollow&quot;&gt;Financial Ombudsman Service&lt;/a&gt; have a narrow remit in settling disputes, so don&#039;t seem appropriate. They also have been the subject of &lt;a href=&quot;http://www.lightbluetouchpaper.org/2007/02/08/financial-ombudsman-on-chip-pin-infallibility/&quot; rel=&quot;nofollow&quot;&gt;substantial&lt;/a&gt; &lt;a href=&quot;http://www.fipr.org/080116huntreview.pdf&quot; rel=&quot;nofollow&quot;&gt;criticism&lt;/a&gt;.

Probably your best approach is the &lt;a href=&quot;http://www.fsa.gov.uk/&quot; rel=&quot;nofollow&quot;&gt;Financial Services Authority&lt;/a&gt;, who are at least accountable to parliament.  They are having their &lt;a href=&quot;http://www.guardian.co.uk/business/2009/feb/11/banking-hbos&quot; rel=&quot;nofollow&quot;&gt;own&lt;/a&gt; &lt;a href=&quot;http://business.timesonline.co.uk/tol/business/industry_sectors/banking_and_finance/article5864476.ece&quot; rel=&quot;nofollow&quot;&gt;problems&lt;/a&gt; at the moment though. Your MP is also in a good position to apply pressure to the right people.</description>
		<content:encoded><![CDATA[<p>@Vicky</p>
<p><a href="http://www.apacs.org.uk/" rel="nofollow">APACS</a>, who are the official spokesman for the banks, said that they were <a href="http://news.zdnet.co.uk/security/0,1000000189,39621475,00.htm" rel="nofollow">already aware</a> of the vulnerabilities. <a href="http://www.barclays.co.uk/" rel="nofollow">Barclays</a> claimed their system was <a href="http://www.computerweekly.com/Articles/2009/03/02/235091/online-card-readers-will-become-fraud-target.htm" rel="nofollow">infallible</a>!  You still might get something different from the customer care representatives, rather than their PR side.</p>
<p>The <a href="http://www.bba.org.uk/" rel="nofollow">BBA</a>, like APACS, represent the bank and not the customer, so are unlikely to help. The <a href="http://www.financial-ombudsman.org.uk/" rel="nofollow">Financial Ombudsman Service</a> have a narrow remit in settling disputes, so don&#8217;t seem appropriate. They also have been the subject of <a href="http://www.lightbluetouchpaper.org/2007/02/08/financial-ombudsman-on-chip-pin-infallibility/" rel="nofollow">substantial</a> <a href="http://www.fipr.org/080116huntreview.pdf" rel="nofollow">criticism</a>.</p>
<p>Probably your best approach is the <a href="http://www.fsa.gov.uk/" rel="nofollow">Financial Services Authority</a>, who are at least accountable to parliament.  They are having their <a href="http://www.guardian.co.uk/business/2009/feb/11/banking-hbos" rel="nofollow">own</a> <a href="http://business.timesonline.co.uk/tol/business/industry_sectors/banking_and_finance/article5864476.ece" rel="nofollow">problems</a> at the moment though. Your MP is also in a good position to apply pressure to the right people.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

