Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Honestly it doesn't make much of a difference when it comes to classic skimming, because, yes, as you say, you can put a keylogger on the pinpad.

The problem comes from physically stolen cards, if your card doesn't rely on cryptography to secure the request/response channel you can insert a shim between the reader and the card to fake acceptance of an arbitrary pin. This specific attack has already been demonstrated, and if my memory serves correctly it's already being used in the wild.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: