Attend a special evening hosted by Mike Atherton
TWO Cambridge scientists face a court gag after discovering what they claim is a serious flaw in the software used to protect credit card Pin numbers.
Ross Anderson and PhD student Mike Bond, who are based at Cambridge University’s world-renowned Computer Laboratory, say they discovered a flaw in the cryptographic equipment commonly used to generate Pins while working as expert witnesses on a “phantom withdrawal” case.
Citibank, one of the world’s biggest banks and owner of Diners Club, has won an order in the High Court to prevent details of the research falling into the public domain on the grounds that it could compromise the company’s security.
Credit card fraud in Britain amounts to about £700m a year. Overall fraud is not growing rapidly, although Bond says card companies and criminals are constantly trying to outwit each other.
Anderson and Bond are witnesses in a case that involves a businessman in Durban, South Africa. He received a Pin for his Diners Club card, which can be used to withdraw money from cashpoints, in February 2000 but found it would not work. However, over the following two days a copy of the card was used 6,000 miles away in London to withdraw £55,000 in cash from machines in 190 separate transactions.
Curiously the thieves also appear to have bypassed any limit on withdrawals for the businessman’s card, a detail that has so far not been explained by Citibank.
Such phantom withdrawals are often put down to “shoulder surfing” — a technique in which fraudsters obtain a victim’s Pin number by discreetly watching them type it into a cashpoint. But in the Citibank case the victim’s lawyers argued he had been the subject of a new and more sophisticated fraud involving company insiders “cracking” the machines that generate Pins.
“All the big card issuers use similar machines that are based on 1980s technology,” says Anderson. “Computers have gone through something like eight generations since then, but these machines have not kept up.”
The matter went to court in South Africa, where the judge agreed to take evidence from expert witnesses including Anderson and Bond.
While preparing his submissions for the case, Bond says he discovered the machines that generate Pins can be compromised using a simple mathematical technique. “It is then possible to guess each Pin using an average of 15 guesses instead of nearly 10,000,” says Bond. In a lunch break an attacker on the inside could discover about 7,000 Pins and with a £200 limit on each card the potential bounty is about £1.4m. ”
Bond, with a colleague, has already written a paper on the new technique for cracking the encryption machines that was discussed in a seminar organised by Microsoft in Cambridge last week. The High Court has now agreed that the hearings in front of the South African judge, due to begin next month, should be held in camera to prevent sensitive details of banking security getting into the public domain.
Last night Citibank denied its cards were insecure or that it was trying to limit academic freedom. “The High Court has ordered that information that is not already in the public domain must be protected in the proceedings and Citigroup will assist on that basis,” it said.
Industry sectors news at a glance. Interactive heatmap, video and podcast
Everything the Business Traveller needs to know to make a better trip
Get ready for the winter sports season, with our resort guides and snow reports
We are backing British business, what is the confidence of the nation and what businesses are succeeding?
Growing demand for energy, oil that is harder to reach and the rise of carbon dioxide emissions. We examine the energy challenge
With rail travel in Europe on the rise, we review the benefits of travelling by train
In this special section we explore new food trends to help improve your dinner party and impress guests
Enjoy further reading from Travel to Fashion, Business to Sport, discover more
Shortcuts to help you find sections and articles
1998
£47,955
12 months for the price of 11 and a 5% discount.
Offer ends 31/11/09
Check your free Experian credit report before applying
Car Insurance
£100,000
Barnardos
UK
PwC’s Consulting practice helps businesses of all shapes and sizes work smarter and grow faster
PwC
£37,000
Department for Culture, Media and Sport
London
Currently £36,285
Department for Culture, Media and Sport
London
Moments from Battersea Park.
For sale with Winkworth
Find out about shared ownership.
See your free Experian credit report beforehand
Includes flights, accommodation with room upgrades, transfers city tours in Hong Kong and Bangkok.
PremierHolidays.co.uk
For your ultimate tailor-made ski holiday, click here
Get covered on your travels with a superb range of policies at great prices. Visit InsureandGo.com
World Class Golf, Spa and preferential Beach Club. Private estate overlooking West Coast
Villas from £275 per night inclusive of Golf
Contact our advertising team for advertising and sponsorship in Times Online, The Times and The Sunday Times, or place your advertisement.
Times Online Services: Dating | Jobs | Property Search | Used Cars | Holidays | Births, Marriages, Deaths | Subscriptions | E-paper
News International associated websites: Globrix Property Search | Milkround
Copyright 2009 Times Newspapers Ltd.
This service is provided on Times Newspapers' standard Terms and Conditions. Please read our Privacy Policy.To inquire about a licence to reproduce material from Times Online, The Times or The Sunday Times, click here.This website is published by a member of the News International Group. News International Limited, 1 Virginia St, London E98 1XY, is the holding company for the News International group and is registered in England No 81701. VAT number GB 243 8054 69.