TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Shimming: the newest con for stealing credit card info from ATM machines

26 pointsby Julie188almost 15 years ago

3 comments

wmfalmost 15 years ago
This doesn't work in the US because we don't have smart cards.<p>Edit: My point stands that <i>this particular attack</i> does not exist in the US and people don't need to worry about it. Existing precautions against magstripe card skimming are adequate.
评论 #1509138 未加载
评论 #1509146 未加载
评论 #1510034 未加载
JoelBalmost 15 years ago
From my understanding of smart cards, I don't see how this is possible.<p>Communication between the card and the reader is typically done using encryption with a Diffie-Hellman key exchange with a man-in-the-middle resistant protocol. You would need to attack whatever encryption algorithm is being used, which is non-trivial even with physical access. You would need to either perform differential power analysis attack or a timing attack or attack a weakness in the algorithm.<p>Seeing as how one of the primary purposes of smart cards was to eliminate skimming and similar attacks, I can't fathom why any reader would ever be created that didn't support session encryption. Why use a chip if it's basically the same as a magnetic stripe? I'll plead ignorance on the workings of the European debit system as I'm Canadian and we're just getting smart cards now.<p>Does anyone have a better source than the linked article?<p>EDIT: Nevermind, apparently the security was broken a while ago:<p><a href="http://www.cl.cam.ac.uk/research/security/banking/nopin/oakland10chipbroken.pdf" rel="nofollow">http://www.cl.cam.ac.uk/research/security/banking/nopin/oakl...</a>
adortonalmost 15 years ago
Interesting, but how could collected data be retrieved? Could a wireless transmitter be built to fit on this 0.1mm card?
评论 #1510134 未加载